<?xml version="1.0" encoding="UTF-8"?>
<nvd nvd_xml_version="1.2" pub_date="2008-09-05" xmlns="http://nvd.nist.gov/feeds/cve/1.2" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://nvd.nist.gov/feeds/cve/1.2 http://nvd.nist.gov/schema/nvdcve.xsd"><!--This XML file has been upgraded to support CVSS version 2.  The following new attributes have been added to CVS entries:
* CVSS_version - Indicates the version of the CVSS data
* CVSS_base_score - The CVSSv2 base score
* CVSS_impact_subscore - The CVSSv2 impact sub-score
* CVSS_exploit_subscore - the CVSSv2 exploit sub-score

The following attributes have been mapped to new content in CVS entries:
* CVSS_score - This attribute is the same as the CVSS_base_score and is now deprecated.
* CVSS_vector - Contains the new CVSSv2 vector string--><entry CVSS_base_score="6.9" CVSS_exploit_subscore="3.4" CVSS_impact_subscore="10.0" CVSS_score="6.9" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2007-02-07" name="CVE-2005-0001" published="2005-05-02" seq="2005-0001" severity="Medium" type="CVE"><desc><descript source="cve">Race condition in the page fault handler (fault.c) for Linux kernel 2.2.x to 2.2.7, 2.4 to 2.4.29, and 2.6 to 2.6.10, when running on multiprocessor machines, allows local users to execute arbitrary code via concurrent threads that share the same virtual memory space and simultaneously request stack expansion.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><race/></vuln_types><range><local/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110554694522719&amp;w=2">20050112 Linux kernel i386 SMP page fault handler privilege escalation</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-January/030826.html">20050112 Linux kernel i386 SMP page fault handler privilege escalation</ref><ref source="MISC" url="http://isec.pl/vulnerabilities/isec-0022-pagefault.txt">http://isec.pl/vulnerabilities/isec-0022-pagefault.txt</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/index.php?id=a&amp;anuncio=000930">CLA-2005:930</ref><ref source="FEDORA" url="https://bugzilla.fedora.us/show_bug.cgi?id=2336">FLSA:2336</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:022">MDKSA-2005:022</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-043.html">RHSA-2005:043</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-092.html">RHSA-2005:092</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2005/0001/">2005-0001</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110581146702951&amp;w=2">20050114 [USN-60-0] Linux kernel vulnerabilities</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18849">linux-fault-handler-gain-privileges(18849)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1012862">1012862</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13822">13822</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-016.html">RHSA-2005:016</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1070">DSA-1070</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1067">DSA-1067</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1069">DSA-1069</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-017.html">RHSA-2005:017</ref><ref source="BID" url="http://www.securityfocus.com/bid/12244">12244</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20163">20163</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20202">20202</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1082">DSA-1082</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20338">20338</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:022">MDKSA-2005:022</ref></refs><vuln_soft><prod name="Secure Linux" vendor="Trustix"><vers num="2.1"/><vers num="2.2"/></prod><prod name="Desktop" vendor="Red Hat"><vers num="3.0"/><vers num="4.0"/></prod><prod name="Kernel" vendor="Linux"><vers num="2.2.7"/><vers num="2.4.0"/><vers num="2.4.1"/><vers num="2.4.2"/><vers num="2.4.3"/><vers num="2.4.4"/><vers num="2.4.5"/><vers num="2.4.6"/><vers num="2.4.7"/><vers num="2.4.8"/><vers num="2.4.9"/><vers num="2.4.10"/><vers num="2.4.11"/><vers num="2.4.12"/><vers num="2.4.13"/><vers num="2.4.14"/><vers num="2.4.15"/><vers num="2.4.16"/><vers num="2.4.17"/><vers num="2.4.18"/><vers num="2.4.19"/><vers num="2.4.20"/><vers num="2.4.21"/><vers num="2.4.22"/><vers num="2.4.23"/><vers num="2.4.24"/><vers num="2.4.25"/><vers num="2.4.26"/><vers num="2.4.27"/><vers num="2.4.28"/><vers num="2.4.29"/><vers num="2.6.0"/><vers num="2.6.1"/><vers num="2.6.2"/><vers num="2.6.3"/><vers num="2.6.4"/><vers num="2.6.5"/><vers num="2.6.6"/><vers num="2.6.7"/><vers num="2.6.8"/><vers edition="2.6.20" num="2.6.9"/><vers num="2.6.10"/></prod><prod name="Trustix Enterprise Server" vendor="Trustix"><vers num="2"/></prod><prod name="Enterprise Linux" vendor="Red Hat"><vers edition="Advanced Server" num="3.0"/><vers edition="Enterprise Server" num="3.0"/><vers edition="Workstation Server" num="3.0"/><vers edition="Advanced Server" num="4.0"/><vers edition="Enterprise Server" num="4.0"/><vers edition="Workstation" num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0002" published="2005-05-02" seq="2005-0002" severity="High" type="CVE"><desc><descript source="cve">poppassd_pam 1.0 and earlier, when changing a user password, does not verify that the user entered the old password correctly, which allows remote attackers to change passwords for arbitrary users.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200501-22.xml">GLSA-200501-22</ref><ref source="Secunia" url="http://secunia.com/advisories/13865/">Gentoo update for poppassd_pam </ref><ref source="SECTRACK" url="http://securitytracker.com/id?1012840">1012840</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13865">13865</ref></refs><vuln_soft><prod name="poppassd_pam" vendor="Gentoo"><vers num="1.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-11-30" name="CVE-2005-0003" published="2005-04-14" seq="2005-0003" severity="Low" type="CVE"><desc><descript source="cve">The 64 bit ELF support in Linux kernel 2.6 before 2.6.10, on 64-bit architectures, does not properly check for overlapping VMA (virtual memory address) allocations, which allows local users to cause a denial of service (system crash) or execute arbitrary code via a crafted ELF or a.out file.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2005-043.html">Updated kernel packages fix security vulnerabilities</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/12261">bid 12261</ref><ref source="CONFIRM" url="http://linux.bkbits.net:8080/linux-2.4/cset@41c36fb6q1Z68WUzKQFjJR-40Ev3tw">http://linux.bkbits.net:8080/linux-2.4/cset@41c36fb6q1Z68WUzKQFjJR-40Ev3tw</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:022">MDKSA-2005:022</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_18_kernel.html">SUSE-SA:2005:018</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2005/0001/">2005-0001</ref><ref source="MISC" url="http://linux.bkbits.net:8080/linux-2.6/cset@41a6721cce-LoPqkzKXudYby_3TUmg">http://linux.bkbits.net:8080/linux-2.6/cset@41a6721cce-LoPqkzKXudYby_3TUmg</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18886">linux-vma-gain-privileges(18886)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1012885">1012885</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1070">DSA-1070</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1067">DSA-1067</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1069">DSA-1069</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-017.html">RHSA-2005:017</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20163">20163</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20202">20202</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1082">DSA-1082</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20338">20338</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:022">MDKSA-2005:022</ref></refs><vuln_soft><prod name="S8300" vendor="Avaya"><vers num="R2.0.1"/><vers num="R2.0.0"/></prod><prod name="Mandrake Linux" vendor="MandrakeSoft"><vers edition="amd64" num="9.2"/><vers num="9.2"/><vers edition="AMD64" num="10.0"/><vers num="10.0"/><vers edition="x86_64" num="10.1"/><vers num="10.1"/></prod><prod name="Enterprise Linux AS" vendor="Red Hat"><vers edition="Advanced Servers" num="3.0"/></prod><prod name="Intuity" vendor="Avaya"><vers num="LX"/></prod><prod name="S8710" vendor="Avaya"><vers num="R2.0.1"/><vers num="R2.0.0"/></prod><prod name="Enterprise Linux WS" vendor="Red Hat"><vers edition="Workstation" num="3.0"/></prod><prod name="Mandrake Multi Network Firewall" vendor="MandrakeSoft"><vers num="8.2"/></prod><prod name="Desktop" vendor="Red Hat"><vers num="3.0"/></prod><prod name="Mandrake Corporate Server" vendor="MandrakeSoft"><vers edition="x86_64" num="2.1"/><vers num="2.1"/><vers num="3.0"/></prod><prod name="Modular Messaging Message Storage Server" vendor="Avaya"><vers num="1.1"/><vers num="2.0"/></prod><prod name="Converged Communications Server" vendor="Avaya"><vers num="2.0"/></prod><prod name="Kernel" vendor="Linux"><vers num="2.4.0 test9"/><vers num="2.4.0 test8"/><vers num="2.4.0 test7"/><vers num="2.4.0 test6"/><vers num="2.4.0 test5"/><vers num="2.4.0 test4"/><vers num="2.4.0 test3"/><vers num="2.4.0 test2"/><vers num="2.4.0 test12"/><vers num="2.4.0 test11"/><vers num="2.4.0 test10"/><vers num="2.4.0 test1"/><vers num="2.4.0"/><vers num="2.4.1"/><vers num="2.4.2"/><vers num="2.4.3"/><vers num="2.4.4"/><vers num="2.4.5"/><vers num="2.4.6"/><vers num="2.4.7"/><vers num="2.4.8"/><vers num="2.4.9"/><vers num="2.4.10"/><vers num="2.4.11"/><vers num="2.4.12"/><vers num="2.4.13"/><vers num="2.4.14"/><vers num="2.4.15"/><vers num="2.4.16"/><vers num="2.4.17"/><vers num="2.4.18 pre8"/><vers num="2.4.18 pre7"/><vers num="2.4.18 pre6"/><vers num="2.4.18 pre5"/><vers num="2.4.18 pre4"/><vers num="2.4.18 pre3"/><vers num="2.4.18 pre2"/><vers num="2.4.18 pre1"/><vers edition="x86" num="2.4.18"/><vers num="2.4.18"/><vers num="2.4.19 pre6"/><vers num="2.4.19 pre5"/><vers num="2.4.19 pre4"/><vers num="2.4.19 pre3"/><vers num="2.4.19 pre2"/><vers num="2.4.19 pre1"/><vers num="2.4.19"/><vers num="2.4.20"/><vers num="2.4.21 pre7"/><vers num="2.4.21 pre4"/><vers num="2.4.21 pre1"/><vers num="2.4.21"/><vers num="2.4.22"/><vers num="2.4.23 pre9"/><vers num="2.4.23 ow2"/><vers num="2.4.23"/><vers num="2.4.24 ow1"/><vers num="2.4.24"/><vers num="2.4.25"/><vers num="2.4.26"/><vers num="2.4.27 pre5"/><vers num="2.4.27 pre4"/><vers num="2.4.27 pre3"/><vers num="2.4.27 pre2"/><vers num="2.4.27 pre1"/><vers num="2.4.27"/><vers num="2.4.28"/><vers num="2.4.29 rc2"/><vers num="2.4.29 rc1"/></prod><prod name="S8500" vendor="Avaya"><vers num="R2.0.1"/><vers num="R2.0.0"/></prod><prod name="Enterprise Linux ES" vendor="Red Hat"><vers edition="Enterprise Server" num="3.0"/></prod><prod name="Network Routing" vendor="Avaya"><vers num=""/></prod><prod name="S8700 Series" vendor="Avaya"><vers num="R2.0.1"/><vers num="R2.0.0"/></prod><prod name="MN100" vendor="Avaya"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-03-28" name="CVE-2005-0004" published="2005-04-14" seq="2005-0004" severity="Medium" type="CVE"><desc><descript source="cve">The mysqlaccess script in MySQL 4.0.23 and earlier, 4.1.x before 4.1.10, 5.0.x before 5.0.3, and other versions including 3.x, allows local users to overwrite arbitrary files or read temporary files via a symlink attack on temporary files.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2005/dsa-647">mysql -- insecure temporary files</ref><ref adv="1" patch="1" source="Secunia.com" url="http://secunia.com/advisories/13867">MySQL mysqlaccess Script Insecure Temporary File Creation</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/12277">bid 12277</ref><ref source="CONFIRM" url="http://lists.mysql.com/internals/20600">http://lists.mysql.com/internals/20600</ref><ref source="CONFIRM" url="http://mysql.osuosl.org/doc/mysql/en/News-4.1.10.html">http://mysql.osuosl.org/doc/mysql/en/News-4.1.10.html</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000947">CLA-2005:947</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:036">MDKSA-2005:036</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110608297217224&amp;w=2">20050118 [USN-63-1] MySQL client vulnerability</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18922">mysql-mysqlaccess-symlink(18922)</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101864-1">101864</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:036">MDKSA-2005:036</ref></refs><vuln_soft><prod name="Linux" vendor="Gentoo"><vers num=""/></prod><prod name="MySQL" vendor="MySQL"><vers num="4.0.0"/><vers num="4.0.1"/><vers num="4.0.2"/><vers num="4.0.3"/><vers num="4.0.4"/><vers num="4.0.5a"/><vers num="4.0.5"/><vers num="4.0.6"/><vers num="4.0.7 gamma"/><vers num="4.0.7"/><vers num="4.0.8 gamma"/><vers num="4.0.8"/><vers num="4.0.9 gamma"/><vers num="4.0.9"/><vers num="4.0.10"/><vers num="4.0.11 gamma"/><vers num="4.0.11"/><vers num="4.0.12"/><vers num="4.0.13"/><vers num="4.0.14"/><vers num="4.0.15"/><vers num="4.0.18"/><vers num="4.0.20"/><vers num="4.0.21"/><vers num="4.1.0 alpha"/><vers num="4.1.0.0"/><vers num="4.1.2 alpha"/><vers num="4.1.3 beta"/><vers num="4.1.3.0"/><vers num="4.1.4"/><vers num="4.1.5"/></prod><prod name="Linux" vendor="Red Hat"><vers edition="i386" num="7.3"/><vers edition="i386" num="9.0"/></prod><prod name="Fedora" vendor="Red Hat"><vers num="Core 1.0"/></prod><prod name="Debian Linux" vendor="Debian"><vers num="3.0 sparc"/><vers num="3.0 s_390"/><vers num="3.0 ppc"/><vers num="3.0 mipsel"/><vers num="3.0 mips"/><vers num="3.0 m68k"/><vers num="3.0 ia-64"/><vers num="3.0 ia-32"/><vers num="3.0 hppa"/><vers num="3.0 arm"/><vers num="3.0 alpha"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0005" published="2005-05-02" seq="2005-0005" severity="High" type="CVE"><desc><descript source="cve">Heap-based buffer overflow in psd.c for ImageMagick 6.1.0, 6.1.7, and possibly earlier versions allows remote attackers to execute arbitrary code via a .PSD image file with a large number of layers.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=184&amp;type=vulnerabilities">20050117 Multiple Vendor ImageMagick .psd Image File Decode Heap Overflow Vulnerability</ref><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-646">DSA-646</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200501-37.xml">GLSA-200501-37</ref><ref patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-071.html">RHSA-2005:071</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110608222117215&amp;w=2">20050118 [USN-62-1] imagemagick vulnerability</ref><ref patch="1" source="bid" url="http://www.securityfocus.com/bid/12287">12287</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-070.html">RHSA-2005:070</ref></refs><vuln_soft><prod name="Linux" vendor="Gentoo"><vers num="0.5"/><vers num="0.7"/><vers num="1.1a"/><vers num="1.2"/><vers num="1.4 rc3"/><vers num="1.4 rc2"/><vers num="1.4 rc1"/><vers num="1.4"/></prod><prod name="SuSE Linux" vendor="SuSE"><vers edition="i386" num="8.0"/><vers num="8.0"/><vers num="8.1"/><vers num="8.2"/><vers edition="x86_64" num="9.0"/><vers num="9.0"/><vers num="9.1"/><vers num="9.2"/></prod><prod name="GraphicsMagick" vendor="GraphicsMagick"><vers num="1.0"/><vers num="1.0.6"/><vers num="1.1"/><vers num="1.1.3"/><vers num="1.1.4"/></prod><prod name="ProPack" vendor="SGI"><vers num="3.0"/></prod><prod name="Debian Linux" vendor="Debian"><vers num="3.0 sparc"/><vers num="3.0 s_390"/><vers num="3.0 ppc"/><vers num="3.0 mipsel"/><vers num="3.0 mips"/><vers num="3.0 m68k"/><vers num="3.0 ia-64"/><vers num="3.0 ia-32"/><vers num="3.0 hppa"/><vers num="3.0 arm"/><vers num="3.0 alpha"/></prod><prod name="ImageMagick" vendor="ImageMagick"><vers num="5.3.3"/><vers num="5.4.3"/><vers num="5.4.7"/><vers num="6.0"/><vers num="6.0.1"/><vers num="6.0.2.5"/><vers num="6.0.2"/><vers num="6.0.3"/><vers num="6.0.4"/><vers num="6.0.5"/><vers num="6.0.6"/><vers num="6.0.7"/><vers num="6.0.8"/><vers num="6.1"/><vers num="6.1.1.6"/><vers num="6.1.2"/><vers num="6.1.3"/><vers num="6.1.4"/><vers num="6.1.5"/><vers num="6.1.6"/><vers num="6.1.7"/><vers num="6.2.0.7"/><vers num="6.2.0.4"/><vers num="6.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0006" published="2005-05-02" seq="2005-0006" severity="Medium" type="CVE"><desc><descript source="cve">The COPS dissector in Ethereal 0.10.6 through 0.10.8 allows remote attackers to cause a denial of service (infinite loop).</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="CONFIRM" url="http://www.ethereal.com/appnotes/enpa-sa-00017.html">http://www.ethereal.com/appnotes/enpa-sa-00017.html</ref><ref adv="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200501-27.xml">GLSA-200501-27</ref><ref adv="1" source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:013">MDKSA-2005:013</ref><ref adv="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-037.html">RHSA-2005:037</ref><ref adv="1" source="CIAC" url="http://www.ciac.org/ciac/bulletins/p-106.shtml">P-106</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/13946/">13946</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18999">ethereal-cops-dos(18999)</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00003.html">FLSA-2006:152922</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-011.html">RHSA-2005:011</ref><ref source="BID" url="http://www.securityfocus.com/bid/12326">12326</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:013">MDKSA-2005:013</ref></refs><vuln_soft><prod name="Ethereal" vendor="Ethereal Group"><vers num="0.10.6"/><vers num="0.10.7"/><vers num="0.10.8"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0007" published="2005-05-02" seq="2005-0007" severity="Medium" type="CVE"><desc><descript source="cve">Unknown vulnerability in the DLSw dissector in Ethereal 0.10.6 through 0.10.8 allows remote attackers to cause a denial of service (application crash from assertion).</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="CONFIRM" url="http://www.ethereal.com/appnotes/enpa-sa-00017.html">http://www.ethereal.com/appnotes/enpa-sa-00017.html</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200501-27.xml">GLSA-200501-27</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:013">MDKSA-2005:013</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-037.html">RHSA-2005:037</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/p-106.shtml">P-106</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/13946/">13946</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19000">ethereal-dlsw-dos(19000)</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00003.html">FLSA-2006:152922</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-011.html">RHSA-2005:011</ref><ref source="BID" url="http://www.securityfocus.com/bid/12326">12326</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:013">MDKSA-2005:013</ref></refs><vuln_soft><prod name="Ethereal" vendor="Ethereal Group"><vers num="0.10.6"/><vers num="0.10.7"/><vers num="0.10.8"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0008" published="2005-05-02" seq="2005-0008" severity="Medium" type="CVE"><desc><descript source="cve">Unknown vulnerability in the DNP dissector in Ethereal 0.10.5 through 0.10.8 allows remote attackers to cause &quot;memory corruption.&quot;</descript></desc><loss_types><int/></loss_types><range><network/></range><refs><ref patch="1" source="CONFIRM" url="http://www.ethereal.com/appnotes/enpa-sa-00017.html">http://www.ethereal.com/appnotes/enpa-sa-00017.html</ref><ref adv="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200501-27.xml">GLSA-200501-27</ref><ref adv="1" source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:013">MDKSA-2005:013</ref><ref adv="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-037.html">RHSA-2005:037</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/p-106.shtml">P-106</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13946/">13946</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19001">ethereal-dnp-memory-corruption(19001)</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00003.html">FLSA-2006:152922</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-011.html">RHSA-2005:011</ref><ref source="BID" url="http://www.securityfocus.com/bid/12326">12326</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:013">MDKSA-2005:013</ref></refs><vuln_soft><prod name="Ethereal" vendor="Ethereal Group"><vers num="0.10.5"/><vers num="0.10.6"/><vers num="0.10.7"/><vers num="0.10.8"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0009" published="2005-05-02" seq="2005-0009" severity="Medium" type="CVE"><desc><descript source="cve">Unknown vulnerability in the Gnutella dissector in Ethereal 0.10.6 through 0.10.8 allows remote attackers to cause a denial of service (application crash).</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref source="CONFIRM" url="http://www.ethereal.com/appnotes/enpa-sa-00017.html">http://www.ethereal.com/appnotes/enpa-sa-00017.html</ref><ref patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200501-27.xml">GLSA-200501-27</ref><ref adv="1" source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:013">MDKSA-2005:013</ref><ref adv="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-037.html">RHSA-2005:037</ref><ref adv="1" source="CIAC" url="http://www.ciac.org/ciac/bulletins/p-106.shtml">P-106</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/13946/">13946</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19002">ethereal-gnutella-dos(19002)</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00003.html">FLSA-2006:152922</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-011.html">RHSA-2005:011</ref><ref source="BID" url="http://www.securityfocus.com/bid/12326">12326</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:013">MDKSA-2005:013</ref></refs><vuln_soft><prod name="Ethereal" vendor="Ethereal Group"><vers num="0.10.6"/><vers num="0.10.7"/><vers num="0.10.8"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0010" published="2005-05-02" seq="2005-0010" severity="Medium" type="CVE"><desc><descript source="cve">Unknown vulnerability in the MMSE dissector in Ethereal 0.10.4 through 0.10.8 allows remote attackers to cause a denial of service by triggering a free of statically allocated memory.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/><other/></vuln_types><range><network/></range><refs><ref source="CONFIRM" url="http://www.ethereal.com/appnotes/enpa-sa-00017.html">http://www.ethereal.com/appnotes/enpa-sa-00017.html</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200501-27.xml">GLSA-200501-27</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:013">MDKSA-2005:013</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-037.html">RHSA-2005:037</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/p-106.shtml">P-106</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/13946/">13946</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19003">ethereal-mmse-free-memory(19003)</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00003.html">FLSA-2006:152922</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-011.html">RHSA-2005:011</ref><ref source="BID" url="http://www.securityfocus.com/bid/12326">12326</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:013">MDKSA-2005:013</ref></refs><vuln_soft><prod name="Ethereal" vendor="Ethereal Group"><vers num="0.10.4"/><vers num="0.10.5"/><vers num="0.10.6"/><vers num="0.10.7"/><vers num="0.10.8"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0011" published="2005-05-02" seq="2005-0011" severity="High" type="CVE"><desc><descript source="cve">Multiple vulnerabilities in fliccd, when installed setuid root as part of the kdeedu Kstars support for Instrument Neutral Distributed Interface (INDI) in KDE 3.3 to 3.3.2, allow local users and remote attackers to execute arbitrary code via stack-based buffer overflows.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CONFIRM" url="http://www.kde.org/info/security/advisory-20050215-1.txt">http://www.kde.org/info/security/advisory-20050215-1.txt</ref><ref adv="1" source="FEDORA" url="http://www.redhat.com/archives/fedora-announce-list/2005-February/msg00044.html">FEDORA-2005-148</ref><ref adv="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200502-23.xml">GLSA-200502-23</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/14306">14306</ref></refs><vuln_soft><prod name="KDE" vendor="KDE"><vers num="3.3"/><vers num="3.3.1"/><vers num="3.3.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0012" published="2005-05-02" seq="2005-0012" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in the a_Interface_msg function in Dillo before 0.8.3-r4 allows remote attackers to execute arbitrary code via format string specifiers in a web page.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200501-11.xml">GLSA-200501-11</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/12203">12203</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/13760/">13760</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18807">dillo-capi-format-string(18807)</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13764">13764</ref></refs><vuln_soft><prod name="Dillo Web Browser" vendor="Dillo"><vers num="0.2"/><vers num="0.2.1"/><vers num="0.2.2"/><vers num="0.2.3"/><vers num="0.2.4"/><vers num="0.3"/><vers num="0.3.1"/><vers num="0.4"/><vers num="0.5.1"/><vers num="0.6"/><vers num="0.6.1"/><vers num="0.6.2"/><vers num="0.6.3"/><vers num="0.6.4"/><vers num="0.6.5"/><vers num="0.6.6"/><vers num="0.7"/><vers num="0.7.1.2"/><vers num="0.7.1"/><vers num="0.7.2"/><vers num="0.7.3"/><vers num="0.8"/><vers num="0.8.1"/><vers num="0.8.2"/><vers num="0.8.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0013" published="2005-05-02" seq="2005-0013" severity="High" type="CVE"><desc><descript source="cve">nwclient.c in ncpfs before 2.2.6 does not drop root privileges before executing utilities using the NetWare client functions, which allows local users to gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref source="CONFIRM" url="ftp://platan.vc.cvut.cz/pub/linux/ncpfs/Changes-2.2.6">ftp://platan.vc.cvut.cz/pub/linux/ncpfs/Changes-2.2.6</ref><ref patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-665">DSA-665</ref><ref adv="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200501-44.xml">GLSA-200501-44</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:028">MDKSA-2005:028</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-371.html">RHSA-2005:371</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/433927/100/0/threaded">FLSA:152904</ref><ref source="BID" url="http://www.securityfocus.com/bid/12400">12400</ref><ref source="OSVDB" url="http://www.osvdb.org/13297">13297</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013019">1013019</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:028">MDKSA-2005:028</ref></refs><vuln_soft><prod name="ncpfs" vendor="ncpfs"><vers num="2.2.1"/><vers num="2.2.2"/><vers num="2.2.3"/><vers num="2.2.4"/><vers num="2.2.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0014" published="2005-05-02" seq="2005-0014" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in ncplogin in ncpfs before 2.2.6 allows remote malicious NetWare servers to execute arbitrary code on the NetWare client.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref source="CONFIRM" url="ftp://platan.vc.cvut.cz/pub/linux/ncpfs/Changes-2.2.6">ftp://platan.vc.cvut.cz/pub/linux/ncpfs/Changes-2.2.6</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200501-44.xml">GLSA-200501-44</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:028">MDKSA-2005:028</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/433927/100/0/threaded">FLSA:152904</ref><ref source="BID" url="http://www.securityfocus.com/bid/12400">12400</ref><ref source="OSVDB" url="http://www.osvdb.org/13298">13298</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013019">1013019</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:028">MDKSA-2005:028</ref></refs><vuln_soft><prod name="ncpfs" vendor="ncpfs"><vers num="2.2.5" prev="1"/><vers num="2.2.1"/><vers num="2.2.2"/><vers num="2.2.3"/><vers num="2.2.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0015" published="2005-05-02" seq="2005-0015" severity="High" type="CVE"><desc><descript source="cve">diatheke.pl in Sword 1.5.7a allows remote attackers to execute arbitrary commands via shell metacharacters in a URL.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-650">DSA-650</ref><ref source="MISC" url="http://www.securitytracker.com/alerts/2005/Jan/1012955.html">http://www.securitytracker.com/alerts/2005/Jan/1012955.html</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13897">13897</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18997">sword-diatheke-command-execution(18997)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1012955">1012955</ref><ref source="BID" url="http://www.securityfocus.com/bid/12320">12320</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13941">13941</ref></refs><vuln_soft><prod name="SWORD" vendor="CrossWire Bible Society"><vers num="1.5.7a"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0016" published="2005-04-14" seq="2005-0016" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the exported_display function in xatitv in gatos before 0.0.5 allows local users to execute arbitrary code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2005/dsa-640">gatos -- buffer overflow</ref><ref adv="1" patch="1" source="Secunia.com" url="http://secunia.com/advisories/13884/">Debian GATOS xatitv &quot;exported_display()&quot; Buffer Overflow</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/18930">GATOS xatitv buffer overflow</ref></refs><vuln_soft><prod name="gatos" vendor="gatos"><vers num="0.0.5"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0017" published="2005-05-02" seq="2005-0017" severity="Low" type="CVE"><desc><descript source="cve">The f2c translator in the f2c package 3.1 allows local users to read arbitrary files via a symlink attack on temporary files.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-661">DSA-661</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200501-43.xml">GLSA-200501-43</ref><ref source="BID" url="http://www.securityfocus.com/bid/12380">12380</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013028">1013028</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14041">14041</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14052">14052</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14067">14067</ref></refs><vuln_soft><prod name="f2c translator" vendor="f2c Open Source Project"><vers num="3.1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0018" published="2005-05-02" seq="2005-0018" severity="Low" type="CVE"><desc><descript source="cve">The f2 shell script in the f2c package 3.1 allows local users to read arbitrary files via a symlink attack on temporary files.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-661">DSA-661</ref><ref patch="1" source="" url="http://www.securityfocus.com/bid/12380"></ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013028">1013028</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14041">14041</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14052">14052</ref></refs><vuln_soft><prod name="f2c translator" vendor="f2c Open Source Project"><vers num="3.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0019" published="2005-04-27" seq="2005-0019" severity="Medium" type="CVE"><desc><descript source="cve">Unknown vulnerability in hztty 2.0 and earlier allows local users to execute arbitrary commands.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><other/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Debian.org" url="http://www.debian.org/security/2005/dsa-675">hztty -- privilege escalation</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/12518">bid 12518</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/19297">hztty command execution</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013154">1013154</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14236">14236</ref></refs><vuln_soft><prod name="hztty" vendor="Yongguang Zhang"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0020" published="2005-04-14" seq="2005-0020" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in playmidi before 2.4 allows local users to execute arbitrary code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2005/dsa-641">playmidi -- buffer overflow</ref><ref adv="1" patch="1" source="Mandrakesoft.com" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:010">playmidi</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/18933">Playmidi buffer overflow</ref><ref source="BID" url="http://www.securityfocus.com/bid/12274">12274</ref><ref source="OSVDB" url="http://www.osvdb.org/13049">13049</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1012957">1012957</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13828">13828</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13890">13890</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13898">13898</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:010">MDKSA-2005:010</ref></refs><vuln_soft><prod name="Mandrake Corporate Server" vendor="MandrakeSoft"><vers num="3.0"/></prod><prod name="Mandrake Linux" vendor="MandrakeSoft"><vers edition="AMD64" num="10.0"/><vers num="10.0"/><vers edition="x86_64" num="10.1"/><vers num="10.1"/></prod><prod name="Playmidi" vendor="Playmidi"><vers num="2.3.26"/><vers num="2.3.25.1"/><vers num="2.3.25"/><vers num="2.3.24"/><vers num="2.3.23"/><vers num="2.3.22"/><vers num="2.3.21"/><vers num="2.3.20"/><vers num="2.3.19"/><vers num="2.3.18"/><vers num="2.3.17"/><vers num="2.3.16"/><vers num="2.3.15"/><vers num="2.3.14"/><vers num="2.3.13"/><vers num="2.3.12"/><vers num="2.3.11"/><vers num="2.3.10"/><vers num="2.3.9"/><vers num="2.3.8"/><vers num="2.3.7"/><vers num="2.3.6"/><vers num="2.3.5"/><vers num="2.3.4"/><vers num="2.3.3"/><vers num="2.3.2"/><vers num="2.3.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0021" published="2005-05-02" seq="2005-0021" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in Exim before 4.43 may allow attackers to execute arbitrary code via (1) an IPv6 address with more than 8 components, as demonstrated using the -be command line option, which triggers an overflow in the host_aton function, or (2) the -bh command line option or dnsdb PTR lookup, which triggers an overflow in the dns_build_reverse function.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=179&amp;type=vulnerabilities">20050107 Exim host_aton() Buffer Overflow Vulnerability</ref><ref adv="1" source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=183&amp;type=vulnerabilities">20050114 Exim dns_buld_reverse() Buffer Overflow Vulnerability</ref><ref source="MLIST" url="http://www.exim.org/mail-archives/exim-users/Week-of-Mon-20050103/msg00028.html">[exim] 20050104 2 smallish security issues</ref><ref source="CONFIRM" url="http://ftp6.us.freebsd.org/pub/mail/exim/ChangeLogs/ChangeLog-4.44">http://ftp6.us.freebsd.org/pub/mail/exim/ChangeLogs/ChangeLog-4.44</ref><ref adv="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-635">DSA-635</ref><ref adv="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-637">DSA-637</ref><ref adv="1" source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200501-23.xml">GLSA-200501-23</ref><ref patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-025.html">RHSA-2005:025</ref><ref patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/132992">VU#132992</ref></refs><vuln_soft><prod name="Exim" vendor="University of Cambridge"><vers num="4.42"/><vers num="4.41"/><vers num="4.40" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0022" published="2005-05-02" seq="2005-0022" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in the spa_base64_to_bits function in Exim before 4.43, as originally obtained from Samba code, and as called by the auth_spa_client function, may allow attackers to execute arbitrary code during SPA authentication.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=178&amp;type=vulnerabilities">20050107 Exim auth_spa_server() Buffer Overflow Vulnerability</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110824870908614&amp;w=2">20050212 exim auth_spa_server() PoC exploit</ref><ref patch="1" source="MLIST" url="http://www.exim.org/mail-archives/exim-users/Week-of-Mon-20050103/msg00028.html">[exim] 20050104 2 smallish security issues</ref><ref source="CONFIRM" url="http://ftp6.us.freebsd.org/pub/mail/exim/ChangeLogs/ChangeLog-4.44">http://ftp6.us.freebsd.org/pub/mail/exim/ChangeLogs/ChangeLog-4.44</ref><ref adv="1" source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200501-23.xml">GLSA-200501-23</ref><ref patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-025.html">RHSA-2005:025</ref><ref source="BID" url="http://www.securityfocus.com/bid/12188">12188</ref></refs><vuln_soft><prod name="Exim" vendor="University of Cambridge"><vers num="4.42"/><vers num="4.41"/><vers num="4.40" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0023" published="2005-10-05" seq="2005-0023" severity="Low" type="CVE"><desc><descript source="cve">gnome-pty-helper in GNOME libzvt2 and libvte4 allows local users to spoof the logon hostname via a modified DISPLAY environment variable. NOTE: the severity of this issue has been disputed.</descript></desc><loss_types><int/></loss_types><vuln_types><input/><env/></vuln_types><range><local/></range><refs><ref source="" url="http://bugzilla.gnome.org/show_bug.cgi?id=317312"></ref><ref source="" url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=330907"></ref><ref source="BID" url="http://www.securityfocus.com/bid/15004">15004</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/1931">ADV-2005-1931</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/17023">17023</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/22496">libzvt-gnomeptyhelper-spoof(22496)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112879572407250&amp;w=2">20051007 gnome-pty-helper writes arbitrary utmp records</ref></refs><vuln_soft><prod name="libzvt2" vendor="GNOME"><vers num="1.4.2.19"/></prod><prod name="libvte4" vendor="GNOME"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0033" published="2005-05-02" seq="2005-0033" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in the code for recursion and glue fetching in BIND 8.4.4 and 8.4.5 allows remote attackers to cause a denial of service (crash) via queries that trigger the overflow in the q_usedns array that tracks nameservers and addresses.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref patch="1" source="MISC" url="http://www.uniras.gov.uk/niscc/docs/al-20050125-00059.html">http://www.uniras.gov.uk/niscc/docs/al-20050125-00059.html</ref><ref patch="1" source="CONFIRM" url="http://www.isc.org/index.pl?/sw/bind/bind-security.php">http://www.isc.org/index.pl?/sw/bind/bind-security.php</ref><ref patch="1" source="CONFIRM" url="http://www.isc.org/index.pl?/sw/bind/bind8.php">http://www.isc.org/index.pl?/sw/bind/bind8.php</ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/327633">VU#327633</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19063">bind-qusedns-bo(19063)</ref><ref source="BID" url="http://www.securityfocus.com/bid/12364">12364</ref><ref source="SCO" url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2006.1/SCOSA-2006.1.txt">SCOSA-2006.1</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14009">14009</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18291">18291</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1012996">1012996</ref></refs><vuln_soft><prod name="BIND" vendor="ISC"><vers num="8.4.4"/><vers num="8.4.5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0034" published="2005-05-02" seq="2005-0034" severity="Medium" type="CVE"><desc><descript source="cve">An &quot;incorrect assumption&quot; in the authvalidated validator function in BIND 9.3.0, when DNSSEC is enabled, allows remote attackers to cause a denial of service (named server exit) via crafted DNS packets that cause an internal consistency test (self-check) to fail.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref patch="1" source="MISC" url="http://www.uniras.gov.uk/niscc/docs/al-20050125-00060.html">http://www.uniras.gov.uk/niscc/docs/al-20050125-00060.html</ref><ref patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/938617">VU#938617</ref><ref patch="1" source="CONFIRM" url="http://www.isc.org/index.pl?/sw/bind/bind-security.php">http://www.isc.org/index.pl?/sw/bind/bind-security.php</ref><ref source="CONFIRM" url="http://www.isc.org/index.pl?/sw/bind/bind9.php">http://www.isc.org/index.pl?/sw/bind/bind9.php</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2005/0003/">2005-0003</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19062">bind-named-dns-dos(19062)</ref><ref source="BID" url="http://www.securityfocus.com/bid/12365">12365</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1012995">1012995</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14008">14008</ref></refs><vuln_soft><prod name="BIND" vendor="ISC"><vers num="9.3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0035" published="2005-05-02" seq="2005-0035" severity="Medium" type="CVE"><desc><descript source="cve">The Acrobat web control in Adobe Acrobat and Acrobat Reader 7.0 and earlier, when used with Internet Explorer, allows remote attackers to determine the existence of arbitrary files via the LoadFile ActiveX method.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><env/></vuln_types><range><network/><user_init/></range><refs><ref source="CONFIRM" url="http://www.adobe.com/support/techdocs/331465.html">http://www.adobe.com/support/techdocs/331465.html</ref><ref source="MISC" url="http://www.niscc.gov.uk/niscc/docs/re-20050401-00264.pdf">http://www.niscc.gov.uk/niscc/docs/re-20050401-00264.pdf</ref><ref source="MISC" url="http://www.frsirt.com/english/advisories/2005/0310">http://www.frsirt.com/english/advisories/2005/0310</ref><ref source="MISC" url="http://www.hyperdose.com/advisories/H2005-06.txt">http://www.hyperdose.com/advisories/H2005-06.txt</ref><ref source="BID" url="http://www.securityfocus.com/bid/12989">12989</ref><ref source="OSVDB" url="http://www.osvdb.org/15242">15242</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14813">14813</ref></refs><vuln_soft><prod name="Acrobat Reader" vendor="Adobe"><vers num="7.0"/><vers num="6.0.3"/><vers num="6.0.2"/><vers num="6.0.1"/><vers num="6.0"/><vers num="5.1"/><vers num="5.0.5"/><vers num="5.0"/><vers num="4.5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-28" name="CVE-2005-0036" published="2005-12-31" seq="2005-0036" severity="Medium" type="CVE"><desc><descript source="cve">The DNS implementation in DeleGate 8.10.2 and earlier allows remote attackers to cause a denial of service via a compressed DNS packet with a label length byte with an incorrect offset, which could trigger an infinite loop.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="NISCC" url="http://www.niscc.gov.uk/niscc/docs/re-20050524-00432.pdf?lang=en">NISCC Vulnerability Advisory 589088</ref><ref patch="1" source="NISCC" url="http://www.niscc.gov.uk/niscc/docs/al-20050524-00433.html">Id: 20050524-00433</ref><ref source="BID" url="http://www.securityfocus.com/bid/13729">13729</ref><ref source="OSVDB" url="http://www.osvdb.org/25291">25291</ref></refs><vuln_soft><prod name="DeleGate" vendor="DeleGate"><vers num="8.10.2" prev="1"/><vers num="8.10.1"/><vers num="8.10"/><vers num="8.9.6"/><vers num="8.9.5"/><vers num="8.9.4"/><vers num="8.9.3"/><vers num="8.9.2"/><vers num="8.9.1"/><vers num="8.9"/><vers num="8.5.0"/><vers num="8.4.0"/><vers num="8.3.4"/><vers num="8.3.3"/><vers num="7.9.11"/><vers num="7.8.2"/><vers num="7.8.1"/><vers num="7.8.0"/><vers num="7.7.1"/><vers num="7.7.0"/><vers num="5.9.3"/></prod><prod name="Delegate" vendor="ETL"><vers num="6.0"/><vers num="5.9"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-28" name="CVE-2005-0037" published="2005-12-31" seq="2005-0037" severity="Medium" type="CVE"><desc><descript source="cve">The DNS implementation of DNRD before 2.10 allows remote attackers to cause a denial of service via a compressed DNS packet with a label length byte with an incorrect offset, which could trigger an infinite loop.</descript></desc><sols><sol source="nvd">This vulnerability is addressed in the following product release:
dnrd, dnrd, 2.10 </sol></sols><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref patch="1" source="NISCC" url="http://www.niscc.gov.uk/niscc/docs/al-20050524-00433.html">Id: 20050524-00433</ref><ref source="" url="http://www.niscc.gov.uk/niscc/docs/re-20050524-00432.pdf?lang=en"></ref><ref source="BID" url="http://www.securityfocus.com/bid/13729">13729</ref><ref source="OSVDB" url="http://www.osvdb.org/25291">25291</ref></refs><vuln_soft><prod name="dnrd" vendor="dnrd"><vers num="2.9"/><vers num="2.8"/><vers num="2.7"/><vers num="2.6"/><vers num="2.5"/><vers num="2.4"/><vers num="2.3"/><vers num="2.2"/><vers num="2.1"/><vers num="2.0"/><vers num="1.4"/><vers num="1.3"/><vers num="1.2"/><vers num="1.1"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-28" name="CVE-2005-0038" published="2005-12-31" seq="2005-0038" severity="Medium" type="CVE"><desc><descript source="cve">The DNS implementation of PowerDNS 2.9.16 and earlier allows remote attackers to cause a denial of service via a compressed DNS packet with a label length byte with an incorrect offset, which could trigger an infinite loop.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="NISCC" url="http://www.niscc.gov.uk/niscc/docs/al-20050524-00433.html">Id: 20050524-00433</ref><ref source="" url="http://www.niscc.gov.uk/niscc/docs/re-20050524-00432.pdf?lang=en"></ref><ref source="BID" url="http://www.securityfocus.com/bid/13729">13729</ref><ref source="OSVDB" url="http://www.osvdb.org/25291">25291</ref></refs><vuln_soft><prod name="PowerDNS" vendor="PowerDNS"><vers num="2.9.16" prev="1"/><vers num="2.9.15"/><vers num="2.9.14"/><vers num="2.9.13"/><vers num="2.9.12"/><vers num="2.9.11"/><vers num="2.9.10"/><vers num="2.9.8"/><vers num="2.9.7"/><vers num="2.9.6"/><vers num="2.9.5"/><vers num="2.9.4"/><vers num="2.9.3a"/><vers num="2.9.2"/><vers num="2.9.1"/><vers num="2.9.0"/><vers num="2.8"/><vers num="2.0 RC1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0039" published="2005-05-10" seq="2005-0039" severity="Medium" type="CVE"><desc><descript source="cve">Certain configurations of IPsec, when using Encapsulating Security Payload (ESP) in tunnel mode, integrity protection at a higher layer, or Authentication Header (AH), allow remote attackers to decrypt IPSec communications by modifying the outer packet in ways that cause plaintext data from the inner packet to be returned in ICMP messages, as demonstrated using bit-flipping attacks and (1) Destination Address Rewriting, (2) a modified header length that causes portions of the packet to be interpreted as IP Options, or (3) a modified protocol field and source address.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref source="MISC" url="http://www.niscc.gov.uk/niscc/docs/al-20050509-00386.html?lang=en">http://www.niscc.gov.uk/niscc/docs/al-20050509-00386.html?lang=en</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/407774">HPSBTU01217</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/302220">VU#302220</ref><ref source="BID" url="http://www.securityfocus.com/bid/13562">13562</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/0507">ADV-2005-0507</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/2806">ADV-2005-2806</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015320">1015320</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17938">17938</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111566201610350&amp;w=2">20050509 NISCC Vulnerability Advisory IPSEC - 004033</ref></refs><vuln_soft><prod name="IPsec" vendor="NISSC"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0040" published="2005-05-19" seq="2005-0040" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in DotNetNuke before 3.0.12 allow remote attackers to inject arbitrary web script or HTML via the (1) register a new user page, (2) User-Agent, or (3) Username, which is not properly quoted before sending to the error log.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111627180518591&amp;w=2">20050516 DotNetNuke (Multiple XSS)</ref><ref adv="1" source="MISC" url="http://www.woany.co.uk/advisories/dotnetnukexss.txt">http://www.woany.co.uk/advisories/dotnetnukexss.txt</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15397">15397</ref><ref source="BID" url="http://www.securityfocus.com/bid/13644">13644</ref><ref source="BID" url="http://www.securityfocus.com/bid/13646">13646</ref><ref source="BID" url="http://www.securityfocus.com/bid/13647">13647</ref></refs><vuln_soft><prod name="DotNetNuke" vendor="DotNetNuke"><vers num="3.0.11" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0043" published="2005-05-02" seq="2005-0043" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Apple iTunes 4.7 allows remote attackers to execute arbitrary code via a long URL in (1) .m3u or (2) .pls playlist files.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref patch="1" source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=180&amp;type=vulnerabilities">20050113 Apple iTunes Playlist Parsing Buffer Overflow Vulnerability</ref><ref patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/Jan/msg00000.html">APPLE-SA-2005-01-11</ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/377368">VU#377368</ref><ref source="BID" url="http://www.securityfocus.com/bid/12238">12238</ref><ref source="OSVDB" url="http://www.osvdb.org/12833">12833</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1012839">1012839</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13804">13804</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18851">itunes-m3u-pls-bo(18851)</ref></refs><vuln_soft><prod name="iTunes" vendor="Apple"><vers num="4.7"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-01" name="CVE-2005-0044" published="2005-05-02" seq="2005-0044" severity="High" type="CVE"><desc><descript source="cve">The OLE component in Windows 98, 2000, XP, and Server 2003, and Exchange Server 5.0 through 2003, does not properly validate the lengths of messages for certain OLE data, which allows remote attackers to execute arbitrary code, aka the &quot;Input Validation Vulnerability.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms05-012.mspx">MS05-012</ref><ref patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/927889">VU#927889</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1180.html">OVAL1180</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval2917.html">OVAL2917</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval3568.html">OVAL3568</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval4499.html">OVAL4499</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19109">win-ole-code-execution(19109)</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA05-039A.html">TA05-039A</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1180">oval:org.mitre.oval:def:1180</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2917">oval:org.mitre.oval:def:2917</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3568">oval:org.mitre.oval:def:3568</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4499">oval:org.mitre.oval:def:4499</ref></refs><vuln_soft><prod name="Windows 98" vendor="Microsoft"><vers num="Gold"/><vers num="SE"/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers edition="64-bit" num="R2"/><vers edition="Datacenter 64-bit" num="R2"/><vers edition="64-bit" num="Enterprise"/><vers num="Enterprise 64-bit"/><vers edition="64-bit" num="Standard"/><vers num="Web"/></prod><prod name="Windows XP" vendor="Microsoft"><vers edition="SP1" num="64-bit"/><vers num="64-bit"/><vers num="64-bit Version 2003"/><vers edition="SP2" num="Home"/><vers edition="SP1" num="Home"/><vers num="Home"/><vers edition="Gold" num="Professional"/><vers edition="Gold" num="Professional"/><vers edition="Gold" num="Professional"/><vers edition="SP2" num="Media Center"/><vers edition="SP1" num="Media Center"/><vers num="Media Center"/><vers edition="SP2" num="Tablet PC"/><vers edition="SP2" num="Tablet PC"/><vers edition="SP2" num="Tablet PC"/></prod><prod name="exchange srv" vendor="Microsoft"><vers num="5.0"/></prod><prod name="Windows ME" vendor="Microsoft"><vers num=""/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num="Advanced Server SP4"/><vers num="Advanced Server SP3"/><vers num="Advanced Server SP2"/><vers num="Advanced Server SP1"/><vers num="Advanced Server"/><vers num="Datacenter Server SP4"/><vers num="Datacenter Server SP3"/><vers num="Datacenter Server SP2"/><vers num="Datacenter Server SP1"/><vers num="Datacenter Server"/><vers num="Professional SP4"/><vers num="Professional SP3"/><vers num="Professional SP2"/><vers num="Professional SP1"/><vers num="Professional"/><vers num="Server SP4"/><vers num="Server SP3"/><vers num="Server SP2"/><vers num="Server SP1"/><vers num="Server"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0045" published="2005-05-02" seq="2005-0045" severity="High" type="CVE"><desc><descript source="cve">The Server Message Block (SMB) implementation for Windows NT 4.0, 2000, XP, and Server 2003 does not properly validate certain SMB packets, which allows remote attackers to execute arbitrary code via Transaction responses containing (1) Trans or (2) Trans2 commands, aka the &quot;Server Message Block Vulnerability,&quot; and as demonstrated using Trans2 FIND_FIRST2 responses with large file name length fields.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110792638401852&amp;w=2">20050209 EEYE: Windows SMB Client Transaction Response Handling Vulnerability</ref><ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=110795643831169&amp;w=2">20050209 EEYE: Windows SMB Client Transaction Response Handling Vulnerability</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111040962600205&amp;w=2">20050309 Update: MS05-011 EEYE: Windows SMB Client Transaction Response Handling Vulnerability</ref><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms05-011.mspx">MS05-011</ref><ref adv="1" patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA05-039A.html">TA05-039A</ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/652537">VU#652537</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1606.html">OVAL1606</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1847.html">OVAL1847</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1889.html">OVAL1889</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval4043.html">OVAL4043</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19089">win-smb-code-execution(19089)</ref><ref source="BID" url="http://www.securityfocus.com/bid/12484">12484</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1606">oval:org.mitre.oval:def:1606</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1847">oval:org.mitre.oval:def:1847</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1889">oval:org.mitre.oval:def:1889</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4043">oval:org.mitre.oval:def:4043</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num="Enterprise Server 4.0 SP6a"/><vers num="Enterprise Server 4.0 SP5"/><vers num="Enterprise Server 4.0 SP4"/><vers num="Enterprise Server 4.0 SP3"/><vers num="Enterprise Server 4.0 SP2"/><vers num="Enterprise Server 4.0 SP1"/><vers num="Enterprise Server 4.0"/><vers num="Server 4.0 SP6a"/><vers num="Server 4.0 SP5"/><vers num="Server 4.0 SP4"/><vers num="Server 4.0 SP3"/><vers num="Server 4.0 SP2"/><vers num="Server 4.0 SP1"/><vers num="Server 4.0"/><vers num="Terminal Server 4.0 SP6a"/><vers num="Terminal Server 4.0 SP5"/><vers num="Terminal Server 4.0 SP4"/><vers num="Terminal Server 4.0 SP3"/><vers num="Terminal Server 4.0 SP2"/><vers num="Terminal Server 4.0 SP1"/><vers num="Terminal Server 4.0"/><vers num="Workstation 4.0 SP6a"/><vers num="Workstation 4.0 SP5"/><vers num="Workstation 4.0 SP4"/><vers num="Workstation 4.0 SP3"/><vers num="Workstation 4.0 SP2"/><vers num="Workstation 4.0 SP1"/><vers num="Workstation 4.0"/></prod><prod name="Windows XP" vendor="Microsoft"><vers edition="SP1" num="64-bit"/><vers num="64-bit"/><vers edition="SP1" num="64-bit Version 2003"/><vers num="64-bit Version 2003"/><vers edition="SP2" num="Home"/><vers edition="SP1" num="Home"/><vers num="Home"/><vers edition="Gold" num="Professional"/><vers edition="Gold" num="Professional"/><vers edition="Gold" num="Professional"/><vers edition="SP2" num="Media Center"/><vers edition="SP1" num="Media Center"/><vers num="Media Center"/><vers edition="SP2" num="Tablet PC"/><vers edition="SP2" num="Tablet PC"/><vers edition="SP2" num="Tablet PC"/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers edition="64-bit" num="R2"/><vers edition="Datacenter 64-bit" num="R2"/><vers edition="64-bit" num="Enterprise"/><vers num="Enterprise 64-bit"/><vers edition="64-bit" num="Standard"/><vers num="Web"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num="Advanced Server SP4"/><vers num="Advanced Server SP3"/><vers num="Advanced Server SP2"/><vers num="Advanced Server SP1"/><vers num="Advanced Server"/><vers num="Professional SP4"/><vers num="Professional SP3"/><vers num="Professional SP2"/><vers num="Professional SP1"/><vers num="Professional"/><vers num="Server SP4"/><vers num="Server SP3"/><vers num="Server SP2"/><vers num="Server SP1"/><vers num="Server"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0047" published="2005-05-02" seq="2005-0047" severity="High" type="CVE"><desc><descript source="cve">Windows 2000, XP, and Server 2003 does not properly &quot;validate the use of memory regions&quot; for COM structured storage files, which allows attackers to execute arbitrary code, aka the &quot;COM Structured Storage Vulnerability.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/><design/></vuln_types><range><local/></range><refs><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms05-012.mspx">MS05-012</ref><ref patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA05-039A.html">TA05-039A</ref><ref patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/597889">VU#597889</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1159.html">OVAL1159</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval2351.html">OVAL2351</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval2892.html">OVAL2892</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval901.html">OVAL901</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19105">win-com-gain-privileges(19105)</ref><ref source="MISC" url="http://www.argeniss.com/research/SSExploit.c">http://www.argeniss.com/research/SSExploit.c</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111755870828817&amp;w=2">20050530 [Argeniss] MS05-012 Exploit</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1159">oval:org.mitre.oval:def:1159</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2351">oval:org.mitre.oval:def:2351</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2892">oval:org.mitre.oval:def:2892</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:901">oval:org.mitre.oval:def:901</ref></refs><vuln_soft><prod name="Windows XP" vendor="Microsoft"><vers edition="SP1" num="64-bit"/><vers num="64-bit"/><vers num="64-bit Version 2003"/><vers edition="SP2" num="Home"/><vers edition="SP1" num="Home"/><vers num="Home"/><vers edition="Gold" num="Professional"/><vers edition="Gold" num="Professional"/><vers edition="Gold" num="Professional"/><vers edition="SP2" num="Media Center"/><vers edition="SP1" num="Media Center"/><vers num="Media Center"/><vers edition="SP2" num="Tablet PC"/><vers edition="SP2" num="Tablet PC"/><vers edition="SP2" num="Tablet PC"/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers edition="64-bit" num="R2"/><vers edition="Datacenter 64-bit" num="R2"/><vers edition="64-bit" num="Enterprise"/><vers num="Enterprise 64-bit"/><vers edition="64-bit" num="Standard"/><vers num="Web"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num="Advanced Server SP4"/><vers num="Advanced Server SP3"/><vers num="Advanced Server SP2"/><vers num="Advanced Server SP1"/><vers num="Advanced Server"/><vers num="Datacenter Server SP4"/><vers num="Datacenter Server SP3"/><vers num="Datacenter Server SP2"/><vers num="Datacenter Server SP1"/><vers num="Datacenter Server"/><vers num="Professional SP4"/><vers num="Professional SP3"/><vers num="Professional SP2"/><vers num="Professional SP1"/><vers num="Professional"/><vers num="Server SP4"/><vers num="Server SP3"/><vers num="Server SP2"/><vers num="Server SP1"/><vers num="Server"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0048" published="2005-05-02" seq="2005-0048" severity="High" type="CVE"><desc><descript source="cve">Microsoft Windows XP SP2 and earlier, 2000 SP3 and SP4, Server 2003, and older operating systems allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted IP packets with malformed options, aka the &quot;IP Validation Vulnerability.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms05-019.mspx">MS05-019</ref><ref adv="1" source="ISS" url="http://xforce.iss.net/xforce/alerts/id/192">20050412 Windows IP Options Remote Compromise</ref><ref patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA05-102A.html">TA05-102A</ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/233754">VU#233754</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval3824.html">OVAL3824</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1744.html">OVAL1744</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval4549.html">OVAL4549</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3824">oval:org.mitre.oval:def:3824</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1744">oval:org.mitre.oval:def:1744</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4549">oval:org.mitre.oval:def:4549</ref></refs><vuln_soft><prod name="Windows XP" vendor="Microsoft"><vers edition="SP1" num="64-bit"/><vers num="64-bit"/><vers edition="SP1" num="64-bit Version 2003"/><vers num="64-bit Version 2003"/><vers edition="SP1" num="Embedded"/><vers num="Embedded"/><vers edition="SP1" num="Home"/><vers num="Home"/><vers edition="Gold" num="Professional"/><vers edition="Gold" num="Professional"/><vers edition="SP1" num="Media Center"/><vers num="Media Center"/><vers edition="SP2" num="Tablet PC"/><vers edition="SP2" num="Tablet PC"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num="Advanced Server SP4"/><vers num="Advanced Server SP3"/><vers num="Advanced Server SP2"/><vers num="Advanced Server SP1"/><vers num="Advanced Server"/><vers num="Datacenter Server SP4"/><vers num="Datacenter Server SP3"/><vers num="Datacenter Server SP2"/><vers num="Datacenter Server SP1"/><vers num="Datacenter Server"/><vers num="Professional SP4"/><vers num="Professional SP3"/><vers num="Professional SP2"/><vers num="Professional SP1"/><vers num="Professional"/><vers num="Server SP4"/><vers num="Server SP3"/><vers num="Server SP2"/><vers num="Server SP1"/><vers num="Server"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0049" published="2005-05-02" seq="2005-0049" severity="Medium" type="CVE"><desc><descript source="cve">Windows SharePoint Services and SharePoint Team Services for Windows Server 2003 does not properly validate an HTTP redirection query, which allows remote attackers to inject arbitrary HTML and web script via a cross-site scripting (XSS) attack, or to spoof the web cache.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms05-006.mspx">MS05-006</ref><ref patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA05-039A.html">TA05-039A</ref><ref patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/340409">VU#340409</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19091">win-sharepoint-services-xss(19091)</ref></refs><vuln_soft><prod name="Windows SharePoint Services" vendor="Microsoft"><vers num="Windows Server 2003 SP1"/><vers num="Windows Server 2003"/></prod><prod name="SharePoint Team Services" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0050" published="2005-05-02" seq="2005-0050" severity="High" type="CVE"><desc><descript source="cve">The License Logging service for Windows NT Server, Windows 2000 Server, and Windows Server 2003 does not properly validate the length of messages, which leads to an &quot;unchecked buffer&quot; and allows remote attackers to cause a denial of service (crash) and possibly execute arbtirary code, aka the &quot;License Logging Service Vulnerability.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms05-010.mspx">MS05-010</ref><ref patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA05-039A.html">TA05-039A</ref><ref patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/130433">VU#130433</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval2568.html">OVAL2568</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval3582.html">OVAL3582</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval4786.html">OVAL4786</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval644.html">OVAL644</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19101">win-license-code-execution(19101)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2568">oval:org.mitre.oval:def:2568</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3582">oval:org.mitre.oval:def:3582</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4786">oval:org.mitre.oval:def:4786</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:644">oval:org.mitre.oval:def:644</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num="Enterprise Server 4.0 SP6a"/><vers num="Enterprise Server 4.0 SP6"/><vers num="Enterprise Server 4.0 SP5"/><vers num="Enterprise Server 4.0 SP4"/><vers num="Enterprise Server 4.0 SP3"/><vers num="Enterprise Server 4.0 SP2"/><vers num="Enterprise Server 4.0 SP1"/><vers num="Enterprise Server 4.0"/><vers num="Server 4.0 SP6a"/><vers num="Server 4.0 SP6"/><vers num="Server 4.0 SP5"/><vers num="Server 4.0 SP4"/><vers num="Server 4.0 SP3"/><vers num="Server 4.0 SP2"/><vers num="Server 4.0 SP1"/><vers num="Server 4.0"/><vers num="Terminal Server 4.0 SP6a"/><vers num="Terminal Server 4.0 SP6"/><vers num="Terminal Server 4.0 SP5"/><vers num="Terminal Server 4.0 SP4"/><vers num="Terminal Server 4.0 SP3"/><vers num="Terminal Server 4.0 SP2"/><vers num="Terminal Server 4.0 SP1"/><vers num="Terminal Server 4.0"/></prod><prod name="Small Business Server" vendor="Microsoft"><vers num="2000"/><vers num="2003"/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers edition="64-bit" num="R2"/><vers edition="Datacenter 64-bit" num="R2"/><vers edition="64-bit" num="Enterprise"/><vers num="Enterprise 64-bit"/><vers edition="64-bit" num="Standard"/><vers num="Web"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num="Advanced Server SP4"/><vers num="Advanced Server SP3"/><vers num="Advanced Server SP2"/><vers num="Advanced Server SP1"/><vers num="Advanced Server"/><vers num="Datacenter Server SP4"/><vers num="Datacenter Server SP3"/><vers num="Datacenter Server SP2"/><vers num="Datacenter Server SP1"/><vers num="Datacenter Server"/><vers num="Server SP4"/><vers num="Server SP3"/><vers num="Server SP2"/><vers num="Server SP1"/><vers num="Server"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0051" published="2005-05-02" seq="2005-0051" severity="High" type="CVE"><desc><descript source="cve">The Server service (srvsvc.dll) in Windows XP SP1 and SP2 allows remote attackers to obtain sensitive information (users who are accessing resources) via an anonymous logon using a named pipe, which is not properly authenticated, aka the &quot;Named Pipe Vulnerability.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms05-007.mspx">MS05-007</ref><ref adv="1" patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA05-039A.html">TA05-039A</ref><ref patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/939074">VU#939074</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval2292.html">OVAL2292</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval3055.html">OVAL3055</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19093">win-named-pipe-information-disclosure (19093)</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14189">14189</ref><ref source="BID" url="http://www.securityfocus.com/bid/12486">12486</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013112">1013112</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2292">oval:org.mitre.oval:def:2292</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3055">oval:org.mitre.oval:def:3055</ref></refs><vuln_soft><prod name="Windows XP" vendor="Microsoft"><vers edition="Tablet PC" num="SP1"/><vers edition="Tablet PC" num="SP2"/><vers edition="SP1" num="64-bit"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0053" published="2005-05-02" seq="2005-0053" severity="High" type="CVE"><desc><descript source="cve">Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via drag and drop events, aka the &quot;Drag-and-Drop Vulnerability.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms05-014.mspx">MS05-014</ref><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms05-008.mspx">MS05-008</ref><ref patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA05-039A.html">TA05-039A</ref><ref patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/698835">VU#698835</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1334.html">OVAL1334</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval2046.html">OVAL2046</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval2953.html">OVAL2953</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval3006.html">OVAL3006</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval4726.html">OVAL4726</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval4864.html">OVAL4864</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19117">ie-dragdrop-gain-privileges(19117)</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/11466">11466</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1015.html">OVAL1015</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1334">oval:org.mitre.oval:def:1334</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2046">oval:org.mitre.oval:def:2046</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2953">oval:org.mitre.oval:def:2953</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3006">oval:org.mitre.oval:def:3006</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4726">oval:org.mitre.oval:def:4726</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4864">oval:org.mitre.oval:def:4864</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1015">oval:org.mitre.oval:def:1015</ref></refs><vuln_soft><prod name="Windows 98" vendor="Microsoft"><vers num="Gold"/><vers num="SE"/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers edition="64-bit" num="R2"/><vers edition="Datacenter 64-bit" num="R2"/><vers edition="64-bit" num="Enterprise"/><vers num="Enterprise 64-bit"/><vers edition="64-bit" num="Standard"/><vers num="Web"/></prod><prod name="Windows XP" vendor="Microsoft"><vers edition="SP1" num="64-bit"/><vers num="64-bit"/><vers num="64-bit Version 2003"/><vers edition="SP2" num="Home"/><vers edition="SP1" num="Home"/><vers num="Home"/><vers edition="Gold" num="Professional"/><vers edition="Gold" num="Professional"/><vers edition="Gold" num="Professional"/><vers edition="SP2" num="Media Center"/><vers edition="SP1" num="Media Center"/><vers num="Media Center"/><vers edition="SP2" num="Tablet PC"/><vers edition="SP2" num="Tablet PC"/><vers edition="SP2" num="Tablet PC"/></prod><prod name="Internet Explorer" vendor="Microsoft"><vers num="5.0.1 SP4"/><vers num="5.0.1 SP3"/><vers num="5.0.1 SP2"/><vers num="5.0.1 SP1"/><vers num="5.0.1"/><vers num="5.5 SP2"/><vers num="5.5 SP1"/><vers num="5.5"/><vers num="6.0 SP2"/><vers num="6.0 SP1"/><vers num="6.0"/></prod><prod name="Windows ME" vendor="Microsoft"><vers num=""/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num="Advanced Server SP4"/><vers num="Advanced Server SP3"/><vers num="Advanced Server SP2"/><vers num="Advanced Server SP1"/><vers num="Advanced Server"/><vers num="Datacenter Server SP4"/><vers num="Datacenter Server SP3"/><vers num="Datacenter Server SP2"/><vers num="Datacenter Server SP1"/><vers num="Datacenter Server"/><vers num="Professional SP4"/><vers num="Professional SP3"/><vers num="Professional SP2"/><vers num="Professional SP1"/><vers num="Professional"/><vers num="Server SP4"/><vers num="Server SP3"/><vers num="Server SP2"/><vers num="Server SP1"/><vers num="Server"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0054" published="2005-05-02" seq="2005-0054" severity="Medium" type="CVE"><desc><descript source="cve">Internet Explorer 5.01, 5.5, and 6 allows remote attackers to spoof a less restrictive security zone and execute arbitrary code via an HTML page containing URLs that contain hostnames that have been double hex encoded, which are decoded twice to generate a malicious hostname, aka the &quot;URL Decoding Zone Spoofing Vulnerability.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><exception/></vuln_types><range><network/><user_init/></range><refs><ref patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110796851002781&amp;w=2">20050209 Internet Explorer zone spoofing with encoded URLs</ref><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms05-014.mspx">MS05-014</ref><ref patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA05-039A.html">TA05-039A</ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/580299">VU#580299</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1308.html">OVAL1308</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1736.html">OVAL1736</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval3060.html">OVAL3060</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval3196.html">OVAL3196</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval3586.html">OVAL3586</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19214">ie-file-url-encode(19214)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1308">oval:org.mitre.oval:def:1308</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1736">oval:org.mitre.oval:def:1736</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3060">oval:org.mitre.oval:def:3060</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3196">oval:org.mitre.oval:def:3196</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3586">oval:org.mitre.oval:def:3586</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="5.01"/><vers num="5.5"/><vers edition="Windows Server 2003 SP1" num="6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0055" published="2005-05-02" seq="2005-0055" severity="High" type="CVE"><desc><descript source="cve">Internet Explorer 5.01, 5.5, and 6 does not properly validate buffers when handling certain DHTML methods including the createControlRange Javascript function, which allows remote attackers to execute arbitrary code, aka the &quot;DHTML Method Heap Memory Corruption Vulnerability.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms05-014.mspx">MS05-014</ref><ref patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA05-039A.html">TA05-039A</ref><ref patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/843771">VU#843771</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/12427">12427</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1005.html">OVAL1005</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval2692.html">OVAL2692</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval3137.html">OVAL3137</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval3910.html">OVAL3910</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval710.html">OVAL710</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19137">ie-cdf-execute-code(19137)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013125">1013125</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1005">oval:org.mitre.oval:def:1005</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2692">oval:org.mitre.oval:def:2692</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3137">oval:org.mitre.oval:def:3137</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3910">oval:org.mitre.oval:def:3910</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:710">oval:org.mitre.oval:def:710</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="5.0.1 SP4"/><vers num="5.0.1 SP3"/><vers num="5.0.1 SP2"/><vers num="5.0.1 SP1"/><vers num="5.0.1"/><vers num="5.5 SP2"/><vers num="5.5 SP1"/><vers num="5.5"/><vers num="6.0 SP2"/><vers num="6.0 SP1"/><vers num="6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0056" published="2005-05-02" seq="2005-0056" severity="Medium" type="CVE"><desc><descript source="cve">Internet Explorer 5.01, 5.5, and 6 does not properly validate certain URLs in Channel Definition Format (CDF) files, which allows remote attackers to obtain sensitive information or execute arbitrary code, aka the &quot;Channel Definition Format (CDF) Cross Domain Vulnerability.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><design/></vuln_types><range><network/><user_init/></range><refs><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms05-014.mspx">MS05-014</ref><ref patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA05-039A.html">TA05-039A</ref><ref patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/823971">VU#823971</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval2385.html">OVAL2385</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval2817.html">OVAL2817</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval3318.html">OVAL3318</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval4085.html">OVAL4085</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval4947.html">OVAL4947</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19137">ie-cdf-execute-code(19137)</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/12427">12427</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013126">1013126</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2385">oval:org.mitre.oval:def:2385</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2817">oval:org.mitre.oval:def:2817</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3318">oval:org.mitre.oval:def:3318</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4085">oval:org.mitre.oval:def:4085</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4947">oval:org.mitre.oval:def:4947</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="5.01"/><vers num="5.5"/><vers edition="Windows Server 2003 SP1" num="6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0057" published="2005-05-02" seq="2005-0057" severity="High" type="CVE"><desc><descript source="cve">The Hyperlink Object Library for Windows 98, 2000, XP, and Server 2003 allows remote attackers to execute arbitrary code via a crafted link that triggers an &quot;unchecked buffer&quot; in the library, possibly due to a buffer overflow.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms05-015.mspx">MS05-015</ref><ref patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA05-039A.html">TA05-039A</ref><ref patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/820427">VU#820427</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval2570.html">OVAL2570</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval3203.html">OVAL3203</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval713.html">OVAL713</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19110">win-hyperlink-code-execution(19110)</ref><ref source="BID" url="http://www.securityfocus.com/bid/12479">12479</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013119">1013119</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14195">14195</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2570">oval:org.mitre.oval:def:2570</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3203">oval:org.mitre.oval:def:3203</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:713">oval:org.mitre.oval:def:713</ref></refs><vuln_soft><prod name="Windows 98" vendor="Microsoft"><vers num="Gold"/><vers num="SE"/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers edition="64-bit" num="R2"/><vers edition="Datacenter 64-bit" num="R2"/><vers edition="64-bit" num="Enterprise"/><vers num="Enterprise 64-bit"/><vers edition="64-bit" num="Standard"/><vers num="Web"/></prod><prod name="Windows XP" vendor="Microsoft"><vers edition="SP1" num="64-bit"/><vers num="64-bit"/><vers num="64-bit Version 2003"/><vers edition="SP2" num="Home"/><vers edition="SP1" num="Home"/><vers num="Home"/><vers edition="Gold" num="Professional"/><vers edition="Gold" num="Professional"/><vers edition="Gold" num="Professional"/><vers edition="SP2" num="Media Center"/><vers edition="SP1" num="Media Center"/><vers num="Media Center"/><vers edition="SP2" num="Tablet PC"/><vers edition="SP2" num="Tablet PC"/><vers edition="SP2" num="Tablet PC"/></prod><prod name="Windows ME" vendor="Microsoft"><vers num=""/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num="Advanced Server SP4"/><vers num="Advanced Server SP3"/><vers num="Advanced Server SP2"/><vers num="Advanced Server SP1"/><vers num="Advanced Server"/><vers num="Datacenter Server SP4"/><vers num="Datacenter Server SP3"/><vers num="Datacenter Server SP2"/><vers num="Datacenter Server SP1"/><vers num="Datacenter Server"/><vers num="Professional SP4"/><vers num="Professional SP3"/><vers num="Professional SP2"/><vers num="Professional SP1"/><vers num="Professional"/><vers num="Server SP4"/><vers num="Server SP3"/><vers num="Server SP2"/><vers num="Server SP1"/><vers num="Server"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0058" published="2005-08-10" seq="2005-0058" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the Telephony Application Programming Interface (TAPI) for Microsoft Windows 98, Windows 98 SE, Windows ME, Windows 2000, Windows XP, and Windows Server 2003 allows attackers elevate privileges or execute arbitrary code via a crafted message.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref patch="1" source="MS" url="http://www.microsoft.com/technet/Security/bulletin/ms05-040.mspx">MS05-040</ref><ref patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA05-221A.html">TA05-221A</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/16354/">16354</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval100084.html">OVAL100084</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval100085.html">OVAL100085</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval100086.html">OVAL100086</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval100088.html">OVAL100088</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1075.html">OVAL1075</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1213.html">OVAL1213</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1297.html">OVAL1297</ref><ref source="BID" url="http://www.securityfocus.com/bid/14518">14518</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014639">1014639</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100084">oval:org.mitre.oval:def:100084</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100085">oval:org.mitre.oval:def:100085</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100086">oval:org.mitre.oval:def:100086</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100088">oval:org.mitre.oval:def:100088</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1075">oval:org.mitre.oval:def:1075</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1213">oval:org.mitre.oval:def:1213</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1297">oval:org.mitre.oval:def:1297</ref></refs><vuln_soft><prod name="Windows 98" vendor="Microsoft"><vers num="Gold"/><vers num="SE"/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers num="R2"/></prod><prod name="Windows XP" vendor="Microsoft"><vers num="Gold"/></prod><prod name="Windows ME" vendor="Microsoft"><vers num=""/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0059" published="2005-05-02" seq="2005-0059" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the Message Queuing component of Microsoft Windows 2000 and Windows XP SP1 allows remote attackers to execute arbitrary code via a crafted message.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms05-017.mspx">MS05-017</ref><ref patch="1" source="bid" url="http://www.securityfocus.com/bid/13112">13112</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval4384.html">OVAL4384</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval4988.html">OVAL4988</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4384">oval:org.mitre.oval:def:4384</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4988">oval:org.mitre.oval:def:4988</ref></refs><vuln_soft><prod name="Windows 98" vendor="Microsoft"><vers num="Gold"/><vers num="SE"/></prod><prod name="Windows XP" vendor="Microsoft"><vers edition="SP1" num="64-bit"/><vers num="64-bit"/><vers edition="SP1" num="Embedded"/><vers num="Embedded"/><vers edition="SP1" num="Home"/><vers num="Home"/><vers edition="Gold" num="Professional"/><vers edition="Gold" num="Professional"/><vers edition="SP1" num="Media Center"/><vers num="Media Center"/><vers edition="SP2" num="Tablet PC"/><vers edition="SP2" num="Tablet PC"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num="Advanced Server SP4"/><vers num="Advanced Server SP3"/><vers num="Advanced Server SP2"/><vers num="Advanced Server SP1"/><vers num="Advanced Server"/><vers num="Datacenter Server SP4"/><vers num="Datacenter Server SP3"/><vers num="Datacenter Server SP2"/><vers num="Datacenter Server SP1"/><vers num="Datacenter Server"/><vers num="Professional SP4"/><vers num="Professional SP3"/><vers num="Professional SP2"/><vers num="Professional SP1"/><vers num="Professional"/><vers num="Server SP4"/><vers num="Server SP3"/><vers num="Server SP2"/><vers num="Server SP1"/><vers num="Server"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0060" published="2005-05-02" seq="2005-0060" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the font processing component of Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2003 allows local users to gain privileges via a specially-designed application.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><local/></range><refs><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms05-018.mspx">MS05-018</ref><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111343529426926&amp;w=2">20050413 Windows kernel overflow fixed</ref><ref adv="1" source="MISC" url="http://www.ngssoftware.com/advisories/ms-01.txt">http://www.ngssoftware.com/advisories/ms-01.txt</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval2562.html">OVAL2562</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval2731.html">OVAL2731</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval3941.html">OVAL3941</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval4797.html">OVAL4797</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2562">oval:org.mitre.oval:def:2562</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2731">oval:org.mitre.oval:def:2731</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3941">oval:org.mitre.oval:def:3941</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4797">oval:org.mitre.oval:def:4797</ref></refs><vuln_soft><prod name="Windows 98" vendor="Microsoft"><vers num="Gold"/><vers num="SE"/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers edition="64-bit" num="R2"/><vers edition="Datacenter 64-bit" num="R2"/><vers edition="64-bit" num="Enterprise"/><vers num="Enterprise 64-bit"/><vers edition="64-bit" num="Standard"/><vers num="Web"/></prod><prod name="Windows XP" vendor="Microsoft"><vers edition="SP1" num="64-bit"/><vers num="64-bit"/><vers num="64-bit Version 2003"/><vers edition="SP2" num="Home"/><vers edition="SP1" num="Home"/><vers num="Home"/><vers edition="Gold" num="Professional"/><vers edition="Gold" num="Professional"/><vers edition="Gold" num="Professional"/><vers edition="SP2" num="Media Center"/><vers edition="SP1" num="Media Center"/><vers num="Media Center"/><vers edition="SP2" num="Tablet PC"/><vers edition="SP2" num="Tablet PC"/><vers edition="SP2" num="Tablet PC"/></prod><prod name="Windows ME" vendor="Microsoft"><vers num=""/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num="Advanced Server SP4"/><vers num="Advanced Server SP3"/><vers num="Advanced Server SP2"/><vers num="Advanced Server SP1"/><vers num="Advanced Server"/><vers num="Datacenter Server SP4"/><vers num="Datacenter Server SP3"/><vers num="Datacenter Server SP2"/><vers num="Datacenter Server SP1"/><vers num="Datacenter Server"/><vers num="Professional SP4"/><vers num="Professional SP3"/><vers num="Professional SP2"/><vers num="Professional SP1"/><vers num="Professional"/><vers num="Server SP4"/><vers num="Server SP3"/><vers num="Server SP2"/><vers num="Server SP1"/><vers num="Server"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0061" published="2005-05-02" seq="2005-0061" severity="High" type="CVE"><desc><descript source="cve">The kernel of Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2003 allows local users to gain privileges via certain access requests.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><local/></range><refs><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms05-018.mspx">MS05-018</ref><ref patch="1" source="bid" url="http://www.securityfocus.com/bid/13121">13121</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1656.html">OVAL1656</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1761.html">OVAL1761</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval3994.html">OVAL3994</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval4593.html">OVAL4593</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1656">oval:org.mitre.oval:def:1656</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1761">oval:org.mitre.oval:def:1761</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3994">oval:org.mitre.oval:def:3994</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4593">oval:org.mitre.oval:def:4593</ref></refs><vuln_soft><prod name="Windows 98" vendor="Microsoft"><vers num="Gold"/><vers num="SE"/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers edition="64-bit" num="R2"/><vers edition="Datacenter 64-bit" num="R2"/><vers edition="64-bit" num="Enterprise"/><vers num="Enterprise 64-bit"/><vers edition="64-bit" num="Standard"/><vers num="Web"/></prod><prod name="Windows XP" vendor="Microsoft"><vers edition="SP1" num="64-bit"/><vers num="64-bit"/><vers num="64-bit Version 2003"/><vers edition="SP2" num="Home"/><vers edition="SP1" num="Home"/><vers num="Home"/><vers edition="Gold" num="Professional"/><vers edition="Gold" num="Professional"/><vers edition="Gold" num="Professional"/><vers edition="SP2" num="Media Center"/><vers edition="SP1" num="Media Center"/><vers num="Media Center"/></prod><prod name="Windows ME" vendor="Microsoft"><vers num=""/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num="Advanced Server SP4"/><vers num="Advanced Server SP3"/><vers num="Advanced Server SP2"/><vers num="Advanced Server SP1"/><vers num="Advanced Server"/><vers num="Datacenter Server SP4"/><vers num="Datacenter Server SP3"/><vers num="Datacenter Server SP2"/><vers num="Datacenter Server SP1"/><vers num="Datacenter Server"/><vers num="Professional SP4"/><vers num="Professional SP3"/><vers num="Professional SP2"/><vers num="Professional SP1"/><vers num="Professional"/><vers num="Server SP4"/><vers num="Server SP3"/><vers num="Server SP2"/><vers num="Server SP1"/><vers num="Server"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0063" published="2005-05-02" seq="2005-0063" severity="High" type="CVE"><desc><descript source="cve">The document processing application used by the Windows Shell in Microsoft Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code by modifying the CLSID stored in a file so that it is processed by HTML Application Host (MSHTA), as demonstrated using a Microsoft Word document.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms05-016.mspx">MS05-016</ref><ref patch="1" source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=231&amp;type=vulnerabilities">20050412 Microsoft MSHTA Script Execution Vulnerability</ref><ref source="MISC" url="http://www.securiteam.com/exploits/5YP0T0AFFW.html">http://www.securiteam.com/exploits/5YP0T0AFFW.html</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/0335">ADV-2005-0335</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval2184.html">OVAL2184</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval3456.html">OVAL3456</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval407.html">OVAL407</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval4710.html">OVAL4710</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval573.html">OVAL573</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval587.html">OVAL587</ref><ref source="BID" url="http://www.securityfocus.com/bid/13132">13132</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111755356016155&amp;w=2">20050529 Spam exploiting MS05-016</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2184">oval:org.mitre.oval:def:2184</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3456">oval:org.mitre.oval:def:3456</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:407">oval:org.mitre.oval:def:407</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4710">oval:org.mitre.oval:def:4710</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:573">oval:org.mitre.oval:def:573</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:587">oval:org.mitre.oval:def:587</ref></refs><vuln_soft><prod name="Windows 98" vendor="Microsoft"><vers num="Gold"/><vers num="SE"/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers edition="64-bit" num="R2"/><vers edition="64-bit" num="Enterprise"/><vers edition="64-bit" num="Standard"/><vers num="Web"/></prod><prod name="Windows XP" vendor="Microsoft"><vers edition="SP1" num="64-bit"/><vers edition="SP1" num="64-bit Version 2003"/><vers edition="SP2" num="Home"/><vers edition="SP1" num="Home"/><vers num="Home"/><vers edition="Gold" num="Professional"/><vers edition="Gold" num="Professional"/><vers edition="Gold" num="Professional"/><vers edition="SP2" num="Media Center"/><vers edition="SP1" num="Media Center"/><vers num="Media Center"/><vers edition="SP2" num="Tablet PC"/><vers edition="SP2" num="Tablet PC"/><vers edition="SP2" num="Tablet PC"/></prod><prod name="Windows ME" vendor="Microsoft"><vers num=""/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num="Advanced Server SP4"/><vers num="Advanced Server SP3"/><vers num="Advanced Server SP2"/><vers num="Advanced Server SP1"/><vers num="Advanced Server"/><vers num="Datacenter Server SP4"/><vers num="Datacenter Server SP3"/><vers num="Datacenter Server SP2"/><vers num="Datacenter Server SP1"/><vers num="Datacenter Server"/><vers num="Professional SP4"/><vers num="Professional SP3"/><vers num="Professional SP2"/><vers num="Professional SP1"/><vers num="Professional"/><vers num="Server SP4"/><vers num="Server SP3"/><vers num="Server SP2"/><vers num="Server SP1"/><vers num="Server"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2007-02-07" name="CVE-2005-0064" published="2005-05-02" seq="2005-0064" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the Decrypt::makeFileKey2 function in Decrypt.cc for xpdf 3.00 and earlier allows remote attackers to execute arbitrary code via a PDF file with a large /Encrypt /Length keyLength value.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=186&amp;type=vulnerabilities">20050118 Multiple Unix/Linux Vendor Xpdf makeFileKey2 Stack Overflow</ref><ref patch="1" source="CONFIRM" url="ftp://ftp.foolabs.com/pub/xpdf/xpdf-3.00pl3.patch">ftp://ftp.foolabs.com/pub/xpdf/xpdf-3.00pl3.patch</ref><ref adv="1" patch="1" source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000921">CLA-2005:921</ref><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-645">DSA-645</ref><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-648">DSA-648</ref><ref adv="1" patch="1" source="FEDORA" url="https://bugzilla.fedora.us/show_bug.cgi?id=2352">FLSA:2352</ref><ref adv="1" patch="1" source="FEDORA" url="https://bugzilla.fedora.us/show_bug.cgi?id=2353">FLSA:2353</ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200501-28.xml">GLSA-200502-10</ref><ref adv="1" patch="1" source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:016">MDKSA-2005:016</ref><ref adv="1" patch="1" source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:017">MDKSA-2005:017</ref><ref adv="1" patch="1" source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:018">MDKSA-2005:018</ref><ref adv="1" patch="1" source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:019">MDKSA-2005:019</ref><ref adv="1" patch="1" source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:020">MDKSA-2005:020</ref><ref adv="1" patch="1" source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:021">MDKSA-2005:021</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-034.html">RHSA-2005:034</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-053.html">RHSA-2005:053</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-057.html">RHSA-2005:057</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-059.html">RHSA-2005:059</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-066.html">RHSA-2005:066</ref><ref adv="1" patch="1" source="TRUSTIX" url="http://www.trustix.org/errata/2005/0003/">2005-0003</ref><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110625368019554&amp;w=2">20050119 [USN-64-1] xpdf, CUPS vulnerabilities</ref><ref source="SCO" url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.42/SCOSA-2005.42.txt">SCOSA-2005.42</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17277">17277</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-026.html">RHSA-2005:026</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:016">MDKSA-2005:016</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:017">MDKSA-2005:017</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:018">MDKSA-2005:018</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:019">MDKSA-2005:019</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:020">MDKSA-2005:020</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:021">MDKSA-2005:021</ref></refs><vuln_soft><prod name="Xpdf" vendor="Xpdf"><vers num="3.0"/><vers num="2.3"/><vers num="2.2"/><vers num="2.1"/><vers num="2.0"/><vers num="1.1"/><vers num="1.0a"/><vers num="1.0"/><vers num="0.93c"/><vers num="0.93b"/><vers num="0.93a"/><vers num="0.93"/><vers num="0.92e"/><vers num="0.92d"/><vers num="0.92c"/><vers num="0.92b"/><vers num="0.92a"/><vers num="0.92"/><vers num="0.91c"/><vers num="0.91b"/><vers num="0.91a"/><vers num="0.91"/><vers num="0.90"/><vers num="0.80"/><vers num="0.7a"/><vers num="0.7"/><vers num="0.6"/><vers num="0.5a"/><vers num="0.5"/><vers num="0.4"/><vers num="0.3"/><vers num="0.2"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-25" name="CVE-2005-0065" published="2005-05-02" seq="2005-0065" severity="High" type="CVE"><desc><descript source="cve">The original design of TCP does not check that the TCP sequence number in an ICMP error message is within the range of sequence numbers for data that has been sent but not acknowledged (aka &quot;TCP sequence number checking&quot;), which makes it easier for attackers to forge ICMP error messages for specific TCP connections and cause a denial of service, as demonstrated using (1) blind connection-reset attacks with forged &quot;Destination Unreachable&quot; messages, (2) blind throughput-reduction attacks with forged &quot;Source Quench&quot; messages, or (3) blind throughput-reduction attacks with forged ICMP messages that cause the Path MTU to be reduced.  NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability.  While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref source="MISC" url="http://www.gont.com.ar/drafts/icmp-attacks-against-tcp.html">http://www.gont.com.ar/drafts/icmp-attacks-against-tcp.html</ref><ref source="BID" url="http://www.securityfocus.com/bid/13124">13124</ref></refs><vuln_soft><prod name="TCP" vendor="TCP"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-25" name="CVE-2005-0066" published="2004-12-22" seq="2005-0066" severity="Medium" type="CVE"><desc><descript source="cve">The original design of TCP does not check that the TCP Acknowledgement number in an ICMP error message generated by an intermediate router is within the range of possible values for data that has already been acknowledged (aka &quot;TCP acknowledgement number checking&quot;), which makes it easier for attackers to forge ICMP error messages for specific TCP connections and cause a denial of service, as demonstrated using (1) blind connection-reset attacks with forged &quot;Destination Unreachable&quot; messages, (2) blind throughput-reduction attacks with forged &quot;Source Quench&quot; messages, or (3) blind throughput-reduction attacks with forged ICMP messages that cause the Path MTU to be reduced.  NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability.  While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://www.gont.com.ar/drafts/icmp-attacks-against-tcp.html">http://www.gont.com.ar/drafts/icmp-attacks-against-tcp.html</ref><ref source="BID" url="http://www.securityfocus.com/bid/13124">13124</ref></refs><vuln_soft><prod name="TCP" vendor="TCP"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-25" name="CVE-2005-0067" published="2004-12-22" seq="2005-0067" severity="Medium" type="CVE"><desc><descript source="cve">The original design of TCP does not require that port numbers be assigned randomly (aka &quot;Port randomization&quot;), which makes it easier for attackers to forge ICMP error messages for specific TCP connections and cause a denial of service, as demonstrated using (1) blind connection-reset attacks with forged &quot;Destination Unreachable&quot; messages, (2) blind throughput-reduction attacks with forged &quot;Source Quench&quot; messages, or (3) blind throughput-reduction attacks with forged ICMP messages that cause the Path MTU to be reduced.  NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability.  While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://www.gont.com.ar/drafts/icmp-attacks-against-tcp.html">http://www.gont.com.ar/drafts/icmp-attacks-against-tcp.html</ref><ref source="BID" url="http://www.securityfocus.com/bid/13124">13124</ref></refs><vuln_soft><prod name="TCP" vendor="TCP"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-25" name="CVE-2005-0068" published="2004-12-22" seq="2005-0068" severity="Medium" type="CVE"><desc><descript source="cve">The original design of ICMP does not require authentication for host-generated ICMP error messages, which makes it easier for attackers to forge ICMP error messages for specific TCP connections and cause a denial of service, as demonstrated using (1) blind connection-reset attacks with forged &quot;Destination Unreachable&quot; messages, (2) blind throughput-reduction attacks with forged &quot;Source Quench&quot; messages, or (3) blind throughput-reduction attacks with forged ICMP messages that cause the Path MTU to be reduced.  NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability.  While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://www.gont.com.ar/drafts/icmp-attacks-against-tcp.html">http://www.gont.com.ar/drafts/icmp-attacks-against-tcp.html</ref><ref source="BID" url="http://www.securityfocus.com/bid/13124">13124</ref></refs><vuln_soft><prod name="TCP" vendor="TCP"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0069" published="2005-01-13" seq="2005-0069" severity="Medium" type="CVE"><desc><descript source="cve">The (1) tcltags or (2) vimspell.sh scripts in vim 6.3 allow local users to overwrite or create arbitrary files via a symlink attack on temporary files.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="FEDORA" url="https://bugzilla.fedora.us/show_bug.cgi?id=2343">FLSA:2343</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-036.html">RHSA-2005:036</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-122.html">RHSA-2005:122</ref><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110608387001863&amp;w=2">20050118 [USN-61-1] vim vulnerabilities</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/13841/">13841</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18870">vim-symlink(18870)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1012938">1012938</ref></refs><vuln_soft><prod name="VIM" vendor="VIM Development Group"><vers num="6.3.044"/><vers num="6.3.030"/><vers num="6.3.025"/><vers num="6.3.011"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0070" published="2005-05-02" seq="2005-0070" severity="High" type="CVE"><desc><descript source="cve">Synaesthesia 2.1 and earlier, and possibly other versions, when installed setuid root, does not drop privileges before processing configuration and mixer files, which allows local users to read arbitrary files.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-681">DSA-681</ref><ref source="BID" url="http://www.securityfocus.com/bid/12546">12546</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013206">1013206</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14300">14300</ref></refs><vuln_soft><prod name="Synaesthesia" vendor="Synaesthesia"><vers num="2.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0071" published="2005-05-02" seq="2005-0071" severity="Medium" type="CVE"><desc><descript source="cve">vdr before 1.2.6 does not securely create files, which allows attackers to overwrite arbitrary files.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-656">DSA-656</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200501-42.xml">GLSA-200501-42</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19066">vdr-dvdapi-file-overwrite(19066)</ref><ref source="BID" url="http://www.securityfocus.com/bid/12356">12356</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13930">13930</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13995">13995</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14066">14066</ref></refs><vuln_soft><prod name="vdr" vendor="VDR"><vers num="1.2.5"/><vers num="1.2.2"/><vers num="1.2.1"/><vers num="1.2.0"/><vers num="1.0.4"/><vers num="1.0.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0072" published="2005-01-24" seq="2005-0072" severity="Low" type="CVE"><desc><descript source="cve">zhcon before 0.2 does not drop privileges before reading a user configuration file, which allows local users to read arbitrary files.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-655">DSA-655</ref><ref adv="1" patch="1" source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:012">MDKSA-2005:012</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19045">zhcon-information-disclosure(19045)</ref><ref source="BID" url="http://www.securityfocus.com/bid/12343">12343</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1012977">1012977</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13977">13977</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13982">13982</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13987">13987</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:012">MDKSA-2005:012</ref></refs><vuln_soft><prod name="zhcon" vendor="ejoy and Hu Yong"><vers num="0.2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0073" published="2005-05-02" seq="2005-0073" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in queue.c in a support script for sympa 3.3.3, when running setuid, allows local users to execute arbitrary code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-677">DSA-677</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013163">1013163</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14217">14217</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14224">14224</ref></refs><vuln_soft><prod name="sympa" vendor="Debian"><vers num="3.3.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0074" published="2005-02-11" seq="2005-0074" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in pcdsvgaview in xpcd 2.08 allows local users to execute arbitrary code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-676">DSA-676</ref><ref source="BID" url="http://www.securityfocus.com/bid/12523">12523</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013162">1013162</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14248">14248</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14250">14250</ref></refs><vuln_soft><prod name="xpcd" vendor="xpcd"><vers num="2.08"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0075" published="2005-01-29" seq="2005-0075" severity="Medium" type="CVE"><desc><descript source="cve">prefs.php in SquirrelMail before 1.4.4, with register_globals enabled, allows remote attackers to inject local code into the SquirrelMail code via custom preference handlers.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110702772714662&amp;w=2">20050129 SquirrelMail Security Advisory</ref><ref adv="1" patch="1" source="CONFIRM" url="http://www.squirrelmail.org/security/issue/2005-01-14">http://www.squirrelmail.org/security/issue/2005-01-14</ref><ref patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/Mar/msg00000.html">APPLE-SA-2005-03-21</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-099.html">RHSA-2005:099</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-135.html">RHSA-2005:135</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/13962/">13962</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200501-39.xml">GLSA-200501-39</ref></refs><vuln_soft><prod name="SquirrelMail" vendor="SquirrelMail"><vers num="1.4.3a"/><vers num="1.4.3"/><vers num="1.4.2"/><vers num="1.4.1"/><vers num="1.4.0"/><vers num="1.4"/><vers num="1.2.9"/><vers num="1.2.8"/><vers num="1.2.7"/><vers num="1.2.6"/><vers num="1.2.5"/><vers num="1.2.4"/><vers num="1.2.3"/><vers num="1.2.2"/><vers num="1.2.11"/><vers num="1.2.10"/><vers num="1.2.1"/><vers num="1.2.0"/><vers num="1.0.5"/><vers num="1.0.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0076" published="2005-05-02" seq="2005-0076" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in the XView library 3.2 may allow local users to execute arbitrary code via setuid applications that use the library.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-672">DSA-672</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19271">xview-xvparseone-bo(19271)</ref></refs><vuln_soft><prod name="Debian Linux" vendor="Debian"><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0077" published="2005-05-02" seq="2005-0077" severity="Low" type="CVE"><desc><descript source="cve">The DBI library (libdbi-perl) for Perl allows local users to overwrite arbitrary files via a symlink attack on a temporary PID file.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-658">DSA-658</ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200501-38.xml">GLSA-200501-38</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-072.html">RHSA-2005:072</ref><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110667936707597&amp;w=2">20050125 [USN-70-1] Perl DBI module vulnerability</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19068">dbi-library-file-overwrite(19068)</ref><ref source="MANDRAKE" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2005:030">MDKSA-2005:030</ref><ref source="BID" url="http://www.securityfocus.com/bid/12360">12360</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013007">1013007</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14015">14015</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14050">14050</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/426530/30/6600/threaded">
FLSA-2006:178989</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:030">MDKSA-2005:030</ref></refs><vuln_soft><prod name="Linux" vendor="Gentoo"><vers num=""/></prod><prod name="Desktop" vendor="Red Hat"><vers num="4.0"/></prod><prod name="Enterprise Linux WS" vendor="Red Hat"><vers edition="Workstation" num="4.0"/></prod><prod name="Enterprise Linux ES" vendor="Red Hat"><vers edition="Enterprise Server" num="4.0"/></prod><prod name="Ubuntu Linux" vendor="Ubuntu"><vers num="4.10"/></prod><prod name="Enterprise Linux AS" vendor="Red Hat"><vers edition="Advanced Server" num="4.0"/></prod><prod name="Debian Linux" vendor="Debian"><vers edition="woody" num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0078" published="2005-05-02" seq="2005-0078" severity="Medium" type="CVE"><desc><descript source="cve">The KDE screen saver in KDE before 3.0.5 does not properly check the return value from a certain function call, which allows attackers with physical access to cause a crash and access the desktop session.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><exception/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-660">DSA-660</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-009.html">RHSA-2005:009</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19084">kdebase-screensaver-security-bypass(19084)</ref></refs><vuln_soft><prod name="Linux Advanced Workstation" vendor="Red Hat"><vers num="2.1"/></prod><prod name="Desktop" vendor="Red Hat"><vers num="3.0"/></prod><prod name="Enterprise Linux WS" vendor="Red Hat"><vers edition="Workstation" num="2.1"/><vers edition="Workstation" num="3.0"/></prod><prod name="Enterprise Linux ES" vendor="Red Hat"><vers edition="Enterprise Server" num="2.1"/><vers edition="Enterprise Server" num="3.0"/></prod><prod name="KDE" vendor="KDE"><vers num="3.0.4"/><vers num="3.0.3"/><vers num="3.0.2"/><vers num="3.0.1"/><vers num="3.0"/><vers num="3.0 Beta 2"/><vers num="3.0 Beta 1"/><vers num="2.2.1"/><vers num="2.2"/><vers num="2.2 Beta1"/><vers num="2.1"/><vers num="2.1 beta2"/><vers num="2.1 beta1"/><vers num="2.0.1"/><vers num="2.0"/><vers num="1.1.2"/><vers num="1.1.1"/><vers num="1.1"/><vers num="1.0"/></prod><prod name="Enterprise Linux AS" vendor="Red Hat"><vers edition="Advanced Server" num="2.1"/><vers edition="Advanced Servers" num="3.0"/></prod><prod name="Debian Linux" vendor="Debian"><vers edition="woody" num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0079" published="2005-05-02" seq="2005-0079" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in xtrlock 2.0 allows local users to cause a denial of service (application crash) and hijack the desktop session.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-649">DSA-649</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18991">xtrlock-screen-lock-bypass(18991)</ref><ref source="" url="http://www.securitytracker.com/alerts/2005/Jan/1012909.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/12316">12316</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13938">13938</ref></refs><vuln_soft><prod name="xtrlock" vendor="xtrlock"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0080" published="2005-05-02" seq="2005-0080" severity="Medium" type="CVE"><desc><descript source="cve">The 55_options_traceback.dpatch patch for mailman 2.1.5 in Ubuntu 4.10 displays a different error message depending on whether the e-mail address is subscribed to a private list, which allows remote attackers to determine the list membership for a given e-mail address.</descript></desc><loss_types><conf/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110549296126351&amp;w=2">20050110 [USN-59-1] mailman vulnerabilities</ref><ref source="CONFIRM" url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=285839">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=285839</ref><ref source="MISC" url="http://qa.debian.org/bts-security.html">http://qa.debian.org/bts-security.html</ref></refs><vuln_soft><prod name="Mailman" vendor="GNU"><vers num="2.1.5"/></prod><prod name="Ubuntu Linux" vendor="Ubuntu"><vers edition="ia640" num="4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-03-28" name="CVE-2005-0081" published="2005-04-14" seq="2005-0081" severity="Medium" type="CVE"><desc><descript source="cve">MySQL MaxDB 7.5.0.0, and other versions before 7.5.0.21, allows remote attackers to cause a denial of service (crash) via an HTTP request with invalid headers.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="iDefense" url="http://www.idefense.com/application/poi/display?id=187&amp;type=vulnerabilities">MySQL MaxDB Web Agent Multiple Denial of Service Vulnerabilities</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/12313">bid 12313</ref><ref source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=187&amp;type=vulnerabilities">20050119 MySQL MaxDB Web Agent Multiple Denial of Service Vulnerabilities</ref></refs><vuln_soft><prod name="MaxDB" vendor="MySQL"><vers num="7.5.00.19"/><vers num="7.5.00.18"/><vers num="7.5.00.16"/><vers num="7.5.00.15"/><vers num="7.5.00.14"/><vers num="7.5.00.12"/><vers num="7.5.00.11"/><vers num="7.5.00.08"/><vers num="7.5.00"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2007-08-14" name="CVE-2005-0082" published="2005-04-14" seq="2005-0082" severity="Medium" type="CVE"><desc><descript source="cve">The sapdbwa_GetUserData function in MySQL MaxDB 7.5.0.0, and other versions before 7.5.0.21, allows remote attackers to cause a denial of service (crash) via invalid parameters to the WebDAV handler code, which triggers a null dereference that causes the SAP DB Web Agent to crash.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="iDefense" url="http://www.idefense.com/application/poi/display?id=187&amp;type=vulnerabilities">MySQL MaxDB Web Agent Multiple Denial of Service Vulnerabilities</ref><ref adv="1" source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=187&amp;type=vulnerabilities">20050119 MySQL MaxDB Web Agent Multiple Denial of Service Vulnerabilities</ref></refs><vuln_soft><prod name="MaxDB" vendor="MySQL"><vers num="7.5.00.19"/><vers num="7.5.00.18"/><vers num="7.5.00.16"/><vers num="7.5.00.15"/><vers num="7.5.00.14"/><vers num="7.5.00.12"/><vers num="7.5.00.11"/><vers num="7.5.00.08"/><vers num="7.5.00"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-03-28" name="CVE-2005-0083" published="2005-05-02" seq="2005-0083" severity="Medium" type="CVE"><desc><descript source="cve">MySQL MaxDB 7.5.00 for Windows, and possibly earlier versions and other platforms, allows remote attackers to cause a denial of service (application crash) via invalid parameters to the (1) DBMCli_String::ReallocString, (2) DBMCli_String::operator, (3) DBMCli_Buffer::ForceResize, (4) DBMCli_Wizard::InstallDatabase, (5) DBMCli_Devspaces::Complete, (6) DBMWeb_TemplateWizard::askForWriteCountStep5, or (7) DBMWeb_DBMWeb::wizardDB functions, which triggers a null dereference.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=218&amp;type=vulnerabilities">20050314 MySQL MaxDB Web Agent Multiple Denial of Service Vulnerabilities</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19687">maxdb-null-pointer-dos(19687)</ref><ref source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=218&amp;type=vulnerabilities">20050314 MySQL MaxDB Web Agent Multiple Denial of Service Vulnerabilities</ref></refs><vuln_soft><prod name="MaxDB" vendor="MySQL"><vers num="7.5.00"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0084" published="2005-05-02" seq="2005-0084" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the X11 dissector in Ethereal 0.8.10 through 0.10.8 allows remote attackers to execute arbitrary code via a crafted packet.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="CONFIRM" url="http://www.ethereal.com/appnotes/enpa-sa-00017.html">http://www.ethereal.com/appnotes/enpa-sa-00017.html</ref><ref patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-653">DSA-653</ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200501-27.xml">GLSA-200501-27</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:013">MDKSA-2005:013</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-037.html">RHSA-2005:037</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/p-106.shtml">P-106</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/13946/">13946</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19004">ethereal-x11-bo(19004)</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00003.html">FLSA-2006:152922</ref><ref source="BID" url="http://www.securityfocus.com/bid/12326">12326</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:013">MDKSA-2005:013</ref></refs><vuln_soft><prod name="Ethereal" vendor="Ethereal Group"><vers num="0.8"/><vers num="0.9.9"/><vers num="0.9.8"/><vers num="0.9.7"/><vers num="0.9.6"/><vers num="0.9.5"/><vers num="0.9.4"/><vers num="0.9.3"/><vers num="0.9.2"/><vers num="0.9.16"/><vers num="0.9.15"/><vers num="0.9.14"/><vers num="0.9.13"/><vers num="0.9.12"/><vers num="0.9.11"/><vers num="0.9.10"/><vers num="0.9.1"/><vers num="0.9.0"/><vers num="0.9"/><vers num="0.8.20"/><vers num="0.8.19"/><vers num="0.8.18"/><vers num="0.8.17a"/><vers num="0.8.16"/><vers num="0.8.15"/><vers num="0.8.14"/><vers num="0.8.13"/><vers num="0.10.8"/><vers num="0.10.7"/><vers num="0.10.6"/><vers num="0.10.5"/><vers num="0.10.4"/><vers num="0.10.3"/><vers num="0.10.2"/><vers num="0.10.1"/><vers num="0.10.0a"/><vers num="0.10.0"/><vers num="0.10"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0085" published="2005-04-27" seq="2005-0085" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in ht://dig (htdig) before 3.1.6-r7 allows remote attackers to execute arbitrary web script or HTML via the config parameter, which is not properly sanitized before it is displayed in an error message.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Debian.org" url="http://www.debian.org/security/2005/dsa-680">htdig -- unsanitised input</ref><ref adv="1" source="SecurityTracker" url="http://securitytracker.com/alerts/2005/Feb/1013078.html">ht://dig Input Validation Hole in &apos;config&apos; Parameter Permits Cross-Site Scripting Attacks</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/12442">bid 12442</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200502-16.xml">GLSA-200502-16</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:063">MDKSA-2005:063</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-073.html">RHSA-2005:073</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013078">1013078</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19223">htdig-config-xss(19223)</ref><ref source="SCO" url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.46/SCOSA-2005.46.txt">SCOSA-2005.46</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14255">14255</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17414">17414</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17415">17415</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00002.html">FLSA-2006:152907</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14276">14276</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14303">14303</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14795">14795</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15007">15007</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-090.html">RHSA-2005:090</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:063">MDKSA-2005:063</ref></refs><vuln_soft><prod name="Mandrake Corporate Server" vendor="MandrakeSoft"><vers edition="x86_64" num="2.1"/><vers num="2.1"/><vers edition="x86_64" num="3.0"/><vers num="3.0"/></prod><prod name="Fedora" vendor="Red Hat"><vers num="Core 3.0"/></prod><prod name="Mandrake Linux" vendor="MandrakeSoft"><vers edition="AMD64" num="10.0"/><vers num="10.0"/><vers edition="x86_64" num="10.1"/><vers num="10.1"/></prod><prod name="SuSE Linux" vendor="SuSE"><vers edition="i386" num="8.0"/><vers num="8.0"/><vers num="8.1"/><vers num="8.2"/><vers edition="x86_64" num="9.0"/><vers num="9.0"/><vers num="9.1"/><vers num="9.2"/></prod><prod name="htDig" vendor="htDig"><vers num="3.1.5_8"/><vers num="3.1.5_7"/><vers num="3.1.5"/><vers num="3.1.6"/><vers num="3.2.0b6"/><vers num="3.2.0b5"/><vers num="3.2.0b4"/><vers num="3.2.0b3"/><vers num="3.2.0b2"/><vers num="3.2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0086" published="2005-05-02" seq="2005-0086" severity="High" type="CVE"><desc><descript source="cve">Heap-based buffer overflow in less in Red Hat Enterprise Linux 3 allows attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted file, as demonstrated using the UTF-8 locale.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="FEDORA" url="https://bugzilla.fedora.us/show_bug.cgi?id=2404">FLSA:2404</ref><ref adv="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-068.html">RHSA-2005:068</ref><ref source="CONFIRM" url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=145527">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=145527</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19131">less-file-bo(19131)</ref></refs><vuln_soft><prod name="Desktop" vendor="Red Hat"><vers num="3.0"/></prod><prod name="Enterprise Linux WS" vendor="Red Hat"><vers edition="Workstation" num="3.0"/></prod><prod name="Enterprise Linux ES" vendor="Red Hat"><vers edition="Enterprise Server" num="3.0"/></prod><prod name="Enterprise Linux AS" vendor="Red Hat"><vers edition="Advanced Servers" num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0087" published="2005-04-27" seq="2005-0087" severity="Medium" type="CVE"><desc><descript source="cve">The alsa-lib package in Red Hat Linux 4 disables stack protection for the libasound.so library, which makes it easier for attackers to execute arbitrary code if there are other vulnerabilities in the library.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><other/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="RedHat" url="http://www.redhat.com/support/errata/RHSA-2005-033.html">alsa-lib security update</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/12575">bid 12575</ref></refs><vuln_soft><prod name="Enterprise Linux WS" vendor="Red Hat"><vers edition="Workstation" num="4.0"/></prod><prod name="Enterprise Linux ES" vendor="Red Hat"><vers edition="Enterprise Server" num="4.0"/></prod><prod name="alsa-lib" vendor="ALSA"><vers num="1.0.6"/></prod><prod name="Enterprise Linux AS" vendor="Red Hat"><vers edition="Advanced Server" num="4.0"/></prod><prod name="Enterprise Linux Desktop" vendor="Red Hat"><vers edition="Desktop" num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-21" name="CVE-2005-0088" published="2005-05-02" seq="2005-0088" severity="High" type="CVE"><desc><descript source="cve">The publisher handler for mod_python 2.7.8 and earlier allows remote attackers to obtain access to restricted objects via a crafted URL.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/><input/></vuln_types><range><network/></range><refs><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000926">CLA-2005:926</ref><ref patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-689">DSA-689</ref><ref patch="1" source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200502-14.xml">GLSA-200502-14</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-100.html">RHSA-2005:100</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-104.html">RHSA-2005:104</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2005/0003/">2005-0003</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110815313218389&amp;w=2">20050211 [USN-80-1] mod_python vulnerability</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/356409">VU#356409</ref><ref source="BID" url="http://www.securityfocus.com/bid/12519">12519</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013156">1013156</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/430286/100/0/threaded">FLSA:152896</ref></refs><vuln_soft><prod name="mod_python" vendor="Apache Software Foundation"><vers num="2.7.8" prev="1"/><vers num="2.7.7"/><vers num="2.7.6"/><vers num="2.7.5"/><vers num="2.7.4"/><vers num="2.7.3"/><vers num="2.7.2"/><vers num="2.7.1"/><vers num="2.7"/><vers num="2.6.4"/><vers num="2.6.3"/><vers num="2.6.2"/><vers num="2.6.1"/><vers num="2.6"/><vers num="2.5"/><vers num="2.4.1"/><vers num="2.4"/><vers num="2.3"/><vers num="2.2"/><vers num="2.1"/><vers num="2.0"/><vers num="1.9a"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0089" published="2005-05-02" seq="2005-0089" severity="High" type="CVE"><desc><descript source="cve">The SimpleXMLRPCServer library module in Python 2.2, 2.3 before 2.3.5, and 2.4, when used by XML-RPC servers that use the register_instance method to register an object without a _dispatch method, allows remote attackers to read or modify globals of the associated module, and possibly execute arbitrary code, via dotted attributes.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/><env/></vuln_types><range><network/></range><refs><ref patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110746469728728&amp;w=2">20050203 Python Security Advisory PSF-2005-001 - SimpleXMLRPCServer.py</ref><ref patch="1" source="CONFIRM" url="http://www.python.org/security/PSF-2005-001/">http://www.python.org/security/PSF-2005-001/</ref><ref patch="1" source="CONFIRM" url="http://python.org/security/PSF-2005-001/patch-2.2.txt">http://python.org/security/PSF-2005-001/patch-2.2.txt</ref><ref patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-666">DSA-666</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:035">MDKSA-2005:035</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-108.html">RHSA-2005:108</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2005/0003/">2005-0003</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19217">python-simplexmlrpcserver-bypass(19217)</ref><ref source="BID" url="http://www.securityfocus.com/bid/12437">12437</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013083">1013083</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14128">14128</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:035">MDKSA-2005:035</ref></refs><vuln_soft><prod name="Python" vendor="Python Software Foundation"><vers num="2.2"/><vers num="2.3"/><vers num="2.3.1"/><vers num="2.3.2"/><vers num="2.3.3"/><vers num="2.3.4"/><vers num="2.4"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0090" published="2005-05-02" seq="2005-0090" severity="Low" type="CVE"><desc><descript source="cve">A regression error in the Red Hat Enterprise Linux 4 kernel 4GB/4GB split patch omits an &quot;access check,&quot; which allows local users to cause a denial of service (crash).</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/12599">12599</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-092.html">RHSA-2005:092</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20618">red-hat-regression-dos(20618)</ref></refs><vuln_soft><prod name="Desktop" vendor="Red Hat"><vers num="4.0"/></prod><prod name="Enterprise Linux WS" vendor="Red Hat"><vers edition="Workstation" num="4.0"/></prod><prod name="Enterprise Linux ES" vendor="Red Hat"><vers edition="Enterprise Server" num="4.0"/></prod><prod name="Enterprise Linux AS" vendor="Red Hat"><vers edition="Advanced Server" num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0091" published="2005-05-02" seq="2005-0091" severity="High" type="CVE"><desc><descript source="cve">Unknown vulnerability in the Red Hat Enterprise Linux 4 kernel 4GB/4GB split patch, when using the hugemem kernel, allows local users to read and write to arbitrary kernel memory and gain privileges via certain syscalls.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/12599">12599</ref><ref adv="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-092.html">RHSA-2005:092</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20619">red-hat-patch-gain-privileges(20619)</ref></refs><vuln_soft><prod name="Desktop" vendor="Red Hat"><vers num="4.0"/></prod><prod name="Enterprise Linux WS" vendor="Red Hat"><vers edition="Workstation" num="4.0"/></prod><prod name="Enterprise Linux ES" vendor="Red Hat"><vers edition="Enterprise Server" num="4.0"/></prod><prod name="Enterprise Linux AS" vendor="Red Hat"><vers edition="Advanced Server" num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0092" published="2005-02-19" seq="2005-0092" severity="Low" type="CVE"><desc><descript source="cve">Unknown vulnerability in the Red Hat Enterprise Linux 4 kernel 4GB/4GB split patch, when running on x86 with the hugemem kernel, allows local users to cause a denial of service (crash).</descript></desc><loss_types><avail/></loss_types><range><local/></range><refs><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/12599">12599</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-092.html">RHSA-2005:092</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20620">red-hat-patch-dos(20620)</ref></refs><vuln_soft><prod name="Desktop" vendor="Red Hat"><vers num="4.0"/></prod><prod name="Enterprise Linux" vendor="Red Hat"><vers edition="Workstation" num="4.0"/><vers edition="Enterprise Server" num="4.0"/><vers edition="Advanced Server" num="4.0"/></prod></vuln_soft></entry><entry modified="2005-10-20" name="CVE-2005-0093" published="2005-05-02" reject="1" seq="2005-0093" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: none.  Reason: This candidate was withdrawn by its CNA.  Further investigation showed that it was not a security issue.  Notes: none.</descript></desc><refs/></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0094" published="2005-01-15" seq="2005-0094" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in the gopherToHTML function in the Gopher reply parser for Squid 2.5.STABLE7 and earlier allows remote malicious Gopher servers to cause a denial of service (crash) via crafted responses.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="CONFIRM" url="http://www.squid-cache.org/Advisories/SQUID-2005_1.txt">http://www.squid-cache.org/Advisories/SQUID-2005_1.txt</ref><ref adv="1" source="CONFIRM" url="http://www.squid-cache.org/Versions/v2/2.5/bugs/squid-2.5.STABLE7-gopher_html_parsing.patch">http://www.squid-cache.org/Versions/v2/2.5/bugs/squid-2.5.STABLE7-gopher_html_parsing.patch</ref><ref adv="1" source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000923">CLA-2005:923</ref><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-651">DSA-651</ref><ref adv="1" patch="1" source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200501-25.xml">GLSA-200501-25</ref><ref adv="1" patch="1" source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:014">MDKSA-2005:014</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-060.html">RHSA-2005:060</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-061.html">RHSA-2005:061</ref><ref adv="1" source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_06_squid.html">SUSE-SA:2005:006</ref><ref adv="1" source="TRUSTIX" url="http://www.trustix.org/errata/2005/0003/">2005-0003</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/13825">13825</ref><ref source="FEDORA" url="http://fedoranews.org/updates/FEDORA--.shtml">FLSA-2006:152809</ref><ref source="BID" url="http://www.securityfocus.com/bid/12276">12276</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:014">MDKSA-2005:014</ref></refs><vuln_soft><prod name="Squid" vendor="Squid"><vers num="2.5.STABLE7"/><vers num="2.5.STABLE6"/><vers num="2.5.STABLE5"/><vers num="2.5.STABLE4"/><vers num="2.5.STABLE3"/><vers num="2.5.STABLE2"/><vers num="2.5.STABLE1"/><vers num="2.5.6"/><vers num="2.5 Stable9"/><vers num="2.5 STABLE4"/><vers num="2.5 STABLE3"/><vers num="2.5 .STABLE6"/><vers num="2.5 .STABLE5"/><vers num="2.5 .STABLE4"/><vers num="2.5 .STABLE3"/><vers num="2.5 .STABLE1"/><vers num="2.4 STABLE7"/><vers num="2.4 .STABLE7"/><vers num="2.4 .STABLE6"/><vers num="2.4 .STABLE2"/><vers num="2.4"/><vers num="2.3 STABLE5"/><vers num="2.3 .STABLE5"/><vers num="2.3 .STABLE4"/><vers num="2.1 PATCH2"/><vers num="2.0 PATCH2"/><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0095" published="2005-01-15" seq="2005-0095" severity="Medium" type="CVE"><desc><descript source="cve">The WCCP message parsing code in Squid 2.5.STABLE7 and earlier allows remote attackers to cause a denial of service (crash) via malformed WCCP messages with source addresses that are spoofed to reference Squid&apos;s home router and invalid WCCP_I_SEE_YOU cache numbers.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CONFIRM" url="http://www.squid-cache.org/Advisories/SQUID-2005_2.txt">http://www.squid-cache.org/Advisories/SQUID-2005_2.txt</ref><ref adv="1" source="CONFIRM" url="http://www.squid-cache.org/Versions/v2/2.5/bugs/squid-2.5.STABLE7-wccp_denial_of_service.patch">http://www.squid-cache.org/Versions/v2/2.5/bugs/squid-2.5.STABLE7-wccp_denial_of_service.patch</ref><ref adv="1" patch="1" source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000923">CLA-2005:923</ref><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-651">DSA-651</ref><ref adv="1" patch="1" source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200501-25.xml">GLSA-200501-25</ref><ref adv="1" patch="1" source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:014">MDKSA-2005:014</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-060.html">RHSA-2005:060</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-061.html">RHSA-2005:061</ref><ref adv="1" patch="1" source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_06_squid.html">SUSE-SA:2005:006</ref><ref adv="1" patch="1" source="TRUSTIX" url="http://www.trustix.org/errata/2005/0003/">2005-0003</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/13825">13825</ref><ref source="OSVDB" url="http://www.osvdb.org/12886">12886</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1012882">1012882</ref><ref source="FEDORA" url="http://fedoranews.org/updates/FEDORA--.shtml">FLSA-2006:152809</ref><ref source="BID" url="http://www.securityfocus.com/bid/12275">12275</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:014">MDKSA-2005:014</ref></refs><vuln_soft><prod name="Squid" vendor="Squid"><vers num="2.5.STABLE7"/><vers num="2.5.STABLE6"/><vers num="2.5.STABLE5"/><vers num="2.5.STABLE4"/><vers num="2.5.STABLE3"/><vers num="2.5.STABLE2"/><vers num="2.5.STABLE1"/><vers num="2.5.6"/><vers num="2.5 Stable9"/><vers num="2.5 STABLE4"/><vers num="2.5 STABLE3"/><vers num="2.5 .STABLE6"/><vers num="2.5 .STABLE5"/><vers num="2.5 .STABLE4"/><vers num="2.5 .STABLE3"/><vers num="2.5 .STABLE1"/><vers num="2.4 STABLE7"/><vers num="2.4 .STABLE7"/><vers num="2.4 .STABLE6"/><vers num="2.4 .STABLE2"/><vers num="2.4"/><vers num="2.3 STABLE5"/><vers num="2.3 .STABLE5"/><vers num="2.3 .STABLE4"/><vers num="2.1 PATCH2"/><vers num="2.0 PATCH2"/><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0096" published="2005-01-25" seq="2005-0096" severity="Medium" type="CVE"><desc><descript source="cve">Memory leak in the NTLM fakeauth_auth helper for Squid 2.5.STABLE7 and earlier allows remote attackers to cause a denial of service (memory consumption).</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CONFIRM" url="http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE7-fakeauth_auth">http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE7-fakeauth_auth</ref><ref adv="1" patch="1" source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000923">CLA-2005:923</ref><ref adv="1" patch="1" source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200501-25.xml">GLSA-200501-25</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-060.html">RHSA-2005:060</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-061.html">RHSA-2005:061</ref><ref adv="1" source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_06_squid.html">SUSE-SA:2005:006</ref><ref adv="1" source="TRUSTIX" url="http://www.trustix.org/errata/2005/0003/">2005-0003</ref><ref source="BID" url="http://www.securityfocus.com/bid/12324">12324</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1012818">1012818</ref><ref source="FEDORA" url="http://fedoranews.org/updates/FEDORA--.shtml">FLSA-2006:152809</ref></refs><vuln_soft><prod name="Squid" vendor="Squid"><vers num="2.5.STABLE7"/><vers num="2.5.STABLE6"/><vers num="2.5.STABLE5"/><vers num="2.5.STABLE4"/><vers num="2.5.STABLE3"/><vers num="2.5.STABLE2"/><vers num="2.5.STABLE1"/><vers num="2.5.6"/><vers num="2.5 Stable9"/><vers num="2.5 STABLE4"/><vers num="2.5 STABLE3"/><vers num="2.5 .STABLE6"/><vers num="2.5 .STABLE5"/><vers num="2.5 .STABLE4"/><vers num="2.5 .STABLE3"/><vers num="2.5 .STABLE1"/><vers num="2.4 STABLE7"/><vers num="2.4 .STABLE7"/><vers num="2.4 .STABLE6"/><vers num="2.4 .STABLE2"/><vers num="2.4"/><vers num="2.3 STABLE5"/><vers num="2.3 .STABLE5"/><vers num="2.3 .STABLE4"/><vers num="2.1 PATCH2"/><vers num="2.0 PATCH2"/><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0097" published="2005-01-11" seq="2005-0097" severity="Medium" type="CVE"><desc><descript source="cve">The NTLM component in Squid 2.5.STABLE7 and earlier allows remote attackers to cause a denial of service (crash) via a malformed NTLM type 3 message that triggers a NULL dereference.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CONFIRM" url="http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE7-fakeauth_auth">http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE7-fakeauth_auth</ref><ref adv="1" patch="1" source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200501-25.xml">GLSA-200501-25</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-060.html">RHSA-2005:060</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-061.html">RHSA-2005:061</ref><ref adv="1" patch="1" source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_06_squid.html">SUSE-SA:2005:006</ref><ref adv="1" patch="1" source="TRUSTIX" url="http://www.trustix.org/errata/2005/0003/">2005-0003</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/13789">13789</ref><ref source="BID" url="http://www.securityfocus.com/bid/12220">12220</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1012818">1012818</ref><ref source="FEDORA" url="http://fedoranews.org/updates/FEDORA--.shtml">FLSA-2006:152809</ref></refs><vuln_soft><prod name="Squid" vendor="Squid"><vers num="2.5.STABLE7"/><vers num="2.5.STABLE6"/><vers num="2.5.STABLE5"/><vers num="2.5.STABLE4"/><vers num="2.5.STABLE3"/><vers num="2.5.STABLE2"/><vers num="2.5.STABLE1"/><vers num="2.5.6"/><vers num="2.5 Stable9"/><vers num="2.5 STABLE4"/><vers num="2.5 STABLE3"/><vers num="2.5 .STABLE6"/><vers num="2.5 .STABLE5"/><vers num="2.5 .STABLE4"/><vers num="2.5 .STABLE3"/><vers num="2.5 .STABLE1"/><vers num="2.4 STABLE7"/><vers num="2.4 .STABLE7"/><vers num="2.4 .STABLE6"/><vers num="2.4 .STABLE2"/><vers num="2.4"/><vers num="2.3 STABLE5"/><vers num="2.3 .STABLE5"/><vers num="2.3 .STABLE4"/><vers num="2.1 PATCH2"/><vers num="2.0 PATCH2"/><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-08-03" name="CVE-2005-0098" published="2005-03-08" seq="2005-0098" severity="Medium" type="CVE"><desc><descript source="cve">Multiple buffer overflows in the SDL port of abuse (abuse-SDL) before 2.00 allow local users to execute arbitrary code via the command line.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-691">DSA-691</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/14495">14495</ref></refs><vuln_soft><prod name="Abuse-SDL" vendor="Abuse"><vers num="2.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-08-03" name="CVE-2005-0099" published="2005-03-08" seq="2005-0099" severity="Low" type="CVE"><desc><descript source="cve">The SDL port of abuse (abuse-SDL) before 2.00 does not properly drop privileges before creating certain files, which allows local users to create or overwrite arbitrary files.</descript></desc><loss_types><int/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-691">DSA-691</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14495">14495</ref><ref source="OSVDB" url="http://www.osvdb.org/14610">14610</ref></refs><vuln_soft><prod name="Abuse-SDL" vendor="Abuse"><vers num="2.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0100" published="2005-02-07" seq="2005-0100" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in the movemail utility in (1) Emacs 20.x, 21.3, and possibly other versions, and (2) XEmacs 21.4 and earlier, allows remote malicious POP3 servers to execute arbitrary code via crafted packets.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-670">DSA-670</ref><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-671">DSA-671</ref><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-685">DSA-685</ref><ref adv="1" patch="1" source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:038">MDKSA-2005:038</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-110.html">RHSA-2005:110</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-112.html">RHSA-2005:112</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-133.html">RHSA-2005:133</ref><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110780416112719&amp;w=2">20050207 [USN-76-1] Emacs vulnerability</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19246">xemacs-movemail-format-string(19246)</ref><ref source="BID" url="http://www.securityfocus.com/bid/12462">12462</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/433928/30/5010/threaded">
FLSA-2006:152898</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:038">MDKSA-2005:038</ref></refs><vuln_soft><prod name="XEmacs" vendor="GNU"><vers num="21.4" prev="1"/></prod><prod name="Emacs" vendor="GNU"><vers num="20.0" prev="1"/><vers num="21.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0101" published="2005-02-01" seq="2005-0101" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the socket_getline function in Newspost 2.1.1 and earlier allows remote malicious NNTP servers to execute arbitrary code via a long string without a newline character.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110746336728781&amp;w=2">20050202 RE: SECURITEY.NNOV.RU NewsPost buffer overflow [EXPLOIT]</ref><ref adv="1" source="MISC" url="http://people.freebsd.org/~niels/issues/newspost-20050114.txt">http://people.freebsd.org/~niels/issues/newspost-20050114.txt</ref><ref adv="1" source="CONFIRM" url="http://www.vuxml.org/freebsd/7f13607b-6948-11d9-8937-00065be4b5b6.html">http://www.vuxml.org/freebsd/7f13607b-6948-11d9-8937-00065be4b5b6.html</ref><ref adv="1" patch="1" source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200502-05.xml">GLSA-200502-05</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/14092/">14092</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19178">newspost-socketgetline-bo(19178)</ref><ref source="BID" url="http://www.securityfocus.com/bid/12418">12418</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013056">1013056</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14098">14098</ref></refs><vuln_soft><prod name="Newspost" vendor="Newspost"><vers num="2.1.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0102" published="2005-01-24" seq="2005-0102" severity="High" type="CVE"><desc><descript source="cve">Integer overflow in camel-lock-helper in Evolution 2.0.2 and earlier allows local users or remote malicious POP3 servers to execute arbitrary code via a length value of -1, which leads to a zero byte memory allocation and a buffer overflow.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110667319720599&amp;w=2">20050124 [USN-69-1] Evolution vulnerability</ref><ref adv="1" patch="1" source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000925">CLA-2005:925</ref><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-673">DSA-673</ref><ref adv="1" patch="1" source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200501-35.xml">GLSA-200501-35</ref><ref adv="1" patch="1" source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:024">MDKSA-2005:024</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/12354">12354</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19031">evolution-camellockhelper-bo(19031)</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-397.html">RHSA-2005:397</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-238.html">RHSA-2005:238</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-69-1">USN-69-1</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1012981">1012981</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13830">13830</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:024">MDKSA-2005:024</ref></refs><vuln_soft><prod name="Evolution" vendor="Ximian"><vers num="1.3.2 beta"/><vers num="1.2.4"/><vers num="1.2.3"/><vers num="1.2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-28" name="CVE-2005-0103" published="2005-01-24" seq="2005-0103" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in webmail.php in SquirrelMail before 1.4.4 allows remote attackers to execute arbitrary PHP code by modifying a URL parameter to reference a URL on a remote web server that contains the code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110702772714662&amp;w=2">20050129 SquirrelMail Security Advisory</ref><ref adv="1" patch="1" source="CONFIRM" url="http://www.squirrelmail.org/security/issue/2005-01-19?PHPSESSID=8af117822fb1ca3aa966a64248b5d223">http://www.squirrelmail.org/security/issue/2005-01-19?PHPSESSID=8af117822fb1ca3aa966a64248b5d223</ref><ref adv="1" patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/Mar/msg00000.html">APPLE-SA-2005-03-21</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-099.html">RHSA-2005:099</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-135.html">RHSA-2005:135</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/13962/">13962</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200501-39.xml">GLSA-200501-39</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19037">squirrelmail-frame-file-include(19037)</ref></refs><vuln_soft><prod name="SquirrelMail" vendor="SquirrelMail"><vers num="1.4.3 RC1"/><vers num="1.4.3a"/><vers num="1.4.3"/><vers num="1.4.2"/><vers num="1.4.1"/><vers num="1.4.0"/><vers num="1.4"/><vers num="1.2.9"/><vers num="1.2.8"/><vers num="1.2.7"/><vers num="1.2.6"/><vers num="1.2.5"/><vers num="1.2.4"/><vers num="1.2.3"/><vers num="1.2.2"/><vers num="1.2.11"/><vers num="1.2.10"/><vers num="1.2.1"/><vers num="1.2.0"/><vers num="1.0.5"/><vers num="1.0.4"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0104" published="2005-01-29" seq="2005-0104" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in webmail.php in SquirrelMail before 1.4.4 allows remote attackers to inject arbitrary web script or HTML via certain integer variables.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110702772714662&amp;w=2">20050129 SquirrelMail Security Advisory</ref><ref adv="1" patch="1" source="CONFIRM" url="http://www.squirrelmail.org/security/issue/2005-01-20">http://www.squirrelmail.org/security/issue/2005-01-20</ref><ref adv="1" patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/Mar/msg00000.html">APPLE-SA-2005-03-21</ref><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-662">DSA-662</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-099.html">RHSA-2005:099</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-135.html">RHSA-2005:135</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/13962/">13962</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14096">14096</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200501-39.xml">GLSA-200501-39</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19036">squirrelmail-webmailphp-xss(19036)</ref></refs><vuln_soft><prod name="SquirrelMail" vendor="SquirrelMail"><vers num="1.44"/><vers num="1.4.3 RC1"/><vers num="1.4.3a"/><vers num="1.4.3"/><vers num="1.4.2"/><vers num="1.4.1"/><vers num="1.4.0"/><vers num="1.4"/><vers num="1.2.9"/><vers num="1.2.8"/><vers num="1.2.7"/><vers num="1.2.6"/><vers num="1.2.5"/><vers num="1.2.4"/><vers num="1.2.3"/><vers num="1.2.2"/><vers num="1.2.11"/><vers num="1.2.10"/><vers num="1.2.1"/><vers num="1.2.0"/><vers num="1.0.5"/><vers num="1.0.4"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-22" name="CVE-2005-0105" published="2005-02-16" seq="2005-0105" severity="Medium" type="CVE"><desc><descript source="cve">Unknown vulnerability in typespeed 0.4.1 and earlier allows local users to gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-684">DSA-684</ref></refs><vuln_soft><prod name="typespeed" vendor="typespeed"><vers num="0.4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0106" published="2005-05-03" seq="2005-0106" severity="Medium" type="CVE"><desc><descript source="cve">SSLeay.pm in libnet-ssleay-perl before 1.25 uses the /tmp/entropy file for entropy if a source is not set in the EGD_PATH variable, which allows local users to reduce the cryptographic strength of certain operations by modifying the file.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref patch="1" source="CONFIRM" url="http://www.ubuntulinux.org/support/documentation/usn/usn-113-1">http://www.ubuntulinux.org/support/documentation/usn/usn-113-1</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:023">MDKSA-2006:023</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18639">18639</ref><ref source="BID" url="http://www.securityfocus.com/bid/13471">13471</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:023">MDKSA-2006:023</ref></refs><vuln_soft><prod name="Ubuntu Linux" vendor="Ubuntu"><vers num="5.04"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0107" published="2005-02-25" seq="2005-0107" severity="High" type="CVE"><desc><descript source="cve">bsmtpd 2.3 and earlier does not properly sanitize e-mail addresses, which allows remote attackers to execute arbitrary commands.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-690">DSA-690</ref></refs><vuln_soft><prod name="bsmtpd" vendor="Debian"><vers num="2.3" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0108" published="2005-01-11" seq="2005-0108" severity="Medium" type="CVE"><desc><descript source="cve">Apache mod_auth_radius 1.5.4 and libpam-radius-auth allow remote malicious RADIUS servers to cause a denial of service (crash) via a RADIUS_REPLY_MESSAGE with a RADIUS attribute length of 1, which leads to a memcpy operation with a -1 length argument.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110548193312050&amp;w=2">20050111 Apache mod_auth_radius remote integer overflow</ref><ref adv="1" source="MISC" url="http://security.lss.hr/en/index.php?page=details&amp;ID=LSS-2005-01-02">http://security.lss.hr/en/index.php?page=details&amp;ID=LSS-2005-01-02</ref><ref adv="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-659">DSA-659</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18841">modauthradius-dos(18841)</ref><ref source="BID" url="http://www.securityfocus.com/bid/12217">12217</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1012829">1012829</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13773">13773</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14046">14046</ref></refs><vuln_soft><prod name="mod_auth_radius" vendor="Apache Software Foundation"><vers num="1.5.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-05-11" name="CVE-2005-0109" published="2005-03-05" seq="2005-0109" severity="High" type="CVE"><desc><descript source="cve">Hyper-Threading technology, as used in FreeBSD and other operating systems that are run on Intel Pentium and other processors, allows local users to use a malicious thread to create covert channels, monitor the execution of other threads, and obtain sensitive information such as cryptographic keys, via a timing attack on memory cache misses.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/12724">12724</ref><ref source="MISC" url="http://www.daemonology.net/papers/htt.pdf">http://www.daemonology.net/papers/htt.pdf</ref><ref source="MISC" url="http://www.daemonology.net/hyperthreading-considered-harmful/">http://www.daemonology.net/hyperthreading-considered-harmful/</ref><ref source="SCO" url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.24/SCOSA-2005.24.txt">SCOSA-2005.24</ref><ref adv="1" source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101739-1">101739</ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/911878">VU#911878</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/0540">ADV-2005-0540</ref><ref adv="1" patch="1" source="SECTRACK" url="http://securitytracker.com/id?1013967">1013967</ref><ref source="" url="http://www-1.ibm.com/support/docview.wss?uid=isg1SSRVHMCHMC_C081516_754"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/3002">ADV-2005-3002</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15348">15348</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18165">18165</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-476.html">RHSA-2005:476</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-800.html">RHSA-2005:800</ref><ref source="MLIST" url="http://marc.theaimsgroup.com/?l=openbsd-misc&amp;m=110995101417256&amp;w=2">[openbsd-misc] 20050304 Re: FreeBSD hiding security stuff</ref><ref source="MLIST" url="http://marc.theaimsgroup.com/?l=freebsd-security&amp;m=110994370429609&amp;w=2">[freebsd-security] 20050304 [Fwd: Re: FW:FreeBSD hiding security stuff]</ref><ref source="MLIST" url="http://marc.theaimsgroup.com/?l=freebsd-hackers&amp;m=110994026421858&amp;w=2">[freebsd-hackers] 20050304 Re: FW:FreeBSD hiding security stuff</ref></refs><vuln_soft><prod name="Enterprise Linux" vendor="Red Hat"><vers edition="Workstation" num="4.0"/><vers edition="Workstation Server" num="3.0"/><vers edition="Workstation" num="2.1"/><vers edition="Workstation" num="2.1"/><vers edition="Enterprise Server" num="4.0"/><vers edition="Enterprise Server" num="3.0"/><vers edition="Enterprise Server" num="2.1"/><vers edition="Enterprise Server" num="2.1"/><vers edition="Advanced Server" num="4.0"/><vers edition="Advanced Server" num="3.0"/><vers edition="Advanced Server" num="2.1"/><vers edition="Advanced Server" num="2.1"/></prod><prod name="Desktop" vendor="Red Hat"><vers num="4.0"/><vers num="3.0"/></prod><prod name="OpenServer" vendor="SCO"><vers num="5.0.7"/></prod><prod name="Solaris" vendor="Sun"><vers edition="SPARC" num="10.0"/><vers edition="x86 Update 2" num="9.0"/><vers edition="x86" num="9.0"/><vers edition="x86" num="8.0"/><vers edition="x86" num="7.0"/></prod><prod name="Unixware" vendor="SCO"><vers num="7.1.4"/><vers num="7.1.3 up"/><vers num="7.1.3"/></prod><prod name="Fedora" vendor="Red Hat"><vers num="Core 3.0"/></prod><prod name="Ubuntu Linux" vendor="Ubuntu"><vers edition="powerpc" num="5.04"/><vers edition="i386" num="5.04"/><vers edition="amd64" num="5.04"/><vers edition="ppc" num="4.1"/><vers edition="ia64" num="4.1"/><vers edition="ia64" num="4.1"/></prod><prod name="FreeBSD" vendor="FreeBSD"><vers num="5.4 pre"/><vers num="5.3 Stable"/><vers num="5.3 Releng"/><vers num="5.3 Release"/><vers num="5.3"/><vers num="5.2.1 Release"/><vers num="5.2 Releng"/><vers num="5.2 Release"/><vers num="5.2"/><vers num="5.1 Releng"/><vers num="5.1 Release Alpha"/><vers num="5.1 p5 Release"/><vers num="5.1 Release"/><vers num="5.1"/><vers num="5.0 Releng"/><vers num="5.0 p14 Release"/><vers num="5.0 alpha"/><vers num="5.0"/><vers num="4.11 Stable"/><vers num="4.11 Releng"/><vers num="4.11 p3 Release"/><vers num="4.10 Releng"/><vers num="4.10 p8 Release"/><vers num="4.10 Release"/><vers num="4.10"/><vers num="4.9 Releng"/><vers num="4.9 pre"/><vers num="4.9"/><vers num="4.8 Releng"/><vers num="4.8 p6 Release"/><vers num="4.8 pre"/><vers num="4.8"/><vers num="4.7 Stable"/><vers num="4.7 Releng"/><vers num="4.7 p17 Release"/><vers num="4.7 Release"/><vers num="4.7"/><vers num="4.6.2"/><vers num="4.6 Stable"/><vers num="4.6 Releng"/><vers num="4.6 p20 Release"/><vers num="4.6 Release"/><vers num="4.6"/><vers num="4.5 Stable pre 2002-03-07"/><vers num="4.5 Stable"/><vers num="4.5 Releng"/><vers num="4.5 p32 Release"/><vers num="4.5 Release"/><vers num="4.5"/><vers num="4.4 Stable"/><vers num="4.4 Releng"/><vers num="4.4 p42 Release"/><vers num="4.4"/><vers num="4.3 Stable"/><vers num="4.3 Releng"/><vers num="4.3 p38 Release"/><vers num="4.3 Release"/><vers num="4.3"/><vers num="4.2 Stable pre 2000-12-23"/><vers num="4.2 Stable pre 2001-05-02"/><vers num="4.2 Stable"/><vers num="4.2 Release"/><vers num="4.2"/><vers num="4.1.1 Stable"/><vers num="4.1.1 Release"/><vers num="4.1.1"/><vers num="4.1"/><vers num="4.0 Releng"/><vers num="4.0 alpha"/><vers num="4.0"/><vers num="3.5.1 Stable pre 2001-07-20"/><vers num="3.5.1 Stable"/><vers num="3.5.1 Release"/><vers num="3.5.1"/><vers num="3.5 Stable pre 2000-12-23"/><vers num="3.5 Stable pre 2001-05-02"/><vers num="3.5 Stable"/><vers num="3.5"/><vers num="3.4"/><vers num="3.3"/><vers num="3.2"/><vers num="3.1"/><vers num="3.0 Releng"/><vers num="3.0"/><vers num="2.2.8"/><vers num="2.2.6"/><vers num="2.2.5"/><vers num="2.2.4"/><vers num="2.2.3"/><vers num="2.2.2"/><vers num="2.2"/><vers num="2.1.7.1"/><vers num="2.1.6.1"/><vers num="2.1.6"/><vers num="2.1.5"/><vers num="2.1.0"/><vers num="2.0.5"/><vers num="2.0"/><vers num="1.1.5.1"/><vers num="4.10 pre"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0110" published="2005-01-14" seq="2005-0110" severity="Low" type="CVE"><desc><descript source="cve">Internet Explorer 6 on Windows XP SP2 allows remote attackers to bypass the file download warning dialog and possibly trick an unknowledgeable user into executing arbitrary code via a web page with a body element containing an onclick tag, as demonstrated using the createElement function.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=110569119106172&amp;w=2">20050114 Internet Explorer (SP2) - Remote File Download</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers edition="for Microsoft Windows Server 2003 SP1.0 SP2" num="6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-03-28" name="CVE-2005-0111" published="2005-01-13" seq="2005-0111" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in the websql CGI program in MySQL MaxDB 7.5.00 allows remote attackers to execute arbitrary code via a long password parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=181&amp;type=vulnerabilities">20050113 MySQL MaxDB WebAgent websql logon Buffer Overflow Vulnerability</ref><ref source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=181&amp;type=vulnerabilities">20050113 MySQL MaxDB WebAgent websql logon Buffer Overflow Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/12265">12265</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1012893">1012893</ref></refs><vuln_soft><prod name="MaxDB" vendor="MySQL"><vers num="7.5.00"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0112" published="2005-04-14" seq="2005-0112" severity="Medium" type="CVE"><desc><descript source="cve">The web-based administrative interface for 3Com OfficeConnect Wireless 11g Access Point (AP) 1.00.08, and possibly earlier versions before 1.03.07A, allows remote attackers to bypass authentication and obtain sensitive information by directly accessing the (1) config.bin (2) profile.wlp?PN=ggg or (3) event.logs URLs.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="iDefense" url="http://www.idefense.com/application/poi/display?id=188&amp;type=vulnerabilities">3Com OfficeConnect Wireless 11g AP Information Disclosure Vulnerability</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/18994">OfficeConnect Wireless information disclosure</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/12322">bid 12322</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1012958">1012958</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13942">13942</ref></refs><vuln_soft><prod name="3Com OfficeConnect Wireless11g Access Point" vendor="3Com"><vers num="3CRWE454G72 1.0.3.5"/><vers num="3CRWE454G72 1.0.2.11"/><vers num="3CRWE454G72 1.0.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0113" published="2005-01-14" seq="2005-0113" severity="High" type="CVE"><desc><descript source="cve">inpview in SGI IRIX allows local users to execute arbitrary commands via the SUN_TTSESSION_CMD environment variable, which is executed by inpview without dropping privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=182&amp;type=vulnerabilities">20050113 SGI IRIX inpview Design Error Vulnerability</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/13858">13858</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18894">irix-inpview-gain-privileges(18894)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1012894">1012894</ref><ref source="BID" url="http://www.securityfocus.com/bid/12259">12259</ref><ref source="OSVDB" url="http://www.osvdb.org/12915">12915</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num="6.5"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0114" published="2005-02-11" seq="2005-0114" severity="Low" type="CVE"><desc><descript source="cve">vsdatant.sys in Zone Lab ZoneAlarm before 5.5.062.011, ZoneAlarm Wireless before 5.5.080.000, Check Point Integrity Client 4.x before 4.5.122.000 and 5.x before 5.1.556.166 do not properly verify that the ServerPortName argument to the NtConnectPort function is a valid memory address, which allows local users to cause a denial of service (system crash) when ZoneAlarm attempts to dereference an invalid pointer.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=199&amp;type=vulnerabilities">20050211 ZoneAlarm 5.1 Invalid Pointer Dereference Vulnerability</ref><ref adv="1" patch="1" source="CONFIRM" url="http://download.zonelabs.com/bin/free/securityAlert/19.html">http://download.zonelabs.com/bin/free/securityAlert/19.html</ref><ref source="BID" url="http://www.securityfocus.com/bid/12531">12531</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14256">14256</ref></refs><vuln_soft><prod name="ZoneAlarm" vendor="Zone Labs"><vers num="5.5.062.011"/></prod><prod name="ZoneAlarm Wireless" vendor="Zone Labs"><vers num="5.5.080.000" prev="1"/></prod><prod name="Check Point Integrity Client" vendor="Zone Labs"><vers num="4.5.122.000"/><vers num="5.1.556.166" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0115" published="2005-01-24" seq="2005-0115" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in DataRescue Interactive Disassembler (IDA) Pro 4.7 allows attackers to execute arbitrary code via a PE file with an Import Address Table containing a long import library name.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=189&amp;type=vulnerabilities">20050124 DataRescue Interactive Disassembler Pro Buffer Overflow Vulnerability</ref><ref adv="1" patch="1" source="CONFIRM" url="http://www.datarescue.com/ubb/ultimatebb.php?/topic/2/146.html">http://www.datarescue.com/ubb/ultimatebb.php?/topic/2/146.html</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19042">database-ida-portable-executable-bo(19042)</ref><ref source="BID" url="http://www.securityfocus.com/bid/12353">12353</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1012975">1012975</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13980">13980</ref></refs><vuln_soft><prod name="IDA" vendor="DataRescue"><vers num="4.7"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-02-26" name="CVE-2005-0116" published="2005-01-18" seq="2005-0116" severity="High" type="CVE"><desc><descript source="cve">AWStats 6.1, and other versions before 6.3, allows remote attackers to execute arbitrary commands via shell metacharacters in the configdir parameter to aswtats.pl.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=185&amp;type=vulnerabilities&amp;flashstatus=false">20050117 AWStats Remote Command Execution Vulnerability</ref><ref adv="1" patch="1" source="CONFIRM" url="http://awstats.sourceforge.net/docs/awstats_changelog.txt">http://awstats.sourceforge.net/docs/awstats_changelog.txt</ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/272296">VU#272296</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/13893/">13893</ref><ref source="OSVDB" url="http://www.osvdb.org/13002">13002</ref><ref source="" url="http://packetstormsecurity.org/0501-exploits/AWStatsVulnAnalysis.pdf"></ref><ref source="BID" url="http://www.securityfocus.com/bid/12298">12298</ref></refs><vuln_soft><prod name="AWStats" vendor="AWStats"><vers num="6.3" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0117" published="2005-01-11" seq="2005-0117" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in XShisen before 1.36 allows local users to execute arbitrary code via a long GECOS field.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="Debian" url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=289784">289784: xshisen: buffer overflow when handling GECOS field</ref><ref adv="1" source="CONFIRM" url="http://www.vuxml.org/freebsd/56971fa6-641c-11d9-a097-000854d03344.html">http://www.vuxml.org/freebsd/56971fa6-641c-11d9-a097-000854d03344.html</ref></refs><vuln_soft><prod name="XShisen" vendor="XShisen"><vers num="1.36" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0118" published="2005-05-02" seq="2005-0118" severity="Low" type="CVE"><desc><descript source="cve">helvis 1.8h2_1 and earlier stores recovery files in world readable directories with world readable permissions, which allows local users to read the recovered files of other users.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/><design/></vuln_types><range><local/></range><refs><ref adv="1" source="CONFIRM" url="http://www.vuxml.org/freebsd/bb99f803-5fde-11d9-b721-00065be4b5b6.html">http://www.vuxml.org/freebsd/bb99f803-5fde-11d9-b721-00065be4b5b6.html</ref></refs><vuln_soft><prod name="helvis" vendor="Helvis"><vers num="1.8h2_1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0119" published="2005-05-02" seq="2005-0119" severity="Low" type="CVE"><desc><descript source="cve">helvis 1.8h2_1 and earlier allows local users to recover and read the files of other users via the elvrec setuid program.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref source="CONFIRM" url="http://www.vuxml.org/freebsd/bb99f803-5fde-11d9-b721-00065be4b5b6.html">http://www.vuxml.org/freebsd/bb99f803-5fde-11d9-b721-00065be4b5b6.html</ref></refs><vuln_soft><prod name="helvis" vendor="Helvis"><vers num="1.8h2_1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0120" published="2005-05-02" seq="2005-0120" severity="Low" type="CVE"><desc><descript source="cve">helvis 1.8h2_1 and earlier allows local users to delete arbitrary files via the elvprsv setuid program.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="MISC" url="http://people.freebsd.org/~niels/ports/korean/helvis/issues.txt">http://people.freebsd.org/~niels/ports/korean/helvis/issues.txt</ref></refs><vuln_soft><prod name="helvis" vendor="Helvis"><vers num="1.8h2_1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0121" published="2005-05-02" seq="2005-0121" severity="Medium" type="CVE"><desc><descript source="cve">Multiple buffer overflows in golddig 2.0 and earlier allow local users to execute arbitrary code via (1) a long map name command line argument or (2) a long username as recorded in the USER environment variable.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="CONFIRM" url="http://www.vuxml.org/freebsd/949c470e-528f-11d9-ac20-00065be4b5b6.html">http://www.vuxml.org/freebsd/949c470e-528f-11d9-ac20-00065be4b5b6.html</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19039">golddig-long-mapname-bo(19039)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19040">golddig-long-username-bo(19040)</ref></refs><vuln_soft><prod name="golddig" vendor="Alexander Siegel"><vers num="2.0"/></prod></vuln_soft></entry><entry modified="2005-10-25" name="CVE-2005-0122" published="2005-04-14" reject="1" seq="2005-0122" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2005-0975.  Reason: This candidate is a duplicate of CVE-2005-0975.  Notes: All CVE users should reference CVE-2005-0975 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><refs/></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0124" published="2005-04-14" seq="2005-0124" severity="Low" type="CVE"><desc><descript source="cve">The coda_pioctl function in the coda functionality (pioctl.c) for Linux kernel 2.6.9 and 2.4.x before 2.4.29 may allow local users to cause a denial of service (crash) or execute arbitrary code via negative vi.in_size or vi.out_size values, which may trigger a buffer overflow.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="Seclists.org" url="http://seclists.org/lists/linux-kernel/2005/Jan/2018.html">Re: Make pipe data structure be a circular list of pages, rather than</ref><ref source="MLIST" url="http://seclists.org/lists/linux-kernel/2004/Dec/3914.html">[linux-kernel] 20041216 [Coverity] Untrusted user data in kernel</ref><ref source="MLIST" url="http://seclists.org/lists/linux-kernel/2005/Jan/1089.html">[linux-kernel] 20050105 Re: [Coverity] Untrusted user data in kernel</ref><ref source="MLIST" url="http://seclists.org/lists/linux-kernel/2005/Jan/2020.html">[linux-kernel] 20050107 [PATCH 2.6.10-mm2] fs/coda Re: [Coverity] Untrusted user data in kernel</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013018">1013018</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0191.html">RHSA-2006:0191</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18684">18684</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-663.html">RHSA-2005:663</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/428028/100/0/threaded">FLSA:157459-1</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1017">DSA-1017</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19374">19374</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17002">17002</ref><ref source="BID" url="http://www.securityfocus.com/bid/14967">14967</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1070">DSA-1070</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1067">DSA-1067</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1069">DSA-1069</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20163">20163</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20202">20202</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1082">DSA-1082</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/1878">ADV-2005-1878</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20338">20338</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers edition="2.6.20" num="2.6.9"/><vers num="2.4.9"/><vers num="2.4.8"/><vers num="2.4.7"/><vers num="2.4.6"/><vers num="2.4.5"/><vers num="2.4.4"/><vers num="2.4.3-pre3"/><vers num="2.4.3"/><vers num="2.4.29-rc2"/><vers num="2.4.29-rc1"/><vers num="2.4.29"/><vers num="2.4.28"/><vers num="2.4.27-pre5"/><vers num="2.4.27-pre4"/><vers num="2.4.27-pre3"/><vers num="2.4.27-pre2"/><vers num="2.4.27-pre1"/><vers num="2.4.27"/><vers num="2.4.26"/><vers num="2.4.25"/><vers num="2.4.24-ow1"/><vers num="2.4.24"/><vers num="2.4.23-pre9"/><vers num="2.4.23-ow2"/><vers num="2.4.23"/><vers num="2.4.22-pre10"/><vers num="2.4.22"/><vers num="2.4.21-pre7"/><vers num="2.4.21-pre4"/><vers num="2.4.21-pre1"/><vers num="2.4.21"/><vers num="2.4.20"/><vers num="2.4.2"/><vers num="2.4.19-pre6"/><vers num="2.4.19-pre5"/><vers num="2.4.19-pre4"/><vers num="2.4.19-pre3"/><vers num="2.4.19-pre2"/><vers num="2.4.19-pre1"/><vers num="2.4.19"/><vers num="2.4.18-x86"/><vers num="2.4.18-pre-8"/><vers num="2.4.18-pre-7"/><vers num="2.4.18-pre-6"/><vers num="2.4.18-pre-5"/><vers num="2.4.18-pre-4"/><vers num="2.4.18-pre-3"/><vers num="2.4.18-pre-2"/><vers num="2.4.18-pre-1"/><vers num="2.4.18"/><vers num="2.4.17"/><vers num="2.4.16"/><vers num="2.4.15"/><vers num="2.4.14"/><vers num="2.4.13"/><vers num="2.4.12"/><vers num="2.4.11"/><vers num="2.4.10"/><vers num="2.4.1"/><vers num="2.4.0-test9"/><vers num="2.4.0-test8"/><vers num="2.4.0-test7"/><vers num="2.4.0-test6"/><vers num="2.4.0-test5"/><vers num="2.4.0-test4"/><vers num="2.4.0-test3"/><vers num="2.4.0-test2"/><vers num="2.4.0-test12"/><vers num="2.4.0-test11"/><vers num="2.4.0-test10"/><vers num="2.4.0 test1"/><vers num="2.4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0125" published="2005-05-02" seq="2005-0125" severity="High" type="CVE"><desc><descript source="cve">The &quot;at&quot; commands on Mac OS X 10.3.7 and earlier do not properly drop privileges, which allows local users to (1) delete arbitrary files via atrm, (2) execute arbitrary programs via the -f argument to batch, or (3) read arbitrary files via the -f argument to batch, which generates a job file that is readable by the local user.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110685027017411&amp;w=2">20050127 DMA[2005-0127a] - &apos;Apple OSX batch family poor use of setuid&apos;</ref><ref adv="1" source="MISC" url="http://www.digitalmunition.com/DMA%5B2005-0127a%5D.txt">http://www.digitalmunition.com/DMA[2005-0127a].txt</ref><ref adv="1" patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/Jan/msg00001.html">APPLE-SA-2005-01-25</ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/678150">VU#678150</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18981">macos-at-gain-privileges(18981)</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.3.7"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.3.4"/><vers num="10.3.7"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0126" published="2005-05-02" seq="2005-0126" severity="High" type="CVE"><desc><descript source="cve">ColorSync on Mac OS X 10.3.7 and 10.3.8 allows attackers to execute arbitrary code via malformed ICC color profiles that modify the heap.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/Jan/msg00001.html">APPLE-SA-2005-01-25</ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/980078">VU#980078</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19083">macos-icc-profile-bo(19083)</ref><ref source="BID" url="http://www.securityfocus.com/bid/12367">12367</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013000">1013000</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.2.8"/><vers num="10.3.7"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.2.8"/><vers num="10.3.7"/><vers num="10.3.8"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0127" published="2005-05-02" seq="2005-0127" severity="Medium" type="CVE"><desc><descript source="cve">Mail in Mac OS X 10.3.7, when generating a Message-ID header, generates a GUUID that includes information that identifies the Ethernet hardware being used, which allows remote attackers to link mail messages to a particular machine.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/Jan/msg00001.html">APPLE-SA-2005-01-25</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19085">macos-ethernet-address-disclosure(19085)</ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/464662">VU#464662</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14005">14005</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013001">1013001</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.3.7"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.3.7"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0129" published="2005-04-14" seq="2005-0129" severity="High" type="CVE"><desc><descript source="cve">The Quick Buttons feature in Konversation 0.15 allows remote attackers to execute certain IRC commands via a channel name containing &quot;%&quot; variables, which are recursively expanded by the Server::parseWildcards function when the Part Button is selected.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110626383310742&amp;w=2">Multiple vulnerabilities in Konversation</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/19025">Konversation expansion execute code</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-January/031033.html">20050119 Multiple vulnerabilities in Konversation</ref><ref source="" url="http://www.kde.org/info/security/advisory-20050121-1.txt"></ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200501-34.xml">GLSA-200501-34</ref><ref source="BID" url="http://www.securityfocus.com/bid/12312">12312</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1012972">1012972</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13919">13919</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13989">13989</ref></refs><vuln_soft><prod name="Konversation" vendor="Berlios"><vers num="0.15"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0130" published="2005-04-14" seq="2005-0130" severity="High" type="CVE"><desc><descript source="cve">Certain Perl scripts in Konversation 0.15 allow remote attackers to execute arbitrary commands via shell metacharacters in (1) channel names or (2) song names that are not properly quoted when the user runs IRC sripts.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110626383310742&amp;w=2">Multiple vulnerabilities in Konversation</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/19008">Konversation Perl script may allow execution of code</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-January/031033.html">20050119 Multiple vulnerabilities in Konversation</ref><ref source="" url="http://www.kde.org/info/security/advisory-20050121-1.txt"></ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200501-34.xml">GLSA-200501-34</ref><ref source="BID" url="http://www.securityfocus.com/bid/12312">12312</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1012972">1012972</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13919">13919</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13989">13989</ref></refs><vuln_soft><prod name="Konversation" vendor="Berlios"><vers num="0.15"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0131" published="2005-04-14" seq="2005-0131" severity="Medium" type="CVE"><desc><descript source="cve">The Quick Connection dialog in Konversation 0.15 inadvertently uses the user-provided password as the nickname instead of the user-provided nickname when connecting to the IRC server, which could leak the password to other users.</descript></desc><loss_types><conf/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110626383310742&amp;w=2">Multiple vulnerabilities in Konversation</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-January/031033.html">20050119 Multiple vulnerabilities in Konversation</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19038">konversation-nick-password-information-disclosure(19038)</ref><ref source="" url="http://www.kde.org/info/security/advisory-20050121-1.txt"></ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200501-34.xml">GLSA-200501-34</ref><ref source="BID" url="http://www.securityfocus.com/bid/12312">12312</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1012972">1012972</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13919">13919</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13989">13989</ref></refs><vuln_soft><prod name="Konversation" vendor="Berlios"><vers num="0.15"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0133" published="2005-05-02" seq="2005-0133" severity="Medium" type="CVE"><desc><descript source="cve">ClamAV 0.80 and earlier allows remote attackers to cause a denial of service (clamd daemon crash) via a ZIP file with malformed headers.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref patch="1" source="CONFIRM" url="http://sourceforge.net/project/shownotes.php?release_id=300116">http://sourceforge.net/project/shownotes.php?release_id=300116</ref><ref adv="1" patch="1" source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000928">CLA-2005:928</ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200501-46.xml">GLSA-200501-46</ref><ref patch="1" source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:025">MDKSA-2005:025</ref><ref adv="1" patch="1" source="TRUSTIX" url="http://www.trustix.org/errata/2005/0003/">2005-0003</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:025">MDKSA-2005:025</ref></refs><vuln_soft><prod name="ClamAV" vendor="Clam Anti-Virus"><vers num="0.80"/><vers num="0.68.1"/><vers num="0.68"/><vers num="0.67"/><vers num="0.65"/><vers num="0.60"/><vers num="0.54"/><vers num="0.53"/><vers num="0.52"/><vers num="0.51"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0134" published="2005-05-18" seq="2005-0134" severity="Medium" type="CVE"><desc><descript source="cve">The X server in SCO UnixWare 7.1.1, 7.1.3, and 7.1.4 does not properly create socket directories in /tmp, which could allow attackers to hijack local sockets.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/0077">ADV-2005-0077</ref><ref patch="1" source="SCO" url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.8/SCOSA-2005.8.txt">SCOSA-2005.8</ref><ref patch="1" source="Secunia" url="http://secunia.com/advisories/14039/">UnixWare x.org Local Socket Hijacking Vulnerability</ref></refs><vuln_soft><prod name="Unixware" vendor="SCO"><vers num="7.1.1"/><vers num="7.1.3"/><vers num="7.1.4"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0135" published="2005-05-02" seq="2005-0135" severity="Low" type="CVE"><desc><descript source="cve">The unw_unwind_to_user function in unwind.c on Itanium (ia64) architectures in Linux kernel 2.6 allows local users to cause a denial of service (system crash).</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-366.html">RHSA-2005:366</ref><ref patch="1" source="CONFIRM" url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=148868">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=148868</ref><ref source="CONFIRM" url="http://linux.bkbits.net:8080/linux-2.6/cset@41f2beablXVnAs_6fznhhITh1j5hZg">http://linux.bkbits.net:8080/linux-2.6/cset@41f2beablXVnAs_6fznhhITh1j5hZg</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/15019">15019</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-284.html">RHSA-2005:284</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-293.html">RHSA-2005:293</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1070">DSA-1070</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1067">DSA-1067</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1069">DSA-1069</ref><ref source="BID" url="http://www.securityfocus.com/bid/13266">13266</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20163">20163</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20202">20202</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1082">DSA-1082</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20338">20338</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.6"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2005-09-29" modified="2006-06-01" name="CVE-2005-0136" published="2005-12-31" seq="2005-0136" severity="Low" type="CVE"><desc><descript source="cve">The Linux kernel before 2.6.11 on the Itanium IA64 platform has certain &quot;ptrace corner cases&quot; that allow local users to cause a denial of service (crash) via crafted syscalls, possibly related to MCA/INIT, a different vulnerability than CVE-2005-1761.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-420.html">RHSA-2005:420</ref><ref patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-663.html">RHSA-2005:663</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/17002">17002</ref><ref source="MLIST" url="http://lists.alioth.debian.org/pipermail/kernel-svn-changes/2005-August/002597.html">[kernel-svn-changes] 20050816 r3920 - in branches/dist/sarge-security: . kernel kernel/i386 kernel/source kernel/source/kernel-source-2.6.8-2.6.8/debian</ref><ref patch="1" source="MLIST" url="http://www.gelato.unsw.edu.au/archives/linux-ia64/0409/11073.html">[linux-ia64] 20040916 Re: [Patch] Per CPU MCA/INIT data save areas</ref><ref patch="1" source="" url="http://openvz.org/news/updates/kernel-022stab045.1-released"></ref><ref patch="1" source="" url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=148862"></ref><ref patch="1" source="" url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=155283"></ref><ref patch="1" source="" url="http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.11"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/1878">ADV-2005-1878</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.6.10 rc3"/><vers num="2.6.10 rc2"/><vers num="2.6.10 rc1"/><vers num="2.6.10"/><vers num="2.6.9 rc4"/><vers num="2.6.9 rc3"/><vers num="2.6.9 rc2"/><vers num="2.6.9 rc1"/><vers num="2.6.9 final"/><vers edition="2.6.20" num="2.6.9"/><vers num="2.6.8 rc4"/><vers num="2.6.8 rc3"/><vers num="2.6.8 rc2"/><vers num="2.6.8 rc1"/><vers edition="PowerPC_smp" num="2.6.8.1.5"/><vers edition="PowerPC" num="2.6.8.1.5"/><vers edition="Power4_smp" num="2.6.8.1.5"/><vers edition="Power4" num="2.6.8.1.5"/><vers edition="Power3_smp" num="2.6.8.1.5"/><vers edition="Power3" num="2.6.8.1.5"/><vers edition="K7_smp" num="2.6.8.1.5"/><vers edition="K7" num="2.6.8.1.5"/><vers edition="AMD64_Xeon" num="2.6.8.1.5"/><vers edition="AMD64_K8_smp" num="2.6.8.1.5"/><vers edition="AMD64_K8" num="2.6.8.1.5"/><vers edition="AMD64" num="2.6.8.1.5"/><vers edition="686_smp" num="2.6.8.1.5"/><vers edition="686" num="2.6.8.1.5"/><vers edition="386" num="2.6.8.1.5"/><vers num="2.6.8.1.5"/><vers num="2.6.8.1"/><vers num="2.6.8"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0137" published="2005-05-02" seq="2005-0137" severity="Low" type="CVE"><desc><descript source="cve">Linux kernel 2.6 on Itanium (ia64) architectures allows local users to cause a denial of service via a &quot;missing Itanium syscall table entry.&quot;</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-293.html">RHSA-2005:293</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-284.html">RHSA-2005:284</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0138" published="2005-09-21" seq="2005-0138" severity="High" type="CVE"><desc><descript source="cve">rpc.mountd in SGI IRIX 6.5.25, 6.5.26, and 6.5.27 does not correctly allow access to anonymous clients that connect from a system whose hostname can not be determined.  NOTE: while this issue occurs in a security mechanism, there is no apparent attacker role and probably does not satisfy the CVE definition of a vulnerability.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="CIAC" url="http://www.ciac.org/ciac/bulletins/p-214.shtml">P-214</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/0702">ADV-2005-0702</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15619">15619</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num="6.5.25"/><vers num="6.5.26"/><vers num="6.5.27"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0139" published="2005-09-21" seq="2005-0139" severity="High" type="CVE"><desc><descript source="cve">Unknown vulnerability in rpc.mountd in SGI IRIX 6.5.25, 6.5.26, and 6.5.27 does not sufficiently restrict access rights for read-mostly exports, which allows attackers to conduct unauthorized activities.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="CIAC" url="http://www.ciac.org/ciac/bulletins/p-214.shtml">P-214</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/0702">ADV-2005-0702</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15619">15619</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num="6.5.25"/><vers num="6.5.26"/><vers num="6.5.27"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0140" published="2005-05-02" seq="2005-0140" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in PeID allows attackers to execute arbitrary code via a PE file with an Import Address Table containing a long import library name.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=189&amp;type=vulnerabilities">20050124 DataRescue Interactive Disassembler Pro Buffer Overflow Vulnerability</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19042">database-ida-portable-executable-bo(19042)</ref><ref source="BID" url="http://www.securityfocus.com/bid/12355">12355</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13984">13984</ref></refs><vuln_soft><prod name="PeID" vendor="PeID"><vers num="0.92"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0141" published="2005-05-02" seq="2005-0141" severity="Low" type="CVE"><desc><descript source="cve">Firefox before 1.0 and Mozilla before 1.7.5 allow remote attackers to load local files via links &quot;with a custom getter and toString method&quot; that are middle-clicked by the user to be opened in a new tab.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="CONFIRM" url="http://www.mozilla.org/security/announce/mfsa2005-01.html">http://www.mozilla.org/security/announce/mfsa2005-01.html</ref><ref adv="1" source="CONFIRM" url="https://bugzilla.mozilla.org/show_bug.cgi?id=249332">https://bugzilla.mozilla.org/show_bug.cgi?id=249332</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-323.html">RHSA-2005:323</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-335.html">RHSA-2005:335</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19168">mozilla-firefox-file-upload(19168)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval100057.html">OVAL100057</ref><ref source="BID" url="http://www.securityfocus.com/bid/12407">12407</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100057">oval:org.mitre.oval:def:100057</ref></refs><vuln_soft><prod name="Mozilla Browser" vendor="Mozilla"><vers num="1.7 rc3"/><vers num="1.7"/><vers num="1.7.1"/><vers num="1.7.2"/><vers num="1.7.3"/></prod><prod name="Firefox" vendor="Mozilla"><vers num="0.8"/><vers num="0.9"/><vers num="0.9.1"/><vers num="0.9.2"/><vers num="0.9.3"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0142" published="2005-05-02" seq="2005-0142" severity="Low" type="CVE"><desc><descript source="cve">Firefox 0.9, Thunderbird 0.6 and other versions before 0.9, and Mozilla 1.7 before 1.7.5 save temporary files with world-readable permissions, which allows local users to read certain web content or attachments that belong to other users, e.g. content that is managed by helper applications such as PDF.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="CONFIRM" url="http://www.mozilla.org/security/announce/mfsa2005-02.html">http://www.mozilla.org/security/announce/mfsa2005-02.html</ref><ref source="CONFIRM" url="https://bugzilla.mozilla.org/show_bug.cgi?id=251297">https://bugzilla.mozilla.org/show_bug.cgi?id=251297</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-335.html">RHSA-2005:335</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17832">mozilla-world-readable(17832)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval100056.html">OVAL100056</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-384.html">RHSA-2005:384</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_04_25.html">SUSE-SA:2006:022</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19823">19823</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100056">oval:org.mitre.oval:def:100056</ref></refs><vuln_soft><prod name="Thunderbird" vendor="Mozilla"><vers num="0.6"/><vers num="0.7"/><vers num="0.8"/></prod><prod name="Mozilla Browser" vendor="Mozilla"><vers num="1.7 rc3"/><vers num="1.7"/><vers num="1.7.1"/><vers num="1.7.2"/><vers num="1.7.3"/></prod><prod name="Firefox" vendor="Mozilla"><vers num="0.9"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0143" published="2005-03-23" seq="2005-0143" severity="Low" type="CVE"><desc><descript source="cve">Firefox before 1.0 and Mozilla before 1.7.5 display the SSL lock icon when an insecure page loads a binary file from a trusted site, which could facilitate phishing attacks.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="CONFIRM" url="http://www.mozilla.org/security/announce/mfsa2005-03.html">http://www.mozilla.org/security/announce/mfsa2005-03.html</ref><ref adv="1" patch="1" source="CONFIRM" url="https://bugzilla.mozilla.org/show_bug.cgi?id=257308">https://bugzilla.mozilla.org/show_bug.cgi?id=257308</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-335.html">RHSA-2005:335</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19166">mozilla-ssl-spoofing(19166)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval100055.html">OVAL100055</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-384.html">RHSA-2005:384</ref><ref source="BID" url="http://www.securityfocus.com/bid/12407">12407</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100055">oval:org.mitre.oval:def:100055</ref></refs><vuln_soft><prod name="Mozilla" vendor="Mozilla"><vers num="1.7.5"/><vers num="1.7.3"/><vers num="1.7.2"/><vers num="1.7.1"/><vers num="1.7 rc3"/><vers num="1.7 rc2"/><vers num="1.7 rc1"/><vers num="1.7 beta"/><vers num="1.7 alpha"/><vers num="1.7"/><vers num="1.6 beta"/><vers num="1.6 alpha"/><vers num="1.6"/><vers num="1.5.1"/><vers num="1.5 rc2"/><vers num="1.5 rc1"/><vers num="1.5 alpha"/><vers num="1.5"/><vers num="1.4a"/><vers num="1.4.1"/><vers num="1.4"/><vers num="1.3"/><vers num=""/></prod><prod name="Mozilla Browser" vendor="Mozilla"><vers num="1.8 Alpha2"/><vers num="1.7.3"/><vers num="1.7.2"/><vers num="1.7.1"/><vers num="1.7 rc3"/><vers num="1.7 rc2"/><vers num="1.7 rc1"/><vers num="1.7 beta"/><vers num="1.7 alpha"/><vers num="1.7"/><vers num="1.6"/><vers num="1.5.1"/><vers num="1.5"/><vers num="1.4.4"/><vers num="1.4.2"/><vers num="1.4.1"/><vers num="1.4b"/><vers num="1.4a"/><vers num="1.4"/><vers num="1.3.1"/><vers num="1.3"/><vers num="1.2.1"/><vers num="1.2 Beta"/><vers num="1.2 Alpha"/><vers num="1.2"/><vers num="1.1 Beta"/><vers num="1.1 Alpha"/><vers num="1.1"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0 RC2"/><vers num="1.0 RC1"/><vers num="1.0"/><vers num="0.9.9"/><vers num="0.9.8"/><vers num="0.9.7"/><vers num="0.9.6"/><vers num="0.9.5"/><vers num="0.9.48"/><vers num="0.9.4.1"/><vers num="0.9.4"/><vers num="0.9.35"/><vers num="0.9.3"/><vers num="0.9.2.1"/><vers num="0.9.2"/><vers num="0.8"/></prod><prod name="Firefox" vendor="Mozilla"><vers num="1.0"/><vers num="0.9.3"/><vers num="0.9.2"/><vers num="0.9.1"/><vers edition="rc" num="0.9"/><vers num="0.9"/><vers num="0.8"/><vers num="0.10.1"/><vers num="0.10"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0144" published="2005-05-02" seq="2005-0144" severity="Low" type="CVE"><desc><descript source="cve">Firefox before 1.0 and Mozilla before 1.7.5 display the secure site lock icon when a view-source: URL references a secure SSL site while an insecure page is being loaded, which could facilitate phishing attacks.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="CONFIRM" url="http://www.mozilla.org/security/announce/mfsa2005-04.html">http://www.mozilla.org/security/announce/mfsa2005-04.html</ref><ref adv="1" source="CONFIRM" url="https://bugzilla.mozilla.org/show_bug.cgi?id=262689">https://bugzilla.mozilla.org/show_bug.cgi?id=262689</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-323.html">RHSA-2005:323</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-335.html">RHSA-2005:335</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19169">mozilla-ssl-view-source-spoofing(19169)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval100054.html">OVAL100054</ref><ref source="BID" url="http://www.securityfocus.com/bid/12407">12407</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100054">oval:org.mitre.oval:def:100054</ref></refs><vuln_soft><prod name="Mozilla Browser" vendor="Mozilla"><vers num="1.7 rc3"/><vers num="1.7"/><vers num="1.7.1"/><vers num="1.7.2"/><vers num="1.7.3"/></prod><prod name="Firefox" vendor="Mozilla"><vers num="0.8"/><vers num="0.9"/><vers num="0.9.1"/><vers num="0.9.2"/><vers num="0.9.3"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0145" published="2005-01-24" seq="2005-0145" severity="Low" type="CVE"><desc><descript source="cve">Firefox before 1.0 does not properly distinguish between user-generated and synthetic click events, which allows remote attackers to use Javascript to bypass the file download prompt when the user uses the Alt-click feature.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="CONFIRM" url="http://www.mozilla.org/security/announce/mfsa2005-07.html">http://www.mozilla.org/security/announce/mfsa2005-07.html</ref><ref adv="1" patch="1" source="CONFIRM" url="https://bugzilla.mozilla.org/show_bug.cgi?id=265176">https://bugzilla.mozilla.org/show_bug.cgi?id=265176</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19170">mozilla-script-click-event-bypass(19170)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval100051.html">OVAL100051</ref><ref source="BID" url="http://www.securityfocus.com/bid/12407">12407</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100051">oval:org.mitre.oval:def:100051</ref></refs><vuln_soft><prod name="Firefox" vendor="Mozilla"><vers num="1.0"/><vers num="0.9.3"/><vers num="0.9.2"/><vers num="0.9.1"/><vers edition="rc" num="0.9"/><vers num="0.9"/><vers num="0.8"/><vers num="0.10.1"/><vers num="0.10"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0146" published="2005-05-02" seq="2005-0146" severity="Medium" type="CVE"><desc><descript source="cve">Firefox before 1.0 and Mozilla before 1.7.5 allow remote attackers to obtain sensitive data from the clipboard via Javascript that generates a middle-click event on systems for which a middle-click performs a paste operation.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="CONFIRM" url="http://www.mozilla.org/security/announce/mfsa2005-08.html">http://www.mozilla.org/security/announce/mfsa2005-08.html</ref><ref adv="1" source="CONFIRM" url="https://bugzilla.mozilla.org/show_bug.cgi?id=265728">https://bugzilla.mozilla.org/show_bug.cgi?id=265728</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-335.html">RHSA-2005:335</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19171">mozilla-middle-click-information-disclosure(19171)</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-384.html">RHSA-2005:384</ref><ref source="BID" url="http://www.securityfocus.com/bid/12407">12407</ref></refs><vuln_soft><prod name="Mozilla Browser" vendor="Mozilla"><vers num="1.7 rc3"/><vers num="1.7"/><vers num="1.7.1"/><vers num="1.7.2"/><vers num="1.7.3"/></prod><prod name="Firefox" vendor="Mozilla"><vers num="0.8"/><vers num="0.9"/><vers num="0.9.1"/><vers num="0.9.2"/><vers num="0.9.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0147" published="2005-05-02" seq="2005-0147" severity="High" type="CVE"><desc><descript source="cve">Firefox before 1.0 and Mozilla before 1.7.5, when configured to use a proxy, respond to 407 proxy auth requests from arbitrary servers, which allows remote attackers to steal NTLM or SPNEGO credentials.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/><config/></vuln_types><range><network/></range><refs><ref adv="1" source="CONFIRM" url="http://www.mozilla.org/security/announce/mfsa2005-09.html">http://www.mozilla.org/security/announce/mfsa2005-09.html</ref><ref adv="1" source="CONFIRM" url="https://bugzilla.mozilla.org/show_bug.cgi?id=267263">https://bugzilla.mozilla.org/show_bug.cgi?id=267263</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-323.html">RHSA-2005:323</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19174">mozilla-407-proxy-obtain-information(19174)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval100049.html">OVAL100049</ref><ref source="BID" url="http://www.securityfocus.com/bid/12407">12407</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100049">oval:org.mitre.oval:def:100049</ref></refs><vuln_soft><prod name="Mozilla Browser" vendor="Mozilla"><vers num="1.7 rc3"/><vers num="1.7"/><vers num="1.7.1"/><vers num="1.7.2"/><vers num="1.7.3"/></prod><prod name="Firefox" vendor="Mozilla"><vers num="0.8"/><vers num="0.9"/><vers num="0.9.1"/><vers num="0.9.2"/><vers num="0.9.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0148" published="2005-05-02" seq="2005-0148" severity="Medium" type="CVE"><desc><descript source="cve">Thunderbird before 0.9, when running on Windows systems, uses the default handler when processing javascript: links, which invokes Internet Explorer and may expose the Thunderbird user to vulnerabilities in the version of Internet Explorer that is installed on the user&apos;s system.  NOTE: since the invocation between multiple products is a common practice, and the vulnerabilities inherent in multi-product interactions are not easily enumerable, this issue might be REJECTED in the future.</descript></desc><loss_types><int/></loss_types><vuln_types><env/></vuln_types><range><network/></range><refs><ref adv="1" source="CONFIRM" url="http://www.mozilla.org/security/announce/mfsa2005-10.html">http://www.mozilla.org/security/announce/mfsa2005-10.html</ref><ref adv="1" source="CONFIRM" url="https://bugzilla.mozilla.org/show_bug.cgi?id=263546">https://bugzilla.mozilla.org/show_bug.cgi?id=263546</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19173">thunderbird-javascript-handler-launch(19173)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval100048.html">OVAL100048</ref><ref source="BID" url="http://www.securityfocus.com/bid/12407">12407</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100048">oval:org.mitre.oval:def:100048</ref></refs><vuln_soft><prod name="Thunderbird" vendor="Mozilla"><vers num="0.6"/><vers num="0.7"/><vers num="0.8"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0149" published="2005-02-15" seq="2005-0149" severity="Medium" type="CVE"><desc><descript source="cve">Thunderbird 0.6 through 0.9 and Mozilla 1.7 through 1.7.3 does not obey the network.cookie.disableCookieForMailNews preference, which could allow remote attackers bypass the user&apos;s intended privacy and security policy by using cookies in e-mail messages.</descript></desc><loss_types><int/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CONFIRM" url="http://www.mozilla.org/security/announce/mfsa2005-11.html">http://www.mozilla.org/security/announce/mfsa2005-11.html</ref><ref adv="1" patch="1" source="CONFIRM" url="https://bugzilla.mozilla.org/show_bug.cgi?id=268107">https://bugzilla.mozilla.org/show_bug.cgi?id=268107</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-094.html">RHSA-2005:094</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-323.html">RHSA-2005:323</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-335.html">RHSA-2005:335</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19172">mozilla-cookie-policy-bypass(19172)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval100047.html">OVAL100047</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_04_25.html">SUSE-SA:2006:022</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19823">19823</ref><ref source="BID" url="http://www.securityfocus.com/bid/12407">12407</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100047">oval:org.mitre.oval:def:100047</ref></refs><vuln_soft><prod name="Mozilla" vendor="Mozilla"><vers num="1.7.3"/><vers num="1.7.2"/><vers num="1.7.1"/><vers num="1.7 rc3"/><vers num="1.7 rc2"/><vers num="1.7 rc1"/><vers num="1.7 beta"/><vers num="1.7 alpha"/><vers num="1.7"/></prod><prod name="Thunderbird" vendor="Mozilla"><vers num="0.9"/><vers num="0.7.3"/><vers num="0.7.2"/><vers num="0.7.1"/><vers num="0.7"/><vers num="0.6"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0150" published="2005-05-26" seq="2005-0150" severity="Medium" type="CVE"><desc><descript source="cve">Firefox before 1.0 allows the user to store a (1) javascript: or (2) data: URLs as a Livefeed bookmark, then executes it in the security context of the currently loaded page when the user later accesses the bookmark, which could allow remote attackers to execute arbitrary code.</descript></desc><loss_types><int/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CONFIRM" url="http://www.mozilla.org/security/announce/mfsa2005-12.html">http://www.mozilla.org/security/announce/mfsa2005-12.html</ref><ref adv="1" patch="1" source="CONFIRM" url="https://bugzilla.mozilla.org/show_bug.cgi?id=265668">https://bugzilla.mozilla.org/show_bug.cgi?id=265668</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19187">mozilla-firefox-livefeed-xss(19187)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval100046.html">OVAL100046</ref><ref source="BID" url="http://www.securityfocus.com/bid/12407">12407</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100046">oval:org.mitre.oval:def:100046</ref></refs><vuln_soft><prod name="Firefox" vendor="Mozilla"><vers num="1.0"/><vers num="0.9.3"/><vers num="0.9.2"/><vers num="0.9.1"/><vers edition="rc" num="0.9"/><vers num="0.9"/><vers num="0.8"/><vers num="0.10.1"/><vers num="0.10"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0151" published="2005-06-13" seq="2005-0151" severity="High" type="CVE"><desc><descript source="cve">Unknown vulnerability in the installation of Adobe License Management Service, as used in Adobe Photoshop CS, Adobe Creative Suite 1.0, and Adobe Premiere Pro 1.5, allows attackers to gain administrator privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CONFIRM" url="http://www.adobe.com/support/techdocs/331688.html">http://www.adobe.com/support/techdocs/331688.html</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014168">1014168</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014169">1014169</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014170">1014170</ref></refs><vuln_soft><prod name="Premiere Pro" vendor="Adobe"><vers num="1.5"/></prod><prod name="Photoshop" vendor="Adobe"><vers num="CS"/></prod><prod name="Creative Suite" vendor="Adobe"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-28" name="CVE-2005-0152" published="2005-02-02" seq="2005-0152" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in Squirrelmail 1.2.6 allows remote attackers to execute arbitrary code via &quot;URL manipulation.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-662">DSA-662</ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/203214">VU#203214</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14096">14096</ref></refs><vuln_soft><prod name="SquirrelMail" vendor="SquirrelMail"><vers num="1.2.6"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0155" published="2005-05-02" seq="2005-0155" severity="Medium" type="CVE"><desc><descript source="cve">The PerlIO implementation in Perl 5.8.0, when installed with setuid support (sperl), allows local users to create arbitrary files via the PERLIO_DEBUG variable.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/><config/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=110779723332339&amp;w=2">20050207 DMA[2005-0131a] - &apos;Setuid Perl PERLIO_DEBUG root owned file creation&apos;</ref><ref adv="1" source="MISC" url="http://www.digitalmunition.com/DMA%5B2005-0131a%5D.txt">http://www.digitalmunition.com/DMA[2005-0131a].txt</ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200502-13.xml">GLSA-200502-13</ref><ref patch="1" source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:031">MDKSA-2005:031</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-103.html">RHSA-2005:103</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-105.html">RHSA-2005:105</ref><ref patch="1" source="TRUSTIX" url="http://www.trustix.org/errata/2005/0003/">2005-0003</ref><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110737149402683&amp;w=2">20050202 [USN-72-1] Perl vulnerabilities</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/12426">12426</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19207">perl-perliodebug-file-overwrite(19207)</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14120">14120</ref><ref source="FEDORA" url="http://fedoranews.org/updates/FEDORA--.shtml">FLSA-2006:152845</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=001056">CLSA-2006:1056</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-163.htm"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/21646">21646</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:031">MDKSA-2005:031</ref></refs><vuln_soft><prod name="Perl" vendor="Larry Wall"><vers num="5.8.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0156" published="2005-02-07" seq="2005-0156" severity="Low" type="CVE"><desc><descript source="cve">Buffer overflow in the PerlIO implementation in Perl 5.8.0, when installed with setuid support (sperl), allows local users to execute arbitrary code by setting the PERLIO_DEBUG variable and executing a Perl script whose full pathname contains a long directory tree.</descript></desc><loss_types><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=110779721503111&amp;w=2">20050207 DMA[2005-0131b] - &apos;Setuid Perl PERLIO_DEBUG</ref><ref adv="1" source="MISC" url="http://www.digitalmunition.com/DMA%5B2005-0131b%5D.txt">http://www.digitalmunition.com/DMA[2005-0131b].txt</ref><ref adv="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200502-13.xml">GLSA-200502-13</ref><ref adv="1" patch="1" source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:031">MDKSA-2005:031</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-103.html">RHSA-2005:103</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-105.html">RHSA-2005:105</ref><ref adv="1" patch="1" source="TRUSTIX" url="http://www.trustix.org/errata/2005/0003/">2005-0003</ref><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110737149402683&amp;w=2">20050202 [USN-72-1] Perl vulnerabilities</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/12426">12426</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19208">perl-perliodebug-bo(19208)</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14120">14120</ref><ref source="FEDORA" url="http://fedoranews.org/updates/FEDORA--.shtml">FLSA-2006:152845</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=001056">CLSA-2006:1056</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:031">MDKSA-2005:031</ref></refs><vuln_soft><prod name="Enterprise Linux" vendor="Red Hat"><vers edition="Workstation Server" num="3.0"/><vers edition="Enterprise Server" num="3.0"/><vers edition="Advanced Server" num="3.0"/></prod><prod name="SuSE Linux" vendor="SuSE"><vers num="9.2"/><vers num="9.1"/><vers edition="x86_64" num="9.0"/><vers num="9.0"/><vers num="8.2"/><vers num="8.1"/><vers edition="i386" num="8.0"/><vers num="8.0"/></prod><prod name="Perl" vendor="Larry Wall"><vers num="5.8.4.5"/><vers num="5.8.4.4"/><vers num="5.8.4.3"/><vers num="5.8.4.2.3"/><vers num="5.8.4.2"/><vers num="5.8.4.1"/><vers num="5.8.4"/><vers num="5.8.3"/><vers num="5.8.1"/><vers num="5.8.0"/></prod><prod name="Secure Enterprise Linux" vendor="Trustix"><vers num="2.0"/></prod><prod name="Fedora" vendor="Red Hat"><vers num="Core 3.0"/></prod><prod name="Desktop" vendor="Red Hat"><vers num="3.0"/></prod><prod name="Secure Linux" vendor="Trustix"><vers num="2.2"/><vers num="2.1"/><vers num="1.5"/></prod><prod name="Ubuntu Linux" vendor="Ubuntu"><vers edition="ppc" num="4.1"/><vers edition="ia64" num="4.1"/><vers edition="ia64" num="4.1"/></prod><prod name="AIX" vendor="IBM"><vers num="5.3"/><vers num="5.2"/></prod><prod name="ProPack" vendor="SGI"><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0157" published="2005-05-03" seq="2005-0157" severity="High" type="CVE"><desc><descript source="cve">The confirm add-on in SmartList 3.15 and earlier allows attackers to subscribe arbitrary e-mail addresses by using a valid cookie that specifies an address other than the address for which the cookie was assigned.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-720">DSA-720</ref><ref source="Security Focus" url="http://www.securityfocus.org/bid/13474">SmartList ListManager Arbitrary List Addition Vulnerability</ref></refs><vuln_soft><prod name="Smartlist" vendor="Smartlist"><vers num="3.15" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0158" published="2005-05-02" seq="2005-0158" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in bidwatcher before 1.3.17 allows remote malicious web servers from eBay, or a spoofed eBay server, to cause a denial of service and possibly execute arbitrary code via certain responses.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-687">DSA-687</ref><ref patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200503-06.xml">GLSA-200503-06</ref></refs><vuln_soft><prod name="bidwatcher" vendor="Bidwatcher"><vers num="1.3.16"/><vers num="1.3.15"/><vers num="1.3.14"/><vers num="1.3.13"/><vers num="1.3.12"/><vers num="1.3.11"/><vers num="1.3.10"/><vers num="1.3.9"/><vers num="1.3.8"/><vers num="1.3.7"/><vers num="1.3.6"/><vers num="1.3.5"/><vers num="1.3.4"/><vers num="1.3.3"/><vers num="1.3.2"/><vers num="1.3.1"/><vers num="1.3.0 beta"/><vers num="1.2.0"/><vers num="1.1.9.2"/><vers num="1.1.9.1"/><vers num="1.1.9"/><vers num="1.1.8"/><vers num="1.1.7"/><vers num="1.1.2"/><vers num="1.0.5"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0159" published="2005-04-27" seq="2005-0159" severity="Medium" type="CVE"><desc><descript source="cve">The tpkg-* scripts in the toolchain-source 3.0.4 package on Debian GNU/Linux 3.0 allow local users to overwrite arbitrary files via a symlink attack on temporary files.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2005/dsa-679">toolchain-source -- insecure temporary files</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/12540">bid 12540</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19317">toolchain-source-symlink(19317)</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14277">14277</ref></refs><vuln_soft><prod name="Debian Linux" vendor="Debian"><vers num="3.0 sparc"/><vers num="3.0 s_390"/><vers num="3.0 ppc"/><vers num="3.0 mipsel"/><vers num="3.0 mips"/><vers num="3.0 m68k"/><vers num="3.0 ia-64"/><vers num="3.0 ia-32"/><vers num="3.0 hppa"/><vers num="3.0 arm"/><vers num="3.0 alpha"/><vers num="3.0"/></prod><prod name="toolchain-source" vendor="Debian"><vers num="3.0.3.3"/><vers num="3.0.3.2"/><vers num="3.0.3.1"/><vers num="3.0.4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0160" published="2005-02-22" seq="2005-0160" severity="Medium" type="CVE"><desc><descript source="cve">Multiple buffer overflows in unace 1.2b allow attackers to execute arbitrary code via (1) 2 overflows in ACE archives, (2) a long command line argument, or (3) certain &quot;Ready for next volume&quot; messages.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-February/031908.html">20050222 unace-1.2b multiple buffer overflows and directory traversal bugs</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/14359">14359</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_16_sr.html">SUSE-SR:2005:016</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/215006">VU#215006</ref><ref source="BID" url="http://www.securityfocus.com/bid/12630">12630</ref></refs><vuln_soft><prod name="unace" vendor="e-merge"><vers num="1.2b"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0161" published="2005-02-22" seq="2005-0161" severity="Low" type="CVE"><desc><descript source="cve">Multiple directory traversal vulnerabilities in unace 1.2b allow attackers to overwrite arbitrary files via an ACE archive containing (1) ../ sequences or (2) absolute pathnames.</descript></desc><loss_types><int/></loss_types><vuln_types><access/><input/></vuln_types><range><local/></range><refs><ref adv="1" source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-February/031908.html">20050222 unace-1.2b multiple buffer overflows and directory traversal bugs</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/14359">14359</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_16_sr.html">SUSE-SR:2005:016</ref><ref source="BID" url="http://www.securityfocus.com/bid/12628">12628</ref></refs><vuln_soft><prod name="unace" vendor="e-merge"><vers num="1.2b"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0162" published="2005-01-26" seq="2005-0162" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in the get_internal_addresses function in the pluto application for Openswan 1.x before 1.0.9, and Openswan 2.x before 2.3.0, when compiled with XAUTH and PAM enabled, allows remote authenticated attackers to execute arbitrary code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=190&amp;type=vulnerabilities">20050126 Openswan XAUTH/PAM Buffer Overflow Vulnerability</ref><ref adv="1" patch="1" source="CONFIRM" url="http://www.openswan.org/support/vuln/IDEF0785/">http://www.openswan.org/support/vuln/IDEF0785/</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19078">openswan-xauth-pam-bo(19078)</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-announce-list/2005-January/msg00103.html">FEDORA-2005-082</ref><ref source="BID" url="http://www.securityfocus.com/bid/12377">12377</ref><ref source="OSVDB" url="http://www.osvdb.org/13195">13195</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013014">1013014</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14038">14038</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14062">14062</ref></refs><vuln_soft><prod name="openswan" vendor="Openswan"><vers num="1.0.9" prev="1"/><vers num="2.3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0173" published="2005-05-02" seq="2005-0173" severity="High" type="CVE"><desc><descript source="cve">squid_ldap_auth in Squid 2.5 and earlier allows remote authenticated users to bypass username-based Access Control Lists (ACLs) via a username with a space at the beginning or end, which is ignored by the LDAP server.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/><input/></vuln_types><range><network/></range><refs><ref patch="1" source="CONFIRM" url="http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE7-ldap_spaces">http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE7-ldap_spaces</ref><ref source="CONFIRM" url="http://www.squid-cache.org/bugs/show_bug.cgi?id=1187">http://www.squid-cache.org/bugs/show_bug.cgi?id=1187</ref><ref patch="1" source="CONFIRM" url="http://www.squid-cache.org/Versions/v2/2.5/bugs/squid-2.5.STABLE7-ldap_spaces.patch">http://www.squid-cache.org/Versions/v2/2.5/bugs/squid-2.5.STABLE7-ldap_spaces.patch</ref><ref patch="1" source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000923">CLA-2005:923</ref><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-667">DSA-667</ref><ref patch="1" source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:034">MDKSA-2005:034</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-060.html">RHSA-2005:060</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-061.html">RHSA-2005:061</ref><ref adv="1" patch="1" source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_06_squid.html">SUSE-SA:2005:006</ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/924198">VU#924198</ref><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110780531820947&amp;w=2">20050207 [USN-77-1] Squid vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/12431">12431</ref><ref source="FEDORA" url="http://fedoranews.org/updates/FEDORA--.shtml">FLSA-2006:152809</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:034">MDKSA-2005:034</ref></refs><vuln_soft><prod name="Squid" vendor="Squid"><vers num="2.5.STABLE6"/><vers num="2.5.STABLE5"/><vers num="2.5.STABLE4"/><vers num="2.5.STABLE3"/><vers num="2.5.STABLE2"/><vers num="2.5.STABLE1"/><vers num="2.4.STABLE7"/><vers num="2.4.STABLE6"/><vers num="2.4.STABLE4"/><vers num="2.4.STABLE3"/><vers num="2.4.STABLE2"/><vers num="2.4.STABLE1"/><vers num="2.3.DEVEL2"/><vers num="2.3.DEVEL3"/><vers num="2.3.STABLE1"/><vers num="2.3.STABLE2"/><vers num="2.3.STABLE3"/><vers num="2.3.STABLE4"/><vers num="2.3.STABLE5"/><vers num="2.2.PRE1"/><vers num="2.2.PRE2"/><vers num="2.2.DEVEL3"/><vers num="2.2.DEVEL4"/><vers num="2.2.STABLE1"/><vers num="2.2.STABLE2"/><vers num="2.2.STABLE3"/><vers num="2.2.STABLE4"/><vers num="2.2.STABLE5"/><vers num="2.1.PRE1"/><vers num="2.1.PRE3"/><vers num="2.1.PRE4"/><vers num="2.1.RELEASE"/><vers num="2.1.PATCH1"/><vers num="2.1.PATCH2"/><vers num="2.0.PRE1"/><vers num="2.0.RELEASE"/><vers num="2.0.PATCH1"/><vers num="2.0.PATCH2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0174" published="2005-02-07" seq="2005-0174" severity="Medium" type="CVE"><desc><descript source="cve">Squid 2.5 up to 2.5.STABLE7 allows remote attackers to poison the cache or conduct certain attacks via headers that do not follow the HTTP specification, including (1) multiple Content-Length headers, (2) carriage return (CR) characters that are not part of a CRLF pair, and (3) header names containing whitespace characters.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="CONFIRM" url="http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE7-header_parsing">http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE7-header_parsing</ref><ref adv="1" source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000931">CLA-2005:931</ref><ref adv="1" patch="1" source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:034">MDKSA-2005:034</ref><ref patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-060.html">RHSA-2005:060</ref><ref patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-061.html">RHSA-2005:061</ref><ref adv="1" source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_06_squid.html">SUSE-SA:2005:006</ref><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110780531820947&amp;w=2">20050207 [USN-77-1] Squid vulnerabilities</ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/768702">VU#768702</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-announce-list/2005-May/msg00025.html">FEDORA-2005-373</ref><ref source="FEDORA" url="http://fedoranews.org/updates/FEDORA--.shtml">FLSA-2006:152809</ref><ref source="BID" url="http://www.securityfocus.com/bid/12412">12412</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:034">MDKSA-2005:034</ref></refs><vuln_soft><prod name="Squid" vendor="Squid"><vers num="2.5.STABLE7"/><vers num="2.5.STABLE6"/><vers num="2.5.STABLE5"/><vers num="2.5.STABLE4"/><vers num="2.5.STABLE3"/><vers num="2.5.STABLE2"/><vers num="2.5.STABLE1"/><vers num="2.5.6"/><vers num="2.5 Stable9"/><vers num="2.5 STABLE4"/><vers num="2.5 STABLE3"/><vers num="2.5 .STABLE6"/><vers num="2.5 .STABLE5"/><vers num="2.5 .STABLE4"/><vers num="2.5 .STABLE3"/><vers num="2.5 .STABLE1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0175" published="2005-02-07" seq="2005-0175" severity="Medium" type="CVE"><desc><descript source="cve">Squid 2.5 up to 2.5.STABLE7 allows remote attackers to poison the cache via an HTTP response splitting attack.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="CONFIRM" url="http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE7-response_splitting">http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE7-response_splitting</ref><ref adv="1" patch="1" source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000931">CLA-2005:931</ref><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-667">DSA-667</ref><ref adv="1" patch="1" source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:034">MDKSA-2005:034</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-060.html">RHSA-2005:060</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-061.html">RHSA-2005:061</ref><ref adv="1" patch="1" source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_06_squid.html">SUSE-SA:2005:006</ref><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110780531820947&amp;w=2">20050207 [USN-77-1] Squid vulnerabilities</ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/625878">VU#625878</ref><ref adv="1" source="CONFIRM" url="http://www.squid-cache.org/Advisories/SQUID-2005_5.txt">http://www.squid-cache.org/Advisories/SQUID-2005_5.txt</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-announce-list/2005-May/msg00025.html">FEDORA-2005-373</ref><ref source="FEDORA" url="http://fedoranews.org/updates/FEDORA--.shtml">FLSA-2006:152809</ref><ref source="BID" url="http://www.securityfocus.com/bid/12433">12433</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:034">MDKSA-2005:034</ref></refs><vuln_soft><prod name="Squid" vendor="Squid"><vers num="2.5.STABLE7"/><vers num="2.5.STABLE6"/><vers num="2.5.STABLE5"/><vers num="2.5.STABLE4"/><vers num="2.5.STABLE3"/><vers num="2.5.STABLE2"/><vers num="2.5.STABLE1"/><vers num="2.5.6"/><vers num="2.5 Stable9"/><vers num="2.5 STABLE4"/><vers num="2.5 STABLE3"/><vers num="2.5 .STABLE6"/><vers num="2.5 .STABLE5"/><vers num="2.5 .STABLE4"/><vers num="2.5 .STABLE3"/><vers num="2.5 .STABLE1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0176" published="2005-02-15" seq="2005-0176" severity="Medium" type="CVE"><desc><descript source="cve">The shmctl function in Linux 2.6.9 and earlier allows local users to unlock the memory of other processes, which could cause sensitive memory to be swapped to disk, which could allow it to be read by other users once it has been released.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=110846102231365&amp;w=2">20050215 [USN-82-1] Linux kernel vulnerabilities</ref><ref adv="1" source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/index.php?id=a&amp;anuncio=000930">CLA-2005:930</ref><ref adv="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-092.html">RHSA-2005:092</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1225.html">OVAL1225</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-472.html">RHSA-2005:472</ref><ref source="BID" url="http://www.securityfocus.com/bid/12598">12598</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1225">oval:org.mitre.oval:def:1225</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20060402-01-U">
20060402-01-U</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19607">
19607</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.6.9"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2008-06-24" name="CVE-2005-0177" published="2005-03-07" seq="2005-0177" severity="High" type="CVE"><desc><descript source="cve">nls_ascii.c in Linux before 2.6.8.1 uses an incorrect table size, which allows attackers to cause a denial of service (kernel crash) via a buffer overflow.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CONFIRM" url="http://linux.bkbits.net:8080/linux-2.6/cset@41e2bfbeOiXFga62XrBhzm7Kv9QDmQ">http://linux.bkbits.net:8080/linux-2.6/cset@41e2bfbeOiXFga62XrBhzm7Kv9QDmQ</ref><ref adv="1" patch="1" source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/index.php?id=a&amp;anuncio=000930">CLA-2005:930</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-092.html">RHSA-2005:092</ref><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=110846102231365&amp;w=2">20050215 [USN-82-1] Linux kernel vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/12598">12598</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.6.8.1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.2" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="10.0" CVSS_score="6.2" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-05-16" name="CVE-2005-0178" published="2005-03-07" seq="2005-0178" severity="Medium" type="CVE"><desc><descript source="cve">Race condition in the setsid function in Linux before 2.6.8.1 allows local users to cause a denial of service (crash) and possibly access portions of kernel memory, related to TTY changes, locking, and semaphores.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><race/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CONFIRM" url="http://linux.bkbits.net:8080/linux-2.6/cset@41ddda70CWJb5nNL71T4MOlG2sMG8A">http://linux.bkbits.net:8080/linux-2.6/cset@41ddda70CWJb5nNL71T4MOlG2sMG8A</ref><ref adv="1" source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/index.php?id=a&amp;anuncio=000930">CLA-2005:930</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-092.html">RHSA-2005:092</ref><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=110846102231365&amp;w=2">20050215 [USN-82-1] Linux kernel vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/12598">12598</ref></refs><vuln_soft><prod name="Linux-VServer" vendor="VServer"><vers num="1.24"/><vers num="1.23"/><vers num="1.22"/><vers num="1.21"/><vers num="1.20"/></prod><prod name="Linux Netkit" vendor="Netkit"><vers num="0.17.17"/><vers num="0.17"/></prod><prod name="Kernel" vendor="Linux"><vers num="2.6.8 rc3"/><vers num="2.6.8 rc2"/><vers num="2.6.8 rc1"/><vers num="2.6.8"/><vers num="2.6.7 rc1"/><vers num="2.6.7"/><vers num="2.6.6 rc1"/><vers num="2.6.6"/><vers num="2.6.5"/><vers num="2.6.4"/><vers num="2.6.3"/><vers num="2.6.2"/><vers num="2.6.1 rc2"/><vers num="2.6.1 rc1"/><vers num="2.6.12 rc4"/><vers num="2.6.12 rc1"/><vers num="2.6.11.7"/><vers num="2.6.11.6"/><vers num="2.6.11.5"/><vers num="2.6.11.4"/><vers num="2.6.11.3"/><vers num="2.6.11.2"/><vers num="2.6.11.1"/><vers num="2.6.11 rc4"/><vers num="2.6.11 rc3"/><vers num="2.6.11 rc2"/><vers num="2.6.11.8"/><vers num="2.6.11"/><vers num="2.6.10 rc2"/><vers num="2.6.10"/><vers num="2.6.1"/><vers num="2.6.0"/><vers num="2.6 test9 CVS"/><vers num="2.6 test9"/><vers num="2.6 test8"/><vers num="2.6 test7"/><vers num="2.6 test6"/><vers num="2.6 test5"/><vers num="2.6 test4"/><vers num="2.6 test3"/><vers num="2.6 test2"/><vers num="2.6 test11"/><vers num="2.6 test10"/><vers num="2.6 test1"/><vers num="2.6"/><vers num="2.5.9"/><vers num="2.5.8"/><vers num="2.5.7"/><vers num="2.5.69"/><vers num="2.5.68"/><vers num="2.5.67"/><vers num="2.5.66"/><vers num="2.5.65"/><vers num="2.5.64"/><vers num="2.5.63"/><vers num="2.5.62"/><vers num="2.5.61"/><vers num="2.5.60"/><vers num="2.5.6"/><vers num="2.5.59"/><vers num="2.5.58"/><vers num="2.5.57"/><vers num="2.5.56"/><vers num="2.5.55"/><vers num="2.5.54"/><vers num="2.5.53"/><vers num="2.5.52"/><vers num="2.5.51"/><vers num="2.5.50"/><vers num="2.5.5"/><vers num="2.5.49"/><vers num="2.5.48"/><vers num="2.5.47"/><vers num="2.5.46"/><vers num="2.5.45"/><vers num="2.5.44"/><vers num="2.5.43"/><vers num="2.5.42"/><vers num="2.5.41"/><vers num="2.5.40"/><vers num="2.5.4"/><vers num="2.5.39"/><vers num="2.5.38"/><vers num="2.5.37"/><vers num="2.5.36"/><vers num="2.5.35"/><vers num="2.5.34"/><vers num="2.5.33"/><vers num="2.5.32"/><vers num="2.5.31"/><vers num="2.5.30"/><vers num="2.5.3"/><vers num="2.5.29"/><vers num="2.5.28"/><vers num="2.5.27"/><vers num="2.5.26"/><vers num="2.5.25"/><vers num="2.5.24"/><vers num="2.5.23"/><vers num="2.5.22"/><vers num="2.5.21"/><vers num="2.5.20"/><vers num="2.5.2"/><vers num="2.5.19"/><vers num="2.5.18"/><vers num="2.5.17"/><vers num="2.5.16"/><vers num="2.5.15"/><vers num="2.5.14"/><vers num="2.5.13"/><vers num="2.5.12"/><vers num="2.5.11"/><vers num="2.5.10"/><vers num="2.5.1"/><vers num="2.5.0"/><vers num="2.4.9"/><vers num="2.4.8"/><vers num="2.4.7"/><vers num="2.4.6"/><vers num="2.4.5"/><vers num="2.4.4"/><vers num="2.4.3 pre3"/><vers num="2.4.31 pre1"/><vers num="2.4.30 rc3"/><vers num="2.4.30 rc2"/><vers num="2.4.30"/><vers num="2.4.3"/><vers num="2.4.29 rc2"/><vers num="2.4.29 rc1"/><vers num="2.4.29"/><vers num="2.4.28"/><vers num="2.4.27 pre5"/><vers num="2.4.27 pre4"/><vers num="2.4.27 pre3"/><vers num="2.4.27 pre2"/><vers num="2.4.27 pre1"/><vers num="2.4.27"/><vers num="2.4.26"/><vers num="2.4.25"/><vers num="2.4.24 ow1"/><vers num="2.4.24"/><vers num="2.4.23 pre9"/><vers num="2.4.23 ow2"/><vers num="2.4.23"/><vers num="2.4.22 pre10"/><vers num="2.4.22"/><vers num="2.4.21 pre7"/><vers num="2.4.21 pre4"/><vers num="2.4.21 pre1"/><vers num="2.4.21"/><vers num="2.4.20"/><vers num="2.4.2"/><vers num="2.4.19 pre6"/><vers num="2.4.19 pre5"/><vers num="2.4.19 pre4"/><vers num="2.4.19 pre3"/><vers num="2.4.19 pre2"/><vers num="2.4.19 pre1"/><vers num="2.4.19"/><vers edition="x86" num="2.4.18"/><vers num="2.4.18 pre8"/><vers num="2.4.18 pre7"/><vers num="2.4.18 pre6"/><vers num="2.4.18 pre5"/><vers num="2.4.18 pre4"/><vers num="2.4.18 pre3"/><vers num="2.4.18 pre2"/><vers num="2.4.18 pre1"/><vers num="2.4.18"/><vers num="2.4.17"/><vers num="2.4.16"/><vers num="2.4.15"/><vers num="2.4.14"/><vers num="2.4.13"/><vers num="2.4.12"/><vers num="2.4.11"/><vers num="2.4.10"/><vers num="2.4.1"/><vers num="2.4.0 test9"/><vers num="2.4.0 test8"/><vers num="2.4.0 test7"/><vers num="2.4.0 test6"/><vers num="2.4.0 test5"/><vers num="2.4.0 test4"/><vers num="2.4.0 test3"/><vers num="2.4.0 test2"/><vers num="2.4.0 test12"/><vers num="2.4.0 test11"/><vers num="2.4.0 test10"/><vers num="2.4.0 test1"/><vers num="2.4.0"/><vers num="2.3.99 pre7"/><vers num="2.3.99 pre6"/><vers num="2.3.99 pre5"/><vers num="2.3.99 pre4"/><vers num="2.3.99 pre3"/><vers num="2.3.99 pre2"/><vers num="2.3.99 pre1"/><vers num="2.3.99"/><vers num="2.3"/><vers num="2.2.9"/><vers num="2.2.8"/><vers num="2.2.7"/><vers num="2.2.6"/><vers num="2.2.5"/><vers num="2.2.4"/><vers num="2.2.3"/><vers num="2.2.27 rc2"/><vers num="2.2.25"/><vers num="2.2.24"/><vers num="2.2.23"/><vers num="2.2.22"/><vers num="2.2.21"/><vers num="2.2.20"/><vers num="2.2.2"/><vers num="2.2.19"/><vers num="2.2.18"/><vers num="2.2.17"/><vers num="2.2.16 pre6"/><vers num="2.2.16"/><vers num="2.2.15 pre20"/><vers num="2.2.15 pre16"/><vers num="2.2.15"/><vers num="2.2.14"/><vers num="2.2.13"/><vers num="2.2.12"/><vers num="2.2.11"/><vers num="2.2.10"/><vers num="2.2.1"/><vers num="2.2"/><vers num="2.1.89"/><vers num="2.1"/><vers num="2.0.9.9"/><vers num="2.0.9"/><vers num="2.0.8"/><vers num="2.0.7"/><vers num="2.0.6"/><vers num="2.0.5"/><vers num="2.0.4"/><vers num="2.0.39"/><vers num="2.0.38"/><vers num="2.0.37"/><vers num="2.0.36"/><vers num="2.0.35"/><vers num="2.0.34"/><vers num="2.0.33"/><vers num="2.0.32"/><vers num="2.0.31"/><vers num="2.0.30"/><vers num="2.0.3"/><vers num="2.0.29"/><vers num="2.0.28"/><vers num="2.0.27"/><vers num="2.0.26"/><vers num="2.0.25"/><vers num="2.0.24"/><vers num="2.0.23"/><vers num="2.0.22"/><vers num="2.0.21"/><vers num="2.0.20"/><vers num="2.0.2"/><vers num="2.0.19"/><vers num="2.0.18"/><vers num="2.0.17"/><vers num="2.0.16"/><vers num="2.0.15"/><vers num="2.0.14"/><vers num="2.0.13"/><vers num="2.0.12"/><vers num="2.0.11"/><vers num="2.0.10"/><vers num="2.0.1"/><vers num="2.0"/><vers num="2.6.20.1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0179" published="2005-03-07" seq="2005-0179" severity="Low" type="CVE"><desc><descript source="cve">Linux kernel 2.4.x and 2.6.x allows local users to cause a denial of service (CPU and memory consumption) and bypass RLIM_MEMLOCK limits via the mlockall call.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><local/></range><refs><ref adv="1" source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-January/030660.html">20050107 grsecurity 2.1.0 release / 5 Linux kernel advisories</ref><ref adv="1" source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/index.php?id=a&amp;anuncio=000930">CLA-2005:930</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-092.html">RHSA-2005:092</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-663.html">RHSA-2005:663</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17002">17002</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/1878">ADV-2005-1878</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers edition="2.6.20" num="2.6.9"/><vers num="2.6.8.1"/><vers num="2.6.8-rc3"/><vers num="2.6.8-rc2"/><vers num="2.6.8-rc1"/><vers num="2.6.8"/><vers num="2.6.7 rc1"/><vers num="2.6.7"/><vers num="2.6.6-rc1"/><vers num="2.6.6"/><vers num="2.6.5"/><vers num="2.6.4"/><vers num="2.6.3"/><vers num="2.6.2"/><vers num="2.6.12-rc4"/><vers num="2.6.12-rc1"/><vers num="2.6.12 -rc4"/><vers num="2.6.11.4"/><vers num="2.6.11.3"/><vers num="2.6.11.2"/><vers num="2.6.11.1"/><vers num="2.6.11-rc4"/><vers num="2.6.11-rc3"/><vers num="2.6.11-rc2"/><vers num="2.6.11.8"/><vers num="2.6.11.7"/><vers num="2.6.11.6"/><vers num="2.6.11.5"/><vers num="2.6.11"/><vers num="2.6.10-rc2"/><vers num="2.6.1-rc2"/><vers num="2.6.1-rc1"/><vers num="2.6.1"/><vers num="2.6.0"/><vers num="2.6 test 9 CVS"/><vers num="2.6-test9"/><vers num="2.6-test8"/><vers num="2.6-test7"/><vers num="2.6-test6"/><vers num="2.6-test5"/><vers num="2.6-test4"/><vers num="2.6-test3"/><vers num="2.6-test2"/><vers num="2.6-test11"/><vers num="2.6-test10"/><vers num="2.6-test1"/><vers num="2.6.10"/><vers num="2.6"/><vers num="2.4.9"/><vers num="2.4.8"/><vers num="2.4.7"/><vers num="2.4.6"/><vers num="2.4.5"/><vers num="2.4.4"/><vers num="2.4.3-pre3"/><vers num="2.4.31-pre1"/><vers num="2.4.30-rc3"/><vers num="2.4.30-rc2"/><vers num="2.4.30"/><vers num="2.4.3"/><vers num="2.4.29-rc2"/><vers num="2.4.29-rc1"/><vers num="2.4.29"/><vers num="2.4.28"/><vers num="2.4.27-pre5"/><vers num="2.4.27-pre4"/><vers num="2.4.27-pre3"/><vers num="2.4.27-pre2"/><vers num="2.4.27-pre1"/><vers num="2.4.27"/><vers num="2.4.26"/><vers num="2.4.25"/><vers num="2.4.24-ow1"/><vers num="2.4.24"/><vers num="2.4.23-pre9"/><vers num="2.4.23-ow2"/><vers num="2.4.23"/><vers num="2.4.22-pre10"/><vers num="2.4.22"/><vers num="2.4.21-pre7"/><vers num="2.4.21-pre4"/><vers num="2.4.21-pre1"/><vers num="2.4.21"/><vers num="2.4.20"/><vers num="2.4.2"/><vers num="2.4.19-pre6"/><vers num="2.4.19-pre5"/><vers num="2.4.19-pre4"/><vers num="2.4.19-pre3"/><vers num="2.4.19-pre2"/><vers num="2.4.19-pre1"/><vers num="2.4.19"/><vers num="2.4.18-x86"/><vers num="2.4.18-pre-8"/><vers num="2.4.18-pre-7"/><vers num="2.4.18-pre-6"/><vers num="2.4.18-pre-5"/><vers num="2.4.18-pre-4"/><vers num="2.4.18-pre-3"/><vers num="2.4.18-pre-2"/><vers num="2.4.18-pre-1"/><vers num="2.4.18"/><vers num="2.4.17"/><vers num="2.4.16"/><vers num="2.4.15"/><vers num="2.4.14"/><vers num="2.4.13"/><vers num="2.4.12"/><vers num="2.4.11"/><vers num="2.4.10"/><vers num="2.4.1"/><vers num="2.4.0-test9"/><vers num="2.4.0-test8"/><vers num="2.4.0-test7"/><vers num="2.4.0-test6"/><vers num="2.4.0-test5"/><vers num="2.4.0-test4"/><vers num="2.4.0-test3"/><vers num="2.4.0-test2"/><vers num="2.4.0-test12"/><vers num="2.4.0-test11"/><vers num="2.4.0-test10"/><vers num="2.4.0 test1"/><vers num="2.4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="3.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="4.9" CVSS_score="3.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0180" published="2005-03-07" seq="2005-0180" severity="Low" type="CVE"><desc><descript source="cve">Multiple integer signedness errors in the sg_scsi_ioctl function in scsi_ioctl.c for Linux 2.6.x allow local users to read or modify kernel memory via negative integers in arguments to the scsi ioctl, which bypass a maximum length check before calling the copy_from_user and copy_to_user functions.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-January/030660.html">20050107 grsecurity 2.1.0 release / 5 Linux kernel advisories</ref><ref adv="1" source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/index.php?id=a&amp;anuncio=000930">CLA-2005:930</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-092.html">RHSA-2005:092</ref><ref source="MANDRAKE" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2005:218">MDKSA-2005:218</ref><ref source="MANDRAKE" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2005:219">MDKSA-2005:219</ref><ref source="BID" url="http://www.securityfocus.com/bid/12198">12198</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17826">17826</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/386374">20050107 grsecurity 2.1.0 release / 5 Linux kernel advisories</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:218">MDKSA-2005:218</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:219">MDKSA-2005:219</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.6 test 9 CVS"/><vers edition="2.6.20" num="2.6.9"/><vers num="2.6.8.1"/><vers num="2.6.8-rc3"/><vers num="2.6.8-rc2"/><vers num="2.6.8-rc1"/><vers num="2.6.8"/><vers num="2.6.7 rc1"/><vers num="2.6.7"/><vers num="2.6.6-rc1"/><vers num="2.6.6"/><vers num="2.6.5"/><vers num="2.6.4"/><vers num="2.6.3"/><vers num="2.6.2"/><vers num="2.6.1-rc2"/><vers num="2.6.1-rc1"/><vers num="2.6.12-rc4"/><vers num="2.6.12-rc1"/><vers num="2.6.12 -rc4"/><vers num="2.6.11.7"/><vers num="2.6.11.6"/><vers num="2.6.11.5"/><vers num="2.6.11.4"/><vers num="2.6.11.3"/><vers num="2.6.11.2"/><vers num="2.6.11.1"/><vers num="2.6.11 -rc4"/><vers num="2.6.11 -rc3"/><vers num="2.6.11 -rc2"/><vers num="2.6.11 .8"/><vers num="2.6.11 .7"/><vers num="2.6.11 .6"/><vers num="2.6.11 .5"/><vers num="2.6.11"/><vers num="2.6.10-rc2"/><vers num="2.6.10 rc2"/><vers num="2.6.10"/><vers num="2.6.1 -rc2"/><vers num="2.6.1 -rc1"/><vers num="2.6.1"/><vers num="2.6.0"/><vers num="2.6 -test9-CVS"/><vers num="2.6 -test9"/><vers num="2.6 -test8"/><vers num="2.6 -test7"/><vers num="2.6 -test6"/><vers num="2.6 -test5"/><vers num="2.6 -test4"/><vers num="2.6 -test3"/><vers num="2.6 -test2"/><vers num="2.6 -test11"/><vers num="2.6 -test10"/><vers num="2.6 -test1"/><vers num="2.6 .10"/><vers num="2.6"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0182" published="2005-01-06" seq="2005-0182" severity="Medium" type="CVE"><desc><descript source="cve">The mod_dosevasive module 1.9 and earlier for Apache creates temporary files with predictable filenames, which could allow remote attackers to overwrite arbitrary files via a symlink attack.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110547469530582&amp;w=2">20050111 Mod_dosevasive symlink and race vulnerability</ref><ref adv="1" source="MISC" url="http://security.lss.hr/index.php?page=details&amp;ID=LSS-2005-01-01">http://security.lss.hr/index.php?page=details&amp;ID=LSS-2005-01-01</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/12181">12181</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18765">moddosevasive-symlink(18765)</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13725">13725</ref></refs><vuln_soft><prod name="mod_dosevasive" vendor="mod_dosevasive"><vers num="1.9"/><vers num="1.8"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0183" published="2005-05-02" seq="2005-0183" severity="High" type="CVE"><desc><descript source="cve">ftpfile in the Vacation plugin 0.15 and earlier for Squirrelmail allows local users to execute arbitrary commands via shell metacharacters in a command line argument.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110549426300953&amp;w=2">20050111 Squirrelmail vacation v0.15 local root exploit</ref><ref source="MISC" url="http://security.lss.hr/en/index.php?page=details&amp;ID=LSS-2005-01-03">http://security.lss.hr/en/index.php?page=details&amp;ID=LSS-2005-01-03</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18855">vacation-ftpfile-command-execution(18855)</ref><ref source="" url="http://www.squirrelmail.org/plugin_view.php?id=51"></ref><ref source="BID" url="http://www.securityfocus.com/bid/12222">12222</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1012866">1012866</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13791">13791</ref></refs><vuln_soft><prod name="Vacation Plugin" vendor="SquirrelMail"><vers num="0.15" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0184" published="2005-05-02" seq="2005-0184" severity="Low" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in ftpfile in the Vacation plugin 0.15 and earlier for Squirrelmail allows local users to read arbitrary files via a .. (dot dot) in a get request.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110549426300953&amp;w=2">20050111 Squirrelmail vacation v0.15 local root exploit</ref><ref adv="1" source="MISC" url="http://security.lss.hr/en/index.php?page=details&amp;ID=LSS-2005-01-03">http://security.lss.hr/en/index.php?page=details&amp;ID=LSS-2005-01-03</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18856">vacation-ftpfile-directory-traversal(18856)</ref><ref source="" url="http://www.squirrelmail.org/plugin_view.php?id=51"></ref><ref source="BID" url="http://www.securityfocus.com/bid/12222">12222</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1012866">1012866</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13791">13791</ref></refs><vuln_soft><prod name="Vacation Plugin" vendor="SquirrelMail"><vers num="0.15" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0185" published="2005-05-02" seq="2005-0185" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in NodeManager Professional 2.00 allows remote attackers to execute arbitrary commands via a LinkDown-Trap packet that contains a long OCTET-STRING in the Trap variable-bindings field.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110599796118583&amp;w=2">20050117 [SIG^2 G-TEC] NodeManager Professional V2.00 Buffer Overflow Vulnerability</ref><ref adv="1" source="MISC" url="http://www.security.org.sg/vuln/nodemanager200.html">http://www.security.org.sg/vuln/nodemanager200.html</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/13881/">13881</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18937">nodemanager-linkdown-bo(18937)</ref><ref source="BID" url="http://www.securityfocus.com/bid/12283">12283</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1012915">1012915</ref></refs><vuln_soft><prod name="NodeManager Professional" vendor="Mnet Soft Factory"><vers num="2.00"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0186" published="2005-01-19" seq="2005-0186" severity="Medium" type="CVE"><desc><descript source="cve">Cisco IOS 12.1YD, 12.2T, 12.3 and 12.3T, when configured for the IOS Telephony Service (ITS), CallManager Express (CME) or Survivable Remote Site Telephony (SRST), allows remote attackers to cause a denial of service (device reboot) via a malformed packet to the SCCP port.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-sa-20050119-itscme.shtml">20050119 Vulnerability in Cisco IOS Embedded Call Processing Solutions</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18956">cisco-ios-sccp-dos(18956)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1012945">1012945</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13913">13913</ref></refs><vuln_soft><prod name="IOS" vendor="Cisco"><vers num="12.1YD"/><vers num="12.2T"/><vers num="12.3"/><vers num="12.3T"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0187" published="2005-05-02" seq="2005-0187" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in the SetSkin function in AtHoc toolbar allows remote attackers to execute arbitrary code via a long skin name.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109710974324742&amp;w=2">20041006 Patch available for high risk flaws in the AtHoc Toolbar</ref><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110616363415176&amp;w=2">20050119 Multiple vulnerabilities in the AtHoc Toolbar (#NISR19012005c)</ref><ref adv="1" source="MISC" url="http://www.ngssoftware.com/advisories/athoc-01full.txt">http://www.ngssoftware.com/advisories/athoc-01full.txt</ref><ref source="BID" url="http://www.securityfocus.com/bid/11341">11341</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17627">athoc-toolbar-bo(17627)</ref></refs><vuln_soft><prod name="AtHoc Toolbar" vendor="AtHoc"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0188" published="2004-10-06" seq="2005-0188" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in the SetBaseURL function in AtHoc toolbar allows remote attackers to execute arbitrary code via format string specifiers in an invalid URL that is recorded in the debug log.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109710974324742&amp;w=2">20041006 Patch available for high risk flaws in the AtHoc Toolbar</ref><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110616363415176&amp;w=2">20050119 Multiple vulnerabilities in the AtHoc Toolbar (#NISR19012005c)</ref><ref source="MISC" url="http://www.ngssoftware.com/advisories/athoc-01full.txt">http://www.ngssoftware.com/advisories/athoc-01full.txt</ref><ref source="BID" url="http://www.securityfocus.com/bid/11341">11341</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17628">athoc-toolbar-format-string(17628)</ref></refs><vuln_soft><prod name="AtHoc Toolbar" vendor="AtHoc"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-01-05" name="CVE-2005-0189" published="2004-10-06" seq="2005-0189" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in the HandleAction function in RealPlayer 10.5 (6.0.12.1040) and earlier allows remote attackers to execute arbitrary code via a long ShowPreferences argument.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109707741022291&amp;w=2">20041006 Patch available for multiple high risk vulnerabilities in RealPlayer</ref><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110616636318261&amp;w=2">20050119 RealPlayer &apos;ShowPreferences&apos; Buffer Overflow Vulnerability (#NISR19012005e)</ref><ref adv="1" patch="1" source="NTBUGTRAQ" url="http://archives.neohapsis.com/archives/ntbugtraq/2005-q1/0046.html">20050119 RealPlayer &apos;ShowPreferences&apos; Buffer Overflow Vulnerability (#NISR19012005e)</ref><ref adv="1" patch="1" source="MISC" url="http://service.real.com/help/faq/security/040928_player/EN/">http://service.real.com/help/faq/security/040928_player/EN/</ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/698390">VU#698390</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/12311">12311</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109707741022291&amp;w=2">20041006 Patch available for multiple high risk vulnerabilities in RealPlayer</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110616636318261&amp;w=2">20050119 RealPlayer &apos;ShowPreferences&apos; Buffer Overflow Vulnerability (#NISR19012005e)</ref></refs><vuln_soft><prod name="RealPlayer" vendor="RealNetworks"><vers edition="Japanese" num="10.0"/><vers edition="German" num="10.0"/><vers edition="English" num="10.0"/><vers num="10.5_6.0.12.1040"/><vers num="10.5_6.0.12.1016 Beta"/><vers num="10.5"/><vers num="10.0 beta"/><vers num="10.0_6.0.12.690"/></prod><prod name="RealOne Player" vendor="RealNetworks"><vers num="2.0"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-01-05" name="CVE-2005-0190" published="2004-09-29" seq="2005-0190" severity="Low" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in RealPlayer 10.5 (6.0.12.1040) and earlier allows remote attackers to delete arbitrary files via a Real Metadata Packages (RMP) file with a FILENAME tag containing .. (dot dot) sequences in a filename that ends with a ? (question mark) and an allowed file extension (e.g. .mp3), which bypasses the check for the file extension.</descript></desc><loss_types><int/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109707741022291&amp;w=2">20041006 Patch available for multiple high risk vulnerabilities in RealPlayer</ref><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110616160228843&amp;w=2">20050119 RealPlayer Arbitrary File Deletion Vulnerability (#NISR19012005f)</ref><ref adv="1" patch="1" source="MISC" url="http://www.ngssoftware.com/advisories/real-02full.txt">http://www.ngssoftware.com/advisories/real-02full.txt</ref><ref adv="1" patch="1" source="CONFIRM" url="http://service.real.com/help/faq/security/040928_player/EN/">http://service.real.com/help/faq/security/040928_player/EN/</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/11308">11308</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/12672/">12672</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17551">realplayer-media-file-deletion(17551)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109707741022291&amp;w=2">20041006 Patch available for multiple high risk vulnerabilities in RealPlayer</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110616160228843&amp;w=2">20050119 RealPlayer Arbitrary File Deletion Vulnerability (#NISR19012005f)</ref></refs><vuln_soft><prod name="RealPlayer" vendor="RealNetworks"><vers edition="Japanese" num="10.0"/><vers edition="German" num="10.0"/><vers edition="English" num="10.0"/><vers num="10.5_6.0.12.1040"/><vers num="10.5_6.0.12.1016 Beta"/><vers num="10.5"/><vers num="10.0 beta"/><vers num="10.0_6.0.12.690"/></prod><prod name="RealOne Player" vendor="RealNetworks"><vers num="2.0"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-01-05" name="CVE-2005-0191" published="2005-01-19" seq="2005-0191" severity="Medium" type="CVE"><desc><descript source="cve">Off-by-one buffer overflow in the processing of tags in Real Metadata Package (RMP) files in RealPlayer 10.5 (6.0.12.1040) and earlier could allow remote attackers to execute arbitrary code via a long tag.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109707741022291&amp;w=2">20041006 Patch available for multiple high risk vulnerabilities in RealPlayer</ref><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110616302008401&amp;w=2">20050119 RealPlayer Miscellaneous Vulnerabilities (#NISR19012005g)</ref><ref adv="1" patch="1" source="MISC" url="http://www.ngssoftware.com/advisories/real-03full.txt">http://www.ngssoftware.com/advisories/real-03full.txt</ref><ref adv="1" patch="1" source="CONFIRM" url="http://service.real.com/help/faq/security/040928_player/EN/">http://service.real.com/help/faq/security/040928_player/EN/</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18982">realplayer-long-filename-offbyone-bo(18982)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109707741022291&amp;w=2">20041006 Patch available for multiple high risk vulnerabilities in RealPlayer</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110616302008401&amp;w=2">20050119 RealPlayer Miscellaneous Vulnerabilities (#NISR19012005g)</ref></refs><vuln_soft><prod name="RealPlayer" vendor="RealNetworks"><vers edition="Japanese" num="10.0"/><vers edition="German" num="10.0"/><vers edition="English" num="10.0"/><vers num="10.5_6.0.12.1040"/><vers num="10.5_6.0.12.1016 Beta"/><vers num="10.5"/><vers num="10.0 beta"/><vers num="10.0_6.0.12.690"/></prod><prod name="RealOne Player" vendor="RealNetworks"><vers num="2.0"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-01-05" name="CVE-2005-0192" published="2004-10-06" seq="2005-0192" severity="Low" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in the parsing of Skin file names in RealPlayer 10.5 (6.0.12.1040) and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in an RJS filename.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/><input/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109707741022291&amp;w=2">20041006 Patch available for multiple high risk vulnerabilities in RealPlayer</ref><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110616302008401&amp;w=2">20050119 RealPlayer Miscellaneous Vulnerabilities (#NISR19012005g)</ref><ref adv="1" patch="1" source="MISC" url="http://www.ngssoftware.com/advisories/real-03full.txt">http://www.ngssoftware.com/advisories/real-03full.txt</ref><ref adv="1" patch="1" source="MISC" url="http://service.real.com/help/faq/security/040928_player/EN/">http://service.real.com/help/faq/security/040928_player/EN/</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18984">realplayer-rjs-filenane-directory-traversal(18984)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109707741022291&amp;w=2">20041006 Patch available for multiple high risk vulnerabilities in RealPlayer</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110616302008401&amp;w=2">20050119 RealPlayer Miscellaneous Vulnerabilities (#NISR19012005g)</ref></refs><vuln_soft><prod name="RealPlayer" vendor="RealNetworks"><vers edition="Japanese" num="10.0"/><vers edition="German" num="10.0"/><vers edition="English" num="10.0"/><vers num="10.5_6.0.12.1040"/><vers num="10.5_6.0.12.1016 Beta"/><vers num="10.5"/><vers num="10.0 beta"/><vers num="10.0_6.0.12.690"/></prod><prod name="RealOne Player" vendor="RealNetworks"><vers num="2.0"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0193" published="2005-01-22" seq="2005-0193" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the (1) -v and (2) -a switches in mRouter in iSync 1.5 in Mac OS X 10.3.7 and earlier allows local users to execute arbitrary code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110642400018425&amp;w=2">20050122 Mac OS X 10.3 iSync Privilege Escalation</ref><ref adv="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/Apr/msg00001.html">APPLE-SA-2005-04-19</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19011">isync-mrouter-bo(19011)</ref><ref source="BID" url="http://www.securityfocus.com/bid/12334">12334</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1012974">1012974</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13965">13965</ref></refs><vuln_soft><prod name="mRouter" vendor="iSync"><vers num="1.5"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0194" published="2005-05-02" seq="2005-0194" severity="High" type="CVE"><desc><descript source="cve">Squid 2.5, when processing the configuration file, parses empty Access Control Lists (ACLs), including proxy_auth ACLs without defined auth schemes, in a way that effectively removes arguments, which could allow remote attackers to bypass intended ACLs if the administrator ignores the parser warnings.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref patch="1" source="CONFIRM" url="http://www.squid-cache.org/Versions/v2/2.5/bugs/squid-2.5.STABLE7-empty_acls.patch">http://www.squid-cache.org/Versions/v2/2.5/bugs/squid-2.5.STABLE7-empty_acls.patch</ref><ref adv="1" source="CONFIRM" url="http://www.squid-cache.org/bugs/show_bug.cgi?id=1166">http://www.squid-cache.org/bugs/show_bug.cgi?id=1166</ref><ref patch="1" source="CONFIRM" url="http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE7-empty_acls">http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE7-empty_acls</ref><ref patch="1" source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000923">CLA-2005:923</ref><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-667">DSA-667</ref><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110901183320453&amp;w=2">20050221 [USN-84-1] Squid vulnerabilities</ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/260421">VU#260421</ref><ref source="FEDORA" url="http://fedoranews.org/updates/FEDORA--.shtml">FLSA-2006:152809</ref></refs><vuln_soft><prod name="Squid" vendor="Squid"><vers num="2.5.STABLE6"/><vers num="2.5.STABLE5"/><vers num="2.5.STABLE4"/><vers num="2.5.STABLE3"/><vers num="2.5.STABLE2"/><vers num="2.5.STABLE1"/><vers num="2.4.STABLE7"/><vers num="2.4.STABLE6"/><vers num="2.4.STABLE4"/><vers num="2.4.STABLE3"/><vers num="2.4.STABLE2"/><vers num="2.4.STABLE1"/><vers num="2.3.DEVEL2"/><vers num="2.3.DEVEL3"/><vers num="2.3.STABLE1"/><vers num="2.3.STABLE2"/><vers num="2.3.STABLE3"/><vers num="2.3.STABLE4"/><vers num="2.3.STABLE5"/><vers num="2.2.PRE1"/><vers num="2.2.PRE2"/><vers num="2.2.DEVEL3"/><vers num="2.2.DEVEL4"/><vers num="2.2.STABLE1"/><vers num="2.2.STABLE2"/><vers num="2.2.STABLE3"/><vers num="2.2.STABLE4"/><vers num="2.2.STABLE5"/><vers num="2.1.PRE1"/><vers num="2.1.PRE3"/><vers num="2.1.PRE4"/><vers num="2.1.RELEASE"/><vers num="2.1.PATCH1"/><vers num="2.1.PATCH2"/><vers num="2.0.PRE1"/><vers num="2.0.RELEASE"/><vers num="2.0.PATCH1"/><vers num="2.0.PATCH2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0195" published="2005-05-02" seq="2005-0195" severity="Medium" type="CVE"><desc><descript source="cve">Cisco IOS 12.0S through 12.3YH allows remote attackers to cause a denial of service (device restart) via a crafted IPv6 packet.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-sa-20050126-ipv6.shtml">20050126 Multiple Crafted IPv6 Packets Cause Reload</ref><ref adv="1" patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA05-026A.html">TA05-026A</ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/472582">VU#472582</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19072">cisco-ios-ipv6-dos(19072)</ref></refs><vuln_soft><prod name="IOS" vendor="Cisco"><vers num="12.0S"/><vers num="12.0SX"/><vers num="12.0SZ"/><vers num="12.2B"/><vers num="12.2BC"/><vers num="12.2BX"/><vers num="12.2BZ"/><vers num="12.2CX"/><vers num="12.2CZ"/><vers num="12.2EW"/><vers num="12.2EWA"/><vers num="12.2JK"/><vers num="12.2MC"/><vers num="12.2S"/><vers num="12.2SE"/><vers num="12.2SU"/><vers num="12.2SV"/><vers num="12.2SW"/><vers num="12.2SX"/><vers num="12.2SXA"/><vers num="12.2SXB"/><vers num="12.2SXD"/><vers num="12.2SY"/><vers num="12.2SZ"/><vers num="12.2T"/><vers num="12.2YT"/><vers num="12.2YU"/><vers num="12.2YV"/><vers num="12.2YZ"/><vers num="12.2ZC"/><vers num="12.2ZD"/><vers num="12.2ZE"/><vers num="12.2ZF"/><vers num="12.2ZG"/><vers num="12.2ZH"/><vers num="12.2ZI"/><vers num="12.2ZJ"/><vers num="12.2ZL"/><vers num="12.2ZN"/><vers num="12.2ZO"/><vers num="12.2ZP"/><vers num="12.3"/><vers num="12.3BC"/><vers num="12.3B"/><vers num="12.3BW"/><vers num="12.3JA"/><vers num="12.3T"/><vers num="12.3XA"/><vers num="12.3XB"/><vers num="12.3XC"/><vers num="12.3XD"/><vers num="12.3XE"/><vers num="12.3XF"/><vers num="12.3XG"/><vers num="12.3XH"/><vers num="12.3XI"/><vers num="12.3J"/><vers num="12.3XK"/><vers num="12.3XL"/><vers num="12.3XM"/><vers num="12.3XN"/><vers num="12.3XQ"/><vers num="12.3XR"/><vers num="12.3XS"/><vers num="12.3XT"/><vers num="12.3XU"/><vers num="12.3XX"/><vers num="12.3XW"/><vers num="12.3XY"/><vers num="12.3XZ"/><vers num="12.3YA"/><vers num="12.3YD"/><vers num="12.3YE"/><vers num="12.3YF"/><vers num="12.3YG"/><vers num="12.3YH"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0196" published="2005-05-02" seq="2005-0196" severity="Medium" type="CVE"><desc><descript source="cve">Cisco IOS 12.0 through 12.3YL, with BGP enabled and running the bgp log-neighbor-changes command, allows remote attackers to cause a denial of service (device reload) via a malformed BGP packet.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-sa-20050126-bgp.shtml">20050126 Cisco IOS Misformed BGP Packet Causes Reload</ref><ref adv="1" patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA05-026A.html">TA05-026A</ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/689326">VU#689326</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19074">cisco-ios-bgp-packetdos(19074)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013013">1013013</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14034">14034</ref></refs><vuln_soft><prod name="IOS" vendor="Cisco"><vers num="12.0"/><vers num="12.0DA"/><vers num="12.0DB"/><vers num="12.0DC"/><vers num="12.0S"/><vers num="12.0SC"/><vers num="12.0SP"/><vers num="12.0ST"/><vers num="12.0SX"/><vers num="12.0SY"/><vers num="12.0SZ"/><vers num="12.0W5"/><vers num="12.0WC"/><vers num="12.0WT"/><vers num="12.0WX"/><vers num="12.0XA"/><vers num="12.0XB"/><vers num="12.0XC"/><vers num="12.0XD"/><vers num="12.0XE"/><vers num="12.0XF"/><vers num="12.0XG"/><vers num="12.0XH"/><vers num="12.0XI"/><vers num="12.0XJ"/><vers num="12.0XK"/><vers num="12.0XL"/><vers num="12.0XM"/><vers num="12.0XN"/><vers num="12.0XP"/><vers num="12.0XQ"/><vers num="12.0XR"/><vers num="12.0XS"/><vers num="12.0XT"/><vers num="12.0XU"/><vers num="12.0XV"/><vers num="12.1"/><vers num="12.1AA"/><vers num="12.1AX"/><vers num="12.1AY"/><vers num="12.1AZ"/><vers num="12.1DA"/><vers num="12.1DB"/><vers num="12.1DC"/><vers num="12.1E"/><vers num="12.1EA"/><vers num="12.1EC"/><vers num="12.1EO"/><vers num="12.1EV"/><vers num="12.1EW"/><vers num="12.1EX"/><vers num="12.1EY"/><vers num="12.1T"/><vers num="12.1XF"/><vers num="12.1XG"/><vers num="12.1XH"/><vers num="12.1XI"/><vers num="12.1XJ"/><vers num="12.1XA"/><vers num="12.1XB"/><vers num="12.1XL"/><vers num="12.1XM"/><vers num="12.1XP"/><vers num="12.1XQ"/><vers num="12.1XR"/><vers num="12.1XT"/><vers num="12.1XU"/><vers num="12.1XV"/><vers num="12.1YA"/><vers num="12.1YB"/><vers num="12.1XC"/><vers num="12.1XD"/><vers num="12.1XE"/><vers num="12.1YF"/><vers num="12.1YH"/><vers num="12.1YI"/><vers num="12.1YJ"/><vers num="12.2"/><vers num="12.2B"/><vers num="12.2BC"/><vers num="12.2BW"/><vers num="12.2BX"/><vers num="12.2BY"/><vers num="12.2BZ"/><vers num="12.2CZ"/><vers num="12.2DA"/><vers num="12.2DD"/><vers num="12.2DX"/><vers num="12.2EW"/><vers num="12.2JK"/><vers num="12.2MB"/><vers num="12.2MC"/><vers num="12.2MX"/><vers num="12.2S"/><vers num="12.2SE"/><vers num="12.2SU"/><vers num="12.2SW"/><vers num="12.2SX"/><vers num="12.2SXA"/><vers num="12.2SXB"/><vers num="12.2SXD"/><vers num="12.2SY"/><vers num="12.2SZ"/><vers num="12.2T"/><vers num="12.2X"/><vers num="12.2XA"/><vers num="12.2XB"/><vers num="12.2XC"/><vers num="12.2XD"/><vers num="12.2XE"/><vers num="12.2XF"/><vers num="12.2XG"/><vers num="12.2XH"/><vers num="12.2XI"/><vers num="12.2XJ"/><vers num="12.2XK"/><vers num="12.2XL"/><vers num="12.2XM"/><vers num="12.2XN"/><vers num="12.2XQ"/><vers num="12.2XS"/><vers num="12.2XT"/><vers num="12.2XU"/><vers num="12.2XW"/><vers num="12.2XZ"/><vers num="12.2YA"/><vers num="12.2YB"/><vers num="12.2YC"/><vers num="12.2YE"/><vers num="12.2YF"/><vers num="12.2YG"/><vers num="12.2YH"/><vers num="12.2YJ"/><vers num="12.2YK"/><vers num="12.2YL"/><vers num="12.2YM"/><vers num="12.2YN"/><vers num="12.2YO"/><vers num="12.2YP"/><vers num="12.2YQ"/><vers num="12.2YR"/><vers num="12.2YS"/><vers num="12.2YT"/><vers num="12.2YU"/><vers num="12.2YV"/><vers num="12.2YW"/><vers num="12.2YX"/><vers num="12.2YY"/><vers num="12.2YZ"/><vers num="12.2ZA"/><vers num="12.2ZB"/><vers num="12.2ZC"/><vers num="12.2ZD"/><vers num="12.2ZE"/><vers num="12.2ZF"/><vers num="12.2ZG"/><vers num="12.2ZH"/><vers num="12.2ZI"/><vers num="12.2ZJ"/><vers num="12.2ZK"/><vers num="12.2ZL"/><vers num="12.2ZM"/><vers num="12.2ZN"/><vers num="12.2ZO"/><vers num="12.2ZP"/><vers num="12.3"/><vers num="12.3B"/><vers num="12.3BW"/><vers num="12.3T"/><vers num="12.3XA"/><vers num="12.3XB"/><vers num="12.3XC"/><vers num="12.3XD"/><vers num="12.3XE"/><vers num="12.3XF"/><vers num="12.3XG"/><vers num="12.3XH"/><vers num="12.3XI"/><vers num="12.3XJ"/><vers num="12.3XK"/><vers num="12.3XL"/><vers num="12.3XN"/><vers num="12.3XQ"/><vers num="12.3XR"/><vers num="12.3XS"/><vers num="12.3XU"/><vers num="12.3XV"/><vers num="12.3XX"/><vers num="12.3YA"/><vers num="12.3YC"/><vers num="12.3YD"/><vers num="12.3YE"/><vers num="12.3YF"/><vers num="12.3YH"/><vers num="12.3YJ"/><vers num="12.3YL"/></prod></vuln_soft></entry><entry CVSS_base_score="6.1" CVSS_exploit_subscore="6.5" CVSS_impact_subscore="6.9" CVSS_score="6.1" CVSS_vector="(AV:A/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2008-07-22" name="CVE-2005-0197" published="2005-05-02" seq="2005-0197" severity="Medium" type="CVE"><desc><descript source="cve">Cisco IOS 12.1T, 12.2, 12.2T, 12.3 and 12.3T, with Multi Protocol Label Switching (MPLS) installed but disabled, allows remote attackers to cause a denial of service (device reload) via a crafted packet sent to the disabled interface.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><local_network/></range><refs><ref adv="1" patch="1" source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-sa-20050126-les.shtml">20050126 Crafted Packet Causes Reload on Cisco Routers</ref><ref adv="1" patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA05-026A.html">TA05-026A</ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/583638">VU#583638</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19071">cisco-ios-mpls-dos(19071)</ref><ref source="BID" url="http://www.securityfocus.com/bid/12369">12369</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013015">1013015</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14031">14031</ref></refs><vuln_soft><prod name="IOS" vendor="Cisco"><vers num="12.1T"/><vers num="12.2"/><vers num="12.2T"/><vers num="12.3"/><vers num="12.3T"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0198" published="2005-05-02" seq="2005-0198" severity="High" type="CVE"><desc><descript source="cve">A logic error in the CRAM-MD5 code for the University of Washington IMAP (UW-IMAP) server, when Challenge-Response Authentication Mechanism with MD5 (CRAM-MD5) is enabled, does not properly enforce all the required conditions for successful authentication, which allows remote attackers to authenticate as arbitrary users.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><access/><design/></vuln_types><range><network/></range><refs><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/702777">VU#702777</ref><ref patch="1" source="CONFIRM" url="http://www.kb.cert.org/vuls/id/CRDY-68QSL5">http://www.kb.cert.org/vuls/id/CRDY-68QSL5</ref><ref patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200502-02.xml">GLSA-200502-02</ref><ref patch="1" source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:026">MDKSA-2005:026</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-128.html">RHSA-2005:128</ref><ref source="BID" url="http://www.securityfocus.com/bid/12391">12391</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013037">1013037</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14057">14057</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14097">14097</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:026">MDKSA-2005:026</ref></refs><vuln_soft><prod name="UW-IMAP" vendor="University of Washington"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0199" published="2005-05-02" seq="2005-0199" severity="High" type="CVE"><desc><descript source="cve">Integer underflow in the Lists_MakeMask() function in lists.c in ngIRCd before 0.8.2 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long MODE line that causes an incorrect length calculation, which leads to a buffer overflow.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref patch="1" source="MLIST" url="http://arthur.ath.cx/pipermail/ngircd-ml/2005-January/000228.html">[ngIRCd-ML] 20050126 ngIRCd 0.8.2</ref><ref adv="1" source="CONFIRM" url="http://bugs.gentoo.org/show_bug.cgi?id=79705">http://bugs.gentoo.org/show_bug.cgi?id=79705</ref><ref patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200501-40.xml">GLSA-200501-40</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/12397">12397</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19143">ngircd-listmakemask-bo(19143)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013047">1013047</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14056">14056</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14059">14059</ref></refs><vuln_soft><prod name="ngIRCd" vendor="ngIRCd"><vers num="0.8.1"/><vers num="0.8"/><vers num="0.7.7"/><vers num="0.7.6"/><vers num="0.7.5"/><vers num="0.7.1"/><vers num="0.7"/><vers num="0.6.1"/><vers num="0.6"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-25" name="CVE-2005-0200" published="2005-05-02" seq="2005-0200" severity="Medium" type="CVE"><desc><descript source="cve">TikiWiki before 1.8.5 does not properly validate files that have been uploaded to the temp directory, which could allow remote attackers to upload and execute arbitrary PHP scripts, a different vulnerability than CVE-2004-1386.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200501-41.xml">GLSA-200501-41</ref><ref patch="1" source="CONFIRM" url="http://tikiwiki.org/art102">http://tikiwiki.org/art102</ref><ref adv="1" source="MISC" url="http://www.lovebug.org/imd_advisory.txt">http://www.lovebug.org/imd_advisory.txt</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13948">13948</ref></refs><vuln_soft><prod name="TikiWiki" vendor="TikiWiki Project"><vers num="1.8.4.1"/><vers num="1.8.4"/><vers num="1.8.3"/><vers num="1.8.2"/><vers num="1.8.1"/><vers num="1.8"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0201" published="2005-06-29" seq="2005-0201" severity="Low" type="CVE"><desc><descript source="cve">D-BUS (dbus) before 0.22 does not properly restrict access to a socket, if the socket address is known, which allows local users to listen or send arbitrary messages on another user&apos;s per-user session bus via that socket.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:105">MDKSA-2005:105</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-102.html">RHSA-2005:102</ref><ref adv="1" source="AUSCERT" url="http://www.auscert.org.au/render.html?it=5156">ESB-2005.0435</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-144-1">USN-144-1</ref><ref source="BID" url="http://www.securityfocus.com/bid/12435">12435</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013075">1013075</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14119">14119</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15638">15638</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15833">15833</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15844">15844</ref></refs><vuln_soft><prod name="D-BUS" vendor="D-BUS"><vers num="0.22" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0202" published="2005-05-02" seq="2005-0202" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in the true_path function in private.py for Mailman 2.1.5 and earlier allows remote attackers to read arbitrary files via &quot;.../....///&quot; sequences, which are not properly cleansed by regular expressions that are intended to remove &quot;../&quot; and &quot;./&quot; sequences.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/><input/></vuln_types><range><network/></range><refs><ref adv="1" source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-February/031562.html">20050209 Administrivia: List Compromised due to Mailman Vulnerability</ref><ref patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/Mar/msg00000.html">APPLE-SA-2005-03-21</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-674">DSA-674</ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200502-11.xml">GLSA-200502-11</ref><ref patch="1" source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:037">MDKSA-2005:037</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-136.html">RHSA-2005:136</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-137.html">RHSA-2005:137</ref><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110805795122386&amp;w=2">20050209 [USN-78-1] Mailman vulnerability</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013145">1013145</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14211">14211</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:037">MDKSA-2005:037</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_07_mailman.html">SUSE-SA:2005:007</ref></refs><vuln_soft><prod name="Mailman" vendor="GNU"><vers num="2.1b1"/><vers num="2.1"/><vers num="2.1.1"/><vers num="2.1.2"/><vers num="2.1.3"/><vers num="2.1.4"/><vers num="2.1.5"/></prod></vuln_soft></entry><entry modified="2005-10-20" name="CVE-2005-0203" published="2005-06-09" reject="1" seq="2005-0203" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: none.  Reason: This candidate has been revoked by its Candidate Numbering Authority (CNA) because it was initially assigned to a problem that was not a security issue.  Notes: none.</descript></desc><refs/></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0204" published="2005-05-02" seq="2005-0204" severity="Medium" type="CVE"><desc><descript source="cve">Linux kernel before 2.6.9, when running on the AMD64 and Intel EM64T architectures, allows local users to write to privileged IO ports via the OUTS instruction.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-092.html">RHSA-2005:092</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-293.html">RHSA-2005:293</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2006/0006">2006-0006</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18784">18784</ref><ref source="BID" url="http://www.securityfocus.com/bid/12598">12598</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.6.8.1"/><vers num="2.6.8"/><vers num="2.6.7"/><vers num="2.6.6"/><vers num="2.6.5"/><vers num="2.6.4"/><vers num="2.6.3"/><vers num="2.6.2"/><vers num="2.6.1"/><vers num="2.6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0205" published="2005-05-02" seq="2005-0205" severity="Medium" type="CVE"><desc><descript source="cve">KPPP 2.1.2 in KDE 3.1.5 and earlier, when setuid root without certain wrappers, does not properly close a privileged file descriptor for a domain socket, which allows local users to read and write to /etc/hosts and /etc/resolv.conf and gain control over DNS name resolution by opening a number of file descriptors before executing kppp.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=208&amp;type=vulnerabilities">20050228 KPPP Privileged File Descriptor Leak Vulnerability</ref><ref adv="1" patch="1" source="CONFIRM" url="http://www.kde.org/info/security/advisory-20050228-1.txt">http://www.kde.org/info/security/advisory-20050228-1.txt</ref><ref patch="1" source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000934">CLA-2005:934</ref><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-692">DSA-692</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-175.html">RHSA-2005:175</ref></refs><vuln_soft><prod name="KDE" vendor="KDE"><vers num="3.1.5"/><vers num="3.1.4"/><vers num="3.1.3"/><vers num="3.1.2"/><vers num="3.1.1"/><vers num="3.1"/></prod><prod name="KPPP" vendor="Bernd Wuebben"><vers num="2.1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-25" name="CVE-2005-0206" published="2005-04-27" seq="2005-0206" severity="High" type="CVE"><desc><descript source="cve">The patch for integer overflow vulnerabilities in Xpdf 2.0 and 3.0 (CVE-2004-0888) is incomplete for 64-bit architectures on certain Linux distributions such as Red Hat, which could leave Xpdf users exposed to the original vulnerabilities.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="RedHat" url="http://www.redhat.com/support/errata/RHSA-2005-213.html">xpdf security update</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11501">bid 11501</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:041">MDKSA-2005:041</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:042">MDKSA-2005:042</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:043">MDKSA-2005:043</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:044">MDKSA-2005:044</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:052">MDKSA-2005:052</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:056">MDKSA-2005:056</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-034.html">RHSA-2005:034</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-053.html">RHSA-2005:053</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-057.html">RHSA-2005:057</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-132.html">RHSA-2005:132</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17818">xpdf-pdf-bo(17818)</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:041">MDKSA-2005:041</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:042">MDKSA-2005:042</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:043">MDKSA-2005:043</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:044">MDKSA-2005:044</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:052">MDKSA-2005:052</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:056">MDKSA-2005:056</ref></refs><vuln_soft><prod name="GPdf" vendor="GNOME"><vers num="0.110"/><vers num="0.112"/><vers num="0.131"/></prod><prod name="pTeX" vendor="ASCII"><vers num="3.1.4"/></prod><prod name="Desktop" vendor="Red Hat"><vers num="3.0"/></prod><prod name="CUPS" vendor="Easy Software Products"><vers num="1.0.4_8"/><vers num="1.0.4"/><vers num="1.1.1"/><vers num="1.1.4_5"/><vers num="1.1.4_3"/><vers num="1.1.4_2"/><vers num="1.1.4"/><vers num="1.1.6"/><vers num="1.1.7"/><vers num="1.1.10"/><vers num="1.1.12"/><vers num="1.1.13"/><vers num="1.1.14"/><vers num="1.1.15"/><vers num="1.1.16"/><vers num="1.1.17"/><vers num="1.1.18"/><vers num="1.1.19 rc5"/><vers num="1.1.19"/><vers num="1.1.20"/></prod><prod name="Mandrake Corporate Server" vendor="MandrakeSoft"><vers edition="x86_64" num="3.0"/><vers num="3.0"/></prod><prod name="PDFTOHTML" vendor="PDFTOHTML"><vers num="0.32b"/><vers num="0.32a"/><vers num="0.33a"/><vers num="0.33"/><vers num="0.34"/><vers num="0.35"/><vers num="0.36"/></prod><prod name="Linux" vendor="Gentoo"><vers num=""/></prod><prod name="Xpdf" vendor="Xpdf"><vers num="0.90"/><vers num="0.91"/><vers num="0.92"/><vers num="0.93"/><vers num="1.1"/><vers num="1.0a"/><vers num="1.0"/><vers num="2.3"/><vers num="2.1"/><vers num="2.0"/><vers num="3.0"/></prod><prod name="Ubuntu Linux" vendor="Ubuntu"><vers edition="ppc" num="4.1"/><vers edition="ia64" num="4.1"/><vers edition="ia64" num="4.1"/></prod><prod name="Enterprise Linux AS" vendor="Red Hat"><vers edition="Advanced Servers" num="3.0"/><vers edition="Advanced Server" num="2.1"/><vers edition="Advanced Server" num="2.1"/></prod><prod name="Enterprise Linux ES" vendor="Red Hat"><vers edition="Enterprise Server" num="3.0"/><vers edition="Enterprise Server" num="2.1"/><vers edition="Enterprise Server" num="2.1"/></prod><prod name="ProPack" vendor="SGI"><vers num="3.0"/></prod><prod name="Advanced Workstation Itanium Processor" vendor="Red Hat"><vers edition="IA64" num="2.1"/><vers num="2.1"/></prod><prod name="cstetex" vendor="CSTeX"><vers num="2.0.2"/></prod><prod name="kpdf" vendor="KDE"><vers num="3.2"/></prod><prod name="SuSE Linux" vendor="SuSE"><vers num="1.0"/><vers num="2.0"/><vers num="3.0"/><vers num="4.0"/><vers num="4.2"/><vers num="4.3"/><vers num="4.4"/><vers num="4.4.1"/><vers num="5.0"/><vers num="5.1"/><vers num="5.2"/><vers num="5.3"/><vers num="6.0"/><vers num="6.1 alpha"/><vers num="6.1"/><vers num="6.2"/><vers edition="ppc" num="6.3"/><vers num="6.3 alpha"/><vers num="6.3"/><vers edition="ppc" num="6.4"/><vers edition="i386" num="6.4"/><vers num="6.4 alpha"/><vers num="6.4"/><vers edition="sparc" num="7.0"/><vers edition="ppc" num="7.0"/><vers edition="i386" num="7.0"/><vers num="7.0 alpha"/><vers num="7.0"/><vers edition="x86" num="7.1"/><vers edition="spa" num="7.1"/><vers edition="sparc" num="7.1"/><vers num="7.1 alpha"/><vers num="7.1"/><vers edition="i386" num="7.2"/><vers num="7.2"/><vers edition="sparc" num="7.3"/><vers edition="ppc" num="7.3"/><vers edition="i386" num="7.3"/><vers num="7.3"/><vers edition="i386" num="8.0"/><vers num="8.0"/><vers num="8.1"/><vers num="8.2"/><vers edition="x86_64" num="9.0"/><vers num="9.0"/><vers edition="x86_64" num="9.1"/><vers num="9.1"/><vers edition="x86_64" num="9.2"/><vers num="9.2"/></prod><prod name="Enterprise Linux WS" vendor="Red Hat"><vers edition="Workstation" num="3.0"/><vers edition="Workstation" num="2.1"/><vers edition="Workstation" num="2.1"/></prod><prod name="Debian Linux" vendor="Debian"><vers num="3.0 sparc"/><vers num="3.0 s_390"/><vers num="3.0 ppc"/><vers num="3.0 mipsel"/><vers num="3.0 mips"/><vers num="3.0 m68k"/><vers num="3.0 ia-64"/><vers num="3.0 ia-32"/><vers num="3.0 hppa"/><vers num="3.0 arm"/><vers num="3.0 alpha"/><vers num="3.0"/></prod><prod name="Advanced Linux Environment" vendor="SGI"><vers num="3.0"/></prod><prod name="Koffice" vendor="KDE"><vers num="1.3 Beta3"/><vers num="1.3 Beta2"/><vers num="1.3 Beta1"/><vers num="1.3"/><vers num="1.3.1"/><vers num="1.3.2"/><vers num="1.3.3"/></prod><prod name="KDE" vendor="KDE"><vers num="3.2"/><vers num="3.2.1"/><vers num="3.2.2"/><vers num="3.2.3"/><vers num="3.3"/><vers num="3.3.1"/></prod><prod name="Linux" vendor="Red Hat"><vers edition="i386" num="9.0"/></prod><prod name="teTeX" vendor="teTeX"><vers num="1.0.6"/><vers num="1.0.7"/><vers num="2.0"/><vers num="2.0.1"/><vers num="2.0.2"/></prod><prod name="Fedora" vendor="Red Hat"><vers num="Core 3.0"/><vers num="Core 2.0"/><vers num="Core 1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0207" published="2005-05-02" seq="2005-0207" severity="Low" type="CVE"><desc><descript source="cve">Unknown vulnerability in Linux kernel 2.4.x, 2.5.x, and 2.6.x allows NFS clients to cause a denial of service via O_DIRECT.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref patch="1" source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000930">CLA-2005:930</ref><ref adv="1" patch="1" source="SUSE" url="http://www.securityfocus.com/advisories/7880">SUSE-SA:2005:003</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/12330">12330</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-366.html">RHSA-2005:366</ref></refs><vuln_soft><prod name="SuSE Linux" vendor="SuSE"><vers num="9.2"/><vers num="9.1"/><vers num="9.0"/><vers num="8.2"/><vers num="8.1"/></prod><prod name="Conectiva Linux" vendor="Conectiva"><vers num="10.0"/></prod><prod name="SuSE Linux Enterprise Server" vendor="SuSE"><vers num="9"/><vers num="8"/></prod><prod name="Desktop" vendor="Red Hat"><vers num="4.0"/></prod><prod name="SuSE Novell Linux Desktop" vendor="SuSE"><vers num="9.0"/></prod><prod name="Kernel" vendor="Linux"><vers num="2.6.10 rc2"/><vers num="2.6.10"/><vers edition="2.6.20" num="2.6.9"/><vers num="2.6.8 rc3"/><vers num="2.6.8 rc2"/><vers num="2.6.8 rc1"/><vers num="2.6.8"/><vers num="2.6.7 rc1"/><vers num="2.6.7"/><vers num="2.6.6 rc1"/><vers num="2.6.6"/><vers num="2.6.5"/><vers num="2.6.4"/><vers num="2.6.3"/><vers num="2.6.2"/><vers num="2.6.1 rc2"/><vers num="2.6.1 rc1"/><vers num="2.6.1"/><vers num="2.6 test9 CVS"/><vers num="2.6 test9"/><vers num="2.6 test8"/><vers num="2.6 test7"/><vers num="2.6 test6"/><vers num="2.6 test5"/><vers num="2.6 test4"/><vers num="2.6 test3"/><vers num="2.6 test2"/><vers num="2.6 test11"/><vers num="2.6 test10"/><vers num="2.6 test1"/><vers num="2.6"/><vers num="2.5.69"/><vers num="2.5.68"/><vers num="2.5.67"/><vers num="2.5.66"/><vers num="2.5.65"/><vers num="2.5.64"/><vers num="2.5.63"/><vers num="2.5.62"/><vers num="2.5.61"/><vers num="2.5.60"/><vers num="2.5.59"/><vers num="2.5.58"/><vers num="2.5.57"/><vers num="2.5.56"/><vers num="2.5.55"/><vers num="2.5.54"/><vers num="2.5.53"/><vers num="2.5.52"/><vers num="2.5.51"/><vers num="2.5.50"/><vers num="2.5.49"/><vers num="2.5.48"/><vers num="2.5.47"/><vers num="2.5.46"/><vers num="2.5.45"/><vers num="2.5.44"/><vers num="2.5.43"/><vers num="2.5.42"/><vers num="2.5.41"/><vers num="2.5.40"/><vers num="2.5.39"/><vers num="2.5.38"/><vers num="2.5.37"/><vers num="2.5.36"/><vers num="2.5.35"/><vers num="2.5.34"/><vers num="2.5.33"/><vers num="2.5.32"/><vers num="2.5.31"/><vers num="2.5.30"/><vers num="2.5.29"/><vers num="2.5.28"/><vers num="2.5.27"/><vers num="2.5.26"/><vers num="2.5.25"/><vers num="2.5.24"/><vers num="2.5.23"/><vers num="2.5.22"/><vers num="2.5.21"/><vers num="2.5.20"/><vers num="2.5.19"/><vers num="2.5.18"/><vers num="2.5.17"/><vers num="2.5.16"/><vers num="2.5.15"/><vers num="2.5.14"/><vers num="2.5.13"/><vers num="2.5.12"/><vers num="2.5.11"/><vers num="2.5.10"/><vers num="2.5.9"/><vers num="2.5.8"/><vers num="2.5.7"/><vers num="2.5.6"/><vers num="2.5.5"/><vers num="2.5.4"/><vers num="2.5.3"/><vers num="2.5.2"/><vers num="2.5.1"/><vers num="2.5.0"/><vers num="2.4.29 rc2"/><vers num="2.4.29 rc1"/><vers num="2.4.28"/><vers num="2.4.27 pre5"/><vers num="2.4.27 pre4"/><vers num="2.4.27 pre3"/><vers num="2.4.27 pre2"/><vers num="2.4.27 pre1"/><vers num="2.4.27"/><vers num="2.4.26"/><vers num="2.4.25"/><vers num="2.4.24 ow1"/><vers num="2.4.24"/><vers num="2.4.23 pre9"/><vers num="2.4.23 ow2"/><vers num="2.4.23"/><vers num="2.4.22"/><vers num="2.4.21 pre7"/><vers num="2.4.21 pre4"/><vers num="2.4.21 pre1"/><vers num="2.4.21"/><vers num="2.4.20"/><vers num="2.4.19 pre6"/><vers num="2.4.19 pre5"/><vers num="2.4.19 pre4"/><vers num="2.4.19 pre3"/><vers num="2.4.19 pre2"/><vers num="2.4.19 pre1"/><vers num="2.4.19"/><vers num="2.4.18 pre8"/><vers num="2.4.18 pre7"/><vers num="2.4.18 pre6"/><vers num="2.4.18 pre5"/><vers num="2.4.18 pre4"/><vers num="2.4.18 pre3"/><vers num="2.4.18 pre2"/><vers num="2.4.18 pre1"/><vers edition="x86" num="2.4.18"/><vers num="2.4.18"/><vers num="2.4.17"/><vers num="2.4.16"/><vers num="2.4.15"/><vers num="2.4.14"/><vers num="2.4.13"/><vers num="2.4.12"/><vers num="2.4.11"/><vers num="2.4.10"/><vers num="2.4.9"/><vers num="2.4.8"/><vers num="2.4.7"/><vers num="2.4.6"/><vers num="2.4.5"/><vers num="2.4.4"/><vers num="2.4.3"/><vers num="2.4.2"/><vers num="2.4.1"/><vers num="2.4.0 test9"/><vers num="2.4.0 test8"/><vers num="2.4.0 test7"/><vers num="2.4.0 test6"/><vers num="2.4.0 test5"/><vers num="2.4.0 test4"/><vers num="2.4.0 test3"/><vers num="2.4.0 test2"/><vers num="2.4.0 test12"/><vers num="2.4.0 test11"/><vers num="2.4.0 test10"/><vers num="2.4.0 test1"/><vers num="2.4.0"/></prod><prod name="Enterprise Linux" vendor="Red Hat"><vers edition="Workstation" num="4.0"/><vers edition="Enterprise Server" num="4.0"/><vers edition="Advanced Server" num="4.0"/></prod><prod name="SuSE Linux Desktop" vendor="SuSE"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-25" name="CVE-2005-0208" published="2005-05-02" seq="2005-0208" severity="Medium" type="CVE"><desc><descript source="cve">The HTML parsing functions in Gaim before 1.1.4 allow remote attackers to cause a denial of service (application crash) via malformed HTML that causes &quot;an invalid memory access,&quot; a different vulnerability than CVE-2005-0473.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="CONFIRM" url="http://gaim.sourceforge.net/security/?id=12">http://gaim.sourceforge.net/security/?id=12</ref><ref patch="1" source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000933">CLA-2005:933</ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200503-03.xml">GLSA-200503-03</ref><ref patch="1" source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:049">MDKSA-2005:049</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-215.html">RHSA-2005:215</ref><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110935655500670&amp;w=2">20050225 [USN-85-1] Gaim vulnerabilities</ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/795812">VU#795812</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14386">14386</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/426078/100/0/threaded">FLSA:158543</ref><ref source="BID" url="http://www.securityfocus.com/bid/12660">12660</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_36_sudo.html">SUSE-SA:2005:036</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:049">MDKSA-2005:049</ref></refs><vuln_soft><prod name="Gaim" vendor="Rob Flynn"><vers num="1.1.0"/><vers num="1.1.1"/><vers num="1.1.2"/><vers num="1.1.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2008-06-24" name="CVE-2005-0209" published="2005-05-02" seq="2005-0209" severity="High" type="CVE"><desc><descript source="cve">Netfilter in Linux kernel 2.6.8.1 allows remote attackers to cause a denial of service (kernel crash) via crafted IP packet fragments.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111091402626556&amp;w=2">20050315 [USN-95-1] Linux kernel vulnerabilities</ref><ref patch="1" source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000945">CLA-2005:945</ref><ref adv="1" patch="1" source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_18_kernel.html">SUSE-SA:2005:018</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-366.html">RHSA-2005:366</ref><ref source="BID" url="http://www.securityfocus.com/bid/12598">12598</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-420.html">RHSA-2005:420</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.6.8.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.9" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.9" CVSS_score="4.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2008-06-24" name="CVE-2005-0210" published="2005-05-02" seq="2005-0210" severity="Medium" type="CVE"><desc><descript source="cve">Netfilter in the Linux kernel 2.6.8.1 allows local users to cause a denial of service (memory consumption) via certain packet fragments that are reassembled twice, which causes a data structure to be allocated twice.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111091402626556&amp;w=2">20050315 [USN-95-1] Linux kernel vulnerabilities</ref><ref patch="1" source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000945">CLA-2005:945</ref><ref adv="1" patch="1" source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_18_kernel.html">SUSE-SA:2005:018</ref><ref source="MANDRAKE" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2005:218">MDKSA-2005:218</ref><ref source="MANDRAKE" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2005:219">MDKSA-2005:219</ref><ref source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2005-366.html">RHSA-2005:366</ref><ref source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2005-663.html">RHSA-2005:663</ref><ref source="BID" url="http://www.securityfocus.com/bid/12816">12816</ref><ref source="OSVDB" url="http://www.osvdb.org/14966">14966</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14295">14295</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17826">17826</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17002">17002</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/1878">ADV-2005-1878</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:218">MDKSA-2005:218</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:219">MDKSA-2005:219</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.6.8.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0211" published="2005-05-02" seq="2005-0211" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in wccp.c in Squid 2.5 before 2.5.STABLE7 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long WCCP packet, which is processed by a recvfrom function call that uses an incorrect length parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref patch="1" source="CONFIRM" url="http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE7-wccp_buffer_overflow">http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE7-wccp_buffer_overflow</ref><ref patch="1" source="CONFIRM" url="http://www.squid-cache.org/Versions/v2/2.5/bugs/squid-2.5.STABLE7-wccp_buffer_overflow.patch">http://www.squid-cache.org/Versions/v2/2.5/bugs/squid-2.5.STABLE7-wccp_buffer_overflow.patch</ref><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-667">DSA-667</ref><ref patch="1" source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:034">MDKSA-2005:034</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-060.html">RHSA-2005:060</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-061.html">RHSA-2005:061</ref><ref adv="1" patch="1" source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_06_squid.html">SUSE-SA:2005:006</ref><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110780531820947&amp;w=2">20050207 [USN-77-1] Squid vulnerabilities</ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/886006">VU#886006</ref><ref source="BID" url="http://www.securityfocus.com/bid/12432">12432</ref><ref source="OSVDB" url="http://www.osvdb.org/13319">13319</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013045">1013045</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14076">14076</ref><ref source="FEDORA" url="http://fedoranews.org/updates/FEDORA--.shtml">FLSA-2006:152809</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:034">MDKSA-2005:034</ref></refs><vuln_soft><prod name="Squid" vendor="Squid"><vers num="2.5.STABLE6"/><vers num="2.5.STABLE5"/><vers num="2.5.STABLE4"/><vers num="2.5.STABLE3"/><vers num="2.5.STABLE2"/><vers num="2.5.STABLE1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0212" published="2005-05-02" seq="2005-0212" severity="Medium" type="CVE"><desc><descript source="cve">The Amp II engine as used by Gore: Ultimate Soldier 1.50 and earlier allows remote attackers to cause a denial of service (infinite loop) via a zero byte UDP packet.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="Luigi Auriemma" url="http://aluigi.altervista.org/adv/amp2zero-adv.txt">http://aluigi.altervista.org/adv/amp2zero-adv.txt</ref><ref source="BID" url="http://www.securityfocus.com/bid/12192">12192</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18789">amp-3d-socket-dos(18789)</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13754">13754</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110503597505648&amp;w=2">20050106 Socket unreacheable in Amp II engine</ref></refs><vuln_soft><prod name="Amp II 3D Game Engine" vendor="Amp"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0213" published="2005-05-02" seq="2005-0213" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in WinHKI 1.4d allows remote attackers to overwrite arbitrary files via a .. (dot dot) in a zip file.</descript></desc><loss_types><int/></loss_types><vuln_types><access/><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110505334903257&amp;w=2">20050106 WinAc AND WinHKI ZIP File Directory Transversal </ref><ref source="BID" url="http://www.securityfocus.com/bid/12176">12176</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18798">winhki-zip-directory-traversal(18798)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1012798">1012798</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13738">13738</ref></refs><vuln_soft><prod name="WinHKI" vendor="Webtoolmaster Software"><vers num="1.4d"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0214" published="2005-05-02" seq="2005-0214" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in Simple PHP Blog (SPHPBlog) 0.3.7c allows remote attackers to read or create arbitrary files via a .. (dot dot) in the entry parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110512850603989&amp;w=2">20050107 Simple PHP Blog directory traversal vulnerability </ref><ref adv="1" source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2005-01/0210.html">20050107 Simple PHP Blog directory traversal vulnerability </ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/12193">12193</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18802">sphp-dotdot-directory-traversal(18802)</ref></refs><vuln_soft><prod name="Simple PHP Blog" vendor="Alexander Palmo"><vers num="0.3.7c"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0215" published="2005-05-02" seq="2005-0215" severity="Medium" type="CVE"><desc><descript source="cve">Mozilla 1.6 and possibly other versions allows remote attackers to cause a denial of service (application crash) via a XBM (X BitMap) file with a large (1) height or (2) width value.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110512665029209&amp;w=2">20050107 Mozilla XBM Image Vulnerability</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18803">mozilla-xbm-dos(18803)</ref></refs><vuln_soft><prod name="Mozilla" vendor="Mozilla"><vers num="1.6"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0216" published="2005-05-02" seq="2005-0216" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in formmail.php in Woltlab Burning Board Lite 1.0.0, 1.0.1e, and possibly other versions, allows remote attackers to inject arbitrary web sript and HTML via the userid parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110537385427004&amp;w=2">20050108 Security Advisory: Woltlab Burning Board Lite formmail.php XSS </ref><ref source="BID" url="http://www.securityfocus.com/bid/12199">12199</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18814">wbb-formmail-userid-xss(18814)</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13782">13782</ref></refs><vuln_soft><prod name="Burning Board Lite" vendor="Woltlab"><vers num="1.0.1e"/><vers num="1.0.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0217" published="2005-05-02" seq="2005-0217" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in index.php in Invision Community Blog allows remote attackers to execute arbitrary SQL commands via the eid parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110538277223800&amp;w=2">20050109 SQL Injection Vulnerability in Invision Community Blog</ref><ref source="BID" url="http://www.securityfocus.com/bid/12205">12205</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18815">icb-sql-injection(18815)</ref><ref source="OSVDB" url="http://www.osvdb.org/12817">12817</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1012831">1012831</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13783">13783</ref></refs><vuln_soft><prod name="Invision Community Blog" vendor="Invision Power Services"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0218" published="2005-05-02" seq="2005-0218" severity="Medium" type="CVE"><desc><descript source="cve">ClamAV 0.80 and earlier allows remote attackers to bypass virus scanning via a base64 encoded image in a data: (RFC 2397) URL.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="CONFIRM" url="http://sourceforge.net/project/shownotes.php?release_id=300116">http://sourceforge.net/project/shownotes.php?release_id=300116</ref><ref patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200501-46.xml">GLSA-200501-46</ref><ref patch="1" source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:025">MDKSA-2005:025</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/13900/">13900</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:025">MDKSA-2005:025</ref></refs><vuln_soft><prod name="ClamAV" vendor="Clam Anti-Virus"><vers num="0.80"/><vers num="0.68.1"/><vers num="0.68"/><vers num="0.67"/><vers num="0.65"/><vers num="0.60"/><vers num="0.54"/><vers num="0.53"/><vers num="0.52"/><vers num="0.51"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-08-17" name="CVE-2005-0219" published="2005-05-02" seq="2005-0219" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Gallery 1.3.4-pl1 allow remote attackers to inject arbitrary web script or HTML via (1) the index field in add_comment.php, (2) set_albumName, (3) slide_index, (4) slide_full, (5) slide_loop, (6) slide_pause, (7) slide_dir fields in slideshow_low.php, or (8) username field in search.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110608459222364&amp;w=2">20050117 Gallery v1.3.4-pl1, v1.4.4-pl2, 2.0 Alpha Cross Site Scripting Vulnerability</ref><ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2005-q1/0031.html">20050117 Gallery v1.3.4-pl1, v1.4.4-pl2, 2.0 Alpha Cross Site Scripting Vulnerability</ref><ref patch="1" source="CONFIRM" url="http://gallery.menalto.com/modules.php?op=modload&amp;name=News&amp;file=article&amp;sid=147">http://gallery.menalto.com/modules.php?op=modload&amp;name=News&amp;file=article&amp;sid=147</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18938">gallery-multiple-xss(18938)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/43473">gallery-multiple-scripts-xss(43473)</ref></refs><vuln_soft><prod name="Gallery" vendor="Gallery Project"><vers num="1.3.4 pl1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-08-17" name="CVE-2005-0220" published="2005-05-02" seq="2005-0220" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting vulnerability in login.php in Gallery 1.4.4-pl2 allows remote attackers to inject arbitrary web script or HTML via the username field.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110608459222364&amp;w=2">20050117 Gallery v1.3.4-pl1, v1.4.4-pl2, 2.0 Alpha Cross Site Scripting Vulnerability</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200501-45.xml">GLSA-200501-45</ref><ref patch="1" source="CONFIRM" url="http://gallery.menalto.com/modules.php?op=modload&amp;name=News&amp;file=article&amp;sid=147">http://gallery.menalto.com/modules.php?op=modload&amp;name=News&amp;file=article&amp;sid=147</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/13887/">13887</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18938">gallery-multiple-xss(18938)</ref></refs><vuln_soft><prod name="Gallery" vendor="Gallery Project"><vers num="1.4.4 pl2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-08-17" name="CVE-2005-0221" published="2005-01-17" seq="2005-0221" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in login.php in Gallery 2.0 Alpha allows remote attackers to inject arbitrary web script or HTML via the g2_form[subject] field.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110608459222364&amp;w=2">20050117 Gallery v1.3.4-pl1, v1.4.4-pl2, 2.0 Alpha Cross Site Scripting Vulnerability</ref><ref adv="1" source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2005-q1/0031.html">20050117 [VulnWatch] Gallery v1.3.4-pl1, v1.4.4-pl2, 2.0 Alpha Cross Site Scripting Vulnerability</ref><ref adv="1" source="MISC" url="http://theinsider.deep-ice.com/texts/advisory69.txt">http://theinsider.deep-ice.com/texts/advisory69.txt</ref><ref adv="1" patch="1" source="CONFIRM" url="http://gallery.menalto.com/modules.php?op=modload&amp;name=News&amp;file=article&amp;sid=147">http://gallery.menalto.com/modules.php?op=modload&amp;name=News&amp;file=article&amp;sid=147</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18938">gallery-multiple-xss(18938)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/43472">gallery-g2formsubject-xss(43472)</ref></refs><vuln_soft><prod name="Gallery" vendor="Gallery Project"><vers num="2.0 Alpha"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-08-17" name="CVE-2005-0222" published="2005-05-02" seq="2005-0222" severity="Medium" type="CVE"><desc><descript source="cve">main.php in Gallery 2.0 Alpha allows remote attackers to gain sensitive information by changing the value of g2_subView parameter, which reveals the path in an error message.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110608459222364&amp;w=2">20050117 Gallery v1.3.4-pl1, v1.4.4-pl2, 2.0 Alpha Cross Site Scripting Vulnerability</ref><ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2005-q1/0031.html">20050117 [VulnWatch] Gallery v1.3.4-pl1, v1.4.4-pl2, 2.0 Alpha Cross Site Scripting Vulnerability</ref><ref adv="1" source="MISC" url="http://theinsider.deep-ice.com/texts/advisory69.txt">http://theinsider.deep-ice.com/texts/advisory69.txt</ref><ref source="CONFIRM" url="http://gallery.menalto.com/modules.php?op=modload&amp;name=News&amp;file=article&amp;sid=147">http://gallery.menalto.com/modules.php?op=modload&amp;name=News&amp;file=article&amp;sid=147</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18940">gallery-mainphp-obtain-information(18940)</ref></refs><vuln_soft><prod name="Gallery" vendor="Gallery Project"><vers num="2.0 Alpha"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0223" published="2005-05-02" seq="2005-0223" severity="Medium" type="CVE"><desc><descript source="cve">The Software Development Kit (SDK) and Run Time Environment (RTE) 1.4.1 and 1.4.2 for Tru64 UNIX allows remote attackers to cause a denial of service (Java Virtual Machine hang) via object deserialization.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="HP" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110719624029320&amp;w=2">SSRT4875</ref></refs><vuln_soft><prod name="RTE" vendor="Sun"><vers num="1.4.1"/><vers num="1.4.2"/></prod><prod name="Tru64" vendor="Compaq"><vers num=""/></prod><prod name="SDK" vendor="Sun"><vers num="1.4.1"/><vers num="1.4.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0224" published="2005-01-31" seq="2005-0224" severity="Medium" type="CVE"><desc><descript source="cve">Unknown vulnerability in HP-UX B.11.04 running Virtualvault 4.5 through 4.7, when running the TGA daemon, allows remote attackers to cause a denial of service via certain network traffic.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="HP" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110726808700080&amp;w=2">SSRT5900</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14082/">14082</ref></refs><vuln_soft><prod name="VirtualVault" vendor="HP"><vers num="4.5"/><vers num="4.6"/><vers num="4.7"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0225" published="2005-05-02" seq="2005-0225" severity="Low" type="CVE"><desc><descript source="cve">firehol.sh in FireHOL before 1.224 creates temporary files with predictable file names, which could allow local users to overwrite arbitrary files via a symlink attack.</descript></desc><loss_types><int/></loss_types><vuln_types><exception/></vuln_types><range><local/></range><refs><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200502-01.xml">GLSA-200502-01</ref><ref source="CONFIRM" url="http://cvs.sourceforge.net/viewcvs.py/firehol/firehol/firehol.sh">http://cvs.sourceforge.net/viewcvs.py/firehol/firehol/firehol.sh</ref><ref source="BID" url="http://www.securityfocus.com/bid/12336">12336</ref><ref source="OSVDB" url="http://www.osvdb.org/13137">13137</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1012969">1012969</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13970">13970</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14102">14102</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19032">firehol-symlink(19032)</ref></refs><vuln_soft><prod name="FireHOL" vendor="FireHOL"><vers num="1.224"/><vers num="1.223"/><vers num="1.222"/><vers num="1.221"/><vers num="1.220"/><vers num="1.219"/><vers num="1.218"/><vers num="1.217"/><vers num="1.216"/><vers num="1.215"/><vers num="1.214"/><vers num="1.213"/><vers num="1.212"/><vers num="1.211"/><vers num="1.210"/><vers num="1.209"/><vers num="1.208"/><vers num="1.207"/><vers num="1.206"/><vers num="1.205"/><vers num="1.204"/><vers num="1.203"/><vers num="1.202"/><vers num="1.201"/><vers num="1.200"/><vers num="1.199"/><vers num="1.198"/><vers num="1.197"/><vers num="1.196"/><vers num="1.195"/><vers num="1.194"/><vers num="1.193"/><vers num="1.192"/><vers num="1.191"/><vers num="1.190"/><vers num="1.189"/><vers num="1.188"/><vers num="1.187"/><vers num="1.186"/><vers num="1.185"/><vers num="1.184"/><vers num="1.183"/><vers num="1.182"/><vers num="1.181"/><vers num="1.180"/><vers num="1.179"/><vers num="1.178"/><vers num="1.177"/><vers num="1.176"/><vers num="1.175"/><vers num="1.174"/><vers num="1.173"/><vers num="1.172"/><vers num="1.171"/><vers num="1.170"/><vers num="1.169"/><vers num="1.168"/><vers num="1.167"/><vers num="1.166"/><vers num="1.165"/><vers num="1.164"/><vers num="1.163"/><vers num="1.162"/><vers num="1.161"/><vers num="1.160"/><vers num="1.159"/><vers num="1.158"/><vers num="1.157"/><vers num="1.156"/><vers num="1.155"/><vers num="1.154"/><vers num="1.153"/><vers num="1.152"/><vers num="1.151"/><vers num="1.150"/><vers num="1.149"/><vers num="1.148"/><vers num="1.147"/><vers num="1.146"/><vers num="1.145"/><vers num="1.144"/><vers num="1.143"/><vers num="1.142"/><vers num="1.141"/><vers num="1.140"/><vers num="1.139"/><vers num="1.138"/><vers num="1.137"/><vers num="1.136"/><vers num="1.135"/><vers num="1.134"/><vers num="1.133"/><vers num="1.132"/><vers num="1.131"/><vers num="1.130"/><vers num="1.129"/><vers num="1.128"/><vers num="1.127"/><vers num="1.126"/><vers num="1.125"/><vers num="1.124"/><vers num="1.123"/><vers num="1.122"/><vers num="1.121"/><vers num="1.120"/><vers num="1.119"/><vers num="1.118"/><vers num="1.117"/><vers num="1.116"/><vers num="1.115"/><vers num="1.114"/><vers num="1.113"/><vers num="1.112"/><vers num="1.111"/><vers num="1.110"/><vers num="1.109"/><vers num="1.108"/><vers num="1.107"/><vers num="1.106"/><vers num="1.105"/><vers num="1.104"/><vers num="1.103"/><vers num="1.102"/><vers num="1.101"/><vers num="1.100"/><vers num="1.99"/><vers num="1.98"/><vers num="1.97"/><vers num="1.96"/><vers num="1.95"/><vers num="1.94"/><vers num="1.93"/><vers num="1.92"/><vers num="1.91"/><vers num="1.90"/><vers num="1.89"/><vers num="1.88"/><vers num="1.87"/><vers num="1.86"/><vers num="1.85"/><vers num="1.84"/><vers num="1.83"/><vers num="1.82"/><vers num="1.81"/><vers num="1.80"/><vers num="1.79"/><vers num="1.78"/><vers num="1.77"/><vers num="1.76"/><vers num="1.75"/><vers num="1.74"/><vers num="1.73"/><vers num="1.72"/><vers num="1.71"/><vers num="1.70"/><vers num="1.69"/><vers num="1.68"/><vers num="1.67"/><vers num="1.66"/><vers num="1.65"/><vers num="1.64"/><vers num="1.63"/><vers num="1.62"/><vers num="1.61"/><vers num="1.60"/><vers num="1.59"/><vers num="1.58"/><vers num="1.57"/><vers num="1.56"/><vers num="1.55"/><vers num="1.54"/><vers num="1.53"/><vers num="1.52"/><vers num="1.51"/><vers num="1.50"/><vers num="1.49"/><vers num="1.48"/><vers num="1.47"/><vers num="1.46"/><vers num="1.45"/><vers num="1.44"/><vers num="1.43"/><vers num="1.42"/><vers num="1.41"/><vers num="1.40"/><vers num="1.39"/><vers num="1.38"/><vers num="1.37"/><vers num="1.36"/><vers num="1.35"/><vers num="1.34"/><vers num="1.33"/><vers num="1.32"/><vers num="1.31"/><vers num="1.30"/><vers num="1.29"/><vers num="1.28"/><vers num="1.27"/><vers num="1.26"/><vers num="1.25"/><vers num="1.24"/><vers num="1.23"/><vers num="1.22"/><vers num="1.21"/><vers num="1.20"/><vers num="1.19"/><vers num="1.18"/><vers num="1.17"/><vers num="1.16"/><vers num="1.15"/><vers num="1.14"/><vers num="1.13"/><vers num="1.12"/><vers num="1.11"/><vers num="1.10"/><vers num="1.9"/><vers num="1.8"/><vers num="1.7"/><vers num="1.6"/><vers num="1.5"/><vers num="1.4"/><vers num="1.3"/><vers num="1.2"/><vers num="1.1"/><vers num="1.1.1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0226" published="2005-02-03" seq="2005-0226" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in the Log_Resolver function in log.c for ngIRCd 0.8.2 and earlier, when compiled with IDENT, logging to SYSLOG, and with DEBUG enabled, allows remote attackers to execute arbitrary code.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110746413108183&amp;w=2">20050203 ngIRCd &lt;= v0.8.2 Format String Vulnerability</ref><ref adv="1" patch="1" source="MISC" url="http://www.nosystem.com.ar/advisories/advisory-11.txt">http://www.nosystem.com.ar/advisories/advisory-11.txt</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14114/">14114</ref><ref source="BID" url="http://www.securityfocus.com/bid/12434">12434</ref></refs><vuln_soft><prod name="ngIRCd" vendor="ngIRCd"><vers num="0.8.2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0227" published="2005-05-02" seq="2005-0227" severity="Medium" type="CVE"><desc><descript source="cve">PostgreSQL (pgsql) 7.4.x, 7.2.x, and other versions allows local users to load arbitrary shared libraries and execute code via the LOAD extension.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" source="MLIST" url="http://archives.postgresql.org/pgsql-bugs/2005-01/msg00269.php">[pgsql-bugs] 20050121 Privilege escalation via LOAD</ref><ref patch="1" source="MLIST" url="http://archives.postgresql.org/pgsql-announce/2005-02/msg00000.php">[pgsql-announce] 20050201 PostgreSQL Security Release</ref><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-668">DSA-668</ref><ref patch="1" source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200502-08.xml">200502-08</ref><ref patch="1" source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:040">MDKSA-2005:040</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-138.html">RHSA-2005:138</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-150.html">RHSA-2005:150</ref><ref adv="1" patch="1" source="TRUSTIX" url="http://www.trustix.org/errata/2005/0003/">2005-0003</ref><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110726899107148&amp;w=2">20050201 [USN-71-1] PostgreSQL vulnerability</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/12948">12948</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_36_sudo.html">SUSE-SA:2005:036</ref><ref source="BID" url="http://www.securityfocus.com/bid/12411">
12411</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:040">MDKSA-2005:040</ref></refs><vuln_soft><prod name="PostgreSQL" vendor="PostgreSQL"><vers num="7.4.1"/><vers num="7.4.2"/><vers num="7.4.3"/><vers num="7.4.4"/><vers num="7.4.5"/><vers num="7.4.6"/><vers num="7.4.7"/><vers num="7.2.1"/><vers num="7.2.2"/><vers num="7.2.3"/><vers num="7.2.4"/><vers num="7.2.5"/><vers num="7.2.6"/><vers num="7.2.7"/></prod></vuln_soft></entry><entry modified="2005-10-25" name="CVE-2005-0228" published="2005-05-02" reject="1" seq="2005-0228" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2004-1388.  Reason: This candidate is a duplicate of CVE-2004-1388.  Notes: All CVE users should reference CVE-2004-1388 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript></desc><refs/></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-05-12" name="CVE-2005-0229" published="2005-04-27" seq="2005-0229" severity="Medium" type="CVE"><desc><descript source="cve">CitrusDB 0.3.5 and earlier stores the newfile.txt temporary data file under the web root, which allows remote attackers to steal credit card information via a direct request to newfile.txt.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/12402">bid 12402</ref><ref adv="1" patch="1" source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=110824766519417&amp;w=2">20050212 Credit Card data disclosure in CitrusDB</ref><ref source="CONFIRM" url="http://www.citrusdb.org/forums/viewtopic.php?t=49">http://www.citrusdb.org/forums/viewtopic.php?t=49</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19145">citrus-information-disclosure(19145)</ref><ref adv="1" source="" url="http://www.redteam-pentesting.de/advisories/rt-sa-2005-001.txt"></ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013040">1013040</ref></refs><vuln_soft><prod name="CitrusDB Customer Database" vendor="CitrusDB"><vers num="0.1.2"/><vers num="0.2"/><vers num="0.2.1"/><vers num="0.3"/><vers num="0.3.1"/><vers num="0.3.5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0230" published="2005-05-02" seq="2005-0230" severity="Medium" type="CVE"><desc><descript source="cve">Firefox 1.0 does not prevent the user from dragging an executable file to the desktop when it has an image/gif content type but has a dangerous extension such as .bat or .exe, which allows remote attackers to bypass the intended restriction and execute arbitrary commands via malformed GIF files that can still be parsed by the Windows batch file parser, aka &quot;firedragging.&quot;</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200503-30.xml">GLSA-200503-30</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval100033.html">OVAL100033</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_04_25.html">SUSE-SA:2006:022</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19823">19823</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100033">oval:org.mitre.oval:def:100033</ref><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110780995232064&amp;w=2">20050207 Firedragging [Firefox 1.0]</ref><ref source="MISC" url="http://www.mikx.de/firedragging/">http://www.mikx.de/firedragging/</ref><ref adv="1" source="CONFIRM" url="https://bugzilla.mozilla.org/show_bug.cgi?id=279945">https://bugzilla.mozilla.org/show_bug.cgi?id=279945</ref><ref patch="1" source="CONFIRM" url="http://www.mozilla.org/security/announce/mfsa2005-25.html">http://www.mozilla.org/security/announce/mfsa2005-25.html</ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200503-10.xml">GLSA-200503-10</ref></refs><vuln_soft><prod name="Firefox" vendor="Mozilla"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0231" published="2005-02-07" seq="2005-0231" severity="Low" type="CVE"><desc><descript source="cve">Firefox 1.0 does not invoke the Javascript Security Manager when a user drags a javascript: or data: URL to a tab, which allows remote attackers to bypass the security model, aka &quot;firetabbing.&quot;</descript></desc><loss_types><int/></loss_types><vuln_types><access/><input/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110781134617144&amp;w=2">20050207 Firetabbing [Firefox 1.0]</ref><ref adv="1" source="MISC" url="http://www.mikx.de/firetabbing/">http://www.mikx.de/firetabbing/</ref><ref adv="1" patch="1" source="CONFIRM" url="https://bugzilla.mozilla.org/show_bug.cgi?id=280056">https://bugzilla.mozilla.org/show_bug.cgi?id=280056</ref><ref adv="1" patch="1" source="CONFIRM" url="http://www.mozilla.org/security/announce/mfsa2005-26.html">http://www.mozilla.org/security/announce/mfsa2005-26.html</ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200503-10.xml">GLSA-200503-10</ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200503-30.xml">GLSA-200503-30</ref><ref adv="1" patch="1" source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_16_mozilla_firefox.html">SUSE-SA:2005:016</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19264">mozilla-firefox-tab-gain-access(19264)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval100032.html">OVAL100032</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-176.html">RHSA-2005:176</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-384.html">RHSA-2005:384</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100032">oval:org.mitre.oval:def:100032</ref></refs><vuln_soft><prod name="Firefox" vendor="Mozilla"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0232" published="2005-05-02" seq="2005-0232" severity="Low" type="CVE"><desc><descript source="cve">Firefox 1.0 allows remote attackers to modify Boolean configuration parameters for the about:config site by using a plugin such as Flash, and the -moz-opacity filter, to display the about:config site then cause the user to double-click at a certain screen position, aka &quot;Fireflashing.&quot;</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="MISC" url="http://www.mikx.de/fireflashing/">http://www.mikx.de/fireflashing/</ref><ref adv="1" source="CONFIRM" url="https://bugzilla.mozilla.org/show_bug.cgi?id=280664">https://bugzilla.mozilla.org/show_bug.cgi?id=280664</ref><ref adv="1" source="CONFIRM" url="http://www.mozilla.org/security/announce/mfsa2005-27.html">http://www.mozilla.org/security/announce/mfsa2005-27.html</ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200503-10.xml">GLSA-200503-10</ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200503-30.xml">GLSA-200503-30</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-323.html">RHSA-2005:323</ref><ref adv="1" patch="1" source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_16_mozilla_firefox.html">SUSE-SA:2005:016</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19266">mozilla-firefox-aboutconfig-modify(19266)</ref><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110781055630856&amp;w=2">20050207 Fireflashing [Firefox 1.0]</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-176.html">RHSA-2005:176</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-384.html">RHSA-2005:384</ref></refs><vuln_soft><prod name="Firefox" vendor="Mozilla"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-21" name="CVE-2005-0233" published="2005-02-08" seq="2005-0233" severity="High" type="CVE"><desc><descript source="cve">The International Domain Name (IDN) support in Firefox 1.0, Camino .8.5, and Mozilla before 1.7.6 allows remote attackers to spoof domain names using punycode encoded domain names that are decoded in URLs and SSL certificates in a way that uses homograph characters from other character sets, which facilitates phishing attacks.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-February/031459.html">20050206 state of homograph attacks</ref><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110782704923280&amp;w=2">20050208 International Domain Name [IDN] support in modern browsers allows attackers to spoof domain name URLs + SSL certs.</ref><ref adv="1" source="MISC" url="http://www.shmoo.com/idn">http://www.shmoo.com/idn</ref><ref adv="1" source="MISC" url="http://www.shmoo.com/idn/homograph.txt">http://www.shmoo.com/idn/homograph.txt</ref><ref adv="1" patch="1" source="CONFIRM" url="http://www.mozilla.org/security/announce/mfsa2005-29.html">http://www.mozilla.org/security/announce/mfsa2005-29.html</ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200503-10.xml">GLSA-200503-10</ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200503-30.xml">GLSA-200503-30</ref><ref adv="1" patch="1" source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_16_mozilla_firefox.html">SUSE-SA:2005:016</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19236">multiple-browsers-idn-spoof(19236)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval100029.html">OVAL100029</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-176.html">RHSA-2005:176</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-384.html">RHSA-2005:384</ref><ref source="BID" url="http://www.securityfocus.com/bid/12461">12461</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100029">oval:org.mitre.oval:def:100029</ref></refs><vuln_soft><prod name="OmniWeb" vendor="OmniGroup"><vers num="5"/></prod><prod name="Opera Web Browser" vendor="Opera Software"><vers num="7.54"/></prod><prod name="Camino" vendor="Mozilla"><vers num=".8.5"/></prod><prod name="Mozilla Browser" vendor="Mozilla"><vers num="1.6"/><vers num="1.5.1"/><vers num="1.5"/><vers num="1.4.4"/><vers num="1.4.2"/><vers num="1.4.1"/><vers num="1.4b"/><vers num="1.4a"/><vers num="1.4"/><vers num="1.3.1"/><vers num="1.3"/><vers num="1.2.1"/><vers num="1.2 Beta"/><vers num="1.2 Alpha"/><vers num="1.2"/><vers num="1.1 Beta"/><vers num="1.1 Alpha"/><vers num="1.1"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0 RC2"/><vers num="1.0 RC1"/><vers num="1.0"/><vers num="0.9.9"/><vers num="0.9.8"/><vers num="0.9.7"/><vers num="0.9.6"/><vers num="0.9.5"/><vers num="0.9.48"/><vers num="0.9.4.1"/><vers num="0.9.4"/><vers num="0.9.35"/><vers num="0.9.3"/><vers num="0.9.2.1"/><vers num="0.9.2"/><vers num="0.8"/></prod><prod name="Firefox" vendor="Mozilla"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0234" published="2005-05-02" seq="2005-0234" severity="Medium" type="CVE"><desc><descript source="cve">The International Domain Name (IDN) support in Safari 1.2.5 allows remote attackers to spoof domain names using punycode encoded domain names that are decoded in URLs and SSL certificates in a way that uses homograph characters from other character sets, which facilitates phishing attacks.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-February/031459.html">20050206 state of homograph attacks</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110782704923280&amp;w=2">20050208 International Domain Name [IDN] support in modern browsers allows attackers to spoof domain name URLs + SSL certs.</ref><ref source="MISC" url="http://www.shmoo.com/idn">http://www.shmoo.com/idn</ref><ref adv="1" source="MISC" url="http://www.shmoo.com/idn/homograph.txt">http://www.shmoo.com/idn/homograph.txt</ref><ref adv="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/Mar/msg00000.html">APPLE-SA-2005-03-21</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19236">multiple-browsers-idn-spoof(19236)</ref><ref source="BID" url="http://www.securityfocus.com/bid/12461">12461</ref></refs><vuln_soft><prod name="Safari" vendor="Apple"><vers num="1.2.5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0235" published="2005-05-02" seq="2005-0235" severity="Medium" type="CVE"><desc><descript source="cve">The International Domain Name (IDN) support in Opera 7.54 allows remote attackers to spoof domain names using punycode encoded domain names that are decoded in URLs and SSL certificates in a way that uses homograph characters from other character sets, which facilitates phishing attacks.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-February/031459.html">20050206 state of homograph attacks</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110782704923280&amp;w=2">20050208 International Domain Name [IDN] support in modern browsers allows attackers to spoof domain name URLs + SSL certs.</ref><ref source="MISC" url="http://www.shmoo.com/idn">http://www.shmoo.com/idn</ref><ref source="MISC" url="http://www.shmoo.com/idn/homograph.txt">http://www.shmoo.com/idn/homograph.txt</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19236">multiple-browsers-idn-spoof(19236)</ref><ref source="BID" url="http://www.securityfocus.com/bid/12461">12461</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_31_opera.html">SUSE-SA:2005:031</ref></refs><vuln_soft><prod name="Opera Web Browser" vendor="Opera Software"><vers num="7.54"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-21" name="CVE-2005-0236" published="2005-05-02" seq="2005-0236" severity="Medium" type="CVE"><desc><descript source="cve">The International Domain Name (IDN) support in Omniweb 5 allows remote attackers to spoof domain names using punycode encoded domain names that are decoded in URLs and SSL certificates in a way that uses homograph characters from other character sets, which facilitates phishing attacks.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-February/031459.html">20050206 state of homograph attacks</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110782704923280&amp;w=2">20050208 International Domain Name [IDN] support in modern browsers allows attackers to spoof domain name URLs + SSL certs.</ref><ref source="MISC" url="http://www.shmoo.com/idn">http://www.shmoo.com/idn</ref><ref source="MISC" url="http://www.shmoo.com/idn/homograph.txt">http://www.shmoo.com/idn/homograph.txt</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19236">multiple-browsers-idn-spoof(19236)</ref><ref source="BID" url="http://www.securityfocus.com/bid/12461">12461</ref></refs><vuln_soft><prod name="OmniWeb" vendor="OmniGroup"><vers num="5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0237" published="2005-05-02" seq="2005-0237" severity="Medium" type="CVE"><desc><descript source="cve">The International Domain Name (IDN) support in Konqueror 3.2.1 on KDE 3.2.1 allows remote attackers to spoof domain names using punycode encoded domain names that are decoded in URLs and SSL certificates in a way that uses homograph characters from other character sets, which facilitates phishing attacks.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-February/031459.html">20050206 state of homograph attacks</ref><ref adv="1" source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-February/031460.html">20050206 Re: state of homograph attacks</ref><ref source="MISC" url="http://www.shmoo.com/idn">http://www.shmoo.com/idn</ref><ref source="MISC" url="http://www.shmoo.com/idn/homograph.txt">http://www.shmoo.com/idn/homograph.txt</ref><ref adv="1" patch="1" source="CONFIRM" url="http://www.kde.org/info/security/advisory-20050316-2.txt">http://www.kde.org/info/security/advisory-20050316-2.txt</ref><ref patch="1" source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:058">MDKSA-2005:058</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14162">14162</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19236">multiple-browsers-idn-spoof(19236)</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-325.html">RHSA-2005:325</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/427976/100/0/threaded">FLSA:178606</ref><ref source="BID" url="http://www.securityfocus.com/bid/12461">12461</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:058">MDKSA-2005:058</ref></refs><vuln_soft><prod name="KDE" vendor="KDE"><vers num="3.2.1"/></prod><prod name="Konqueror" vendor="KDE"><vers num="3.2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-21" name="CVE-2005-0238" published="2005-05-02" seq="2005-0238" severity="Medium" type="CVE"><desc><descript source="cve">The International Domain Name (IDN) support in Epiphany allows remote attackers to spoof domain names using punycode encoded domain names that are decoded in URLs and SSL certificates in a way that uses homograph characters from other character sets, which facilitates phishing attacks.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-February/031459.html">20050206 state of homograph attacks</ref><ref adv="1" source="MISC" url="http://www.shmoo.com/idn">http://www.shmoo.com/idn</ref><ref adv="1" source="MISC" url="http://www.shmoo.com/idn/homograph.txt">http://www.shmoo.com/idn/homograph.txt</ref><ref adv="1" patch="1" source="CONFIRM" url="https://bugzilla.redhat.com/beta/show_bug.cgi?id=147399">https://bugzilla.redhat.com/beta/show_bug.cgi?id=147399</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19236">multiple-browsers-idn-spoof(19236)</ref><ref source="BID" url="http://www.securityfocus.com/bid/12461">12461</ref></refs><vuln_soft><prod name="OmniWeb" vendor="OmniGroup"><vers num="5"/></prod><prod name="Opera Web Browser" vendor="Opera Software"><vers num="7.54"/></prod><prod name="Epiphany" vendor="GNOME"><vers num=""/></prod><prod name="Camino" vendor="Mozilla"><vers num=".8.5"/></prod><prod name="Mozilla Browser" vendor="Mozilla"><vers num="1.6"/><vers num="1.5.1"/><vers num="1.5"/><vers num="1.4.4"/><vers num="1.4.2"/><vers num="1.4.1"/><vers num="1.4b"/><vers num="1.4a"/><vers num="1.4"/><vers num="1.3.1"/><vers num="1.3"/><vers num="1.2.1"/><vers num="1.2 Beta"/><vers num="1.2 Alpha"/><vers num="1.2"/><vers num="1.1 Beta"/><vers num="1.1 Alpha"/><vers num="1.1"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0 RC2"/><vers num="1.0 RC1"/><vers num="1.0"/><vers num="0.9.9"/><vers num="0.9.8"/><vers num="0.9.7"/><vers num="0.9.6"/><vers num="0.9.5"/><vers num="0.9.48"/><vers num="0.9.4.1"/><vers num="0.9.4"/><vers num="0.9.35"/><vers num="0.9.3"/><vers num="0.9.2.1"/><vers num="0.9.2"/><vers num="0.8"/></prod><prod name="Firefox" vendor="Mozilla"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0239" published="2005-05-02" seq="2005-0239" severity="High" type="CVE"><desc><descript source="cve">viewcert.php in the S/MIME plugin 0.4 and 0.5 for Squirrelmail allows remote attackers to execute arbitrary commands via shell metacharacters in the cert parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=191&amp;type=vulnerabilities&amp;flashstatus=false">20050207 SquirrelMail S/MIME Plugin Command Injection Vulnerability</ref><ref source="CONFIRM" url="http://www.squirrelmail.org/plugin_view.php?id=54">http://www.squirrelmail.org/plugin_view.php?id=54</ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/502328">VU#502328</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19242">squirrelmail-smime-command-execution(19242)</ref></refs><vuln_soft><prod name="S/MIME Plugin" vendor="Squirrelmail"><vers num="0.4"/><vers num="0.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0240" published="2005-05-02" seq="2005-0240" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in chdev on IBM AIX 5.2 allows local users to execute arbitrary code via format string specifiers in a command line argument, which is not properly handled when printing an error message.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref source="IDEFENSE" url="http://www.idefense.com/application/poi/display?type=vulnerabilities">20050207 IBM AIX chdev Local Format String Vulnerability</ref><ref adv="1" source="AIXAPAR" url="http://www-1.ibm.com/support/docview.wss?uid=isg1IY67455">IY67455</ref><ref adv="1" source="AIXAPAR" url="http://www-1.ibm.com/support/docview.wss?uid=isg1IY67654">IY67654</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19244">aix-chdev-format-string(19244)</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="5.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0241" published="2005-05-02" seq="2005-0241" severity="Medium" type="CVE"><desc><descript source="cve">The httpProcessReplyHeader function in http.c for Squid 2.5-STABLE7 and earlier does not properly set the debug context when it is handling &quot;oversized&quot; HTTP reply headers, which might allow remote attackers to poison the cache or bypass access controls based on header size.</descript></desc><loss_types><int/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref patch="1" source="CONFIRM" url="http://www.squid-cache.org/bugs/show_bug.cgi?id=1216">http://www.squid-cache.org/bugs/show_bug.cgi?id=1216</ref><ref patch="1" source="CONFIRM" url="http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE7-oversize_reply_headers">http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE7-oversize_reply_headers</ref><ref patch="1" source="CONFIRM" url="http://www.squid-cache.org/Versions/v2/2.5/bugs/squid-2.5.STABLE7-oversize_reply_headers.patch">http://www.squid-cache.org/Versions/v2/2.5/bugs/squid-2.5.STABLE7-oversize_reply_headers.patch</ref><ref patch="1" source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000931">CLA-2005:931</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-060.html">RHSA-2005:060</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-061.html">RHSA-2005:061</ref><ref adv="1" patch="1" source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_06_squid.html">SUSE-SA:2005:006</ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/823350">VU#823350</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19060">squid-http-cache-poisoning(19060)</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14091">14091</ref><ref source="FEDORA" url="http://fedoranews.org/updates/FEDORA--.shtml">FLSA-2006:152809</ref><ref source="BID" url="http://www.securityfocus.com/bid/12412">12412</ref></refs><vuln_soft><prod name="Squid" vendor="Squid"><vers num="2.5.STABLE7"/><vers num="2.5.STABLE6"/><vers num="2.5.STABLE5"/><vers num="2.5.STABLE4"/><vers num="2.5.STABLE3"/><vers num="2.5.STABLE2"/><vers num="2.5.STABLE1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0242" published="2005-02-18" seq="2005-0242" severity="Medium" type="CVE"><desc><descript source="cve">The Audio Setup Wizard (asw.dll) in Yahoo! Messenger 6.0.0.1750, and possibly other versions, allows attackers to arbitrary code by placing a malicious ping.exe program into the Messenger program directory, which is installed with weak default permissions.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="MISC" url="http://secunia.com/secunia_research/2004-6/advisory/">http://secunia.com/secunia_research/2004-6/advisory/</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/11815">11815</ref></refs><vuln_soft><prod name="Messenger" vendor="Yahoo"><vers num="6.0.0.1750"/><vers num="6.0"/><vers num="5.6.0.1351"/><vers num="5.6"/><vers num="5.5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0243" published="2005-02-17" seq="2005-0243" severity="Medium" type="CVE"><desc><descript source="cve">Yahoo! Messenger 6.0.0.1750, and possibly other versions before 6.0.0.1921, does not properly display long filenames in file dialog boxes, which could allow remote attackers to trick users into downloading and executing programs via file names containing a large number of spaces and multiple file extensions.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="MISC" url="http://secunia.com/secunia_research/2005-2/advisory/">http://secunia.com/secunia_research/2005-2/advisory/</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/13712">13712</ref></refs><vuln_soft><prod name="Messenger" vendor="Yahoo"><vers num="6.0.0.1750"/><vers num="6.0"/><vers num="5.6.0.1351"/><vers num="5.6"/><vers num="5.5"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0244" published="2005-05-02" seq="2005-0244" severity="Medium" type="CVE"><desc><descript source="cve">PostgreSQL 8.0.0 and earlier allows local users to bypass the EXECUTE permission check for functions by using the CREATE AGGREGATE command.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" source="MLIST" url="http://archives.postgresql.org/pgsql-hackers/2005-01/msg00922.php">[pgsql-hackers] 20050127 Permissions on aggregate component functions</ref><ref adv="1" patch="1" source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:040">MDKSA-2005:040</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-138.html">RHSA-2005:138</ref><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110806034116082&amp;w=2">20050210 [USN-79-1] PostgreSQL vulnerabilities</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/12948">12948</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19184">postgresql-security-bypass(19184)</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_36_sudo.html">SUSE-SA:2005:036</ref><ref source="BID" url="http://www.securityfocus.com/bid/12417">
12417</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:040">MDKSA-2005:040</ref></refs><vuln_soft><prod name="PostgreSQL" vendor="PostgreSQL"><vers num="8.0.0"/><vers num="7.4"/><vers num="7.4.1"/><vers num="7.4.2"/><vers num="7.4.3"/><vers num="7.4.4"/><vers num="7.4.5"/><vers num="7.4.6"/><vers num="7.4.7"/><vers num="7.3"/><vers num="7.3.1"/><vers num="7.3.2"/><vers num="7.3.3"/><vers num="7.3.4"/><vers num="7.3.5"/><vers num="7.3.6"/><vers num="7.3.7"/><vers num="7.3.8"/><vers num="7.3.9"/><vers num="7.2"/><vers num="7.2.1"/><vers num="7.2.2"/><vers num="7.2.3"/><vers num="7.2.4"/><vers num="7.2.5"/><vers num="7.2.6"/><vers num="7.2.7"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-25" name="CVE-2005-0245" published="2005-02-01" seq="2005-0245" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in gram.y for PostgreSQL 8.0.0 and earlier may allow attackers to execute arbitrary code via a large number of arguments to a refcursor function (gram.y), which leads to a heap-based buffer overflow, a different vulnerability than CVE-2005-0247.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="MLIST" url="http://archives.postgresql.org/pgsql-patches/2005-01/msg00216.php">[pgsql-patches] 20050120 Re: WIP: pl/pgsql cleanup</ref><ref adv="1" source="MLIST" url="http://archives.postgresql.org/pgsql-committers/2005-01/msg00298.php">[pgsql-committers] 20050121 pgsql: Prevent overrunning a heap-allocated buffer is more than 1024</ref><ref adv="1" source="MLIST" url="http://archives.postgresql.org/pgsql-committers/2005-02/msg00049.php">[pgsql-committers] 20050207 pgsql: Prevent 4 more buffer overruns in the PL/PgSQL parser.</ref><ref adv="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-683">DSA-683</ref><ref adv="1" patch="1" source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:040">MDKSA-2005:040</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-138.html">RHSA-2005:138</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-150.html">RHSA-2005:150</ref><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110806034116082&amp;w=2">20050210 [USN-79-1] PostgreSQL vulnerabilities</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/12948">12948</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19188">postgresql-cursor-bo(19188)</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_36_sudo.html">SUSE-SA:2005:036</ref><ref source="BID" url="http://www.securityfocus.com/bid/12417">
12417</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:040">MDKSA-2005:040</ref></refs><vuln_soft><prod name="PostgreSQL" vendor="PostgreSQL"><vers num="8.0"/><vers num="7.4.7"/><vers num="7.4.6"/><vers num="7.4.5"/><vers num="7.4.4"/><vers num="7.4.3"/><vers num="7.4.2"/><vers num="7.4.1"/><vers num="7.4"/><vers num="7.3.9"/><vers num="7.3.8"/><vers num="7.3.7"/><vers num="7.3.6"/><vers num="7.3.5"/><vers num="7.3.4"/><vers num="7.3.3"/><vers num="7.3.2"/><vers num="7.3.1"/><vers num="7.3"/><vers num="7.2.7"/><vers num="7.2.6"/><vers num="7.2.5"/><vers num="7.2.4"/><vers num="7.2.3"/><vers num="7.2.2"/><vers num="7.2.1"/><vers num="7.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0246" published="2005-05-02" seq="2005-0246" severity="Medium" type="CVE"><desc><descript source="cve">The intagg contrib module for PostgreSQL 8.0.0 and earlier allows attackers to cause a denial of service (crash) via crafted arrays.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="MLIST" url="http://archives.postgresql.org/pgsql-committers/2005-01/msg00401.php">[pgsql-committers] 20050127 pgsql: Fix security and 64-bit issues in contrib/intagg.</ref><ref adv="1" patch="1" source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:040">MDKSA-2005:040</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-138.html">RHSA-2005:138</ref><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110806034116082&amp;w=2">20050210 [USN-79-1] PostgreSQL vulnerabilities</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/12948">12948</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19185">postgresql-contribintagg-dos(19185)</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_36_sudo.html">SUSE-SA:2005:036</ref><ref source="BID" url="http://www.securityfocus.com/bid/12417">
12417</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:040">MDKSA-2005:040</ref></refs><vuln_soft><prod name="PostgreSQL" vendor="PostgreSQL"><vers num="8.0.0"/><vers num="7.4"/><vers num="7.4.1"/><vers num="7.4.2"/><vers num="7.4.3"/><vers num="7.4.4"/><vers num="7.4.5"/><vers num="7.4.6"/><vers num="7.4.7"/><vers num="7.3"/><vers num="7.3.1"/><vers num="7.3.2"/><vers num="7.3.3"/><vers num="7.3.4"/><vers num="7.3.5"/><vers num="7.3.6"/><vers num="7.3.7"/><vers num="7.3.8"/><vers num="7.3.9"/><vers num="7.2"/><vers num="7.2.1"/><vers num="7.2.2"/><vers num="7.2.3"/><vers num="7.2.4"/><vers num="7.2.5"/><vers num="7.2.6"/><vers num="7.2.7"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-25" name="CVE-2005-0247" published="2005-05-02" seq="2005-0247" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in gram.y for PostgreSQL 8.0.1 and earlier may allow attackers to execute arbitrary code via (1) a large number of variables in a SQL statement being handled by the read_sql_construct function, (2) a large number of INTO variables in a SELECT statement being handled by the make_select_stmt function, (3) a large number of arbitrary variables in a SELECT statement being handled by the make_select_stmt function, and (4) a large number of INTO variables in a FETCH statement being handled by the make_fetch_stmt function, a different set of vulnerabilities than CVE-2005-0245.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref patch="1" source="MLIST" url="http://archives.postgresql.org/pgsql-committers/2005-02/msg00049.php">[pgsql-committers] 20050207 pgsql: Prevent 4 more buffer overruns in the PL/PgSQL parser.</ref><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-683">DSA-683</ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200502-19.xml">GLSA-200502-19</ref><ref patch="1" source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:040">MDKSA-2005:040</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-138.html">RHSA-2005:138</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-150.html">RHSA-2005:150</ref><ref adv="1" patch="1" source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_27_postgresql.html">SUSE-SA:2005:027</ref><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110806034116082&amp;w=2">20050210 [USN-79-1] PostgreSQL vulnerabilities</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19378">postgresql-fetch-makefetchstmt-bo(19378)</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19377">postgresql-makeselectstmt-arbitrary-bo(19377)</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19376">postgresql-makeselectstmt-input-bo(19376)</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19375">postgresql-readsqlconstruct-bo(19375)</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_36_sudo.html">SUSE-SA:2005:036</ref><ref source="BID" url="http://www.securityfocus.com/bid/12417">
12417</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:040">MDKSA-2005:040</ref></refs><vuln_soft><prod name="PostgreSQL" vendor="PostgreSQL"><vers num="8.0.1"/><vers num="8.0.0"/><vers num="7.4"/><vers num="7.4.1"/><vers num="7.4.2"/><vers num="7.4.3"/><vers num="7.4.4"/><vers num="7.4.5"/><vers num="7.4.6"/><vers num="7.4.7"/><vers num="7.3"/><vers num="7.3.1"/><vers num="7.3.2"/><vers num="7.3.3"/><vers num="7.3.4"/><vers num="7.3.5"/><vers num="7.3.6"/><vers num="7.3.7"/><vers num="7.3.8"/><vers num="7.3.9"/><vers num="7.2"/><vers num="7.2.1"/><vers num="7.2.2"/><vers num="7.2.3"/><vers num="7.2.4"/><vers num="7.2.5"/><vers num="7.2.6"/><vers num="7.2.7"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0248" published="2005-05-02" seq="2005-0248" severity="High" type="CVE"><desc><descript source="cve">The Solaris Management Console (SMC) GUI for Solaris 8 and 9, when creating user accounts that are configured for password aging, creates the accounts with a blank password, which allows remote or local attackers to break into those accounts.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref patch="1" source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57717-1">57717</ref><ref adv="1" source="CIAC" url="http://www.ciac.org/ciac/bulletins/p-096.shtml">P-096</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/12260">12260</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/13803/">13803</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18868">solaris-smc-blank-password(18868)</ref><ref source="BID" url="http://www.securityfocus.com/bid/12260/">12260</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1012860">1012860</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers edition="x86" num="9.0"/><vers edition="SPARC" num="9.0"/><vers edition="x86" num="8.0"/><vers num="8.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-28" name="CVE-2005-0249" published="2005-02-08" seq="2005-0249" severity="High" type="CVE"><desc><descript source="cve">Heap-based buffer overflow in the DEC2EXE module for Symantec AntiVirus Library allows remote attackers to execute arbitrary code via a UPX compressed file containing a negative virtual offset to a crafted PE header.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS" url="http://xforce.iss.net/xforce/alerts/id/187">20050208 Symantec AntiVirus Library Heap Overflow</ref><ref adv="1" patch="1" source="CONFIRM" url="http://www.symantec.com/avcenter/security/Content/2005.02.08.html">http://www.symantec.com/avcenter/security/Content/2005.02.08.html</ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/107822">VU#107822</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18869">upx-engine-gain-control(18869)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013133">1013133</ref></refs><vuln_soft><prod name="Symantec Web Security" vendor="Symantec"><vers num="3.0.1.59"/><vers num="3.0.1.60"/><vers num="3.0.1.61"/><vers num="3.0.1.62"/><vers num="3.0.1.63"/><vers num="3.0.1.67"/><vers num="3.0.1.68"/></prod><prod name="Norton System Works" vendor="Symantec"><vers edition="Windows" num="2004"/><vers edition="Macintosh" num="3.0" prev="1"/></prod><prod name="Norton Internet Security" vendor="Symantec"><vers edition="Professional" num="2004"/><vers edition="Macintosh" num="3.0" prev="1"/></prod><prod name="SAV_Filter Domino NT" vendor="Symantec"><vers num="3.1.1"/></prod><prod name="Symantec Mail Security SMTP" vendor="Symantec"><vers num="4.0.2" prev="1"/></prod><prod name="Symantec Gateway Security" vendor="Symantec"><vers num="2.0"/><vers num="2.0.1"/><vers num="1.0"/></prod><prod name="Symantec AntiVirus Scan Engine Netapp NetCache" vendor="Symantec"><vers num="4.0" prev="1"/><vers num="4.3.3" prev="1"/></prod><prod name="Symantec AntiVirus Scan Engine Netapp Filer" vendor="Symantec"><vers num="4.0" prev="1"/><vers num="4.3.3" prev="1"/></prod><prod name="Mail Security" vendor="Symantec"><vers edition="Exchange" num="4.01 build461"/><vers edition="Exchange" num="4.01 build459"/><vers edition="Exchange" num="4.01 build458"/><vers edition="Exchange" num="4.5 build719"/><vers edition="Domino" num="4.0"/></prod><prod name="BrightMail AntiSpam" vendor="Symantec"><vers num="4.0" prev="1"/><vers num="5.5" prev="1"/></prod><prod name="SAV_Filter Domino NT Ports" vendor="Symantec"><vers edition="AIX" num="build3.0.5"/><vers edition="OS_400" num="build3.0.5"/></prod><prod name="Symantec AntiVirus" vendor="Symantec"><vers edition="Corporate" num="8.1.1 build8.1.1.314a"/><vers edition="Corporate" num="8.1.1 build8.1.1.319"/><vers edition="Corporate" num="8.1.1 build8.1.1.323"/><vers edition="Corporate" num="8.1.1 build8.1.1.329"/><vers edition="Corporate" num="8.01 build8.01.434"/><vers edition="Corporate" num="8.01 build8.01.437"/><vers edition="Corporate" num="8.01 build8.01.446"/><vers edition="Corporate" num="8.01 build8.01.457"/><vers edition="Corporate" num="8.01 build8.01.460"/><vers edition="Corporate" num="8.1 build8.01.464"/><vers edition="Corporate" num="8.01 build8.01.471"/></prod><prod name="Symantec AntiVirus Scan Engine" vendor="Symantec"><vers num="4.0" prev="1"/><vers num="4.3" prev="1"/><vers edition="Bluecoat" num="4.0" prev="1"/><vers edition="Bluecoat" num="4.3.3" prev="1"/><vers edition="Filers" num="4.3.3" prev="1"/><vers edition="Caching" num="4.3.3" prev="1"/></prod><prod name="Norton Antivirus" vendor="Symantec"><vers edition="Windows" num="2004"/><vers edition="Macintosh OSX" num="9.0" prev="1"/><vers edition="Macintosh Corporate" num="9.0"/></prod><prod name="Norton AntiVirus for Exchange" vendor="Symantec"><vers num="2.18 build 83"/></prod><prod name="Symantec Client Security" vendor="Symantec"><vers num="1.1.1 MR1 build 8.1.1.314a"/><vers num="1.1.1 MR2 build 8.1.1.319"/><vers num="1.1.1 MR3 build 8.1.1.323"/><vers num="1.1.1 MR4 build 8.1.1.329"/><vers num="1.1.1 MR5 build 8.1.1.336"/><vers num="1.0.1 MR3 build 8.01.434"/><vers num="1.0.1 build 8.01.437"/><vers num="1.0.1 MR4 build 8.01.446"/><vers num="1.0.1 MR5 build 8.01.457"/><vers num="1.0.1 MR6 build 8.01.460"/><vers num="1.0.1 MR7 build 8.01.464"/><vers num="1.0.1 MR8 build 8.01.471"/></prod><prod name="Symantec AntiVirus SMTP" vendor="Symantec"><vers num="3.1.1"/><vers num="3.1.2"/><vers num="3.1.3"/><vers num="3.1.4"/><vers num="3.1.5"/><vers num="3.1.6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0250" published="2005-05-02" seq="2005-0250" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in auditselect on IBM AIX 5.1, 5.2, and 5.3 allows local users to execute arbitrary code via format string specifiers in a command line argument.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=193&amp;type=vulnerabilities&amp;flashstatus=false">20050208 IBM AIX auditselect Local Format String Vulnerability</ref><ref adv="1" source="AIXAPAR" url="http://www-1.ibm.com/support/docview.wss?uid=isg1IY67519">IY67519</ref><ref adv="1" source="AIXAPAR" url="http://www-1.ibm.com/support/docview.wss?uid=isg1IY67472">IY67472</ref><ref adv="1" source="AIXAPAR" url="http://www-1.ibm.com/support/docview.wss?uid=isg1IY67802">IY67802</ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/896729">VU#896729</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/12496">12496</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/14198">14198</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19255">aix-auditselect-format-string(19255)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013103">1013103</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="5.1"/><vers num="5.2"/><vers num="5.3"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0251" published="2005-05-02" seq="2005-0251" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in bibindex.php for BibORB 1.3.2, and possibly earlier versions, allows remote attackers to inject arbitrary HTML and web script via the search parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110868948719773&amp;w=2">20050217 Advisory: Multiple Vulnerabilities in BibORB</ref><ref adv="1" source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=110864983905770&amp;w=2">20050217 Advisory: Multiple Vulnerabilities in BibORB</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/12583">12583</ref></refs><vuln_soft><prod name="BibORB" vendor="BibORB"><vers num="1.3.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0252" published="2005-05-02" seq="2005-0252" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in BibORB 1.3.2, and possibly earlier versions, allows remote attackers to execute arbitrary SQL commands via the (1) Username or (2) Password.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110868948719773&amp;w=2">20050217 Advisory: Multiple Vulnerabilities in BibORB</ref><ref adv="1" source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=110864983905770&amp;w=2">20050217 Advisory: Multiple Vulnerabilities in BibORB</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/12583">12583</ref></refs><vuln_soft><prod name="BibORB" vendor="BibORB"><vers num="1.3.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0253" published="2005-05-02" seq="2005-0253" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in index.php for BibORB 1.3.2, and possibly earlier versions, allows remote attackers to delete arbitrary files via a Delete action and .. (dot dot) sequences in the database_name parameter.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110868948719773&amp;w=2">20050217 Advisory: Multiple Vulnerabilities in BibORB</ref><ref adv="1" source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=110864983905770&amp;w=2">20050217 Advisory: Multiple Vulnerabilities in BibORB</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/12583">12583</ref></refs><vuln_soft><prod name="BibORB" vendor="BibORB"><vers num="1.3.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0254" published="2005-05-02" seq="2005-0254" severity="Medium" type="CVE"><desc><descript source="cve">BibORB 1.3.2, and possibly earlier versions, does not properly enforce a restriction for uploading only PDF and PS files, which allows remote attackers to upload arbitrary files that are presented to other users with PDF or PS icons, which may trick some users into downloading and executing those files.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110868948719773&amp;w=2">20050217 Advisory: Multiple Vulnerabilities in BibORB</ref><ref adv="1" source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=110864983905770&amp;w=2">20050217 Advisory: Multiple Vulnerabilities in BibORB</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/12583">12583</ref></refs><vuln_soft><prod name="BibORB" vendor="BibORB"><vers num="1.3.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0255" published="2005-05-02" seq="2005-0255" severity="Medium" type="CVE"><desc><descript source="cve">String handling functions in Mozilla 1.7.3, Firefox 1.0, and Thunderbird before 1.0.2, such as the nsTSubstring_CharT::Replace function, do not properly check the return values of other functions that resize the string, which allows remote attackers to cause a denial of service and possibly execute arbitrary code by forcing an out-of-memory state that causes a reallocation to fail and return a pointer to a fixed address, which leads to heap corruption.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=200&amp;type=vulnerabilities">20050228 Mozilla Firefox and Mozilla Browser Out Of Memory Heap Corruption Design Error</ref><ref adv="1" source="CONFIRM" url="http://www.mozilla.org/security/announce/mfsa2005-18.html">http://www.mozilla.org/security/announce/mfsa2005-18.html</ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200503-10.xml">GLSA-200503-10</ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200503-30.xml">GLSA-200503-30</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-277.html">RHSA-2005:277</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-337.html">RHSA-2005:337</ref><ref adv="1" patch="1" source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_16_mozilla_firefox.html">SUSE-SA:2005:016</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval100040.html">OVAL100040</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-176.html">RHSA-2005:176</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_04_25.html">SUSE-SA:2006:022</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19823">19823</ref><ref source="BID" url="http://www.securityfocus.com/bid/12659">12659</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100040">oval:org.mitre.oval:def:100040</ref></refs><vuln_soft><prod name="Mozilla" vendor="Mozilla"><vers num="1.7.3"/></prod><prod name="Thunderbird" vendor="Mozilla"><vers num="1.0"/><vers num="0.9"/><vers num="0.8"/><vers num="0.7"/><vers num="0.6"/><vers num="0.5"/><vers num="0.4"/><vers num="0.3"/><vers num="0.2"/><vers num="0.1"/></prod><prod name="Firefox" vendor="Mozilla"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2008-01-03" name="CVE-2005-0256" published="2005-05-02" seq="2005-0256" severity="Medium" type="CVE"><desc><descript source="cve">The wu_fnmatch function in wu_fnmatch.c in wu-ftpd 2.6.1 and 2.6.2 allows remote attackers to cause a denial of service (CPU exhaustion by recursion) via a glob pattern with a large number of * (wildcard) characters, as demonstrated using the dir command.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=207&amp;type=vulnerabilities">20050225 WU-FTPD File Globbing Denial of Service Vulnerability</ref><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-705">DSA-705</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57795-1">57795</ref><ref source="SCO" url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.63/SCOSA-2005.63.txt">SCOSA-2005.63</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18210">18210</ref><ref source="HP" url="http://itrc.hp.com/service/cki/docDisplay.do?docId=c00637342">HPSBUX02110</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/0588">ADV-2005-0588</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1271">ADV-2006-1271</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/14411">14411</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19561">19561</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101699-1">101699</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1265">oval:org.mitre.oval:def:1265</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1333">oval:org.mitre.oval:def:1333</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1762">oval:org.mitre.oval:def:1762</ref><ref source="OSVDB" url="http://www.osvdb.org/14203">14203</ref></refs><vuln_soft><prod name="wu-ftpd" vendor="Washington University"><vers num="2.6.1"/><vers num="2.6.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0258" published="2005-03-14" seq="2005-0258" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in (1) usercp_register.php and (2) usercp_avatar.php for phpBB 2.0.11, and possibly other versions, with gallery avatars enabled, allows remote attackers to delete (unlink) arbitrary files via &quot;/../&quot; sequences in the avatarselect parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="iDefense" url="http://www.idefense.com/application/poi/display?id=205&amp;type=vulnerabilities">phpBB Group phpBB2 Arbitrary File Unlink Vulnerability</ref><ref adv="1" source="Phpbb.com" url="http://www.phpbb.com/support/documents.php?mode=changelog">PhPBB CHANGELOG</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/12623">bid 12623</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200503-02.xml">GLSA-200503-02</ref></refs><vuln_soft><prod name="PhpBB" vendor="PhpBB Group"><vers num="2.0.0"/><vers num="2.0 RC4"/><vers num="2.0 RC3"/><vers num="2.0 RC2"/><vers num="2.0 RC1"/><vers num="2.0 Beta1"/><vers num="2.0.1"/><vers num="2.0.2"/><vers num="2.0.3"/><vers num="2.0.4"/><vers num="2.0.5"/><vers num="2.0.6d"/><vers num="2.0.6c"/><vers num="2.0.6"/><vers num="2.0.7a"/><vers num="2.0.7"/><vers num="2.0.8a"/><vers num="2.0.8"/><vers num="2.0.9"/><vers num="2.0.10"/><vers num="2.0.11"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0259" published="2005-03-14" seq="2005-0259" severity="Medium" type="CVE"><desc><descript source="cve">phpBB 2.0.11, and possibly other versions, with remote avatars and avatar uploading enabled, allows local users to read arbitrary files by providing both a local and remote location for an avatar, then modifying the &quot;Upload Avatar from a URL:&quot; field to reference the target file.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="iDefense" url="http://www.idefense.com/application/poi/display?id=204&amp;type=vulnerabilities">phpBB Group phpBB Arbitrary File Disclosure Vulnerability</ref><ref adv="1" source="Phpbb.com" url="http://www.phpbb.com/support/documents.php?mode=changelog">PhPBB CHANGELOG</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/12621">bid 12621</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200503-02.xml">GLSA-200503-02</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/774686">VU#774686</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14362/">14362</ref></refs><vuln_soft><prod name="PhpBB" vendor="PhpBB Group"><vers num="2.0.0"/><vers num="2.0 RC4"/><vers num="2.0 RC3"/><vers num="2.0 RC2"/><vers num="2.0 RC1"/><vers num="2.0 Beta1"/><vers num="2.0.1"/><vers num="2.0.2"/><vers num="2.0.3"/><vers num="2.0.4"/><vers num="2.0.5"/><vers num="2.0.6d"/><vers num="2.0.6c"/><vers num="2.0.6"/><vers num="2.0.7a"/><vers num="2.0.7"/><vers num="2.0.8a"/><vers num="2.0.8"/><vers num="2.0.9"/><vers num="2.0.10"/><vers num="2.0.11"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0260" published="2005-05-02" seq="2005-0260" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in the Discovery Service for BrightStor ARCserve Backup 11.1 and earlier allows remote attackers to execute arbitrary code via a long packet to UDP port 41524, which is not properly handled in a recvfrom call.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=194&amp;type=vulnerabilities">20050209 Computer Associates BrightStor ARCserve Backup v11 Discovery Service Remote Buffer Overflow Vulnerability</ref><ref patch="1" source="CONFIRM" url="http://supportconnectw.ca.com/public/enews/BrightStor/brigcurrent.asp#news1">http://supportconnectw.ca.com/public/enews/BrightStor/brigcurrent.asp#news1</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19251">brightstor-discovery-bo(19251)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013138">1013138</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14183">14183</ref></refs><vuln_soft><prod name="BrightStor ARCServe Backup" vendor="Computer Associates"><vers num="11.1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0261" published="2005-02-10" seq="2005-0261" severity="Low" type="CVE"><desc><descript source="cve">lspath in AIX 5.2, 5.3, and possibly earlier versions, does not drop privileges before processing the -f option, which allows local users to read one line of arbitrary files.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=195&amp;type=vulnerabilities">20050210 IBM AIX lspath Local File Access Vulnerability</ref><ref adv="1" patch="1" source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY67457&amp;apar=only">IY67457</ref><ref adv="1" patch="1" source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY67655&amp;apar=only">IY67655</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19281">ibm-aix-ispath-information-disclosure(19281)</ref><ref source="BID" url="http://www.securityfocus.com/bid/12513">12513</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14232">14232</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="5.3"/><vers num="5.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0262" published="2005-05-02" seq="2005-0262" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in ipl_varyon on AIX 5.1, 5.2, and 5.3 allows local users to execute arbitrary code via a long -d argument.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=196&amp;type=vulnerabilities">20050210 IBM AIX ipl_varyon Local Buffer Overflow Vulnerability</ref><ref source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY67812&amp;apar=only">IY67812</ref><ref source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY67750&amp;apar=only">IY67750</ref><ref source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY66933&amp;apar=only">IY66933</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19282">ibm-aix-iplvaryon-bo(19282)</ref><ref source="BID" url="http://www.securityfocus.com/bid/12516">12516</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14231">14231</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="5.1"/><vers num="5.2"/><vers num="5.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0263" published="2005-05-02" seq="2005-0263" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in netpmon on AIX 5.1, 5.2, and 5.3 allows local users to execute arbitrary code via a long -O argument.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=197&amp;type=vulnerabilities">20050210 IBM AIX netpmon Local Buffer Overflow Vulnerability</ref><ref source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY67807&amp;apar=only">IY67807</ref><ref source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY67136&amp;apar=only">IY67136</ref><ref source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY67124&amp;apar=only">IY67124</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19278">ibm-aix-netpmon-bo(19278)</ref><ref source="BID" url="http://www.securityfocus.com/bid/12517">12517</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14237">14237</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="5.1"/><vers num="5.2"/><vers num="5.3"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0264" published="2005-05-02" seq="2005-0264" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in browse.php in OWL 0.7 and 0.8 allow remote attackers to inject arbitrary web script or HTML via the (1) expand or (2) order parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110461644407935&amp;w=2">20050101 Various Vulnerabilities in OWL Intranet Engine</ref><ref source="BID" url="http://www.securityfocus.com/bid/12114">12114</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18705">owl-intranet-engine-xss(18705)</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13695">13695</ref></refs><vuln_soft><prod name="Owl Intranet Engine" vendor="Owl"><vers num="0.73"/><vers num="0.72"/><vers num="0.71"/><vers num="0.7"/><vers num="0.6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0265" published="2005-05-02" seq="2005-0265" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in browse.php in OWL 0.7 and 0.8 allow remote attackers to execute arbitrary SQL commands via the (1) parent or (2) sortposted parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110461644407935&amp;w=2">20050101 Various Vulnerabilities in OWL Intranet Engine</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/12114">12114</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18704">owl-intranet-engine-sql-injection(18704)</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13695">13695</ref></refs><vuln_soft><prod name="Owl Intranet Engine" vendor="Owl"><vers num="0.7"/><vers num="0.8"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0266" published="2005-01-01" seq="2005-0266" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in SugarCRM 1.X allows remote attackers to inject arbitrary web script or HTML via the (1) return_module, (2) return_action, (3) name, (4) module, or (5) record parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110461706232174&amp;w=2">20050101 Cross Site Scripting Vulnerabilities and Possible Code Execution</ref><ref source="BID" url="http://www.securityfocus.com/bid/12113">12113</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18719">sugar-sales-index-xss(18719)</ref></refs><vuln_soft><prod name="SugarCRM" vendor="SugarCRM"><vers num="2.0.1a"/><vers num="2.0.1"/><vers num="1.5d"/><vers num="1.1f"/><vers num="1.1e"/><vers num="1.1d"/><vers num="1.1c"/><vers num="1.1b"/><vers num="1.1a"/><vers num="1.1"/><vers num="1.0g"/><vers num="1.0f"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0267" published="2005-05-02" seq="2005-0267" severity="High" type="CVE"><desc><descript source="cve">index.php in FlatNuke 2.5.1 allows remote attackers to create an andministrator account via carriage returns and #10 in the url_avatar field, which is interpreted as a sensitive directive.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110477752916772&amp;w=2">20050102 Multiple Vulnerabilities in FlatNuke</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/12150">12150</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18741">flatnuke-indexphp-gain-access(18741)</ref></refs><vuln_soft><prod name="FlatNuke" vendor="FlatNuke"><vers num="2.5.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0268" published="2005-01-03" seq="2005-0268" severity="High" type="CVE"><desc><descript source="cve">Direct code injection vulnerability in FlatNuke 2.5.1 allows remote attackers to execute arbitrary PHP code by placing the code into the url_avatar field.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110477752916772&amp;w=2">20050102 Multiple Vulnerabilities in FlatNuke</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/12150">12150</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18746">flatnuke-indexphp-xss(18746)</ref></refs><vuln_soft><prod name="FlatNuke" vendor="FlatNuke"><vers num="2.5.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-06-15" name="CVE-2005-0269" published="2005-05-02" seq="2005-0269" severity="High" type="CVE"><desc><descript source="cve">The file extension check in GNUBoard 3.40 and earlier only verifies extensions that contain all lowercase letters, which allows remote attackers to upload arbitrary files via file extensions that include uppercase letters.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110477648219738&amp;w=2">20050103 STG Security Advisory: [SSA-20041224-21] File extensions</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18729">gnuboard-gbupdate-file-upload(18729)</ref><ref source="BID" url="http://www.securityfocus.com/bid/12149">12149</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13711">13711</ref></refs><vuln_soft><prod name="GNUBoard" vendor="SIR"><vers num="3.40"/><vers num="3.39"/><vers num="3.38"/><vers num="3.37"/><vers num="3.36"/><vers num="3.35"/><vers num="3.34"/><vers num="3.33"/><vers num="3.32"/><vers num="3.31"/><vers num="3.30"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-22" name="CVE-2005-0270" published="2005-05-02" seq="2005-0270" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in ReviewPost PHP Pro before 2.84 allow remote attackers to inject arbitrary web script or HTML via the (1) si parameter to showcat.php, (2) cat or (3) page parameter to showproduct.php, or (4) report parameter to reportproduct.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110485682424110&amp;w=2">20050103 Serious Vulnerabilities In PhotoPost ReviewPost</ref><ref adv="1" source="MISC" url="http://www.gulftech.org/?node=research&amp;article_id=00062-01022005">http://www.gulftech.org/?node=research&amp;article_id=00062-01022005</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/13697/">13697</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18731">reviewpost-php-xss(18731)</ref></refs><vuln_soft><prod name="ReviewPost PHP Pro" vendor="PhotoPost"><vers num="2.84" prev="1"/><vers num="2.5.1"/><vers num="2.5"/><vers num="1.0.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-22" name="CVE-2005-0271" published="2005-01-03" seq="2005-0271" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in ReviewPost PHP Pro before 2.84 allow remote attackers to execute arbitrary SQL commands via the (1) cat parameter to showcat.php or (2) product parameter to addfav.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110485682424110&amp;w=2">20050103 Serious Vulnerabilities In PhotoPost ReviewPost</ref><ref adv="1" patch="1" source="MISC" url="http://www.gulftech.org/?node=research&amp;article_id=00062-01022005">http://www.gulftech.org/?node=research&amp;article_id=00062-01022005</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/13697/">13697</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18732">reviewpost-php-sql-injection(18732)</ref></refs><vuln_soft><prod name="ReviewPost PHP Pro" vendor="PhotoPost"><vers num="2.5.1" prev="1"/><vers num="2.5"/><vers num="1.0.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-22" name="CVE-2005-0272" published="2005-05-02" seq="2005-0272" severity="High" type="CVE"><desc><descript source="cve">ReviewPost PHP Pro before 2.84 allows remote attackers to upload and execute arbitrary PHP files by posting a review file with multiple extensions, which bypasses the intended restrictions.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110485682424110&amp;w=2">20050103 Serious Vulnerabilities In PhotoPost ReviewPost</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/13697/">13697</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18735">reviewpost-php-file-upload(18735)</ref></refs><vuln_soft><prod name="ReviewPost PHP Pro" vendor="PhotoPost"><vers num="2.5.1" prev="1"/><vers num="2.5"/><vers num="1.0.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-27" name="CVE-2005-0273" published="2005-05-02" seq="2005-0273" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in showgallery.php in PhotoPost before 4.86 allow remote attackers to execute arbitrary SQL commands via the (1) cat or (2) ppuser parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110486165802196&amp;w=2">20050103 Multiple PhotoPost Pro Vulnerabilities</ref><ref adv="1" source="MISC" url="http://www.gulftech.org/?node=research&amp;article_id=00063-01032005">http://www.gulftech.org/?node=research&amp;article_id=00063-01032005</ref><ref source="BID" url="http://www.securityfocus.com/bid/12156">12156</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/13680/">13680</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18744">photopost-php-showgallery-xss(18744)</ref></refs><vuln_soft><prod name="PhotoPost PHP Pro" vendor="PhotoPost"><vers num="4.85" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-27" name="CVE-2005-0274" published="2005-01-03" seq="2005-0274" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in showgallery.php in PhotoPost before 4.86 allow remote attackers to inject arbitrary web script or HTML via the (1) cat, (2) si, (3) page, or (4) ppuser parameters.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110486165802196&amp;w=2">20050103 Multiple PhotoPost Pro Vulnerabilities</ref><ref adv="1" patch="1" source="MISC" url="http://www.gulftech.org/?node=research&amp;article_id=00063-01032005">http://www.gulftech.org/?node=research&amp;article_id=00063-01032005</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/12156">12156</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/13680/">13680</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18744">photopost-php-showgallery-xss(18744)</ref></refs><vuln_soft><prod name="PhotoPost PHP Pro" vendor="PhotoPost"><vers num="4.85" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0275" published="2005-05-02" seq="2005-0275" severity="Medium" type="CVE"><desc><descript source="cve">TFTP in 3Com 3CDaemon 2.0 revision 10 allows remote attackers to cause a denial of service (application crash) via a GET request containing an MS-DOS device name.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110485674622696&amp;w=2">20050104 3Com 3CDaemon Multiple Vulnerabilities</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18750">3cdaemon-reserved-name-dos(18750)</ref></refs><vuln_soft><prod name="3CDaemon" vendor="3Com"><vers num="2.0 revision 10"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0276" published="2005-05-02" seq="2005-0276" severity="Medium" type="CVE"><desc><descript source="cve">Multiple format string vulnerabilities in the FTP service in 3Com 3CDaemon 2.0 revision 10 allow remote attackers to cause a denial of service (application crash) via format string specifiers in (1) the username, (2) cd, (3) delete, (4) rename, (5) rmdir, (6) literal, (7) stat, or (8) CWD commands.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110485674622696&amp;w=2">20050104 3Com 3CDaemon Multiple Vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/12155">12155</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18751">3cdaemon-login-dos(18751)</ref></refs><vuln_soft><prod name="3CDaemon" vendor="3Com"><vers num="2.0 revision 10"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0277" published="2005-05-02" seq="2005-0277" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in the FTP service in 3Com 3CDaemon 2.0 revision 10 allows remote attackers to cause a denial of service (application crash) and execute arbitrary code via (1) a long username in the USER command or (2) an FTP command that contains a long argument, such as cd, send, or ls.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110485674622696&amp;w=2">20050104 3Com 3CDaemon Multiple Vulnerabilities</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110886719528518&amp;w=2">20050218 3com 3CDaemon FTP Unauthorized </ref><ref source="BID" url="http://www.securityfocus.com/bid/12155">12155</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18754">3cdaemon-long-command-dos(18754)</ref></refs><vuln_soft><prod name="3CDaemon" vendor="3Com"><vers num="2.0 revision 10"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0278" published="2005-05-02" seq="2005-0278" severity="Medium" type="CVE"><desc><descript source="cve">The FTP service in 3Com 3CDaemon 2.0 revision 10 allows remote attackers to gain sensitive information via a cd command that contains an MS-DOS device name, which reveals the installation path in an error message.</descript></desc><loss_types><conf/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110485674622696&amp;w=2">20050104 3Com 3CDaemon Multiple Vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/12155">12155</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18756">3cdaemon-command-obtain-information(18756)</ref></refs><vuln_soft><prod name="3CDaemon" vendor="3Com"><vers num="2.0 revision 10"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-08-23" name="CVE-2005-0279" published="2005-05-02" seq="2005-0279" severity="Medium" type="CVE"><desc><descript source="cve">Soldner Secret Wars 30830 and earlier does not properly handle the &quot;message too long&quot; socket error, which allows remote attackers to cause a denial of service (socket termination) via a long UDP packet.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110486654213504&amp;w=2">20050104 Socket termination, format string and XSS in Soldner Secret Wars</ref><ref source="BID" url="http://www.securityfocus.com/bid/12162">12162</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18749">soldner-secret-wars-dos(18749)</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13716">13716</ref></refs><vuln_soft><prod name="Soldner Secret Wars" vendor="Jowood Productions"><vers num="30830" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-08-23" name="CVE-2005-0280" published="2005-01-04" seq="2005-0280" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in Soldner Secret Wars 30830 and earlier allows remote attackers to cause a denial of service (server crash) and possibly execute arbitrary code via format string specifiers in a message.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110486654213504&amp;w=2">20050104 Socket termination, format string and XSS in Soldner Secret Wars</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/12162">12162</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18752">soldner-secret-wars-format-string(18752)</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13716">13716</ref></refs><vuln_soft><prod name="Soldner Secret Wars" vendor="Jowood Productions"><vers num="30830"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-08-23" name="CVE-2005-0281" published="2005-05-02" seq="2005-0281" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in the web interface in Soldner Secret Wars 30830 allows remote attackers to inject arbitrary web script or HTML via a user message, which is not filtered or quoted when the administrator views the server logs.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110486654213504&amp;w=2">20050104 Socket termination, format string and XSS in Soldner Secret Wars</ref><ref source="BID" url="http://www.securityfocus.com/bid/12162">12162</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18753">soldner-secret-wars-xss(18753)</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13716">13716</ref></refs><vuln_soft><prod name="Soldner Secret Wars" vendor="Jowood Productions"><vers num="30830" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0282" published="2005-05-02" seq="2005-0282" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in member.php in MyBulletinBoard (MyBB) allows remote attackers to execute arbitrary SQL commands via the uid parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110486566600980&amp;w=2">20050104 MyBB SQL Injection</ref><ref source="BID" url="http://www.securityfocus.com/bid/12161">12161</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/187">mybb-member-sql-injection(18755)</ref></refs><vuln_soft><prod name="MyBulletinBoard" vendor="MyBulletinBoard"><vers num="1.0 RC4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0283" published="2005-01-04" seq="2005-0283" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in index.php in QwikiWiki allows remote attackers to read arbitrary files via a .. (dot dot) and a %00 at the end of the filename in the page parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110486832621053&amp;w=2">20050104 QWikiwiki directory traversal vulnerability</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/12163">12163</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18748">qwikiwiki-directory-traversal(18748)</ref><ref source="" url="http://www.qwikiwiki.com/index.php?page=QwikiVulnerability"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/12044">12044</ref></refs><vuln_soft><prod name="QwikiWiki" vendor="David Barrett"><vers num="1.4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0284" published="2005-01-10" seq="2005-0284" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in addentry.php in Woltlab Burning Book 1.0 Gold, 1.1.1e, and possibly other versions, allows remote attackers to execute arbitrary SQL commands via the user-agent parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110548032401506&amp;w=2">20050110 Woltlab Burning Book addentry.php SQL Injection</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18859">woltlab-book-addentry-sql-injection(18859)</ref></refs><vuln_soft><prod name="Burning Book" vendor="Woltlab"><vers num="1.0 Gold"/><vers num="1.1.1e"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0285" published="2005-05-02" seq="2005-0285" severity="Medium" type="CVE"><desc><descript source="cve">Webseries Payment Application does not properly restrict privileged operations, which allows remote authenticated users to gain privileges by directly accessing certain URLs.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110547396124885&amp;w=2">20050110 Portcullis Security Advisory 05-001</ref><ref source="BID" url="http://www.securityfocus.com/bid/12216">12216</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18848">webseries-pa-url-security-bypass(18848)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1012854">1012854</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13821">13821</ref></refs><vuln_soft><prod name="WebSeries Payment Application" vendor="BottomLine"><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0286" published="2005-05-02" seq="2005-0286" severity="Medium" type="CVE"><desc><descript source="cve">eMotion MediaPartner Web Server 5.0 and 5.1 allows remote attackers to obtain sensitive information via an HTTP request for a .bhtml file that contains a (1) . (dot) or (2) + (plus sign) at the end, which returns the source code for that file.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110547824902053&amp;w=2">20050110 Portcullis Security Advisory 05-004</ref><ref source="BID" url="http://www.securityfocus.com/bid/12236">12236</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18861">mediapartner-bhtml-source-disclosure(18861)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1012855">1012855</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13820">13820</ref></refs><vuln_soft><prod name="MediaPartner Web Server" vendor="eMotion"><vers num="5.0"/><vers num="5.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0287" published="2005-01-10" seq="2005-0287" severity="Medium" type="CVE"><desc><descript source="cve">Bottomline Webseries Payment Application allows remote attackers to read arbitrary files on the network via a report template with modified ReportPath or ReportName values.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110548383812462&amp;w=2">20050110 Portcullis Security Advisory 05-009</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18862">webseries-report-execution(18862)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1012854">1012854</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13821">13821</ref></refs><vuln_soft><prod name="WebSeries Payment Application" vendor="BottomLine"><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="3.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="4.9" CVSS_score="3.6" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0288" published="2005-01-11" seq="2005-0288" severity="Low" type="CVE"><desc><descript source="cve">The change password functionality in Bottomline Webseries Payment Application does not require the old password when users enter a new password, which could allow remote authenticated users to change other users&apos; passwords.</descript></desc><loss_types><avail/><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110549684319400&amp;w=2">20050110 Portcullis Security Advisory 05-008</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/12231">12231</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18860">webseries-pa-password-gain-access(18860)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1012854">1012854</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13821">13821</ref></refs><vuln_soft><prod name="WebSeries Payment Application" vendor="BottomLine"><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0289" published="2005-05-02" seq="2005-0289" severity="Medium" type="CVE"><desc><descript source="cve">Apple AirPort Express prior to 6.1.1 and Extreme prior to 5.5.1, configured as a Wireless Data Service (WDS), allows remote attackers to cause a denial of service (device freeze) by connecting to UDP port 161 and before link-state change occurs.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110582124528867&amp;w=2">20050115 Apple Airport WDS DoS</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18865">apple-airport-dos(18865)</ref><ref source="BID" url="http://www.securityfocus.com/bid/12152">12152</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13753">13753</ref></refs><vuln_soft><prod name="AirPort Express" vendor="Apple"><vers num="6.1" prev="1"/></prod><prod name="AirPort Extreme" vendor="Apple"><vers num="5.5" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0290" published="2005-01-17" seq="2005-0290" severity="High" type="CVE"><desc><descript source="cve">NETGEAR FVS318 running firmware 2.4, and possibly other versions, allows remote attackers to bypass the filters using hex encoded URLs, as demonstrated using a hex encoded file extension.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><access/><input/></vuln_types><range><network/></range><refs><ref adv="1" source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-January/030984.html">20050117 Multiple Vulnerabilities in Netgear FVS318 Router</ref><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110599727631560&amp;w=2">20050117 Multiple Vulnerabilities in Netgear FVS318 Router</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/12278">12278</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18920">netgear-fvs318-filter-bypass(18920)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1012913">1012913</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13787">13787</ref></refs><vuln_soft><prod name="FVS318v2" vendor="NetGear"><vers num="2.4"/></prod><prod name="FVS318" vendor="NetGear"><vers num="2.4"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0291" published="2005-01-17" seq="2005-0291" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in the log viewer in NETGEAR FVS318 running firmware 2.4, and possibly other versions, allows remote attackers to inject arbitrary web script or HTML via a blocked URL phrase.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-January/030984.html">20050117 Multiple Vulnerabilities in Netgear FVS318 Router</ref><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110599727631560&amp;w=2">20050117 Multiple Vulnerabilities in Netgear FVS318 Router</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/12278">12278</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18921">netgear-fvs318-log-xss(18921)</ref><ref source="OSVDB" url="http://www.osvdb.org/13012">13012</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1012913">1012913</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13787">13787</ref></refs><vuln_soft><prod name="FVS318v2" vendor="NetGear"><vers num="2.4"/></prod><prod name="FVS318" vendor="NetGear"><vers num="2.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0292" published="2005-01-17" seq="2005-0292" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in index.php in PHP Gift Registry (phpGiftReg) 1.4.0, and possibly other versions before 1.5.0b1, allow remote attackers to execute arbitrary SQL commands via the (1) messageid, (2) shopper, (3) shopfor, or (4) itemid parameters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-January/030965.html">20050116 phpGiftReq SQL Injection</ref><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110599710017066&amp;w=2">20050116 phpGiftReq SQL Injection</ref><ref adv="1" patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/392485">20050307 Re: phpGiftReq SQL Injection</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/12289">12289</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/13873">13873</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18925">phpgiftregistry-sql-injection(18925)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1012910">1012910</ref></refs><vuln_soft><prod name="phpgiftreg" vendor="PHP Gift Registry"><vers num="1.4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0293" published="2005-05-02" seq="2005-0293" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in minis.php in Minis 0.2.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the month parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110599953704025&amp;w=2">20050116 Minis directory traversal vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/12279">12279</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18928">minis-month-directory-traversal(18928)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1012911">1012911</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13866">13866</ref></refs><vuln_soft><prod name="Minis" vendor="Minis"><vers num="0.2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0294" published="2005-01-16" seq="2005-0294" severity="Medium" type="CVE"><desc><descript source="cve">minis.php in Minis 0.2.1 allows remote attackers to cause a denial of service (infinite loop) via an HTTP request for a file that the web server does not have permission to read, as demonstrated using the month parameter.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-January/030966.html">20050116 Minis directory traversal vulnerability</ref><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110599953704025&amp;w=2">20050116 Minis directory traversal vulnerability</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18929">minis-month-dos(18929)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1012911">1012911</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13866">13866</ref></refs><vuln_soft><prod name="Minis" vendor="Minis"><vers num="0.2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0295" published="2005-01-17" seq="2005-0295" severity="Medium" type="CVE"><desc><descript source="cve">npptnt2.sys in nProtect Gameguard provides unrestricted I/O to any process that calls it, which allows local users to gain privileges.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110608422029555&amp;w=2">20050116 Unrestricted I/O access vulnerability in INCA Gameguard</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/12280">12280</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18952">nprotect-npptnt2-gain-access(18952)</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13928">13928</ref></refs><vuln_soft><prod name="nProtect Gameguard" vendor="INCA"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0296" published="2005-01-17" seq="2005-0296" severity="Medium" type="CVE"><desc><descript source="cve">** DISPUTED **  NOTE: this issue has been disputed by the vendor.  The error module in Novell GroupWise WebAccess allows remote attackers who have not authenticated to read potentially sensitive information, such as the version, via an incorrect login and a modified (1) error or (2) modify parameter that returns template files or the &quot;about&quot; information page.  NOTE: the vendor has disputed this issue.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110608203729814&amp;w=2">20050117 Novell GroupWise WebAccess error modules loading</ref><ref adv="1" source="FULLDISC" url="http://www.derkeiler.com/Mailing-Lists/Full-Disclosure/2005-01/0771.html">20050121 NOVL-2005-10096251 GroupWise WebAccess error handling modules (report)</ref><ref adv="1" source="BUGTRAQ" url="http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2005-01/0341.html">20050127 NOVL-2005-10096251 GroupWise WebAccess error handling modules (report)</ref><ref adv="1" source="MISC" url="http://support.novell.com/servlet/tidfinder/10096251">http://support.novell.com/servlet/tidfinder/10096251</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/12285">12285</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18954">groupwise-error-auth-bypass(18954)</ref><ref source="OSVDB" url="http://www.osvdb.org/13135">13135</ref></refs><vuln_soft><prod name="GroupWise WebAccess" vendor="Novell"><vers num="6.5 SP2"/><vers num="6.5 SP1"/><vers num="6.5"/><vers num="6.0 SP4"/></prod><prod name="Groupwise" vendor="Novell"><vers num="6.5 SP2"/><vers num="6.5 SP1"/><vers num="6.5"/><vers num="6.0 SP4"/><vers num="6.0 SP3"/><vers num="6.0 SP2"/><vers num="6.0 SP1"/><vers num="6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0297" published="2005-01-18" seq="2005-0297" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in Oracle Database 9i and 10g allows remote attackers to execute arbitrary SQL commands and gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110606477308492&amp;w=2">20050118 Multiple high risk vulnerabilities in Oracle RDBMS 10g/9i</ref></refs><vuln_soft><prod name="Oracle9i Database Server" vendor="Oracle"><vers num=""/></prod><prod name="Oracle10g Database Server" vendor="Oracle"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0298" published="2005-05-02" seq="2005-0298" severity="Medium" type="CVE"><desc><descript source="cve">The DIRECTORY objects in Oracle 8i through Oracle 10g contain the location of a specific operating system directory, which allows users with read privileges to a DIRECTORY object to obtain sensitive information.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110608912525883&amp;w=2">20050118 PeteFinnigan.com - Oracle security advisory</ref><ref adv="1" patch="1" source="MISC" url="http://www.petefinnigan.com/directory_traversal.pdf">http://www.petefinnigan.com/directory_traversal.pdf</ref><ref patch="1" source="MISC" url="http://www.oracle.com/technology/deploy/security/pdf/cpu-jan-2005_advisory.pdf">http://www.oracle.com/technology/deploy/security/pdf/cpu-jan-2005_advisory.pdf</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18947">oracle-directory-lob-obtain-info(18947)</ref></refs><vuln_soft><prod name="Oracle9i Database Server Release 1" vendor="Oracle"><vers num="9.0.1.4"/><vers num="9.0.1.5"/><vers num="9.0.4"/></prod><prod name="Oracle10g Database Server Release 1" vendor="Oracle"><vers num="10.1.0.2"/><vers num="10.1.0.3"/><vers num="10.1.0.3.1"/></prod><prod name="Oracle9i Database Server Release 2" vendor="Oracle"><vers num="9.2.0.4"/><vers num="9.2.0.5"/><vers num="9.2.0.6"/></prod><prod name="Oracle8i Database Server Release 3" vendor="Oracle"><vers num="8.1.7.4"/></prod><prod name="Oracle8i Database Server" vendor="Oracle"><vers num="8.0.6"/><vers num="8.0.6.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-06-15" name="CVE-2005-0299" published="2005-05-02" seq="2005-0299" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in GForge 3.3 and earlier allows remote attackers to list arbitrary directories via a .. (dot dot) in the (1) dir parameter to controller.php or (2) dir_name parameter to controlleroo.php.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110627132209963&amp;w=2">20050120 STG Security Advisory: [SSA-20050120-24] GForge 3.x directory</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/12318">12318</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18988">gforge-dir-dirname-directory-traversal(18988)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1012950">1012950</ref></refs><vuln_soft><prod name="GForge" vendor="GForge"><vers num="3.21"/><vers num="3.3"/><vers num="3.2"/><vers num="3.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0300" published="2005-01-20" seq="2005-0300" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in session.php in JSBoard 2.0.9 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the table parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110627201120011&amp;w=2">20050120 STG Security Advisory: [SSA-20050120-22] JSBoard file disclosure</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/12319">12319</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18990">jsboard-session-file-include(18990)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1012949">1012949</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13920">13920</ref></refs><vuln_soft><prod name="JSBoard" vendor="JSBoard"><vers num="2.0.9"/><vers num="2.0.8"/><vers num="2.0.7"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0301" published="2005-05-02" seq="2005-0301" severity="High" type="CVE"><desc><descript source="cve">comersus_backoffice_install10.asp in BackOffice Lite 6.0 and 6.01 allows remote attackers to bypass authentication and gain privileges via a direct request to the program.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110636597832556&amp;w=2">20050121 bug report comersus Back Office Lite 6.0 and 6.0.1</ref><ref adv="1" source="CONFIRM" url="http://www.comersus.org/forum/displayMessage.asp?mid=32753">http://www.comersus.org/forum/displayMessage.asp?mid=32753</ref><ref adv="1" source="MISC" url="http://www.securiteam.com/windowsntfocus/5TP0Q0UEKI.html">http://www.securiteam.com/windowsntfocus/5TP0Q0UEKI.html</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19010">backoffice-lite-administrative-bypass(19010)</ref></refs><vuln_soft><prod name="Comersus BackOffice Lite" vendor="Comersus Open Technologies"><vers num="6.0"/><vers num="6.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0302" published="2005-05-02" seq="2005-0302" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in default.asp in BackOffice Lite 6.0 and 6.01 allows remote attackers to execute arbitrary SQL commands via the referer field in the HTTP header.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110636597832556&amp;w=2">20050121 bug report comersus Back Office Lite 6.0 and 6.0.1</ref><ref patch="1" source="MISC" url="http://www.securiteam.com/windowsntfocus/5TP0Q0UEKI.html">http://www.securiteam.com/windowsntfocus/5TP0Q0UEKI.html</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19013">backoffice-lite-sql-injection(19013)</ref></refs><vuln_soft><prod name="Comersus BackOffice Lite" vendor="Comersus Open Technologies"><vers num="6.0"/><vers num="6.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0303" published="2005-05-02" seq="2005-0303" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in (1) comersus_supportError.asp or (2) comersus_backofficelite_supportError.asp in BackOffice Lite 6.0 and 6.01 allow remote attackers to inject arbitrary web script or HTML via the error parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110636597832556&amp;w=2">20050121 bug report comersus Back Office Lite 6.0 and 6.0.1</ref><ref adv="1" source="MISC" url="http://www.securiteam.com/windowsntfocus/5TP0Q0UEKI.html">http://www.securiteam.com/windowsntfocus/5TP0Q0UEKI.html</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19014">backoffice-lite-xss(19014)</ref></refs><vuln_soft><prod name="Comersus BackOffice Lite" vendor="Comersus Open Technologies"><vers num="6.0"/><vers num="6.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0304" published="2005-05-02" seq="2005-0304" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in DivX Player 2.6 and earlier allows remote attackers to overwrite arbitrary files via a .. (dot dot) in a filename in a ZIP file for a skin.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110642748517854&amp;w=2">20050121 Arbitrary files overwriting through skins in DivX Player 2.6</ref><ref source="BID" url="http://www.securityfocus.com/bid/12332">12332</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19030">divx-player-directory-traversal(19030)</ref><ref source="" url="http://aluigi.altervista.org/adv/divxplayer-adv.txt"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/13969">13969</ref></refs><vuln_soft><prod name="DivX Player" vendor="DivX"><vers num="2.6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0305" published="2005-05-02" seq="2005-0305" severity="High" type="CVE"><desc><descript source="cve">CRLF injection vulnerability in users.php in Siteman 1.1.10 and earlier allows remote attackers to add arbitrary users and gain privileges via the line parameter in a docreate operation.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110627350616949&amp;w=2">20050120 God Admin Injection Vulnerability in Siteman 1.0.x,</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110643320814371&amp;w=2">20050122 Siteman User Database Line Insertion Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/12304">12304</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18998">siteman-gain-access(18998)</ref><ref source="OSVDB" url="http://www.osvdb.org/13131">13131</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1012951">1012951</ref></refs><vuln_soft><prod name="Siteman" vendor="Siteman"><vers num="1.1.10"/><vers num="1.1.9"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0306" published="2005-01-25" seq="2005-0306" severity="Medium" type="CVE"><desc><descript source="cve">MercuryBoard 1.1.1 allows remote attackers to gain sensitive information via an HTTP request with the n parameter set to 0, which causes a divide-by-zero error and reveals the path in the resulting error message.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110661795632354&amp;w=2">20050124 Multiple vulnerabilities in MercuryBoard 1.1.1</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/12359">12359</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19048">mercuryboard-multiple-script-path-disclosure(19048)</ref></refs><vuln_soft><prod name="MercuryBoard" vendor="MercuryBoard"><vers num="1.1.1"/><vers num="1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0307" published="2005-01-25" seq="2005-0307" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in index.php in MercuryBoard 1.1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) s, (2) l, (3) a, (4) t, (5) to, or (6) re parameters.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110661795632354&amp;w=2">20050124 Multiple vulnerabilities in MercuryBoard 1.1.1</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/12359">12359</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19050">mercuryboard-multiple-scripts-xss(19050)</ref></refs><vuln_soft><prod name="MercuryBoard" vendor="MercuryBoard"><vers num="1.1.1"/><vers num="1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0308" published="2005-01-24" seq="2005-0308" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the wsprintf function in W32Dasm 8.93 and earlier allows remote attackers to execute arbitrary code via a large import or export function name.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110661194108205&amp;w=2">20050124 Local buffer-overflow in W32Dasm 8.93</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/12352">12352</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19044">w32dasm-wsprintf-bo(19044)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1012997">1012997</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13986">13986</ref></refs><vuln_soft><prod name="W32Dasm" vendor="URsoftware"><vers num="8.94"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0309" published="2005-01-25" seq="2005-0309" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in (1) index.php or (2) mod.php in Exponent 0.95 allow remote attackers to inject arbitrary web script or HTML via the module parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110666998407073&amp;w=2">20050125 Vulnerabilities in eXponent 0.95</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/12358">12358</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19061">exponent-module-xss(19061)</ref><ref source="OSVDB" url="http://www.osvdb.org/13188">13188</ref><ref source="OSVDB" url="http://www.osvdb.org/13190">13190</ref></refs><vuln_soft><prod name="Exponent" vendor="Exponent"><vers num="0.95"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0310" published="2005-05-02" seq="2005-0310" severity="Medium" type="CVE"><desc><descript source="cve">Exponent 0.95 allows remote attackers to obtain sensitive information via a direct HTTP request to (1) search.info.php, (2) permissions.info.php, (3) security.info.php, (4) formcontrol.php, or (5) file_modules.php, which reveals the path in an error message because the pathos_core_version variable is undefined.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110666998407073&amp;w=2">20050125 Vulnerabilities in eXponent 0.95</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19064">exponent-pathoscoreversion-path-disclosure(19064)</ref></refs><vuln_soft><prod name="Exponent" vendor="Exponent"><vers num="0.95"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0311" published="2005-05-02" seq="2005-0311" severity="Medium" type="CVE"><desc><descript source="cve">Ingate Firewall 4.1.3 and earlier does not terminate the PPTP session for an active user when the administrator disables that user from a resource, which could allow remote authenticated users to retain unauthorized access to resources.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110684375429946&amp;w=2">20050127 Ingate Firewall: Removed PPTP tunnels not deactivated</ref><ref source="BID" url="http://www.securityfocus.com/bid/12383">12383</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19123">ingate-firewall-unath-access(19123)</ref><ref source="" url="http://www.ingate.com/relnote-422.php"></ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013022">1013022</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14060">14060</ref></refs><vuln_soft><prod name="Ingate Firewall" vendor="Ingate"><vers num="4.1.3"/><vers num="3.3.1"/><vers num="3.2.1"/><vers num="3.2"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0312" published="2005-01-27" seq="2005-0312" severity="Low" type="CVE"><desc><descript source="cve">WarFTPD 1.82 RC9, when running as an NT service, allows remote authenticated users to cause a denial of service (access violation) via a CWD command with a crafted pathname, as demonstrated using a large string of &quot;%s&quot; sequences, possibly indicating a format string vulnerability.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/><exception/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110687202332039&amp;w=2">20050127 WarFTPD 1.82 RC9 DoS</ref><ref adv="1" source="CONFIRM" url="http://support.jgaa.com/index.php?cmd=ShowReport&amp;ID=02643">http://support.jgaa.com/index.php?cmd=ShowReport&amp;ID=02643</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/12384">12384</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19129">warftpd-cwd-dos(19129)</ref></refs><vuln_soft><prod name="War FTP Daemon" vendor="War FTP Daemon"><vers num="1.82 RC9"/><vers num="1.8"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-08-01" name="CVE-2005-0313" published="2005-01-27" seq="2005-0313" severity="High" type="CVE"><desc><descript source="cve">Multiple directory traversal vulnerabilities in Magic Winmail Server 4.0 Build 1112 allow remote attackers to (1) upload arbitrary files via certain parameters to upload.php or (2) read arbitrary files via certain parameters to download.php, and remote authenticated users to read, create, or delete arbitrary directories and files via the IMAP commands (3) CREATE, (4) EXAMINE, (5) SELECT, or (6) DELETE.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110685011825461&amp;w=2">20050127 [SIG^2 G-TEC] Magic Winmail Server v4.0 Multiple Vulnerabilities</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/12388">12388</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19114">magic-winmail-command-directory-traversal(19114)</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19108">magicwinmail-uploadphp-file-upload(19108)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013017">1013017</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14053">14053</ref></refs><vuln_soft><prod name="Magic Winmail Server" vendor="AMAX Information Technologies"><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-08-01" name="CVE-2005-0314" published="2005-01-27" seq="2005-0314" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in user.php in Magic Winmail Server 4.0 Build 1112 allows remote attackers to inject arbitrary web script or HTML via the personal information fields.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110685011825461&amp;w=2">20050127 [SIG^2 G-TEC] Magic Winmail Server v4.0 Multiple Vulnerabilities</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/12388">12388</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19113">magic-winmail-userphp-xss(19113)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013017">1013017</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14053">14053</ref></refs><vuln_soft><prod name="Magic Winmail Server" vendor="AMAX Information Technologies"><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-08-01" name="CVE-2005-0315" published="2005-01-27" seq="2005-0315" severity="Medium" type="CVE"><desc><descript source="cve">The FTP service in Magic Winmail Server 4.0 Build 1112 does not verify that the IP address in a PORT command is the same as the IP address of the user of the FTP session, which allows remote authenticated users to use the server as an intermediary for port scanning.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110685011825461&amp;w=2">20050127 [SIG^2 G-TEC] Magic Winmail Server v4.0 Multiple Vulnerabilities</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/12388">12388</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19115">magicwinmail-ftp-obtain-information(19115)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013017">1013017</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14053">14053</ref></refs><vuln_soft><prod name="Magic Winmail Server" vendor="AMAX Information Technologies"><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0316" published="2005-01-28" seq="2005-0316" severity="High" type="CVE"><desc><descript source="cve">WebWasher Classic 2.2.1 and 3.3, when running in server mode, does not properly drop CONNECT requests to the localhost from external systems, which could allow remote attackers to bypass intended access restrictions.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110693045507245&amp;w=2">20050128 WebWasher Classic - HTTP CONNECT weakness</ref><ref adv="1" source="MISC" url="http://www.oliverkarow.de/research/WebWasherCONNECT.txt">http://www.oliverkarow.de/research/WebWasherCONNECT.txt</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/12394">12394</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14058">14058</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19144">webwasher-classic-connect-gain-access(19144)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013036">1013036</ref></refs><vuln_soft><prod name="WebWasher Classic" vendor="WebWasher"><vers num="3.3"/><vers num="2.2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-22" name="CVE-2005-0317" published="2005-01-28" seq="2005-0317" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in useredit_account.wdm in Alt-N WebAdmin 3.0.4 allows remote attackers to inject arbitrary web script or HTML via the user parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110692897003614&amp;w=2">20050128 Multiple vulnerabilities in Alt-N WebAdmin &lt;= 3.0.2</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/12395">12395</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19161">webadmin-usereditaccountwdm-xss(19161)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013038">1013038</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14079">14079</ref></refs><vuln_soft><prod name="WebAdmin" vendor="Alt-N"><vers num="3.0.2"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-22" name="CVE-2005-0318" published="2005-01-28" seq="2005-0318" severity="Low" type="CVE"><desc><descript source="cve">useredit_account.wdm in Alt-N WebAdmin 3.0.4 does not properly validate account edits by the logged in user, which allows remote authenticated users to edit other users&apos; account information via a modified user parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110692897003614&amp;w=2">20050128 Multiple vulnerabilities in Alt-N WebAdmin &lt;= 3.0.2</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/12395">12395</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013038">1013038</ref></refs><vuln_soft><prod name="WebAdmin" vendor="Alt-N"><vers num="3.0.2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-22" name="CVE-2005-0319" published="2005-01-28" seq="2005-0319" severity="Medium" type="CVE"><desc><descript source="cve">Direct remote injection vulnerability in modalfram.wdm in Alt-N WebAdmin 3.0.4 allows remote attackers to load external webpages that appear to come from the WebAdmin server, which allows remote attackers to inject arbitrary HTML or web script to facilitate cross-site scripting (XSS) and phishing attacks.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110692897003614&amp;w=2">20050128 Multiple vulnerabilities in Alt-N WebAdmin &lt;= 3.0.2</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/12395">12395</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19162">webadmin-html-injection(19162)</ref></refs><vuln_soft><prod name="WebAdmin" vendor="Alt-N"><vers num="3.0.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0320" published="2005-01-28" seq="2005-0320" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting vulnerabilities in MERAK Mail Server 7.6.0 with Icewarp Web Mail 5.3.0 allow remote attackers to inject arbitrary web script or HTML via the (1) username parameter to login.html, (2) accountid parameter to accountsettings_add.html, or the (3) note, (4) title, and (5) location fields to calendar.html.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110693950205007&amp;w=2">20050128 Multiple vulnerabilities in Icewarp Web Mail 5.3.0: New holes</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/12396">12396</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19147">merak-icewarp-multiple-xss(19147)</ref></refs><vuln_soft><prod name="Web Mail" vendor="IceWarp"><vers num="5.3"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0321" published="2005-05-02" seq="2005-0321" severity="Low" type="CVE"><desc><descript source="cve">MERAK Mail Server 7.6.0 with Icewarp Web Mail 5.3.0 allows remote authenticated users to gain sensitive information via an HTTP request to (1) calendar_d.html, (2) calendar_m.html, (3) calendar_w.html, or (4) calendar_y.html, which reveal the installation path.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110693950205007&amp;w=2">20050128 Multiple vulnerabilities in Icewarp Web Mail 5.3.0: New holes</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19152">merak-icewarp-user-path-disclosure(19152)</ref></refs><vuln_soft><prod name="Web Mail" vendor="IceWarp"><vers num="5.3.0"/></prod><prod name="Mail Server" vendor="Merak"><vers num="7.6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2007-01-24" name="CVE-2005-0322" published="2005-05-02" seq="2005-0322" severity="High" type="CVE"><desc><descript source="cve">MERAK Mail Server 7.6.0 with Icewarp Web Mail 5.3.0 and Mail Server 7.6.4r with Icewarp Mail Server 5.3.2 uses weak encryption in the (1) users.cfg, (2) settings.cfg, (3) users.dat or (4) user.dat files, which allows local users to extract the passwords.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110693950205007&amp;w=2">20050128 Multiple vulnerabilities in Icewarp Web Mail 5.3.0: New holes</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19153">merak-icewarp-weak-password-encryption(19153)</ref></refs><vuln_soft><prod name="Web Mail" vendor="IceWarp"><vers num="5.3.0"/><vers num="5.3.2"/></prod><prod name="Mail Server" vendor="Merak"><vers num="7.6.0"/><vers num="7.6.4r"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0323" published="2005-05-02" seq="2005-0323" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Infinite Mobile Delivery Webmail 2.6 allows remote attackers to inject arbitrary web script or HTML via the URL.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110703630922262&amp;w=2">20050129 XSS in Infinite Mobile Delivery v2.6 Webmail</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19151">infinite-mobile-delivery-xss(19151)</ref><ref source="" url="http://www.lovebug.org/imd_advisory.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/12399">12399</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013044">1013044</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14075">14075</ref></refs><vuln_soft><prod name="Infinite Mobile Delivery Webmail" vendor="Captaris"><vers num="2.6"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0324" published="2005-05-02" seq="2005-0324" severity="Medium" type="CVE"><desc><descript source="cve">Infinite Mobile Delivery Webmail 2.6 allows remote attackers to gain sensitive information via an HTTP request that contains invalid characters for a Windows foldername, which reveals the path in an error message.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110703630922262&amp;w=2">20050129 XSS in Infinite Mobile Delivery v2.6 Webmail</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19154">infinite-mobile-delivery-path-disclosure (19154)</ref><ref source="" url="http://www.lovebug.org/imd_advisory.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/12399">12399</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013044">1013044</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14075">14075</ref></refs><vuln_soft><prod name="Infinite Mobile Delivery Webmail" vendor="Captaris"><vers num="2.6"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0325" published="2005-05-02" seq="2005-0325" severity="Medium" type="CVE"><desc><descript source="cve">Xpand Rally 1.0.0.0 allows remote attackers or remote malicious game servers to cause a denial of service (application crash) via a packet with large values that are not properly handled in certain malloc or memcpy operations.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref patch="1" source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-January/031336.html">20050130 Broadcast crash in Xpand Rally 1.0.0.0</ref><ref patch="1" source="Luigi Auriemma" url="http://aluigi.altervista.org/adv/xprallyboom-adv.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/12409">12409</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19150">xpand-rally-memory-dos(19150)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013043">1013043</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14073">14073</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110720064811485&amp;w=2">20050130 Broadcast crash in Xpand Rally 1.0.0.0</ref></refs><vuln_soft><prod name="XPand Rally" vendor="Techland"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0326" published="2005-05-02" seq="2005-0326" severity="Medium" type="CVE"><desc><descript source="cve">pafiledb.php in PaFileDB 3.1 allows remote attackers to gain sensitive information via an invalid or missing action parameter, which reveals the path in an error message when it cannot include a login.php script.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110720365923818&amp;w=2">20050131 [PersianHacker.net] Full Path Disclosure and PHP Injection In Pafiledb 3.1 Final</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19175">pafiledb-login-path-disclosure(19175)</ref></refs><vuln_soft><prod name="paFileDB" vendor="PHP Arena"><vers num="3.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0327" published="2005-05-02" seq="2005-0327" severity="High" type="CVE"><desc><descript source="cve">pafiledb.php in Pafiledb 3.1 may allow remote attackers to execute arbitrary PHP code via a modified action parameter that is used in an include statement for login.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110720365923818&amp;w=2">20050131 [PersianHacker.net] Full Path Disclosure and PHP Injection In Pafiledb 3.1 Final</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19176">pafiledb-login-file-include(19176)</ref></refs><vuln_soft><prod name="paFileDB" vendor="PHP Arena"><vers num="3.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0328" published="2005-05-02" seq="2005-0328" severity="Medium" type="CVE"><desc><descript source="cve">Zyxel P310, P314, P324 and Netgear RT311, RT314 running the latest firmware, allows remote attackers on the WAN to obtain the IP address of the LAN side interface by pinging a valid LAN IP address, which generates an ARP reply from the WAN address side that maps the LAN IP address to the WAN&apos;s MAC address.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110720465527599&amp;w=2">20050131 Zyxel / Netgear and probably other routers leaking information.</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20609">zyxel-netgear-ping-information-disclosure(20609)</ref></refs><vuln_soft><prod name="RT311" vendor="Netgear"><vers num=""/></prod><prod name="Prestige" vendor="ZyXEL"><vers num="310"/><vers num="314"/><vers num="324"/></prod><prod name="RT314" vendor="Netgear"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-05-01" name="CVE-2005-0329" published="2005-05-02" seq="2005-0329" severity="Low" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in ZipGenius 5.5 and earlier allows remote attackers to create and possibly modify arbitrary files via a ZIP file with a file whose name includes .. (dot dot) sequences.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110736990230696&amp;w=2">20050202 7a69Adv#19 - ZipGenius unpack path disclosure</ref><ref patch="1" source="MISC" url="http://securitytracker.com/id?1013542">http://securitytracker.com/id?1013542</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/12419">12419</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19203">zipgenius-path-disclosure(19203)</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14123">14123</ref></refs><vuln_soft><prod name="ZipGenius" vendor="ZipGenius"><vers num="Suite 5.5"/><vers num="Standard 5.5"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0330" published="2005-05-02" seq="2005-0330" severity="Low" type="CVE"><desc><descript source="cve">Buffer overflow in Painkiller 1.35 and earlier, and possibly other versions before 1.61, allows remote authenticated users to cause a denial of service and possibly execute arbitrary code via a long cd-key hash.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/12423">12423</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/14113/">14113</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19205">painkiller-long-cdkey-bo(19205)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013066">1013066</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110736915015707&amp;w=2">20050202 Limited buffer-overflow in Painkiller 1.35</ref></refs><vuln_soft><prod name="Painkiller" vendor="People can Fly"><vers num="1.3.5"/><vers num="1.3.1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0331" published="2005-05-02" seq="2005-0331" severity="Low" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in WinRAR 3.42 and earlier, when the user clicks on the ZIP file to extract it, allows remote attackers to create arbitrary files via a ... (triple dot) in the filename of the ZIP file.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110737609604210&amp;w=2">20050202 7a69Adv#21 - WinRAR unpack one-folder path disclosure</ref><ref source="BID" url="http://www.securityfocus.com/bid/12422">12422</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20585">winrar-dotdotdotdirectory-traversal(20585)</ref></refs><vuln_soft><prod name="WinRar" vendor="RARLAB"><vers num="3.42"/><vers num="3.41"/><vers num="3.40"/><vers num="3.20"/><vers num="3.11"/><vers num="3.10 beta5"/><vers num="3.10 beta3"/><vers num="3.10"/><vers num="3.0.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-06-15" name="CVE-2005-0332" published="2005-05-02" seq="2005-0332" severity="High" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in DeskNow Mail and Collaboration Server 2.5.12 allows remote attackers to (1) upload and possibly execute files outside the directory via the AttachmentsKey parameter to attachment.do, as demonstrated using JSP pages, or (2) delete arbitrary files via the select_file parameter to file.do.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110737616324614&amp;w=2">20050202 [SIG^2 G-TEC] DeskNow Mail and Collaboration Server Directory Traversal Vulnerabilities</ref><ref adv="1" source="MISC" url="http://www.security.org.sg/vuln/desknow2512.html">http://www.security.org.sg/vuln/desknow2512.html</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/12421">12421</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19206">desknow-attachmentkey-file-upload(19206)</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19211">desknow-jsp-gain-access(19211)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19212">desknow-filedo-file-deletion(19212)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013060">1013060</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14116">14116</ref></refs><vuln_soft><prod name="DeskNow Mail and Collaboration Server" vendor="Ventia"><vers num="2.5.13"/><vers num="2.5.12"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0333" published="2005-05-02" seq="2005-0333" severity="Medium" type="CVE"><desc><descript source="cve">LANChat Pro Revival 1.666c allows remote attackers to cause a denial of service (application crash) via a malformed UDP packet.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110746524021133&amp;w=2">20050203 DoS in LANChat Pro Revival 1.666c</ref><ref adv="1" source="MISC" url="http://www.autistici.org/fdonato/advisory/LANChatRevival1.666c-adv.txt">http://www.autistici.org/fdonato/advisory/LANChatRevival1.666c-adv.txt</ref><ref source="BID" url="http://www.securityfocus.com/bid/12439">12439</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19213">lanchatpro-udp-packet-dos(19213)</ref></refs><vuln_soft><prod name="LANChat Pro Revival" vendor="LANChat Pro Revival"><vers num="1.666c"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0334" published="2005-05-02" seq="2005-0334" severity="Medium" type="CVE"><desc><descript source="cve">Linksys PSUS4 running firmware 6032 allows remote attackers to cause a denial of service (device crash) via an HTTP POST request containing an unknown parameter without a value.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110747234701646&amp;w=2">20050203 [ RSTACK Public Security Advisory ] Remote DOS against Linksys PSUS4</ref><ref source="BID" url="http://www.securityfocus.com/bid/12443">12443</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/14136">14136</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19222">linksys-psus4-dos(19222)</ref></refs><vuln_soft><prod name="PSUS4 PrintServer" vendor="Linksys"><vers num="6032"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0335" published="2005-05-02" seq="2005-0335" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in EMotion MediaPartner Web Server 5.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the URL.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110547214224714&amp;w=2">20050110 Portcullis Security Advisory 05-010</ref><ref adv="1" source="MISC" url="http://www.securitytracker.com/alerts/2005/Jan/1012838.html">http://www.securitytracker.com/alerts/2005/Jan/1012838.html</ref><ref source="BID" url="http://www.securityfocus.com/bid/12236">12236</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18842">mediapartner-dotdot-directory-traversal(18842)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1012838">1012838</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13820">13820</ref></refs><vuln_soft><prod name="MediaPartner Web Server" vendor="EMotion"><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0336" published="2005-05-02" seq="2005-0336" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in EMotion MediaPartner Web Server 5.0 allows remote attackers to inject arbitrary HTML or web script, as demonstrated using a URL containing .. sequences and HTML, which results in a directory browsing page that does not properly filter the HTML.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110547214224714&amp;w=2">20050110 Portcullis Security Advisory 05-010</ref><ref adv="1" source="MISC" url="http://www.securitytracker.com/alerts/2005/Jan/1012838.html">http://www.securitytracker.com/alerts/2005/Jan/1012838.html</ref><ref source="BID" url="http://www.securityfocus.com/bid/12236">12236</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18845">mediapartner-url-xss(18845)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1012838">1012838</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13820">13820</ref></refs><vuln_soft><prod name="MediaPartner Web Server" vendor="EMotion"><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0337" published="2005-05-02" seq="2005-0337" severity="High" type="CVE"><desc><descript source="cve">Postfix 2.1.3, when /proc/net/if_inet6 is not available and permit_mx_backup is enabled in smtpd_recipient_restrictions, allows remote attackers to bypass e-mail restrictions and perform mail relaying by sending mail to an IPv6 hostname.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110763358832637&amp;w=2">20050204 [USN-74-1] Postfix vulnerability</ref><ref adv="1" source="CONFIRM" url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=267837">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=267837</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/12445">12445</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/14137/">14137</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19218">postfix-ipv6-security-bypass(19218)</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-152.html">RHSA-2005:152</ref></refs><vuln_soft><prod name="Postfix" vendor="Wietse Venema"><vers num="2.1.3"/></prod><prod name="SuSE Linux" vendor="SuSE"><vers num="9.2"/><vers num="9.1"/><vers edition="x86_64" num="9.0"/><vers num="9.0"/><vers num="8.2"/><vers num="8.1"/><vers edition="i386" num="8.0"/><vers num="8.0"/></prod><prod name="Desktop" vendor="Red Hat"><vers num="4.0"/></prod><prod name="Enterprise Linux" vendor="Red Hat"><vers edition="Workstation" num="4.0"/><vers edition="Enterprise Server" num="4.0"/><vers edition="Advanced Server" num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0338" published="2005-05-02" seq="2005-0338" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Savant Web Server 3.1 allows remote attackers to execute arbitrary code via a long HTTP request.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=110725682327452&amp;w=2">20050201 Remotely exploitable buffer overflow vulnerability in Savant Web Server 3.1</ref><ref source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=110728448025559&amp;w=2">20050201 Remotely exploitable buffer overflow vulnerability in Savant Web Server 3.1</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110756234611259&amp;w=2">20050204 Exploit For Savant Web Server 3.1 (tested on win2003)</ref><ref source="BID" url="http://www.securityfocus.com/bid/12429">12429</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19177">savant-bo(19177)</ref></refs><vuln_soft><prod name="Savant Webserver" vendor="Savant"><vers num="3.1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0339" published="2005-05-02" seq="2005-0339" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Foxmail 2.0 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long MAIL FROM command.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110763204301080&amp;w=2">20050205 Foxmail Server Remote Buffer Overflow Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/12454">12454</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19229">foxmail-mailfrom-bo(19229)</ref></refs><vuln_soft><prod name="Foxmail Email Server" vendor="Foxmail"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0340" published="2005-05-02" seq="2005-0340" severity="Medium" type="CVE"><desc><descript source="cve">Integer signedness error in Apple File Service (AFP Server) allows remote attackers to cause a denial of service (application crash) via a negative UAM string length in a FPLoginExt packet.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110791369419784&amp;w=2">20050208 AppleFileServer Denial of Service.</ref><ref patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/Mar/msg00000.html">APPLE-SA-2005-03-21</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19263">Applefileserver-fploginext-dos(19263)</ref><ref source="BID" url="http://www.securityfocus.com/bid/12478">12478</ref></refs><vuln_soft><prod name="AFP Server" vendor="Apple"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0341" published="2005-05-02" seq="2005-0341" severity="Medium" type="CVE"><desc><descript source="cve">Apple Safari 1.2.4 does not obey the Content-type field in the HTTP header and renders text as HTML, which allows remote attackers to inject arbitrary web script or HTML and perform cross-site scripting (XSS) attacks.</descript></desc><loss_types><int/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110756965213819&amp;w=2">20050204 Input Validation Vulnerability in Apple Safari version 1.2.4 v125.12</ref><ref adv="1" source="MISC" url="http://tigger.uic.edu/~jrockw2/safari_20050204.txt">http://tigger.uic.edu/~jrockw2/safari_20050204.txt</ref><ref adv="1" source="MISC" url="http://www.securitytracker.com/alerts/2005/Feb/1013087.html">http://www.securitytracker.com/alerts/2005/Feb/1013087.html</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19227">safari-contenttype-xss(19227)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013087">1013087</ref></refs><vuln_soft><prod name="Safari" vendor="Apple"><vers num="1.2.4"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0342" published="2005-05-02" seq="2005-0342" severity="Low" type="CVE"><desc><descript source="cve">The Finder in Mac OS X and earlier allows local users to overwrite arbitrary files and gain privileges by creating a hard link from the .DS_Store file to an arbitrary file.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110780124707975&amp;w=2">20050207 [OSX Finder] DS_Store arbitrary file overwrite vulnerability.</ref><ref source="BID" url="http://www.securityfocus.com/bid/12458">12458</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14188">14188</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19253">Finder-dsstore-file-overwrite(19253)</ref><ref patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/May/msg00001.html">APPLE-SA-2005-05-03</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.3.7"/><vers num="10.3.6"/><vers num="10.3.5"/><vers num="10.3.4"/><vers num="10.3.3"/><vers num="10.3.2"/><vers num="10.3.1"/><vers num="10.3"/><vers num="10.2.8"/><vers num="10.2.7"/><vers num="10.2.6"/><vers num="10.2.5"/><vers num="10.2.4"/><vers num="10.2.3"/><vers num="10.2.2"/><vers num="10.2.1"/><vers num="10.2"/><vers num="10.1.5"/><vers num="10.1.4"/><vers num="10.1.3"/><vers num="10.1.2"/><vers num="10.1.1"/><vers num="10.1"/><vers num="10.0"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.3.7"/><vers num="10.3.6"/><vers num="10.3.5"/><vers num="10.3.4"/><vers num="10.3.3"/><vers num="10.3.2"/><vers num="10.3.1"/><vers num="10.3"/><vers num="10.2.8"/><vers num="10.2.7"/><vers num="10.2.6"/><vers num="10.2.5"/><vers num="10.2.4"/><vers num="10.2.3"/><vers num="10.2.2"/><vers num="10.2.1"/><vers num="10.2"/><vers num="10.1.5"/><vers num="10.1.4"/><vers num="10.1.3"/><vers num="10.1.2"/><vers num="10.1.1"/><vers num="10.1"/><vers num="10.0.4"/><vers num="10.0.3"/><vers num="10.0.2"/><vers num="10.0.1"/><vers num="10.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0343" published="2005-05-02" seq="2005-0343" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in PerlDesk 1.x allows remote attackers to inject arbitrary SQL commands via the view parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110782042532295&amp;w=2">20050207 [SePro Bugtraq] SQL-Injection in PerlDesk 1.x</ref><ref adv="1" source="MISC" url="http://www.security-project.org/projects/board/showthread.php?p=5172#post5172">http://www.security-project.org/projects/board/showthread.php?p=5172#post5172</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/12471">12471</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/12512">12512</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19245">perldesk-view-sql-injection(19245)</ref></refs><vuln_soft><prod name="PerlDesk" vendor="logicNow"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0344" published="2005-05-02" seq="2005-0344" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in 602LAN SUITE 2004.0.04.1221 allows remote authenticated users to upload and execute arbitrary files via a .. (dot dot) in the filename parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110793103506620&amp;w=2">20050208 [SIG^2 G-TEC] 602LAN SUITE Web Mail Vulnerability Allows File Upload to Arbitrary Directories</ref><ref adv="1" patch="1" source="MISC" url="http://www.security.org.sg/vuln/602lansuite1221.html">http://www.security.org.sg/vuln/602lansuite1221.html</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14169/">14169</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19258">602lansuite-webmail-directory-traversal(19258)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013106">1013106</ref></refs><vuln_soft><prod name="602LAN Suite" vendor="Software602"><vers num="2004.0.04.1221"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0345" published="2005-05-02" seq="2005-0345" severity="Medium" type="CVE"><desc><descript source="cve">viewthread.php in php-fusion 4.x does not check the (1) forum_id or (2) forum_cat parameters, which allows remote attackers to view protected forums via the thread_id parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110788267311132&amp;w=2">20050208 php-fusion 4.x vuln</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19257">phpfusion-viewthread-obtain-information(19257)</ref><ref source="BID" url="http://www.securityfocus.com/bid/12482">12482</ref></refs><vuln_soft><prod name="PHP_Fusion" vendor="PHP_Fusion"><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0346" published="2005-05-02" seq="2005-0346" severity="Low" type="CVE"><desc><descript source="cve">SafeNet SoftRemote VPN Client stores the VPN password (pre-shared key) in cleartext in memory of the IreIKE.exe process, which allows local users to gain sensitive information if they have access to that process.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110791865522076&amp;w=2">20050208 SafeNet SoftRemote VPN Client Issue: Clear-text password</ref><ref adv="1" source="MISC" url="http://www.nta-monitor.com/news/vpn-flaws/safenet/index.htm">http://www.nta-monitor.com/news/vpn-flaws/safenet/index.htm</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19256">softremote-vpn-password-disclosure(19256)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013134">1013134</ref></refs><vuln_soft><prod name="SoftRemote VPN Client" vendor="SafeNet"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-01-05" name="CVE-2005-0347" published="2005-05-02" seq="2005-0347" severity="Medium" type="CVE"><desc><descript source="cve">Integer overflow in RealArcade 1.2.0.994 and earlier allows remote attackers to execute arbitrary code via an RGS file with an invalid size string for the GUID and game name, which leads to a buffer overflow.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110792779115794&amp;w=2">20050208 Integer overflow and arbitrary files deletion in RealArcade</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/14187/">14187</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110792779115794&amp;w=2">20050208 Integer overflow and arbitrary files deletion in RealArcade</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19259">realarcade-rgs-bo(19259)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013128">1013128</ref></refs><vuln_soft><prod name="RealArcade" vendor="RealNetworks"><vers num="1.2.0.994" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-01-05" name="CVE-2005-0348" published="2005-05-02" seq="2005-0348" severity="Low" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in RealArcade 1.2.0.994 allows remote attackers to delete arbitrary files via an RGP file with a .. (dot dot) in the FILENAME tag.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110792779115794&amp;w=2">20050208 Integer overflow and arbitrary files deletion in RealArcade</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/14187/">14187</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110792779115794&amp;w=2">20050208 Integer overflow and arbitrary files deletion in RealArcade</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19260">realarcade-rgp-file-deletion(19260)</ref><ref source="BID" url="http://www.securityfocus.com/bid/12494">12494</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013128">1013128</ref></refs><vuln_soft><prod name="RealArcade" vendor="RealNetworks"><vers num="1.2.0.994" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0349" published="2005-05-02" seq="2005-0349" severity="High" type="CVE"><desc><descript source="cve">The production release of the UniversalAgent for UNIX in BrightStor ARCserve Backup 11.1 contains hard-coded credentials, which allows remote attackers to access the file system and possibly execute arbitrary commands.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CONFIRM" url="http://supportconnect.ca.com/sc/solcenter/sol_detail.jsp?aparno=QO63672&amp;os=UNIX&amp;returninput=0">http://supportconnect.ca.com/sc/solcenter/sol_detail.jsp?aparno=QO63672&amp;os=UNIX&amp;returninput=0</ref><ref adv="1" patch="1" source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=198&amp;type=vulnerabilities">20050210 Computer Associates BrightStor ARCserve Backup UniversalAgent Backdoor Vulnerability</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013144">1013144</ref><ref source="BID" url="http://www.securityfocus.com/bid/12522">12522</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/0145">ADV-2005-0145</ref><ref source="OSVDB" url="http://www.osvdb.org/13706">13706</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14233">14233</ref></refs><vuln_soft><prod name="BrightStor ARCServe Backup" vendor="Computer Associates"><vers num="11.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0350" published="2005-05-02" seq="2005-0350" severity="High" type="CVE"><desc><descript source="cve">Heap-based buffer overflow in multiple F-Secure Anti-Virus and Internet Security products allows remote attackers to execute arbitrary code via a crafted ARJ archive.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS" url="http://xforce.iss.net/xforce/alerts/id/188">20050210 F-Secure AntiVirus Library Heap Overflow</ref><ref patch="1" source="CONFIRM" url="http://www.f-secure.com/security/fsc-2005-1.shtml">http://www.f-secure.com/security/fsc-2005-1.shtml</ref></refs><vuln_soft><prod name="Internet Gatekeeper" vendor="F-Secure"><vers num="6.41" prev="1"/><vers edition="Linux" num="2.06"/></prod><prod name="F-Secure Personal Express" vendor="F-Secure"><vers num="5.10" prev="1"/></prod><prod name="F-Secure Anti-Virus" vendor="F-Secure"><vers edition="Workstations" num="5.43" prev="1"/><vers edition="Windows Servers" num="5.5" prev="1"/><vers edition="Citrix Servers" num="5.5"/><vers edition="MIMESweeper" num="5.51" prev="1"/><vers edition="Client Security" num="5.55" prev="1"/><vers edition="MS Exchange" num="6.31" prev="1"/><vers edition="Firewalls" num="6.2" prev="1"/><vers num="2004"/><vers num="2005"/><vers edition="Linux Workstations" num="4.52" prev="1"/><vers edition="Linux Servers" num="4.61" prev="1"/><vers edition="Linux Gateways" num="4.61" prev="1"/><vers edition="Samba Servers" num="4.60"/><vers edition="Linux Client Security" num="5.01" prev="1"/><vers edition="Linux Server Security" num="5.01" prev="1"/></prod><prod name="F-Secure Internet Security" vendor="F-Secure"><vers num="2004"/><vers num="2005"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-01-03" name="CVE-2005-0351" published="2005-04-07" seq="2005-0351" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in (1) termsh, (2) atcronsh, and (3) auditsh in SCO OpenServer 5.0.6 and 5.0.7 might allow local users to execute arbitrary code via a long HOME environment variable.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="SCO" url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.15/SCOSA-2005.15.txt">SCOSA-2005.15</ref><ref source="BID" url="http://www.securityfocus.com/bid/13062">13062</ref></refs><vuln_soft><prod name="OpenServer" vendor="SCO"><vers num="5.0.7"/><vers num="5.0.6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0352" published="2005-03-16" seq="2005-0352" severity="High" type="CVE"><desc><descript source="cve">Servers Alive 4.1 and 5.0, when running as a service, does not drop SYSTEM privileges before loading local manual under the help menu, which allows local users to gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/><config/></vuln_types><range><local/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111100364513513&amp;w=2">20050316 Servers Alive: Local Privilege Escalation</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/12822">12822</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/14616/">14616</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19715">serversalive-gain-privileges(19715)</ref></refs><vuln_soft><prod name="Servers Alive" vendor="Woodstone"><vers num="5.0"/><vers num="4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0353" published="2005-05-02" seq="2005-0353" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the Sentinel LM (Lservnt) service in the Sentinel License Manager 7.2.0.2 allows remote attackers to execute arbitrary code by sending a large amount of data to UDP port 5093.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111022094326772&amp;w=2">20050307 CIRT.DK Advisory - SafeNet Inc Sentinel License Manager 7.2.0.2 Buffer Overflow</ref><ref adv="1" patch="1" source="MISC" url="http://www.cirt.dk/advisories/cirt-30-advisory.pdf">http://www.cirt.dk/advisories/cirt-30-advisory.pdf</ref><ref adv="1" source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=111072872816405&amp;w=2">20050313 [HAT-SQUAD]  SafeNet Sentinel LM, UDP License Manager Exploit</ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/108790">VU#108790</ref><ref source="BID" url="http://www.securityfocus.com/bid/12742">12742</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14511">14511</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19621">sentinel-license-manager-bo(19621)</ref></refs><vuln_soft><prod name="Sentinel License Manager" vendor="SafeNet"><vers num="7.2 .0.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0356" published="2005-05-31" seq="2005-0356" severity="Medium" type="CVE"><desc><descript source="cve">Multiple TCP implementations with Protection Against Wrapped Sequence Numbers (PAWS) with the timestamps option enabled allow remote attackers to cause a denial of service (connection loss) via a spoofed packet with a large timer value, which causes the host to discard later packets because they appear to be too old.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-sn-20050518-tcpts.shtml">20050518 Vulnerability in a Variant of the TCP Timestamps Option</ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/637934">VU#637934</ref><ref source="BID" url="http://www.securityfocus.com/bid/13676">13676</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/15417/">15417</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15393">15393</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20635">tcp-ip-timestamp-dos(20635)</ref><ref source="FREEBSD" url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-05:15.tcp.asc">FreeBSD-SA-05:15</ref><ref source="SCO" url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.64/SCOSA-2005.64.txt">SCOSA-2005.64</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18222">18222</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-032.htm"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/18662">18662</ref></refs><vuln_soft><prod name="GS4000" vendor="Hitachi"><vers num=""/></prod><prod name="Ethernet Routing Switch" vendor="Nortel"><vers num="1648"/><vers num="1624"/><vers num="1612"/></prod><prod name="RTV700" vendor="Yamaha"><vers num=""/></prod><prod name="AP350" vendor="Cisco"><vers num=""/></prod><prod name="RTX2000" vendor="Yamaha"><vers num=""/></prod><prod name="AP1200" vendor="Cisco"><vers num=""/></prod><prod name="Succession Communications Server" vendor="Nortel"><vers num="1000"/></prod><prod name="Secure ACS Solution Engine" vendor="Cisco"><vers num="3.3"/><vers num="3.3.1"/><vers num="3.3.2"/></prod><prod name="GR4000" vendor="Hitachi"><vers num=""/></prod><prod name="Universal Signaling Point" vendor="Nortel"><vers num="5200"/><vers num="Compact_Lite"/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers num="Standard 64-bit"/><vers edition="64-bit" num="R2"/><vers edition="Datacenter 64-bit" num="R2"/><vers edition="64-bit" num="Enterprise"/><vers num="Enterprise 64-bit"/><vers edition="64-bit" num="Standard"/><vers num="Web"/></prod><prod name="CiscoWorks Access Control List Manager" vendor="Cisco"><vers num="1.5"/><vers num="1.6"/></prod><prod name="Storage Router" vendor="Cisco"><vers num="SN5420 1.1 (7)"/><vers num="SN5420 1.1 (5)"/><vers num="SN5420 1.1 (4)"/><vers num="SN5420 1.1 (3)"/><vers num="SN5420 1.1 (2)"/><vers num="SN5420 1.1.3"/><vers num="SN5428 3.3.2-K9"/><vers num="SN5428 3.3.1-K9"/><vers num="SN5428 3.2.2-K9"/><vers num="SN5428 3.2.1-K9"/><vers num="SN5428 2.5.1-K9"/><vers num="SN5428 2-3.3.2-K9"/><vers num="SN5428 2-3.3.1-K9"/><vers num="SN5400"/></prod><prod name="OpenBSD" vendor="OpenBSD"><vers num="3.0"/><vers num="3.1"/><vers num="3.2"/><vers num="3.3"/><vers num="3.4"/><vers num="3.5"/><vers num="3.6"/></prod><prod name="AlaxalA" vendor="Hitachi"><vers num="AX"/></prod><prod name="Support Tools" vendor="Cisco"><vers num=""/></prod><prod name="CiscoWorks Windows" vendor="Cisco"><vers num=""/></prod><prod name="CiscoWorks Common Services" vendor="Cisco"><vers num="2.2"/></prod><prod name="Web Collaboration Option" vendor="Cisco"><vers num=""/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num="Advanced Server SP4"/><vers num="Advanced Server SP3"/><vers num="Advanced Server SP2"/><vers num="Advanced Server SP1"/><vers num="Advanced Server"/><vers num="Datacenter Server SP4"/><vers num="Datacenter Server SP3"/><vers num="Datacenter Server SP2"/><vers num="Datacenter Server SP1"/><vers num="Datacenter Server"/><vers num="Professional SP4"/><vers num="Professional SP3"/><vers num="Professional SP2"/><vers num="Professional SP1"/><vers num="Professional"/><vers num="Server SP4"/><vers num="Server SP3"/><vers num="Server SP2"/><vers num="Server SP1"/><vers num="Server"/></prod><prod name="Intelligent Contact Manager" vendor="Cisco"><vers num="5.0"/></prod><prod name="IP Contact Center Express" vendor="Cisco"><vers num=""/></prod><prod name="Secure ACS" vendor="Cisco"><vers num="3.0"/><vers num="3.1"/><vers num="3.2 (3)"/><vers num="3.2 (2)"/><vers num="3.2 (1.20)"/><vers num="3.2 (1)"/><vers num="3.2"/><vers num="3.2.1"/><vers num="3.2.2"/><vers num="3.3 (1)"/><vers num="3.3"/><vers num="3.3.1"/><vers num="3.3.2"/></prod><prod name="RT300i" vendor="Yamaha"><vers num=""/></prod><prod name="Secure ACS for Windows NT" vendor="Cisco"><vers num="2.1"/><vers num="2.3"/><vers num="2.4"/><vers num="2.5"/><vers num="2.6"/><vers num="2.6.2"/><vers num="2.6.3"/><vers num="2.6.4"/><vers num="2.42"/><vers num="3.0 .1"/><vers num="3.0"/><vers num="3.0.3"/><vers num="3.1.1"/></prod><prod name="Interactive Voice Response" vendor="Cisco"><vers num=""/></prod><prod name="Secure ACS for Unix" vendor="Cisco"><vers num="2.0"/><vers num="2.3"/><vers num="2.3.5 .1"/><vers num="2.3.6 .1"/></prod><prod name="Business Communications Manager" vendor="Nortel"><vers num="400"/><vers num="200"/><vers num="1000"/></prod><prod name="MGX" vendor="Cisco"><vers num="8230 1.2.10"/><vers num="8230 1.2.11"/><vers num="8250 1.2.10"/><vers num="8250 1.2.11"/></prod><prod name="E-Mail Manager" vendor="Cisco"><vers num=""/></prod><prod name="Conact Center" vendor="Nortel"><vers num=""/></prod><prod name="Conference Connection" vendor="Cisco"><vers num="1.1 (1)"/><vers num="1.2"/></prod><prod name="WLAN Access Point" vendor="Nortel"><vers num="7220.0"/><vers num="7250.0"/></prod><prod name="RT250i" vendor="Yamaha"><vers num=""/></prod><prod name="RT105" vendor="Yamaha"><vers num=""/></prod><prod name="Remote Monitoring Suite Option" vendor="Cisco"><vers num=""/></prod><prod name="RTX1500" vendor="Yamaha"><vers num=""/></prod><prod name="Call Manager" vendor="Cisco"><vers num="1.0"/><vers num="2.0"/><vers num="3.0"/><vers num="3.1.3a"/><vers num="3.1.2"/><vers num="3.1"/><vers num="3.2"/><vers num="3.3.3"/><vers num="3.3"/><vers num="4.0"/></prod><prod name="Unity Server" vendor="Cisco"><vers num="2.0"/><vers num="2.1"/><vers num="2.2"/><vers num="2.3"/><vers num="2.4"/><vers num="2.46"/><vers num="3.0"/><vers num="3.1"/><vers num="3.2"/><vers num="3.3"/><vers num="4.0"/></prod><prod name="CiscoWorks 1105 Wireless LAN Solution Engine" vendor="Cisco"><vers num=""/></prod><prod name="CiscoWorks CD1" vendor="Cisco"><vers num="5th"/><vers num="4th"/><vers num="3rd"/><vers num="2nd"/><vers num="1st"/></prod><prod name="CiscoWorks VPN/Security Management Solution" vendor="Cisco"><vers num=""/></prod><prod name="IP Contact Center Enterprise" vendor="Cisco"><vers num=""/></prod><prod name="Secure ACS for Windows Server" vendor="Cisco"><vers num="3.2"/></prod><prod name="GR3000" vendor="Hitachi"><vers num=""/></prod><prod name="Windows XP" vendor="Microsoft"><vers edition="SP1" num="64-bit"/><vers num="64-bit"/><vers edition="SP1" num="64-bit Version 2003"/><vers num="64-bit Version 2003"/><vers edition="SP1" num="Embedded"/><vers num="Embedded"/><vers edition="SP1" num="Home"/><vers num="Home"/><vers edition="Gold" num="Professional"/><vers edition="Gold" num="Professional"/><vers edition="SP1" num="Media Center"/><vers num="Media Center"/><vers edition="SP2" num="Tablet PC"/><vers edition="SP2" num="Tablet PC"/></prod><prod name="FreeBSD" vendor="FreeBSD"><vers num="4.10 pre"/><vers num="1.1.5.1"/><vers num="2.0"/><vers num="2.0.5"/><vers num="2.1.0"/><vers num="2.1.5"/><vers num="2.1.6.1"/><vers num="2.1.6"/><vers num="2.1.7.1"/><vers num="2.2"/><vers num="2.2.2"/><vers num="2.2.3"/><vers num="2.2.4"/><vers num="2.2.5"/><vers num="2.2.6"/><vers num="2.2.8"/><vers num="3.0 Releng"/><vers num="3.0"/><vers num="3.1"/><vers num="3.2"/><vers num="3.3"/><vers num="3.4"/><vers num="3.5 Stable pre 2000-12-23"/><vers num="3.5 Stable pre 2001-05-02"/><vers num="3.5 Stable"/><vers num="3.5"/><vers num="3.5.1 Stable pre 2001-07-20"/><vers num="3.5.1 Stable"/><vers num="3.5.1 Release"/><vers num="3.5.1"/><vers num="4.0 Releng"/><vers num="4.0 alpha"/><vers num="4.0"/><vers num="4.1"/><vers num="4.1.1 Stable"/><vers num="4.1.1 Release"/><vers num="4.1.1"/><vers num="4.2 Stable pre 2000-12-23"/><vers num="4.2 Stable pre 2001-05-02"/><vers num="4.2 Stable"/><vers num="4.2 Release"/><vers num="4.2"/><vers num="4.3 Stable"/><vers num="4.3 Releng"/><vers num="4.3 p38 Release"/><vers num="4.3 Release"/><vers num="4.3"/><vers num="4.4 Stable"/><vers num="4.4 Releng"/><vers num="4.4 p42 Release"/><vers num="4.4"/><vers num="4.5 Stable pre 2002-03-07"/><vers num="4.5 Stable"/><vers num="4.5 Releng"/><vers num="4.5 p32 Release"/><vers num="4.5 Release"/><vers num="4.5"/><vers num="4.6 Stable"/><vers num="4.6 Releng"/><vers num="4.6 p20 Release"/><vers num="4.6 Release"/><vers num="4.6"/><vers num="4.6.2"/><vers num="4.7 Stable"/><vers num="4.7 Releng"/><vers num="4.7 p17 Release"/><vers num="4.7 Release"/><vers num="4.7"/><vers num="4.8 Releng"/><vers num="4.8 p6 Release"/><vers num="4.8 pre"/><vers num="4.8"/><vers num="4.9 Releng"/><vers num="4.9 pre"/><vers num="4.9"/><vers num="4.10 Releng"/><vers num="4.10 p8 Release"/><vers num="4.10 Release"/><vers num="4.10"/><vers num="4.11 Stable"/><vers num="4.11 Releng"/><vers num="4.11 p3 Release"/><vers num="5.0 Releng"/><vers num="5.0 p14 Release"/><vers num="5.0 alpha"/><vers num="5.0"/><vers num="5.1 Releng"/><vers num="5.1 Release Alpha"/><vers num="5.1 p5 Release"/><vers num="5.1 Release"/><vers num="5.1"/><vers num="5.2 Releng"/><vers num="5.2 Release"/><vers num="5.2"/><vers num="5.2.1 Release"/><vers num="5.3 Stable"/><vers num="5.3 Releng"/><vers num="5.3 Release"/><vers num="5.3"/><vers num="5.4 Release"/><vers num="5.4 pre"/></prod><prod name="RTX1100" vendor="Yamaha"><vers num=""/></prod><prod name="BigIP" vendor="F5"><vers num="4.0"/><vers num="4.2"/><vers num="4.3"/><vers num="4.4"/><vers num="4.5"/><vers num="4.5.6"/><vers num="4.5.9"/><vers num="4.5.10"/><vers num="4.5.11"/><vers num="4.5.12"/><vers num="4.6"/><vers num="4.6.2"/><vers num="9.0"/><vers num="9.0.1"/><vers num="9.0.2"/><vers num="9.0.3"/><vers num="9.0.4"/><vers num="9.0.5"/></prod><prod name="Agent Desktop" vendor="Cisco"><vers num=""/></prod><prod name="Optical Metro" vendor="Nortel"><vers num="5200"/><vers num="5100"/><vers num="5000"/></prod><prod name="CiscoWorks Common Management Foundation" vendor="Cisco"><vers num="2.0"/><vers num="2.1"/><vers num="2.2"/></prod><prod name="MeetingPlace" vendor="Cisco"><vers num="0"/></prod><prod name="Content Services Switch" vendor="Cisco"><vers num="CSS11000"/><vers num="CSS11050"/><vers num="CSS11150"/><vers num="CSS11500"/><vers num="CSS11500 7.10 (05.07)S"/><vers num="CSS11500 7.20 (03.10)S"/><vers num="CSS11500 7.20 (03.09)S"/><vers num="CSS11500 7.30 (00.09)S"/><vers num="CSS11500 7.30 (00.08)S"/><vers num="CSS11501"/><vers num="CSS11503"/><vers num="CSS11506"/><vers num="CSS11800"/></prod><prod name="CallPilot" vendor="Nortel"><vers num="703t"/><vers num="702t"/><vers num="201i"/><vers num="200i"/></prod><prod name="RT57i" vendor="Yamaha"><vers num=""/></prod><prod name="ALAXALA Networks" vendor="ALAXALA"><vers num="AX5400S"/><vers num="AX7800R"/><vers num="AX7800S"/></prod><prod name="SRG" vendor="Nortel"><vers num="1.0"/></prod><prod name="CiscoWorks LMS" vendor="Cisco"><vers num="1.3"/></prod><prod name="CiscoWorks 1105 Hosting Solution Engine" vendor="Cisco"><vers num=""/></prod><prod name="Emergency Responder" vendor="Cisco"><vers num="1.1"/></prod><prod name="CiscoWorks Windows/WUG" vendor="Cisco"><vers num=""/></prod><prod name="Personal Assistant" vendor="Cisco"><vers num="1.3 (4)"/><vers num="1.3 (3)"/><vers num="1.3 (2)"/><vers num="1.3 (1)"/><vers num="1.4 (2)"/><vers num="1.4 (1)"/></prod><prod name="RTX1000" vendor="Yamaha"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0357" published="2005-08-23" seq="2005-0357" severity="High" type="CVE"><desc><descript source="cve">EMC Legato NetWorker, Sun Solstice Backup 6.0 and 6.1, and StorEdge Enterprise Backup 7.0 through 7.2 rely on AUTH_UNIX authentication, which relies on user ID for authentication and allows remote attackers to bypass authentication and gain privileges by spoofing a username or UID.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref patch="1" source="LEGATO" url="http://www.legato.com/support/websupport/product_alerts/081605_NW_authentication.htm">Authentication and nwadmin, nsradmin, nsrports</ref><ref adv="1" patch="1" source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101886-1">101886</ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/606857">VU#606857</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/14582">14582</ref><ref source="OSVDB" url="http://www.osvdb.org/18800">18800</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1014713">1014713</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/16470">16470</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/16464">16464</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/21887">legato-authunix-bypass-authentication(21887)</ref></refs><vuln_soft><prod name="StorEdge Enterprise Backup Software" vendor="Sun"><vers num="7.0"/><vers num="7.1"/><vers num="7.2"/></prod><prod name="Legato NetWorker" vendor="EMC Corporation"><vers num="7.2"/><vers num="7.13"/><vers num="4.2.2"/><vers num="6.0"/><vers num="6.1"/></prod><prod name="Solstice Backup" vendor="Sun"><vers num="6.0"/><vers num="6.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0358" published="2005-08-23" seq="2005-0358" severity="High" type="CVE"><desc><descript source="cve">EMC Legato NetWorker, Solstice Backup 6.0 and 6.1, and StorEdge Enterprise Backup 6.0 through 7.2 do not properly verify authentication tokens, which allows remote attackers to gain privileges by modifying an authentication token.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref patch="1" source="LEGATO" url="http://www.legato.com/support/websupport/product_alerts/081605_NW_token_authentication.htmw.legato.com/support/websupport/product_alerts/081605_NW_token_authentication.htm">Retrieving HTTP content in .NET</ref><ref adv="1" patch="1" source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101886-1">101886</ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/407641">VU#407641</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/14582">14582</ref><ref source="OSVDB" url="http://www.osvdb.org/18801">18801</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1014713">1014713</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/16470">16470</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/16464">16464</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/21892">legato-token-gain-privileges(21892)</ref><ref source="" url="http://www.legato.com/support/websupport/product_alerts/081605_NW_token_authentication.htm"></ref></refs><vuln_soft><prod name="StorEdge Enterprise Backup Software" vendor="Sun"><vers num="7.0"/><vers num="7.1"/><vers num="7.2"/></prod><prod name="Legato NetWorker" vendor="EMC Corporation"><vers num="7.2"/><vers num="7.13"/><vers num="4.2.2"/><vers num="6.0"/><vers num="6.1"/></prod><prod name="Solstice Backup" vendor="Sun"><vers num="6.0"/><vers num="6.1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0359" published="2005-08-23" seq="2005-0359" severity="Medium" type="CVE"><desc><descript source="cve">The Legato PortMapper in EMC Legato NetWorker, Sun Solstice Backup 6.0 and 6.1, and StorEdge Enterprise Backup 7.0 through 7.2 does not restrict access to the pmap_set and pmap_unset commands, which allows remote attackers to (1) cause a denial of service by using pmap_unset to un-register a NetWorker service, or (2) obtain sensitive information from NetWorker services by using pmap_set to register a new service.</descript></desc><loss_types><avail/><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref patch="1" source="LEGATO" url="http://www.legato.com/support/websupport/product_alerts/081605_NW_port_mapper.htm">Legato PortMapper and Remote RPC Access</ref><ref adv="1" patch="1" source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101886-1">101886</ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/801089">VU#801089</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/14582">14582</ref><ref source="OSVDB" url="http://www.osvdb.org/18802">18802</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1014713">1014713</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/16470">16470</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/16464">16464</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/21893">legato-portmapper-obtain-information(21893)</ref></refs><vuln_soft><prod name="StorEdge Enterprise Backup Software" vendor="Sun"><vers num="7.0"/><vers num="7.1"/><vers num="7.2"/></prod><prod name="Legato NetWorker" vendor="EMC Corporation"><vers num="7.2"/><vers num="7.13"/><vers num="4.2.2"/><vers num="6.0"/><vers num="6.1"/></prod><prod name="Solstice Backup" vendor="Sun"><vers num="6.0"/><vers num="6.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0360" published="2005-07-05" seq="2005-0360" severity="Medium" type="CVE"><desc><descript source="cve">The Microsoft Log Sink Class ActiveX control in pkmcore.dll is marked as &quot;safe for scripting&quot; for Internet Explorer, which allows remote attackers to create or append to arbitrary files.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/165022">VU#165022</ref></refs><vuln_soft><prod name="Log Sink Class ActiveX Control" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0362" published="2005-02-09" seq="2005-0362" severity="Medium" type="CVE"><desc><descript source="cve">awstats.pl in AWStats 6.2 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) &quot;pluginmode&quot;, (2) &quot;loadplugin&quot;, or (3) &quot;noloadplugin&quot; parameters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" source="CONFIRM" url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=294488">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=294488</ref><ref source="OSVDB" url="http://www.osvdb.org/16089">16089</ref></refs><vuln_soft><prod name="AWStats" vendor="AWStats"><vers num="6.3"/><vers num="6.2"/><vers num="6.1"/><vers num="6.0"/><vers num="5.9"/><vers num="5.8"/><vers num="5.7"/><vers num="5.5"/><vers num="5.4"/><vers num="5.3"/><vers num="5.2"/><vers num="5.1"/><vers num="5.0"/><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0363" published="2005-05-02" seq="2005-0363" severity="High" type="CVE"><desc><descript source="cve">awstats.pl in AWStats 4.0 and 6.2 allows remote attackers to execute arbitrary commands via shell metacharacters in the config parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-682">DSA-682</ref><ref adv="1" source="CONFIRM" url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=294488">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=294488</ref></refs><vuln_soft><prod name="AWStats" vendor="AWStats"><vers num="6.2"/><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0364" published="2005-02-10" seq="2005-0364" severity="Medium" type="CVE"><desc><descript source="cve">Unknown vulnerability in BIND 9.2.0 in HP-UX B.11.00, B.11.11, and B.11.23 allows remote attackers to cause a denial of service.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="HP" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110805105200470&amp;w=2">HPSBUX01117</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14220/">14220</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19276">hpux-bind-dos(19276)</ref></refs><vuln_soft><prod name="HP-UX" vendor="HP"><vers edition="IA64 64-bit" num="B.11.23"/><vers num="B.11.11"/><vers num="B.11.00"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0365" published="2005-05-02" seq="2005-0365" severity="Low" type="CVE"><desc><descript source="cve">The dcopidlng script in KDE 3.2.x and 3.3.x creates temporary files with predictable filenames, which allows local users to overwrite arbitrary files via a symlink attack.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110814653804757&amp;w=2">20050211 insecure temporary file creation in kdelibs 3.3.2</ref><ref adv="1" patch="1" source="CONFIRM" url="http://bugs.kde.org/show_bug.cgi?id=97608">http://bugs.kde.org/show_bug.cgi?id=97608</ref><ref patch="1" source="CONFIRM" url="http://www.kde.org/info/security/advisory-20050316-2.txt">http://www.kde.org/info/security/advisory-20050316-2.txt</ref><ref adv="1" patch="1" source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200503-14.xml">GLSA-200503-14</ref><ref adv="1" patch="1" source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:045">MDKSA-2005:045</ref><ref adv="1" patch="1" source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:058">MDKSA-2005:058</ref><ref source="FEDORA" url="http://fedoranews.org/updates/FEDORA-2005-245.shtml">FEDORA-2005-245</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013525">1013525</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14254">14254</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-325.html">RHSA-2005:325</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:045">MDKSA-2005:045</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:058">MDKSA-2005:058</ref></refs><vuln_soft><prod name="KDE" vendor="KDE"><vers num="3.2.x"/><vers num="3.3.x"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0366" published="2005-05-02" seq="2005-0366" severity="Medium" type="CVE"><desc><descript source="cve">The integrity check feature in OpenPGP, when handling a message that was encrypted using cipher feedback (CFB) mode, allows remote attackers to recover part of the plaintext via a chosen-ciphertext attack when the first 2 bytes of a message block are known, and an oracle or other mechanism is available to determine whether an integrity check failed.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CONFIRM" url="http://www.pgp.com/library/ctocorner/openpgp.html">http://www.pgp.com/library/ctocorner/openpgp.html</ref><ref source="MISC" url="http://eprint.iacr.org/2005/033.pdf">http://eprint.iacr.org/2005/033.pdf</ref><ref adv="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200503-29.xml">GLSA-200503-29</ref><ref adv="1" patch="1" source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:057">MDKSA-2005:057</ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/303094">VU#303094</ref><ref source="BID" url="http://www.securityfocus.com/bid/12529">12529</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013166">1013166</ref><ref source="" url="http://eprint.iacr.org/2005/033"></ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_07_sr.html">SuSE-SR:2005:007</ref><ref source="OSVDB" url="http://www.osvdb.org/13775">13775</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:057">MDKSA-2005:057</ref></refs><vuln_soft><prod name="OpenPGP" vendor="OpenPGP"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-27" name="CVE-2005-0367" published="2005-02-09" seq="2005-0367" severity="Medium" type="CVE"><desc><descript source="cve">Multiple directory traversal vulnerabilities in ArGoSoft Mail Server 1.8.7.3 allow remote authenticated users to read, delete, or upload arbitrary files via a .. (dot dot) in (1) the filename of an e-mail attachment, (2) the _msgatt.rec file, (3) and the /msg, /delete, /folderadd, and /folderdelete operations for the Folder parameter.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110796956011699&amp;w=2">20050209 [SIG^2 G-TEC] ArGoSoft Mail Server Webmail Multiple Directory Traversal Vulnerabilities</ref><ref adv="1" source="MISC" url="http://www.security.org.sg/vuln/argosoftmail1873.html">http://www.security.org.sg/vuln/argosoftmail1873.html</ref></refs><vuln_soft><prod name="ArGoSoft Mail Server" vendor="ArGoSoft"><vers num="1.8.7.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0368" published="2005-05-02" seq="2005-0368" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in CMScore allow remote attackers to execute arbitrary SQL commands via the (1) EntryID or (2) searchterm parameter to index.php, or (3) username parameter to authenticate.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110803385223054&amp;w=2">20050209 CMS Core SQL injection</ref><ref source="BID" url="http://www.securityfocus.com/bid/12457">12457</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/14142/">14142</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19235">cmscore-multiple-sql-injection(19235)</ref></refs><vuln_soft><prod name="CMScore" vendor="Chipmunk Scripts"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0369" published="2005-05-02" seq="2005-0369" severity="Medium" type="CVE"><desc><descript source="cve">Armagetron 0.2.6.0 and earlier and Armagetron Advanced 0.2.7.0 earlier allows remote attackers to cause a denial of service (application crash) via a packet with a large (1) descriptor ID or (2) claim_id, which exceeds the boundaries of an array.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110811699206052&amp;w=2">20050210 Crashes and socket unreacheable in Armagetron Advanced 0.2.7.0</ref></refs><vuln_soft><prod name="Armagetron Advanced" vendor="Armagetron"><vers num="0.2.7.0" prev="1"/></prod><prod name="Armagetron" vendor="Armagetron"><vers num="0.2.6.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0370" published="2005-05-02" seq="2005-0370" severity="Medium" type="CVE"><desc><descript source="cve">Armagetron 0.2.6.0 and earlier and Armagetron Advanced 0.2.7.0 and earlier allow remote attackers to cause a denial of service (network disconnection) via an empty UDP packet, which is not properly distinguished from the &quot;no new packets&quot; state of the associated socket.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110811699206052&amp;w=2">20050210 Crashes and socket unreacheable in Armagetron Advanced 0.2.7.0</ref></refs><vuln_soft><prod name="Armagetron Advanced" vendor="Armagetron"><vers num="0.2.7.0" prev="1"/></prod><prod name="Armagetron" vendor="Armagetron"><vers num="0.2.6.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0371" published="2005-05-02" seq="2005-0371" severity="Medium" type="CVE"><desc><descript source="cve">Armagetron 0.2.6.0 and earlier and Armagetron Advanced 0.2.7.0 and earlier allow remote attackers to cause a denial of service (freeze) via a large number of player connections that do not send any data.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110811699206052&amp;w=2">20050210 Crashes and socket unreacheable in Armagetron Advanced 0.2.7.0</ref></refs><vuln_soft><prod name="Armagetron Advanced" vendor="Armagetron"><vers num="0.2.7.0"/></prod><prod name="Armagetron" vendor="Armagetron"><vers num="0.2.6.0"/><vers num="0.2.5.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0372" published="2005-05-02" seq="2005-0372" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in gftp before 2.0.18 for GTK+ allows remote malicious FTP servers to read arbitrary files via .. (dot dot) sequences in filenames returned from a LIST command.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-686">DSA-686</ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200502-27.xml">GLSA-200502-27</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000957">CLSA-2005:957</ref><ref source="FEDORA" url="http://www.securityfocus.com/advisories/8379">FEDORA-2005-309</ref><ref source="FEDORA" url="http://www.securityfocus.com/advisories/8380">FEDORA-2005-310</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/12539">12539</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval717.html">OVAL717</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-410.html">RHSA-2005:410</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:717">oval:org.mitre.oval:def:717</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:050">MDKSA-2005:050</ref></refs><vuln_soft><prod name="GTK+" vendor="GTK"><vers num="2.0.18"/><vers num="2.0.9"/><vers num="2.0.8"/><vers num="2.0.7"/><vers num="2.0.6"/><vers num="2.0.5"/><vers num="2.0.4"/><vers num="2.0.3"/><vers num="2.0.2"/><vers num="2.0.1"/><vers num="2.0.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0373" published="2004-10-07" seq="2005-0373" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in digestmd5.c CVS release 1.170 (also referred to as digestmda5.c), as used in the DIGEST-MD5 SASL plugin for Cyrus-SASL but not in any official releases, allows remote attackers to execute arbitrary code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="CONFIRM" url="https://bugzilla.andrew.cmu.edu/cgi-bin/cvsweb.cgi/src/sasl/plugins/digestmd5.c?rev=1.171&amp;content-type=text/x-cvsweb-markup">https://bugzilla.andrew.cmu.edu/cgi-bin/cvsweb.cgi/src/sasl/plugins/digestmd5.c?rev=1.171&amp;content-type=text/x-cvsweb-markup</ref><ref adv="1" source="CONFIRM" url="https://bugzilla.andrew.cmu.edu/cgi-bin/cvsweb.cgi/src/sasl/plugins/digestmd5.c.diff?r1=1.170&amp;r2=1.171">https://bugzilla.andrew.cmu.edu/cgi-bin/cvsweb.cgi/src/sasl/plugins/digestmd5.c.diff?r1=1.170&amp;r2=1.171</ref><ref adv="1" patch="1" source="MLIST" url="http://www.monkey.org/openbsd/archive/ports/0407/msg00265.html">[openbsd-ports] 20040717 UPDATE: cyrus-sasl-2.1.19</ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200410-05.xml">GLSA-200410-05</ref><ref adv="1" patch="1" source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:054">MDKSA-2005:054</ref><ref adv="1" patch="1" source="SUSE" url="http://www.linuxcompatible.org/print42495.html">SUSE-SR:2005:006</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/11347">11347</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17642">cyrus-sasl-digestmda5-bo(17642)</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:054">MDKSA-2005:054</ref></refs><vuln_soft><prod name="SuSE cvsup" vendor="SuSE"><vers num="16.1h_36.i586"/></prod><prod name="SuSE Linux" vendor="SuSE"><vers edition="x86_64" num="9.2"/><vers num="9.2"/><vers edition="x86_64" num="9.1"/><vers num="9.1"/><vers edition="x86_64" num="9.0"/><vers num="9.0"/><vers num="8.2"/><vers num="8.1"/><vers edition="i386" num="8.0"/><vers num="8.0"/></prod><prod name="SuSE Linux Enterprise Server" vendor="SuSE"><vers num="9"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.3.8"/><vers num="10.3.7"/><vers num="10.3.6"/><vers num="10.3.5"/><vers num="10.3.4"/><vers num="10.3.3"/><vers num="10.3.2"/><vers num="10.3.1"/><vers num="10.3"/><vers num="10.2.8"/><vers num="10.2.7"/><vers num="10.2.6"/><vers num="10.2.5"/><vers num="10.2.4"/><vers num="10.2.3"/><vers num="10.2.2"/><vers num="10.2.1"/><vers num="10.2"/><vers num="10.1.5"/><vers num="10.1.4"/><vers num="10.1.3"/><vers num="10.1.2"/><vers num="10.1.1"/><vers num="10.1"/><vers num="10.0.4"/><vers num="10.0.3"/><vers num="10.0.2"/><vers num="10.0.1"/><vers num="10.0"/></prod><prod name="Conectiva Linux" vendor="Conectiva"><vers num="10.0"/><vers num="9.0"/></prod><prod name="OpenPKG" vendor="OpenPKG"><vers num="2.2"/><vers num="2.1"/></prod><prod name="Fedora" vendor="Red Hat"><vers num="Core 1.0"/></prod><prod name="SuSE Linux Desktop" vendor="SuSE"><vers num="1.0"/></prod><prod name="Mac OS X Server" vendor="Apple"><vers num="10.3.8"/><vers num="10.3.7"/><vers num="10.3.6"/><vers num="10.3.5"/><vers num="10.3.4"/><vers num="10.3.3"/><vers num="10.3.2"/><vers num="10.3.1"/><vers num="10.3"/><vers num="10.2.8"/><vers num="10.2.7"/><vers num="10.2.6"/><vers num="10.2.5"/><vers num="10.2.4"/><vers num="10.2.3"/><vers num="10.2.2"/><vers num="10.2.1"/><vers num="10.2"/><vers num="10.1.5"/><vers num="10.1.4"/><vers num="10.1.3"/><vers num="10.1.2"/><vers num="10.1.1"/><vers num="10.1"/><vers num="10.0"/></prod><prod name="SASL" vendor="Cyrus"><vers num="2.1.18 r1"/><vers num="2.1.18"/><vers num="2.1.17"/><vers num="2.1.16"/><vers num="2.1.15"/><vers num="2.1.14"/><vers num="2.1.13"/><vers num="2.1.12"/><vers num="2.1.11"/><vers num="2.1.10"/><vers num="2.1.9"/><vers num="1.5.28"/><vers num="1.5.27"/><vers num="1.5.24"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-06-15" name="CVE-2005-0374" published="2005-05-02" seq="2005-0374" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Bitboard 2.5 and earlier allows remote attackers to inject arbitrary web script or HTML via an [img] bbcode image tag with an event such as mouseover.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110555988111899&amp;w=2">20050112 Security Advisory: BiTBOARD xss</ref><ref source="BID" url="http://www.securityfocus.com/bid/12248">12248</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18871">bitshifters-bitboard-xss(18871)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1012864">1012864</ref></refs><vuln_soft><prod name="BiTBOARD" vendor="BiTSHiFTERS"><vers num="2.5"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-08-24" name="CVE-2005-0375" published="2005-05-02" seq="2005-0375" severity="Medium" type="CVE"><desc><descript source="cve">imageview.php in SGallery 1.01 allows remote attackers to obtain sensitive information via an HTTP request with (1) idalbum and (2) idimage unset, which reveals the installation path in an error message for the sql_fetch_row function.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110557050700947&amp;w=2">20050112 [waraxe-2005-SA#039] - Critical Sql Injection in Sgallery module for PhpNuke</ref><ref adv="1" source="MISC" url="http://www.waraxe.us/advisory-39.html">http://www.waraxe.us/advisory-39.html</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18877">sgallery-path-disclosure(18877)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1012868">1012868</ref></refs><vuln_soft><prod name="SGallery" vendor="Sergey Kiselev"><vers num="1.01"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-28" name="CVE-2005-0376" published="2005-01-12" seq="2005-0376" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in SGallery 1.01 allows local and possibly remote attackers to execute arbitrary PHP code by modifying the DOCUMENT_ROOT parameter to reference a URL on a remote web server that contains (1) config.php or (2) sql_layer.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110557050700947&amp;w=2">20050112 [waraxe-2005-SA#039] - Critical Sql Injection in Sgallery module for PhpNuke</ref><ref adv="1" source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-January/030844.html">20050112 [waraxe-2005-SA#039] - Critical Sql Injection in Sgallery module for PhpNuke</ref><ref adv="1" source="MISC" url="http://www.waraxe.us/advisory-39.html">http://www.waraxe.us/advisory-39.html</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/13824">13824</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18878">sgallery-file-include(18878)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1012868">1012868</ref></refs><vuln_soft><prod name="SGallery" vendor="Sergey Kiselev"><vers num="1.01"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-08-24" name="CVE-2005-0377" published="2005-05-02" seq="2005-0377" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in imageview.php for SGallery 1.01 allows remote attackers to execute arbitrary SQL commands via the (1) idalbum or (2) idimage parameters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110557050700947&amp;w=2">20050112 [waraxe-2005-SA#039] - Critical Sql Injection in Sgallery module for PhpNuke</ref><ref source="MISC" url="http://www.waraxe.us/advisory-39.html">http://www.waraxe.us/advisory-39.html</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/12249">12249</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/13824">13824</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18876">sgallery-imageview-sql-injection(18876)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1012868">1012868</ref></refs><vuln_soft><prod name="SGallery" vendor="Sergey Kiselev"><vers num="1.01"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0378" published="2005-05-02" seq="2005-0378" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Horde 3.0 allow remote attackers to inject arbitrary web script or HTML via the (1) group parameter to prefs.php or (2) url parameter to index.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110564059322774&amp;w=2">20050113 Cross Site Scripting holes found in Horde 3.0</ref><ref source="MISC" url="http://www.hyperdose.com/advisories/H2005-01.txt">http://www.hyperdose.com/advisories/H2005-01.txt</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/12255">12255</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18881">horde-prefs-index-xss(18881)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1012892">1012892</ref></refs><vuln_soft><prod name="Horde" vendor="Horde"><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0379" published="2005-05-02" seq="2005-0379" severity="Medium" type="CVE"><desc><descript source="cve">Multiple directory traversal vulnerabilities in ZeroBoard 4.1pl5 and earlier allow remote attackers to read arbitrary files via a .. (dot dot) in the _zb_path parameter to (1) _head.php or (2) outlogin.php, or the dir parameter to (3) write.php.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110565373407474&amp;w=2">20050113 STG Security Advisory: [SSA-20050113-25] ZeroBoard multiple vulnerabilities</ref><ref adv="1" source="MISC" url="http://securitytracker.com/alerts/2005/Jan/1012884.html">http://securitytracker.com/alerts/2005/Jan/1012884.html</ref><ref source="BID" url="http://www.securityfocus.com/bid/12257">12257</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18891">zeroboard-file-disclosure(18891)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1012884">1012884</ref></refs><vuln_soft><prod name="Zeroboard" vendor="Zeroboard"><vers num="4.1 pl5"/><vers num="4.1 pl4"/><vers num="4.1 pl3"/><vers num="4.1 pl2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-28" name="CVE-2005-0380" published="2005-05-02" seq="2005-0380" severity="High" type="CVE"><desc><descript source="cve">Multiple PHP remote file inclusion vulnerabilities in (1) print_category.php, (2) login.php, (3) setup.php, (4) ask_password.php, or (5) error.php in ZeroBoard 4.1pl5 and earlier allow remote attackers to execute arbitrary PHP code by modifying the dir parameter to reference a URL on a remote web server that contains the code.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110565373407474&amp;w=2">20050113 STG Security Advisory: [SSA-20050113-25] ZeroBoard multiple vulnerabilities</ref><ref adv="1" source="MISC" url="http://securitytracker.com/alerts/2005/Jan/1012884.html">http://securitytracker.com/alerts/2005/Jan/1012884.html</ref><ref source="BID" url="http://www.securityfocus.com/bid/12206">12206</ref><ref source="BID" url="http://www.securityfocus.com/bid/12258">12258</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/13769">13769</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18892">zeroboard-printcategory-file-include(18892)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18893">zeroboard-zero-vote-file-include(18893)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1012884">1012884</ref><ref source="OSVDB" url="http://www.osvdb.org/12928">12928</ref><ref source="OSVDB" url="http://www.osvdb.org/12930">12930</ref><ref source="OSVDB" url="http://www.osvdb.org/12931">12931</ref><ref source="OSVDB" url="http://www.osvdb.org/12932">12932</ref><ref source="OSVDB" url="http://www.osvdb.org/12929">12929</ref></refs><vuln_soft><prod name="Zeroboard" vendor="Zeroboard"><vers num="4.1 pl5"/><vers num="4.1 pl4"/><vers num="4.1 pl3"/><vers num="4.1 pl2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0381" published="2005-01-13" seq="2005-0381" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in f.aspx in forumKIT 1.0 allows remote attackers to inject arbitrary web script or HTML via the members parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110563769413994&amp;w=2">20050113 XSS Vulnerability in ForumKIT</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/12256">12256</ref><ref adv="1" source="MISC" url="http://www.securitytracker.com/alerts/2005/Jan/1012895.html">http://www.securitytracker.com/alerts/2005/Jan/1012895.html</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18880">forumkit-members-xss(18880)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1012895">1012895</ref></refs><vuln_soft><prod name="forumKIT" vendor="forumKIT"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0382" published="2005-05-02" seq="2005-0382" severity="Medium" type="CVE"><desc><descript source="cve">Breed patch 1 and earlier allows remote attackers to cause a denial of service (application crash) via an empty UDP packet, which triggers a null dereference.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110565587010998&amp;w=2">20050113 Server crash in Breed patch #1</ref><ref source="BID" url="http://www.securityfocus.com/bid/12262">12262</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/13211">13211</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18890">breed-udp-datagram-dos(18890)</ref></refs><vuln_soft><prod name="Breed" vendor="Breed"><vers num="Patch 1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0383" published="2005-05-02" seq="2005-0383" severity="High" type="CVE"><desc><descript source="cve">Trend Micro Control Manager 3.0 Enterprise Edition allows remote attackers to gain privileges via a replay attack of the encrypted username and password.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110564369316593&amp;w=2">20050113 Trend Micro Control Manager - Enterprise Edition 3.0 Web application Replay attack</ref><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110565281205427&amp;w=2">20050113 Trend Micro Control Manager - Enterprise Edition 3.0 Web application Replay attack</ref><ref adv="1" patch="1" source="MISC" url="http://www.cirt.dk/advisories/cirt-28-advisory.pdf">http://www.cirt.dk/advisories/cirt-28-advisory.pdf</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18887">control-manager-replay-attack(18887)</ref></refs><vuln_soft><prod name="Control Manager" vendor="Trend Micro"><vers num="3.0 Enterprise"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-05" name="CVE-2005-0384" published="2005-03-15" seq="2005-0384" severity="Medium" type="CVE"><desc><descript source="cve">Unknown vulnerability in the PPP driver for the Linux kernel 2.6.8.1 allows remote attackers to cause a denial of service (kernel crash) via a pppd client.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-283.html">RHSA-2005:283</ref><ref adv="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-284.html">RHSA-2005:284</ref><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111091402626556&amp;w=2">20050315 [USN-95-1] Linux kernel vulnerabilities</ref><ref adv="1" source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_18_kernel.html">SUSE-SA:2005:018</ref><ref adv="1" source="TRUSTIX" url="http://www.trustix.org/errata/2005/0009/">2005-0009</ref><ref source="FEDORA" url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=152532">FLSA:152532</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-95-1">USN-95-1</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-293.html">RHSA-2005:293</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-366.html">RHSA-2005:366</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1070">DSA-1070</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1067">DSA-1067</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1069">DSA-1069</ref><ref source="BID" url="http://www.securityfocus.com/bid/12810">12810</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20163">20163</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20202">20202</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1082">DSA-1082</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20338">20338</ref></refs><vuln_soft><prod name="Secure Linux" vendor="Trustix"><vers num="2.2"/><vers num="2.1"/></prod><prod name="SuSE Linux" vendor="SuSE"><vers num="9.2"/><vers num="9.1"/><vers num="9.0"/><vers num="8.2"/></prod><prod name="Enterprise Linux WS" vendor="Red Hat"><vers edition="Workstation" num="2.1"/></prod><prod name="Enterprise Linux ES" vendor="Red Hat"><vers edition="Enterprise Server" num="2.1"/></prod><prod name="Trustix Enterprise Server" vendor="Trustix"><vers num="2"/></prod><prod name="Enterprise Linux AS" vendor="Red Hat"><vers edition="Advanced Server" num="2.1"/></prod><prod name="Ubuntu Linux" vendor="Ubuntu"><vers num="4.10"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0385" published="2005-05-02" seq="2005-0385" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in luxman before 0.41, if used with certain insecure svgalib libraries, allows local users to execute arbitrary code via a long -f command line argument.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/><env/></vuln_types><range><local/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/393195/2005-03-13/2005-03-19/0">20050314 DMA[2005-0310a] - &apos;Frank McIngvale LuxMan buffer overflow&apos;</ref><ref adv="1" source="MISC" url="http://www.digitalmunition.com/DMA%5B2005-0310a%5D.txt">http://www.digitalmunition.com/DMA[2005-0310a].txt </ref><ref adv="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-693">DSA-693</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/12797">12797</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/14582">14582</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19680">luxman-bo-execute-commands(19680)</ref></refs><vuln_soft><prod name="LuxMan" vendor="Frank McIngvale"><vers num="0.41_17"/><vers num="0.41"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0386" published="2005-05-02" seq="2005-0386" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in network.cgi in mailreader before 2.3.29 earlier allows remote attackers to inject arbitrary web script or HTML via MIME text/enriched or text/richtext messages.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-700">DSA-700</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/14777">14777</ref></refs><vuln_soft><prod name="Mailreader.com" vendor="Mailreader.com"><vers num="2.3.20"/><vers num="2.3.21"/><vers num="2.3.22"/><vers num="2.3.23"/><vers num="2.3.24"/><vers num="2.3.25"/><vers num="2.3.26"/><vers num="2.3.27"/><vers num="2.3.28"/><vers num="2.3.29"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0387" published="2005-05-02" seq="2005-0387" severity="Low" type="CVE"><desc><descript source="cve">remstats 1.0.13 and earlier, when processing uptime data, allows local users to create or overwrite arbitrary files via a symlink attack on temporary files.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-704">DSA-704</ref></refs><vuln_soft><prod name="remstats" vendor="Remstats"><vers num="1.0.13"/><vers num="1.0.9b"/><vers num="1.0.8a"/><vers num="1.00a4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0388" published="2005-05-02" seq="2005-0388" severity="High" type="CVE"><desc><descript source="cve">Unknown vulnerability in the remoteping service in remstats 1.0.13 and earlier allows remote attackers to execute arbitrary commands &quot;due to missing input sanitising.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-704">DSA-704</ref></refs><vuln_soft><prod name="remstats" vendor="remstats"><vers num="1.0.13"/></prod></vuln_soft></entry><entry modified="2005-10-25" name="CVE-2005-0389" published="2005-05-02" reject="1" seq="2005-0389" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2005-0814.  Reason: This candidate is a duplicate of CVE-2005-0814.  Notes: All CVE users should reference CVE-2005-0814 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript></desc><refs/></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0390" published="2005-05-02" seq="2005-0390" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the HTTP redirection capability in conn.c for Axel before 1.0b may allow remote attackers to execute arbitrary code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="CONFIRM" url="http://www.mail-archive.com/debian-devel-changes@lists.debian.org/msg118978.html">http://www.mail-archive.com/debian-devel-changes@lists.debian.org/msg118978.html</ref><ref adv="1" patch="1" source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200504-09.xml">GLSA-200504-09</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/13059">13059</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/14831">14831</ref><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-706">DSA-706</ref></refs><vuln_soft><prod name="Axel" vendor="Axel"><vers num="1.0a"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0391" published="2005-05-02" seq="2005-0391" severity="Medium" type="CVE"><desc><descript source="cve">geneweb 4.10 and earlier does not properly check file permissions and content during conversion, which allows attackers to modify arbitrary files.</descript></desc><loss_types><int/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-712">DSA-712</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20176">geneweb-insecure-file-permission(20176)</ref></refs><vuln_soft><prod name="Geneweb" vendor="Daniel de Rauglaudre"><vers num="4.10" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0392" published="2005-05-19" seq="2005-0392" severity="High" type="CVE"><desc><descript source="cve">ppxp does not drop root privileges before opening log files, which allows local users to execute arbitrary commands.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/><design/></vuln_types><range><local/></range><refs><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-725">DSA-725</ref></refs><vuln_soft><prod name="Debian ppxp" vendor="Debian"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0393" published="2005-07-05" seq="2005-0393" severity="High" type="CVE"><desc><descript source="cve">The helper scripts for crip 3.5 do not properly use temporary files, which allows local users to have an unknown impact with unknown attack vectors.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><local/></range><refs><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-733">DSA-733</ref></refs><vuln_soft><prod name="crip" vendor="crip"><vers num="3.5"/></prod></vuln_soft></entry><entry modified="2005-10-20" name="CVE-2005-0395" published="2005-06-09" reject="1" seq="2005-0395" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: none.  Reason: This candidate has been revoked by its Candidate Numbering Authority (CNA) because it was initially assigned to a problem that was not a security issue.  Notes: none.</descript></desc><refs/></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0396" published="2005-05-02" seq="2005-0396" severity="Low" type="CVE"><desc><descript source="cve">Desktop Communication Protocol (DCOP) daemon, aka dcopserver, in KDE before 3.4 allows local users to cause a denial of service (dcopserver consumption) by &quot;stalling the DCOP authentication process.&quot;</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111099766716483&amp;w=2">20050316 Multiple KDE Security Advisories (2005-03-16)</ref><ref adv="1" patch="1" source="CONFIRM" url="http://www.kde.org/info/security/advisory-20050316-1.txt">http://www.kde.org/info/security/advisory-20050316-1.txt</ref><ref adv="1" patch="1" source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200503-22.xml">GLSA-200503-22</ref><ref adv="1" patch="1" source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:058">MDKSA-2005:058</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-307.html">RHSA-2005:307</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-325.html">RHSA-2005:325</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/427976/100/0/threaded">FLSA:178606</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:058">MDKSA-2005:058</ref><ref source="BID" url="http://www.securityfocus.com/bid/12820">12820</ref></refs><vuln_soft><prod name="Desktop Communication Protocol daemon" vendor="KDE"><vers num="3.3" prev="1"/></prod><prod name="dcopserver" vendor="KDE"><vers num="3.3" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0397" published="2005-05-02" seq="2005-0397" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in the SetImageInfo function in image.c for ImageMagick before 6.0.2.5 may allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via format string specifiers in a filename argument to convert, which may be called by other web applications.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110987256010857&amp;w=2">20050303 [USN-90-1] Imagemagick vulnerability</ref><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-702">DSA-702</ref><ref patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200503-11.xml">GLSA-200503-11</ref><ref patch="1" source="CONFIRM" url="http://bugs.gentoo.org/show_bug.cgi?id=83542">http://bugs.gentoo.org/show_bug.cgi?id=83542</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-320.html">RHSA-2005:320</ref><ref adv="1" patch="1" source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_17_imagemagick.html">SUSE-SA:2005:017</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19586">imagemagick-filename-format-string(19586)</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-070.html">RHSA-2005:070</ref></refs><vuln_soft><prod name="ImageMagick" vendor="ImageMagick"><vers num="5.5"/><vers num="5.4"/><vers num="5.3"/><vers num="5.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0398" published="2005-03-14" seq="2005-0398" severity="Medium" type="CVE"><desc><descript source="cve">The KAME racoon daemon in ipsec-tools before 0.5 allows remote attackers to cause a denial of service (crash) via malformed ISAKMP packets.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="MLIST" url="http://sourceforge.net/mailarchive/forum.php?thread_id=6787713&amp;forum_id=32000">[ipsec-tools-devel] 20050312 potential remote crash in racoon</ref><ref adv="1" patch="1" source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200503-33.xml">GLSA-200503-33</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-232.html">RHSA-2005:232</ref><ref adv="1" patch="1" source="MISC" url="https://bugzilla.redhat.com/bugzilla/attachment.cgi?id=109966&amp;action=view">https://bugzilla.redhat.com/bugzilla/attachment.cgi?id=109966&amp;action=view</ref><ref adv="1" patch="1" source="MISC" url="http://www.k-otik.com/english/advisories/2005/0264">http://www.k-otik.com/english/advisories/2005/0264</ref><ref adv="1" patch="1" source="MISC" url="http://securitytracker.com/id?1013433">http://securitytracker.com/id?1013433</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/12804">12804</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14584">14584</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19707">racoon-isakmp-header-dos(19707)</ref><ref adv="1" patch="1" source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:062">MDKSA-2005:062</ref><ref adv="1" patch="1" source="MISC" url="http://www.frsirt.com/english/advisories/2005/0264">http://www.frsirt.com/english/advisories/2005/0264</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:062">MDKSA-2005:062</ref></refs><vuln_soft><prod name="Racoon" vendor="KAME"><vers num="2005-03-07"/><vers num="2005-02-28"/><vers num="2005-02-21"/><vers num="2005-02-14"/><vers num="2005-02-07"/><vers num="2005-01-31"/><vers num="2005-01-24"/><vers num="2005-01-17"/><vers num="2005-01-10"/><vers num="2005-01-03"/><vers num="2004-05-03"/><vers num="2004-04-07b"/><vers num="2004-04-05"/><vers num="2003-07-11"/></prod><prod name="SuSE Novell Linux" vendor="SuSE"><vers num="Desktop"/></prod><prod name="Enterprise Linux AS" vendor="Red Hat"><vers edition="Advanced Server" num="4.0"/><vers edition="Advanced Servers" num="3.0"/></prod><prod name="SuSE Linux" vendor="SuSE"><vers num="Enterprise Server"/><vers edition="x86_64" num="9.2"/><vers num="9.2"/><vers edition="x86_64" num="9.1"/><vers num="9.1"/></prod><prod name="ALT Linux" vendor="ALTLinux"><vers edition="Junior" num="2.3"/><vers edition="Compact" num="2.3"/></prod><prod name="Enterprise Linux WS" vendor="Red Hat"><vers edition="Workstation" num="4.0"/><vers edition="Workstation" num="3.0"/></prod><prod name="Enterprise Linux ES" vendor="Red Hat"><vers edition="Enterprise Server" num="4.0"/><vers edition="Enterprise Server" num="3.0"/></prod><prod name="Desktop" vendor="Red Hat"><vers num="4.0"/><vers num="3.0"/></prod><prod name="IPsec-Tools" vendor="IPsec-Tools"><vers num="0.5"/><vers num="0.3.3"/></prod><prod name="ProPack" vendor="SGI"><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0399" published="2005-05-02" seq="2005-0399" severity="Medium" type="CVE"><desc><descript source="cve">Heap-based buffer overflow in GIF2.cpp in Firefox before 1.0.2, Mozilla before to 1.7.6, and Thunderbird before 1.0.2, and possibly other applications that use the same library, allows remote attackers to execute arbitrary code via a GIF image with a crafted Netscape extension 2 block and buffer size.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="ISS" url="http://xforce.iss.net/xforce/alerts/id/191">20050323 Mozilla Foundation GIF Overflow</ref><ref adv="1" source="CONFIRM" url="http://www.mozilla.org/security/announce/mfsa2005-30.html">http://www.mozilla.org/security/announce/mfsa2005-30.html</ref><ref adv="1" source="MISC" url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=150877">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=150877</ref><ref adv="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200503-30.xml">GLSA-200503-30</ref><ref adv="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-323.html">RHSA-2005:323</ref><ref adv="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-335.html">RHSA-2005:335</ref><ref adv="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-336.html">RHSA-2005:336</ref><ref adv="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-337.html">RHSA-2005:337</ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/557948">VU#557948</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/p-160.shtml">P-160</ref><ref adv="1" source="MISC" url="http://www.frsirt.com/english/advisories/2005/0296">http://www.frsirt.com/english/advisories/2005/0296</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14654">14654</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19269">gif-extension-overflow(19269)</ref><ref source="BID" url="http://www.securityfocus.com/bid/12881">12881</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval100028.html">OVAL100028</ref><ref source="SCO" url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.49/SCOSA-2005.49.txt">SCOSA-2005.49</ref><ref source="BID" url="http://www.securityfocus.com/bid/15495">15495</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_04_25.html">SUSE-SA:2006:022</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19823">19823</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100028">oval:org.mitre.oval:def:100028</ref></refs><vuln_soft><prod name="Mozilla" vendor="Mozilla"><vers num="1.7.5"/><vers num="1.7.3"/><vers num="1.7.2"/><vers num="1.7.1"/><vers num="1.7 rc3"/><vers num="1.7 rc2"/><vers num="1.7 rc1"/><vers num="1.7 beta"/><vers num="1.7 alpha"/><vers num="1.7"/><vers num="1.6 beta"/><vers num="1.6 alpha"/><vers num="1.6"/><vers num="1.5.1"/><vers num="1.5 rc2"/><vers num="1.5 rc1"/><vers num="1.5 alpha"/><vers num="1.5"/><vers num="1.4a"/><vers num="1.4.1"/><vers num="1.4"/><vers num="1.3"/></prod><prod name="Thunderbird" vendor="Mozilla"><vers num="1.0.1"/><vers num="1.0"/><vers num="0.9"/><vers num="0.8"/><vers num="0.7.3"/><vers num="0.7.2"/><vers num="0.7.1"/><vers num="0.7"/><vers num="0.6"/><vers num="0.5"/><vers num="0.4"/><vers num="0.3"/><vers num="0.2"/><vers num="0.1"/></prod><prod name="Firefox" vendor="Mozilla"><vers num="1.0.1"/><vers num="1.0"/><vers num="0.9.3"/><vers num="0.9.2"/><vers num="0.9.1"/><vers edition="rc" num="0.9"/><vers num="0.9"/><vers num="0.8"/><vers num="0.10.1"/><vers num="0.10"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0400" published="2005-05-02" seq="2005-0400" severity="Low" type="CVE"><desc><descript source="cve">The ext2_make_empty function call in the Linux kernel before 2.6.11.6 does not properly initialize memory when creating a block for a new directory entry, which allows local users to obtain potentially sensitive information by reading the block.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="Arkoon" url="http://arkoon.net/advisories/ext2-make-empty-leak.txt">Information leak in the Linux kernel ext2 implementation</ref><ref patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111238412403118&amp;w=2">20050401 [USN-103-1] Linux kernel vulnerabilities</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19866">kernel-ext2-information-disclosure(19866)</ref><ref source="CONFIRM" url="http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.11.6">http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.11.6</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14713/">14713</ref><ref source="FEDORA" url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=152532">FLSA:152532</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-103-1">USN-103-1</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0190.html">RHSA-2006:0190</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0191.html">RHSA-2006:0191</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18684">18684</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-366.html">RHSA-2005:366</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-663.html">RHSA-2005:663</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17002">17002</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111238764720696&amp;w=2">20050401 Information leak in the Linux kernel ext2 implementation</ref><ref source="BID" url="http://www.securityfocus.com/bid/12932">12932</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/1878">ADV-2005-1878</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.6.11.6" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-25" name="CVE-2005-0401" published="2005-05-02" seq="2005-0401" severity="Medium" type="CVE"><desc><descript source="cve">FireFox 1.0.1 and Mozilla before 1.7.6 do not sufficiently address all attack vectors for loading chrome files and hijacking drag and drop events, which allows remote attackers to execute arbitrary XUL code by tricking a user into dragging a scrollbar, a variant of CVE-2005-0527, aka &quot;Firescrolling 2.&quot;</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111168413007891&amp;w=2">20050324 Firescrolling 2 [Firefox 1.0.1]</ref><ref source="MISC" url="http://mikx.de/firescrolling2/">http://mikx.de/firescrolling2/</ref><ref adv="1" source="CONFIRM" url="http://www.mozilla.org/security/announce/mfsa2005-32.html">http://www.mozilla.org/security/announce/mfsa2005-32.html</ref><ref adv="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200503-30.xml">GLSA-200503-30</ref><ref adv="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-335.html">RHSA-2005:335</ref><ref adv="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-336.html">RHSA-2005:336</ref><ref adv="1" source="MISC" url="http://www.frsirt.com/english/advisories/2005/0296">http://www.frsirt.com/english/advisories/2005/0296</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/14654">14654</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/12885">12885</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval100026.html">OVAL100026</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-384.html">RHSA-2005:384</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100026">oval:org.mitre.oval:def:100026</ref></refs><vuln_soft><prod name="Mozilla" vendor="Mozilla"><vers num="1.7.5"/><vers num="1.7.3"/><vers num="1.7.2"/><vers num="1.7.1"/><vers num="1.7 rc3"/><vers num="1.7 rc2"/><vers num="1.7 rc1"/><vers num="1.7 beta"/><vers num="1.7 alpha"/><vers num="1.7"/><vers num="1.6 beta"/><vers num="1.6 alpha"/><vers num="1.6"/><vers num="1.5.1"/><vers num="1.5 rc2"/><vers num="1.5 rc1"/><vers num="1.5 alpha"/><vers num="1.5"/><vers num="1.4a"/><vers num="1.4.1"/><vers num="1.4"/><vers num="1.3"/></prod><prod name="Firefox" vendor="Mozilla"><vers num="1.0"/><vers num="0.9.3"/><vers num="0.9.2"/><vers num="0.9.1"/><vers edition="rc" num="0.9"/><vers num="0.9"/><vers num="0.8"/><vers num="0.10.1"/><vers num="0.10"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0402" published="2005-05-02" seq="2005-0402" severity="Low" type="CVE"><desc><descript source="cve">Firefox before 1.0.2 allows remote attackers to execute arbitrary code by tricking a user into saving a page as a Firefox sidebar panel, then using the sidebar panel to inject Javascript into a privileged page.</descript></desc><loss_types><int/></loss_types><vuln_types><other/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="CONFIRM" url="http://www.mozilla.org/security/announce/mfsa2005-31.html">http://www.mozilla.org/security/announce/mfsa2005-31.html</ref><ref patch="1" source="MISC" url="https://bugzilla.mozilla.org/show_bug.cgi?id=284627">https://bugzilla.mozilla.org/show_bug.cgi?id=284627</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-336.html">RHSA-2005:336</ref><ref adv="1" source="MISC" url="http://www.frsirt.com/english/advisories/2005/0296">http://www.frsirt.com/english/advisories/2005/0296</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14654">14654</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval100027.html">OVAL100027</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100027">oval:org.mitre.oval:def:100027</ref></refs><vuln_soft><prod name="Firefox" vendor="Mozilla"><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0"/><vers num="0.9.3"/><vers num="0.9.2"/><vers num="0.9.1"/><vers edition="rc" num="0.9"/><vers num="0.9"/><vers num="0.8"/><vers num="0.10.1"/><vers num="0.10"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0403" published="2005-09-01" seq="2005-0403" severity="High" type="CVE"><desc><descript source="cve">init_dev in tty_io.c in the Red Hat backport of NPTL to Red Hat Enterprise Linux 3 does not properly clear controlling tty&apos;s in multi-threaded applications, which allows local users to cause a denial of service (crash) and possibly gain tty access via unknown attack vectors that trigger an access of a pointer to a freed structure.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-293.html">RHSA-2005:293</ref><ref source="" url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=144059"></ref></refs><vuln_soft><prod name="Desktop" vendor="Red Hat"><vers num="3.0"/></prod><prod name="Enterprise Linux WS" vendor="Red Hat"><vers edition="Workstation" num="3.0"/></prod><prod name="Enterprise Linux ES" vendor="Red Hat"><vers edition="Enterprise Server" num="3.0"/></prod><prod name="Enterprise Linux AS" vendor="Red Hat"><vers edition="Advanced Servers" num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0404" published="2005-05-02" seq="2005-0404" severity="Medium" type="CVE"><desc><descript source="cve">KMail 1.7.1 in KDE 3.3.2 allows remote attackers to spoof email information, such as whether the email has been digitally signed or encrypted, via HTML formatted email.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="MLIST" url="http://mail.kde.org/pipermail/kmail-devel/2005-February/015490.html">[kmail-devel] 20050215 [Bug 96020] HTML Allows Spoofing of Emails Content</ref><ref adv="1" patch="1" source="MISC" url="http://bugs.kde.org/show_bug.cgi?id=96020">http://bugs.kde.org/show_bug.cgi?id=96020</ref><ref adv="1" patch="1" source="MISC" url="http://www.securiteam.com/unixfocus/5GP0B0AFFE.html">http://www.securiteam.com/unixfocus/5GP0B0AFFE.html</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/14925">14925</ref></refs><vuln_soft><prod name="KMail" vendor="KMail"><vers num="1.7.1"/></prod><prod name="KDE" vendor="KDE"><vers num="3.3.2"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-05-12" name="CVE-2005-0406" published="2005-02-14" seq="2005-0406" severity="Low" type="CVE"><desc><descript source="cve">A design flaw in image processing software that modifies JPEG images might not modify the original EXIF thumbnail, which could lead to an information leak of potentially sensitive visual information that had been removed from the main JPEG image.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="FULLDISC" url="http://seclists.org/lists/fulldisclosure/2005/Feb/0361.html">20050214 Advisory: JPEG EXIF information disclosure</ref><ref source="FULLDISC" url="http://seclists.org/lists/fulldisclosure/2005/Feb/0343.html">20050214 Advisory: JPEG EXIF information disclosure</ref><ref adv="1" source="" url="http://www.redteam-pentesting.de/advisories/rt-sa-2005-008.txt"></ref></refs><vuln_soft><prod name="Image processing software" vendor="Image processing software"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-05-12" name="CVE-2005-0407" published="2005-05-02" seq="2005-0407" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Openconf 1.04, and possibly other versions before 1.10, allows remote attackers to inject arbitrary HTML and web script via the paper title.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="FULLDISC" url="http://seclists.org/lists/fulldisclosure/2005/Feb/0347.html">20050214 Advisory: Cross Site Scripting Vulnerability in Openconf Conference Management Software</ref><ref adv="1" source="" url="http://www.redteam-pentesting.de/advisories/rt-sa-2005-007.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/12554">12554</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/14294">14294</ref></refs><vuln_soft><prod name="Openconf" vendor="Zakon Group"><vers num="1.04"/><vers num="1.03"/><vers num="1.02"/><vers num="1.01"/><vers num="1.0"/><vers num="1.0 RC2"/><vers num="1.0 RC1"/><vers num="1.0 Beta2"/><vers num="1.0 Beta1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-05-12" name="CVE-2005-0408" published="2005-02-14" seq="2005-0408" severity="High" type="CVE"><desc><descript source="cve">CitrusDB 0.3.6 and earlier generates easily predictable MD5 hashes of the user name for the id_hash cookie, which allows remote attackers to bypass authentication and gain privileges by calculating the MD5 checksum of the user name combined with the &quot;boogaadeeboo&quot; string, which is hard-coded in the $hidden_hash variable.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="FULLDISC" url="http://seclists.org/lists/fulldisclosure/2005/Feb/0370.html">20050214 Advisory: Authentication bypass in CitrusDB</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-February/031707.html">20050214 Advisory: Authentication bypass in CitrusDB</ref><ref adv="1" source="" url="http://www.redteam-pentesting.de/advisories/rt-sa-2005-002.txt"></ref></refs><vuln_soft><prod name="CitrusDB" vendor="CitrusDB"><vers num="0.3.6" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-05-12" name="CVE-2005-0409" published="2005-02-14" seq="2005-0409" severity="Medium" type="CVE"><desc><descript source="cve">CitrusDB 0.3.6 and earlier does not verify authorization for the (1) importcc.php and (2) uploadcc.php, which allows remote attackers to upload credit card data and obtain sensitive information such as the pathnames for temporary files that store credit card data, and facilitates the exploitation of other vulnerabilities.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="FULLDISC" url="http://seclists.org/lists/fulldisclosure/2005/Feb/0369.html">20050214 Advisory: Upload Authorization bypass in CitrusDB</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-February/031707.html">20050214 Advisory: Upload Authorization bypass in CitrusDB</ref><ref adv="1" source="" url="http://www.redteam-pentesting.de/advisories/rt-sa-2005-003.txt"></ref></refs><vuln_soft><prod name="CitrusDB" vendor="CitrusDB"><vers num="0.3.6" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-05-12" name="CVE-2005-0410" published="2005-02-14" seq="2005-0410" severity="Medium" type="CVE"><desc><descript source="cve">SQL injection vulnerability in importcc.php for CitrusDB 0.3.6 and earlier allows remote attackers to inject data via the fields of a CSV file.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="FULLDISC" url="http://seclists.org/lists/fulldisclosure/2005/Feb/0371.html">20050214 Advisory: SQL-Injection in CitrusDB</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-February/031709.html">20050214 Advisory: SQL-Injection in CitrusDB</ref><ref adv="1" source="" url="http://www.redteam-pentesting.de/advisories/rt-sa-2005-004.txt"></ref></refs><vuln_soft><prod name="CitrusDB" vendor="CitrusDB"><vers num="0.3.6" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-05-12" name="CVE-2005-0411" published="2005-02-14" seq="2005-0411" severity="High" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in index.php for CitrusDB 0.3.6 and earlier allows remote attackers and local users to include arbitrary PHP files via .. (dot dot) sequences in the load parameter.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="FULLDISC" url="http://seclists.org/lists/fulldisclosure/2005/Feb/0374.html">20050214 Advisory: Directory traversal in CitrusDB</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-February/031710.html">20050214 Advisory: Directory traversal in CitrusDB</ref><ref adv="1" source="" url="http://www.redteam-pentesting.de/advisories/rt-sa-2005-005.txt"></ref></refs><vuln_soft><prod name="CitrusDB" vendor="CitrusDB"><vers num="0.3.6" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0412" published="2005-04-27" seq="2005-0412" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Spidean PostWrap allows remote attackers to inject arbitrary HTML and web script via the page parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="Neohapsis" url="http://archives.neohapsis.com/archives/fulldisclosure/2005-02/0065.html">XSS VULNERABILITY AT MODULE PostWrap</ref><ref adv="1" source="Security Tracker" url="http://securitytracker.com/id?1013130">PostWrap Lets Remote Users Conduct Cross-Site Scripting Attacks</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/19261">PostWrap cross-site scripting</ref></refs><vuln_soft><prod name="PostWrap" vendor="Spidean"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-03-12" name="CVE-2005-0413" published="2005-04-27" seq="2005-0413" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in MyPHP Forum 1.0 allow remote attackers to execute arbitrary SQL commands via (1) the fid in forum.php, (2) the member parameter in member.php, (3) the email parameter in forgot.php, or (4) the nbuser or nbpass parameters in include.php.  NOTE: it was later reported that vector 2 exists in 3.0 and earlier.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="Seclists.org" url="http://seclists.org/lists/bugtraq/2005/Feb/0125.html">Several SQL injection bugs in myPHP Forum v.1.0</ref><ref adv="1" source="Security Tracker" url="http://securitytracker.com/id?1013136">MyPHP Forum Input Validation Holes Let Remote Users Inject SQL Commands</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19272">myphpforum-multiple-sql-injection(19272)</ref><ref source="BID" url="http://www.securityfocus.com/bid/12501">12501</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/14205">14205</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39348">myphpforum-member-sql-injection(39348)</ref></refs><vuln_soft><prod name="MyPHP Forum" vendor="MyPHP Forum"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0414" published="2005-04-27" seq="2005-0414" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in post.php for MercuryBoard 1.1.1 allows remote attackers to execute arbitrary SQL commands via a reply post action for index.php with (1) the t parameter or (2) the qu parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Tracker" url="http://securitytracker.com/id?1013137">MercuryBoard &apos;func/post.php&apos; Input Validation Error in &apos;qu&apos; Parameter Lets Remote Users Inject SQL Commands</ref><ref adv="1" patch="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110661795632354&amp;w=2">Multiple vulnerabilities in MercuryBoard 1.1.1</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110797495532358&amp;w=2">20050209 Mercuryboard =?iso-8859-1?Q?&lt;=3D?= 1.1.1 Working Sql Injection</ref><ref source="" url="http://cvs.sunsite.dk/viewcvs.cgi/mercury/func/post.php.diff?r1=1.68&amp;r2=1.70"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19051">mercuryboard-index-sql-injection(19051)</ref></refs><vuln_soft><prod name="MercuryBoard" vendor="MercuryBoard"><vers num="1.1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0415" published="2005-04-27" seq="2005-0415" severity="Medium" type="CVE"><desc><descript source="cve">Multiple memory leaks in the MQL parser in Emdros before 1.1.22 allow remote attackers to cause a denial of service (memory consumption) via malformed MQL statements.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="SourceForge.com" url="http://sourceforge.net/project/shownotes.php?release_id=303465"></ref><ref adv="1" source="SourceForge.com" url="http://sourceforge.net/tracker/index.php?func=detail&amp;aid=1116935&amp;group_id=37219&amp;atid=419458">Malformed MQL can lead to DOS attack</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/12498">bid 12498</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19273">emdros-mql-dos(19273)</ref></refs><vuln_soft><prod name="Emdros Database Engine" vendor="Ulrik Petersen"><vers num="1.1.14"/><vers num="1.1.15"/><vers num="1.1.16"/><vers num="1.1.17"/><vers num="1.1.18"/><vers num="1.1.19"/><vers num="1.1.20"/><vers num="1.1.21"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0416" published="2005-04-27" seq="2005-0416" severity="High" type="CVE"><desc><descript source="cve">The Windows Animated Cursor (ANI) capability in Windows NT, Windows 2000 through SP4, Windows XP through SP1, and Windows 2003 allows remote attackers to execute arbitrary code via the AnimationHeaderBlock length field, which leads to a stack-based buffer overflow.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/Security/bulletin/ms05-002.mspx">Vulnerability in Cursor and Icon Format Handling Could Allow Remote Code Execution (891711)</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/12233">bid 12233</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/18879">Microsoft Windows USER32.DLL ANI header overflow</ref><ref source="MISC" url="http://eeye.com/html/research/advisories/AD20050111.html">http://eeye.com/html/research/advisories/AD20050111.html</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110547079218397&amp;w=2">20050111 EEYE: Windows ANI File Parsing Buffer Overflow</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110556975827760&amp;w=2">20050112 Windows ANI File Parsing Proof Of Concept (MS05-002)</ref></refs><vuln_soft><prod name="Windows 98" vendor="Microsoft"><vers num="Gold"/><vers num="SE"/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers edition="64-bit" num="R2"/><vers edition="Datacenter 64-bit" num="R2"/><vers edition="64-bit" num="Enterprise"/><vers num="Enterprise 64-bit"/><vers edition="64-bit" num="Standard"/><vers num="Web"/></prod><prod name="Windows XP" vendor="Microsoft"><vers edition="SP1" num="64-bit"/><vers num="64-bit"/><vers edition="SP1" num="64-bit Version 2003"/><vers num="64-bit Version 2003"/><vers edition="SP1" num="Embedded"/><vers num="Embedded"/><vers edition="SP1" num="Home"/><vers num="Home"/><vers edition="Gold" num="Professional"/><vers edition="Gold" num="Professional"/><vers edition="SP1" num="Media Center"/><vers num="Media Center"/><vers edition="SP2" num="Tablet PC"/><vers edition="SP2" num="Tablet PC"/></prod><prod name="Windows ME" vendor="Microsoft"><vers num=""/></prod><prod name="Windows NT" vendor="Microsoft"><vers num="Enterprise Server 4.0 SP6a"/><vers num="Enterprise Server 4.0 SP6"/><vers num="Enterprise Server 4.0 SP5"/><vers num="Enterprise Server 4.0 SP4"/><vers num="Enterprise Server 4.0 SP3"/><vers num="Enterprise Server 4.0 SP2"/><vers num="Enterprise Server 4.0 SP1"/><vers num="Enterprise Server 4.0"/><vers num="Server 4.0 SP6a"/><vers num="Server 4.0 SP6"/><vers num="Server 4.0 SP5"/><vers num="Server 4.0 SP4"/><vers num="Server 4.0 SP3"/><vers num="Server 4.0 SP2"/><vers num="Server 4.0 SP1"/><vers num="Server 4.0"/><vers num="Terminal Server 4.0 SP6"/><vers num="Terminal Server 4.0 SP5"/><vers num="Terminal Server 4.0 SP4"/><vers num="Terminal Server 4.0 SP3"/><vers num="Terminal Server 4.0 SP2"/><vers num="Terminal Server 4.0 SP1"/><vers num="Terminal Server 4.0"/><vers num="Workstation 4.0 SP6a"/><vers num="Workstation 4.0 SP6"/><vers num="Workstation 4.0 SP5"/><vers num="Workstation 4.0 SP4"/><vers num="Workstation 4.0 SP3"/><vers num="Workstation 4.0 SP2"/><vers num="Workstation 4.0 SP1"/><vers num="Workstation 4.0"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num="Advanced Server SP4"/><vers num="Advanced Server SP3"/><vers num="Advanced Server SP2"/><vers num="Advanced Server SP1"/><vers num="Advanced Server"/><vers num="Professional SP4"/><vers num="Professional SP3"/><vers num="Professional SP2"/><vers num="Professional SP1"/><vers num="Professional"/><vers num="Server SP4"/><vers num="Server SP3"/><vers num="Server SP2"/><vers num="Server SP1"/><vers num="Server"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0417" published="2005-04-27" seq="2005-0417" severity="High" type="CVE"><desc><descript source="cve">Unknown &quot;high risk&quot; vulnerability in DB2 Universal Database 8.1 and earlier has unknown impact and attack vectors.  NOTE: due to the delayed disclosure of details for this issue, this candidate may be SPLIT in the future.  In addition, this may be a duplicate of other issues as reported by the vendor.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110801212422825&amp;w=2">Patch available for high risk IBM DB2 Universal Database flaw</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/12508">bid 12508</ref><ref source="MISC" url="http://www.ngssoftware.com/advisories/db2-09-05-05.htm">http://www.ngssoftware.com/advisories/db2-09-05-05.htm</ref></refs><vuln_soft><prod name="DB2 Universal Database" vendor="IBM"><vers num="6.0"/><vers edition="Windows" num="8.2"/><vers edition="Linux" num="7.0"/><vers edition="Linux" num="7.1"/><vers edition="Linux" num="7.2"/><vers edition="Linux" num="8.0"/><vers edition="AIX" num="8.1"/><vers num="6.0"/><vers edition="Windows" num="8.2"/><vers edition="Linux" num="7.0"/><vers edition="Linux" num="7.1"/><vers edition="Linux" num="7.2"/><vers num="6.0"/><vers edition="Windows" num="8.2"/><vers edition="Linux" num="7.0"/><vers edition="Linux" num="7.1"/><vers edition="Linux" num="7.2"/><vers num="6.0"/><vers edition="Windows" num="8.2"/><vers edition="Linux" num="7.0"/><vers edition="Linux" num="7.1"/><vers edition="Linux" num="7.2"/><vers edition="Linux" num="7.1"/><vers edition="Linux" num="7.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-25" name="CVE-2005-0418" published="2005-05-02" seq="2005-0418" severity="High" type="CVE"><desc><descript source="cve">Argument injection vulnerability in Java Web Start for J2SE 1.4.2 up to 1.4.2_06, on Mac OS X, allows untrusted applications to gain privileges via the value parameter of a property tag in a JNLP file. NOTE: it is highly likely that this item will be MERGED with CVE-2005-0836.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/Mar/msg00001.html">APPLE-SA-2005-03-24</ref></refs><vuln_soft><prod name="J2SE" vendor="Sun"><vers num="1.4.2"/><vers num="1.4.2_01"/><vers num="1.4.2_02"/><vers num="1.4.2_03"/><vers num="1.4.2_04"/><vers num="1.4.2_05"/><vers num="1.4.2_06"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0419" published="2005-04-27" seq="2005-0419" severity="High" type="CVE"><desc><descript source="cve">Multiple heap-based buffer overflows in 3Com 3CServer allow remote authenticated users to execute arbitrary code via long FTP commands, as demonstrated using the STAT command.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110780306326130&amp;w=2">Vulnerability in 3Com 3CServer v1.1</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19250">3cserver-multiple-command-bo(19250)</ref></refs><vuln_soft><prod name="3CServer" vendor="3Com"><vers num="1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2008-01-31" name="CVE-2005-0420" published="2005-04-27" seq="2005-0420" severity="High" type="CVE"><desc><descript source="cve">Microsoft Outlook Web Access (OWA), when used with Exchange, allows remote attackers to redirect users to arbitrary URLs for login via a link to the owalogon.asp application.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Secunia.com" url="http://secunia.com/advisories/14144">Microsoft Outlook Web Access </ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/12459">bid 12459</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/19225">Microsoft Outlook Web Access owalogon.asp script URL redirect</ref><ref source="FULLDISC" url="http://seclists.org/lists/fulldisclosure/2005/Feb/0106.html">20050206 Microsoft Outlook Web Access URL Injection Vulnerability</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/0105">ADV-2005-0105</ref></refs><vuln_soft><prod name="exchange srv" vendor="Microsoft"><vers num="2003 SP1"/><vers num="2003"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-05" name="CVE-2005-0421" published="2005-04-27" seq="2005-0421" severity="Low" type="CVE"><desc><descript source="cve">DelphiTurk FTP 1.0 stores usernames and passwords in the profile.dat file, which allows local users to gain privileges.</descript></desc><loss_types><conf/></loss_types><range><local/></range><refs><ref adv="1" source="SecurityTracker" url="http://securitytracker.com/id?1013139">DelphiTurk FTP Discloses Passwords to Local Users</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19248">delphiturkcodebank-obtain-information(19248)</ref></refs><vuln_soft><prod name="DelphiTurk FTP" vendor="DelphiTurk"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0422" published="2005-04-27" seq="2005-0422" severity="Low" type="CVE"><desc><descript source="cve">DelphiTurk CodeBank (aka KodBank) 3.1 and earlier stores usernames and passwords in the Codebank registry key, which allows local users to gain privileges.</descript></desc><loss_types><conf/></loss_types><range><local/></range><refs><ref adv="1" source="SecurityTracker" url="http://securitytracker.com/id?1013139">DelphiTurk FTP Discloses Passwords to Local Users</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/19248">DelphiturkCodeBank obtain information</ref></refs><vuln_soft><prod name="CodeBank" vendor="DelphiTurk"><vers num="3.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0423" published="2005-04-27" seq="2005-0423" severity="Medium" type="CVE"><desc><descript source="cve">SQL injection vulnerability in login.asp in ASPjar Guestbook allows remote attackers to execute arbitrary SQL commands via the password field.</descript></desc><loss_types><conf/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/12521">bid 12521</ref><ref adv="1" source="Secunia.com" url="http://secunia.com/advisories/14225/">AspJar Guestbook Two Vulnerabilities AspJar Guestbook Two Vulnerabilities</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/19299">ASPjar Guestbook login.asp SQL injection</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110809687921701&amp;w=2">20050210 ASPjar guestbook (Injection in login page)</ref></refs><vuln_soft><prod name="ASPJar Guestbook" vendor="ASPJar"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-25" name="CVE-2005-0424" published="2005-04-27" seq="2005-0424" severity="Medium" type="CVE"><desc><descript source="cve">Unknown vulnerability in the delete.asp program in certain versions of ASPjar Guestbook allows remote attackers to delete messages.  NOTE: there is insufficient information to know if this is the same issue as CVE-2002-1730.</descript></desc><loss_types><int/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/12521">bid 12521</ref><ref adv="1" source="Secunia.com" url="http://secunia.com/advisories/14225/"> AspJar Guestbook Two Vulnerabilities</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/19301">ASPjar Guestbook delete.asp message deletion</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110809687921701&amp;w=2">20050210 ASPjar guestbook (Injection in login page)</ref></refs><vuln_soft><prod name="ASPJar Guestbook" vendor="ASPJar"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0425" published="2005-05-02" seq="2005-0425" severity="Medium" type="CVE"><desc><descript source="cve">Unknown vulnerability in IBM Websphere Application Server 5.0, 5.1, and 6.0 when running on Windows, allows remote attackers to obtain the source code for Java Server Pages (.jsp) via a crafted URL that causes the page to be processed by the file serving servlet instead of the JSP engine.</descript></desc><loss_types><conf/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="IBM.com" url="http://www-1.ibm.com/support/docview.wss?uid=swg24008814">Possible JSP source code exposure</ref><ref adv="1" patch="1" source="IBM.com" url="http://www-1.ibm.com/support/docview.wss?uid=swg24008815">Possible JSP source code exposure</ref><ref adv="1" patch="1" source="Secunia.com" url="http://secunia.com/advisories/14274">IBM WebSphere Application Server JSP Source Code Disclosure</ref></refs><vuln_soft><prod name="Websphere Application Server" vendor="IBM"><vers num="5.0"/><vers num="5.1"/><vers num="6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0426" published="2005-05-02" seq="2005-0426" severity="Medium" type="CVE"><desc><descript source="cve">Unknown vulnerability in Solaris 8 and 9 allows remote attackers to cause a denial of service (panic) via &quot;Heavy UDP Usage&quot; that triggers a NULL dereference.</descript></desc><loss_types><avail/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref adv="1" source="Sunsolve.com" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57728-1">Heavy UDP Usage May Cause a System to Panic</ref><ref source="BID" url="http://www.securityfocus.com/bid/12385">12385</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19119">solaris-udp-end-point-dos(19119)</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers num="8.0"/><vers edition="SPARC" num="9.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-06-15" name="CVE-2005-0427" published="2005-05-02" seq="2005-0427" severity="Medium" type="CVE"><desc><descript source="cve">The ebuild of Webmin before 1.170-r3 on Gentoo Linux includes the encrypted root password in the miniserv.users file when building a tbz2 of the webmin package, which allows remote attackers to obtain and possibly crack the encrypted password.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Gentoo.org" url="http://www.gentoo.org/security/en/glsa/glsa-200502-12.xml">Webmin: Information leak in Gentoo binary package</ref><ref adv="1" source="Gentoo.org" url="http://bugs.gentoo.org/show_bug.cgi?id=77731">app-admin/webmin binary package contains sensitive info</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19315">webmin-encrypted-password(19315)</ref></refs><vuln_soft><prod name="webmin" vendor="Gentoo"><vers num="1.140.ebuild"/><vers num="1.150.ebuild"/><vers num="1.160.ebuild"/><vers num="1.170 r1.ebuild"/><vers num="1.170 r2.ebuild"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0428" published="2005-05-02" seq="2005-0428" severity="Medium" type="CVE"><desc><descript source="cve">The DNSPacket::expand method in dnspacket.cc in PowerDNS before 2.9.17 allows remote attackers to cause a denial of service by sending a random stream of bytes.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Gentoo.org" url="http://www.gentoo.org/security/en/glsa/glsa-200502-15.xml">PowerDNS: Denial of Service vulnerability</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/12446">bid 12446</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/19221">PowerDNS random bytes denial of service</ref><ref source="CONFIRM" url="http://doc.powerdns.com/changelog.html#CHANGELOG-2-9-17">http://doc.powerdns.com/changelog.html#CHANGELOG-2-9-17</ref><ref source="MISC" url="http://ds9a.nl/cgi-bin/cvstrac/pdns/tktview?tn=21">http://ds9a.nl/cgi-bin/cvstrac/pdns/tktview?tn=21</ref></refs><vuln_soft><prod name="PowerDNS" vendor="PowerDNS"><vers num="2.0 RC1"/><vers num="2.8"/><vers num="2.9.15"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0429" published="2005-05-02" seq="2005-0429" severity="Medium" type="CVE"><desc><descript source="cve">Direct code injection vulnerability in forumdisplay.php in vBulletin 3.0 through 3.0.4, when showforumusers is enabled, allows remote attackers to execute inject arbitrary PHP commands via the comma parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110840807415315&amp;w=2">20050213 vbulletin 3.0.x PHP code execution</ref><ref source="BID" url="http://www.securityfocus.com/bid/12542">12542</ref></refs><vuln_soft><prod name="vBulletin" vendor="Jelsoft"><vers num="3.0"/><vers num="3.0.1"/><vers num="3.0.2"/><vers num="3.0.3"/><vers num="3.0.4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0430" published="2005-02-12" seq="2005-0430" severity="Medium" type="CVE"><desc><descript source="cve">The Quake 3 engine, as used in multiple game packages, allows remote attackers to cause a denial of service (shutdown game server) and possibly crash the server via a long infostring, possibly triggering a buffer overflow.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Luigi Auriemma" url="http://aluigi.altervista.org/adv/q3infoboom-adv.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/12534">12534</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110824822224025&amp;w=2">20050212 Infostring crash and shutdown in the Quake 3 engine</ref></refs><vuln_soft><prod name="Quake 3 engine" vendor="id software"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-08-23" name="CVE-2005-0431" published="2005-05-02" seq="2005-0431" severity="High" type="CVE"><desc><descript source="cve">Barracuda Spam Firewall 3.1.10 and earlier does not restrict the domains that white-listed domains can send mail to, which allows members of white-listed domains to use Barracuda as an open mail relay for spam.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110805534732492&amp;w=2">20050210 Barracuda Spam Firewall &lt;= 3.1.10 acts as open relay for whitelisted senders.</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/14243">14243</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19283">barracuda-open-relay(19283)</ref></refs><vuln_soft><prod name="Barracuda Spam Firewall" vendor="Barracuda Networks"><vers num="3.1.10"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0432" published="2005-05-02" seq="2005-0432" severity="Medium" type="CVE"><desc><descript source="cve">BEA WebLogic Server 7.0 Service Pack 5 and earlier, and 8.1 Service Pack 3 and earlier, generates different login exceptions that suggest why an authentication attempt fails, which makes it easier for remote attackers to guess passwords via brute force attacks.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CONFIRM" url="http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/BEA05-74.00.jsp">http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/BEA05-74.00.jsp</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14298">14298</ref></refs><vuln_soft><prod name="WebLogic Server" vendor="BEA Systems"><vers num="7.0 SP5"/><vers num="8.1 SP3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0433" published="2005-02-15" seq="2005-0433" severity="Medium" type="CVE"><desc><descript source="cve">Php-Nuke 7.5 allows remote attackers to determine the full path of the web server via invalid or missing arguments to (1) db.php, (2) mainfile.php, (3) Downloads/index.php, or (4) Web_Links/index.php, which lists the path in a PHP error message.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://www.waraxe.us/advisory-40.html">http://www.waraxe.us/advisory-40.html</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/12561">12561</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19344">phpnuke-multiple-scripts-path-disclosure(19344)</ref></refs><vuln_soft><prod name="PHP-Nuke" vendor="Francisco Burzi"><vers num="7.6"/><vers num="7.3"/><vers num="7.2"/><vers num="7.1"/><vers num="7.0 FINAL"/><vers num="7.0"/><vers num="6.9"/><vers num="6.7"/><vers num="6.6"/><vers num="6.5 RC3"/><vers num="6.5 RC2"/><vers num="6.5 RC1"/><vers num="6.5 FINAL"/><vers num="6.5 Beta1"/><vers num="6.5"/><vers num="6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0434" published="2005-02-15" seq="2005-0434" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Php-Nuke 7.5 allow remote attackers to inject arbitrary HTML or web script via (1) the newdownloadshowdays parameter in a NewDownloads operation or (2) the newlinkshowdays parameter in a NewLinks operation.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://www.waraxe.us/advisory-40.html">http://www.waraxe.us/advisory-40.html</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/12561">12561</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19346">phpnuke-downloads-weblinks-xss(19346)</ref></refs><vuln_soft><prod name="PHP-Nuke" vendor="Francisco Burzi"><vers num="7.6"/><vers num="7.3"/><vers num="7.2"/><vers num="7.1"/><vers num="7.0 FINAL"/><vers num="7.0"/><vers num="6.9"/><vers num="6.7"/><vers num="6.6"/><vers num="6.5 RC3"/><vers num="6.5 RC2"/><vers num="6.5 RC1"/><vers num="6.5 FINAL"/><vers num="6.5 Beta1"/><vers num="6.5"/><vers num="6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0435" published="2005-05-02" seq="2005-0435" severity="Medium" type="CVE"><desc><descript source="cve">awstats.pl in AWStats 6.3 and 6.4 allows remote attackers to read server web logs by setting the loadplugin and pluginmode parameters to rawlog.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/390368">20050214 AWStats &lt;= 6.4 Multiple vulnerabilities</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14299">14299</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19333">awstats-awstatpl-obtain-information(19333)</ref></refs><vuln_soft><prod name="AWStats" vendor="AWStats"><vers num="6.3"/><vers num="6.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0436" published="2005-05-02" seq="2005-0436" severity="High" type="CVE"><desc><descript source="cve">Direct code injection vulnerability in awstats.pl in AWStats 6.3 and 6.4 allows remote attackers to execute portions of Perl code via the PluginMode parameter.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/390368">20050214 AWStats &lt;= 6.4 Multiple vulnerabilities</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14299">14299</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19336">awstats-function-code-execution(19336)</ref><ref source="OSVDB" url="http://www.osvdb.org/13832">13832</ref></refs><vuln_soft><prod name="AWStats" vendor="AWStats"><vers num="6.3"/><vers num="6.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0437" published="2005-05-02" seq="2005-0437" severity="High" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in awstats.pl in AWStats 6.3 and 6.4 allows remote attackers to include arbitrary Perl modules via .. (dot dot) sequences in the loadplugin parameter.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/390368">20050214 AWStats &lt;= 6.4 Multiple vulnerabilities</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14299">14299</ref></refs><vuln_soft><prod name="AWStats" vendor="AWStats"><vers num="6.3"/><vers num="6.4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0438" published="2005-05-02" seq="2005-0438" severity="Medium" type="CVE"><desc><descript source="cve">awstats.pl in AWStats 6.3 and 6.4 allows remote attackers to obtain sensitive information by setting the debug parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/390368">20050214 AWStats &lt;= 6.4 Multiple vulnerabilities</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14299">14299</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19477">awstats-information-disclosure(19477)</ref></refs><vuln_soft><prod name="AWStats" vendor="AWStats"><vers num="6.3"/><vers num="6.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-02-14" name="CVE-2005-0439" published="2005-05-02" seq="2005-0439" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the decode_post function in ELOG before 2.5.7 allows remote attackers to execute arbitrary code via attachments with long file names.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref patch="1" source="CONFIRM" url="http://sourceforge.net/project/shownotes.php?group_id=40505&amp;release_id=304880">http://sourceforge.net/project/shownotes.php?group_id=40505&amp;release_id=304880</ref><ref adv="1" patch="1" source="CONFIRM" url="http://midas.psi.ch/elogs/Forum/941">http://midas.psi.ch/elogs/Forum/941</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/12556">12556</ref><ref source="CONFIRM" url="http://sourceforge.net/project/shownotes.php?group_id=40505&amp;release_id=304880">http://sourceforge.net/project/shownotes.php?group_id=40505&amp;release_id=304880</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19313">elog-weblog-bo(19313)</ref></refs><vuln_soft><prod name="Elog Web Logbook" vendor="Stefan Ritt"><vers num="2.5.6"/><vers num="2.5"/><vers num="2.4"/><vers num="2.2.4"/><vers num="2.2.3"/><vers num="2.2.2"/><vers num="2.2.1"/><vers num="2.2.0"/><vers num="2.1.3"/><vers num="2.1.2"/><vers num="2.1.1"/><vers num="2.1.0"/><vers num="2.0.5"/><vers num="2.0.4"/><vers num="2.0.3"/><vers num="2.0.2"/><vers num="2.0.1"/><vers num="2.0.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-02-14" name="CVE-2005-0440" published="2005-05-02" seq="2005-0440" severity="High" type="CVE"><desc><descript source="cve">ELOG before 2.5.7 allows remote attackers to bypass authentication and download a configuration file that contains a sensitive write password via a modified URL.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/><design/></vuln_types><range><network/></range><refs><ref patch="1" source="CONFIRM" url="http://sourceforge.net/project/shownotes.php?group_id=40505&amp;release_id=304880">http://sourceforge.net/project/shownotes.php?group_id=40505&amp;release_id=304880</ref><ref adv="1" source="CONFIRM" url="http://midas.psi.ch/elogs/Forum/941">http://midas.psi.ch/elogs/Forum/941</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/12556">12556</ref><ref source="CONFIRM" url="http://sourceforge.net/project/shownotes.php?group_id=40505&amp;release_id=304880">http://sourceforge.net/project/shownotes.php?group_id=40505&amp;release_id=304880</ref></refs><vuln_soft><prod name="Elog Web Logbook" vendor="Stefan Ritt"><vers num="2.5.6"/><vers num="2.5"/><vers num="2.4"/><vers num="2.2.4"/><vers num="2.2.3"/><vers num="2.2.2"/><vers num="2.2.1"/><vers num="2.2.0"/><vers num="2.1.3"/><vers num="2.1.2"/><vers num="2.1.1"/><vers num="2.1.0"/><vers num="2.0.5"/><vers num="2.0.4"/><vers num="2.0.3"/><vers num="2.0.2"/><vers num="2.0.1"/><vers num="2.0.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0441" published="2004-12-22" seq="2005-0441" severity="High" type="CVE"><desc><descript source="cve">Multiple stack-based buffer overflows in Sybase Adaptive Server Enterprise (ASE) 12.x before 12.5.3 ESD#1 allow remote authenticated users to execute arbitrary code via the (1) attrib_valid function, (2) covert function, (3) declare statement, or (4) a crafted query plan, or remote authenticated users with database owner or &quot;sa&quot; role privileges to execute arbitrary code via (5) a crafted install java statement.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2004-12/0315.html">20041222 Sybase ASE 12.5.2 vulnerabilities</ref><ref adv="1" patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/393851">20050321 Details of Sybase ASE bugs withheld</ref><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111272918117194&amp;w=2">20050405 Sybase ASE Multiple Security Issues (#NISR05042005)</ref><ref adv="1" source="MISC" url="http://www.ngssoftware.com/advisories/sybase-ase.txt">http://www.ngssoftware.com/advisories/sybase-ase.txt</ref><ref adv="1" patch="1" source="CONFIRM" url="http://www.sybase.com/detail?id=1034520">http://www.sybase.com/detail?id=1034520</ref><ref adv="1" patch="1" source="CONFIRM" url="http://www.sybase.com/detail?id=1034752">http://www.sybase.com/detail?id=1034752</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/12080">12080</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/13632">13632</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19354">sybase-adaptive-server(19354)</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19974">sybase-ase-attribvalid-bo(19974)</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19976">sybase-ase-convert-bo(19976)</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19978">sybase-ase-declare-bo(19978)</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19979">sybase-ase-abstract-bo(19979)</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19980">sybase-ase-install-java-bo(19980)</ref></refs><vuln_soft><prod name="Adaptive Server Enterprise" vendor="Sybase"><vers num="12.5.3"/><vers num="12.5.2"/><vers edition="Win" num="12.5"/><vers edition="Sun" num="12.5"/><vers edition="SGI" num="12.5"/><vers edition="Linux" num="12.5"/><vers edition="HP" num="12.5"/><vers edition="Digital Unix" num="12.5"/><vers edition="Win" num="12.0.1"/><vers edition="Sun" num="12.0.1"/><vers edition="HP" num="12.0.1"/><vers edition="Digital Unix" num="12.0.1"/><vers edition="Win" num="12.0"/><vers edition="Sun" num="12.0"/><vers edition="HP" num="12.0"/><vers edition="Digital Unix" num="12.0"/><vers edition="Win" num="11.9.2"/><vers edition="Sun" num="11.9.2"/><vers edition="HP" num="11.9.2"/><vers edition="Digital Unix" num="11.9.2"/><vers edition="Win" num="11.5.1"/><vers edition="Sun" num="11.5.1"/><vers edition="HP" num="11.5.1"/><vers edition="Digital Unix" num="11.5.1"/><vers edition="Win" num="11.5"/><vers edition="Sun" num="11.5"/><vers edition="HP" num="11.5"/><vers edition="Digital Unix" num="11.5"/><vers edition="Linux" num="11.03.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0442" published="2005-05-02" seq="2005-0442" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in index.php for CubeCart 2.0.4 allows remote attackers to read arbitrary files via the language parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110842125901191&amp;w=2">20050214 [NOBYTES.COM: #2] CubeCart 2.0.4 - Multiple Vulnerabilities</ref><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111281888605580&amp;w=2">20050406 RE: [NOBYTES.COM: #6] CubeCart 2.0.6 - Information Disclosure</ref><ref adv="1" patch="1" source="CONFIRM" url="http://www.cubecart.com/site/forums/index.php?showtopic=5741">http://www.cubecart.com/site/forums/index.php?showtopic=5741</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/12549">12549</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14272">14272</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19322">cubecart-dotdot-directory-traversal(19322)</ref></refs><vuln_soft><prod name="CubeCart" vendor="Devellion"><vers num="2.0.4"/><vers num="2.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0443" published="2005-05-02" seq="2005-0443" severity="Medium" type="CVE"><desc><descript source="cve">index.php in CubeCart 2.0.4 allows remote attackers to (1) obtain the full path for the web server or (2) conduct cross-site scripting (XSS) attacks via an invalid language parameter, which echoes the parameter in a PHP error message.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110842125901191&amp;w=2">20050214 [NOBYTES.COM: #2] CubeCart 2.0.4 - Multiple Vulnerabilities</ref><ref adv="1" patch="1" source="CONFIRM" url="http://www.cubecart.com/site/forums/index.php?showtopic=5741">http://www.cubecart.com/site/forums/index.php?showtopic=5741</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/12549">12549</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19328">cubecart-index-xss(19328)</ref><ref source="OSVDB" url="http://www.osvdb.org/14064">14064</ref></refs><vuln_soft><prod name="CubeCart" vendor="Devellion"><vers num="2.0.4"/><vers num="2.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0444" published="2005-02-14" seq="2005-0444" severity="Medium" type="CVE"><desc><descript source="cve">VMware before 4.5.2.8848-r5 searches for gdk-pixbuf shared libraries using a path that includes the rrdharan world-writable temporary directory, which allows local users to execute arbitrary code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><design/><config/></vuln_types><range><local/></range><refs><ref adv="1" source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200502-18.xml">GLSA-200502-18</ref></refs><vuln_soft><prod name="VMWare Workstation" vendor="VMWare"><vers num="4.5.2.8848 r4" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0445" published="2005-05-02" seq="2005-0445" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Open WebMail 2.x allows remote attackers to inject arbitrary HTML or web script via the domain name parameter (logindomain) in the login page.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14253">14253</ref><ref source="CONFIRM" url="http://turtle.ee.ncku.edu.tw/openwebmail/doc/changes.txt">http://turtle.ee.ncku.edu.tw/openwebmail/doc/changes.txt</ref><ref source="CONFIRM" url="http://turtle.ee.ncku.edu.tw/openwebmail/download/cert/patches/SA-05:01/2.5x.patch">http://turtle.ee.ncku.edu.tw/openwebmail/download/cert/patches/SA-05:01/2.5x.patch</ref><ref patch="1" source="openwebmail" url="http://openwebmail.org/openwebmail/download/current/">Index of /openwebmail/download/current</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19335">open-webmail-logindomain-xss(19335)</ref><ref source="BID" url="http://www.securityfocus.com/bid/12547">12547</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013172">1013172</ref></refs><vuln_soft><prod name="Open WebMail" vendor="Open WebMail"><vers num="2.50"/><vers num="2.41"/><vers num="2.40"/><vers num="2.32"/><vers num="2.30"/><vers num="2.21"/><vers num="2.20"/><vers num="2.10"/><vers num="2.01"/><vers num="2.00"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0446" published="2005-05-02" seq="2005-0446" severity="Medium" type="CVE"><desc><descript source="cve">Squid 2.5.STABLE8 and earlier allows remote attackers to cause a denial of service (crash) via certain DNS responses regarding (1) Fully Qualified Domain Names (FQDN) in fqdncache.c or (2) IP addresses in ipcache.c, which trigger an assertion failure.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="CONFIRM" url="http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE8-dns_assert">http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE8-dns_assert</ref><ref patch="1" source="CONFIRM" url="http://www.squid-cache.org/Versions/v2/2.5/bugs/squid-2.5.STABLE8-dns_assert.patch">http://www.squid-cache.org/Versions/v2/2.5/bugs/squid-2.5.STABLE8-dns_assert.patch</ref><ref adv="1" patch="1" source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000931">CLA-2005:931</ref><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-688">DSA-688</ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200502-25.xml">GLSA-200502-25</ref><ref adv="1" patch="1" source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:047">MDKSA-2005:047</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-173.html">RHSA-2005:173</ref><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110901183320453&amp;w=2">20050221 [USN-84-1] Squid vulnerabilities</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14271">14271</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19332">squid-xstrndup-dos(19332)</ref><ref source="FEDORA" url="http://fedoranews.org/updates/FEDORA--.shtml">FLSA-2006:152809</ref><ref source="BID" url="http://www.securityfocus.com/bid/12551">12551</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-201.html">RHSA-2005:201</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:047">MDKSA-2005:047</ref></refs><vuln_soft><prod name="Squid" vendor="Squid"><vers num="2.5.STABLE8"/><vers num="2.5.STABLE7"/><vers num="2.5.STABLE6"/><vers num="2.5.STABLE5"/><vers num="2.5.STABLE4"/><vers num="2.5.STABLE3"/><vers num="2.5.STABLE2"/><vers num="2.5.STABLE1"/><vers num="2.5.6"/><vers num="2.5 Stable9"/><vers num="2.5 STABLE4"/><vers num="2.5 STABLE3"/><vers num="2.5 .STABLE6"/><vers num="2.5 .STABLE5"/><vers num="2.5 .STABLE4"/><vers num="2.5 .STABLE3"/><vers num="2.5 .STABLE1"/><vers num="2.4.STABLE7"/><vers num="2.4.STABLE6"/><vers num="2.4.STABLE4"/><vers num="2.4.STABLE3"/><vers num="2.4.STABLE2"/><vers num="2.4.STABLE1"/><vers num="2.4 STABLE7"/><vers num="2.4 .STABLE7"/><vers num="2.4 .STABLE6"/><vers num="2.4 .STABLE2"/><vers num="2.4"/><vers num="2.3.STABLE5"/><vers num="2.3.STABLE4"/><vers num="2.3.STABLE3"/><vers num="2.3.STABLE2"/><vers num="2.3.STABLE1"/><vers num="2.3.DEVEL3"/><vers num="2.3.DEVEL2"/><vers num="2.3 STABLE5"/><vers num="2.3 .STABLE5"/><vers num="2.3 .STABLE4"/><vers num="2.2.STABLE5"/><vers num="2.2.STABLE4"/><vers num="2.2.STABLE3"/><vers num="2.2.STABLE2"/><vers num="2.2.STABLE1"/><vers num="2.2.PRE2"/><vers num="2.2.PRE1"/><vers num="2.2.DEVEL4"/><vers num="2.2.DEVEL3"/><vers num="2.1.RELEASE"/><vers num="2.1.PRE4"/><vers num="2.1.PRE3"/><vers num="2.1.PRE1"/><vers num="2.1.PATCH2"/><vers num="2.1.PATCH1"/><vers num="2.1 PATCH2"/><vers num="2.0.RELEASE"/><vers num="2.0.PRE1"/><vers num="2.0.PATCH2"/><vers num="2.0.PATCH1"/><vers num="2.0 PATCH2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0447" published="2005-02-15" seq="2005-0447" severity="Medium" type="CVE"><desc><descript source="cve">Solaris 7, 8, and 9 allows remote attackers to cause a denial of service (hang) via a flood of certain ARP packets.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57673-1">57673</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14286">14286</ref><ref source="BID" url="http://www.securityfocus.com/bid/12553">12553</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19331">solaris-arp-dos(19331)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013179">1013179</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers edition="SPARC" num="9.0"/><vers num="8.0"/><vers num="7.0"/></prod></vuln_soft></entry><entry CVSS_base_score="1.2" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="2.9" CVSS_score="1.2" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-25" name="CVE-2005-0448" published="2005-05-02" seq="2005-0448" severity="Low" type="CVE"><desc><descript source="cve">Race condition in the rmtree function in File::Path.pm in Perl before 5.8.4 allows local users to create arbitrary setuid binaries in the tree being deleted, a different vulnerability than CVE-2004-0452.</descript></desc><loss_types><int/></loss_types><vuln_types><race/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111039131424834&amp;w=2">20050309 [USN-94-1] Perl vulnerability</ref><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-696">DSA-696</ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200501-38.xml">GLSA-200501-38</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-881.html">RHSA-2005:881</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-94-1">USN-94-1</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18075">18075</ref><ref source="HP" url="http://www.securityfocus.com/advisories/8704">HPSBUX01208</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2005:079">MDKSA-2005:079</ref><ref source="BID" url="http://www.securityfocus.com/bid/12767">12767</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20060101-01-U">20060101-01-U</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14531">14531</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18517">18517</ref><ref source="FEDORA" url="http://fedoranews.org/updates/FEDORA--.shtml">FLSA-2006:152845</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-674.html">RHSA-2005:674</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17079">17079</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=001056">CLSA-2006:1056</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:728">oval:org.mitre.oval:def:728</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:079">MDKSA-2005:079</ref></refs><vuln_soft><prod name="Perl" vendor="Larry Wall"><vers num="5.8.4"/><vers num="5.8.3"/><vers num="5.8.1"/><vers num="5.8.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.1" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.9" CVSS_score="7.1" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2008-06-24" name="CVE-2005-0449" published="2005-05-02" seq="2005-0449" severity="High" type="CVE"><desc><descript source="cve">The netfilter/iptables module in Linux before 2.6.8.1 allows remote attackers to cause a denial of service (kernel crash) or bypass firewall rules via crafted packets, which are not properly handled by the skb_checksum_help function.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="MLIST" url="http://oss.sgi.com/archives/netdev/2005-01/msg01036.html">[netdev] 20050124 Re: skb_checksum_help</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-283.html">RHSA-2005:283</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-284.html">RHSA-2005:284</ref><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=110846102231365&amp;w=2">20050215 [USN-82-1] Linux kernel vulnerabilities</ref><ref patch="1" source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000945">CLA-2005:945</ref><ref adv="1" patch="1" source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_18_kernel.html">SUSE-SA:2005:018</ref><ref source="FEDORA" url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=152532">FLSA:152532</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-82-1">USN-82-1</ref><ref source="MANDRAKE" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2005:218">MDKSA-2005:218</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-293.html">RHSA-2005:293</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-366.html">RHSA-2005:366</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1017">DSA-1017</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1018">DSA-1018</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19374">19374</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19369">19369</ref><ref source="BID" url="http://www.securityfocus.com/bid/12598">12598</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20060402-01-U">20060402-01-U</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19607">19607</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:218">MDKSA-2005:218</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.6.8"/><vers num="2.6.7"/><vers num="2.6.6"/><vers num="2.6.5"/><vers num="2.6.4"/><vers num="2.6.3"/><vers num="2.6.2"/><vers num="2.6.1"/><vers num="2.6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0450" published="2005-05-02" seq="2005-0450" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in Sami HTTP Server 1.0.5 allows remote attackers to read arbitrary files via an HTTP request containing (1) .. (dot dot) or (2) &quot;%2e%2e&quot; (encoded dot dot) sequences.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="SECTRACK" url="http://securitytracker.com/id?1013191">1013191</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/14283">14283</ref></refs><vuln_soft><prod name="Sami HTTP Server" vendor="Sami"><vers num="1.0.5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0451" published="2005-05-02" seq="2005-0451" severity="Medium" type="CVE"><desc><descript source="cve">Sami HTTP Server 1.0.5 allows remote attackers to cause a denial of service via an HTTP request containing two CRLF sequences, which triggers a NULL dereference.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="SECTRACK" url="http://securitytracker.com/id?1013191">1013191</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/14283">14283</ref></refs><vuln_soft><prod name="Sami HTTP Server" vendor="Sami"><vers num="1.0.5"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-04-07" name="CVE-2005-0452" published="2005-02-16" seq="2005-0452" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Microsoft ASP.NET (.Net) 1.0 and 1.1 to SP1 allow remote attackers to inject arbitrary HTML or web script via Unicode representations for ASCII fullwidth characters that are converted to normal ASCII characters, including &quot;&gt;&quot; and &quot;&lt;&quot;.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110867912714913&amp;w=2">20050217 XSS vulnerabilty in ASP.Net [with details]</ref><ref adv="1" source="MISC" url="http://it-project.ru/andir/docs/aspxvuln/aspxvuln.en.xml">http://it-project.ru/andir/docs/aspxvuln/aspxvuln.en.xml</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/12574">12574</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/14214">14214</ref></refs><vuln_soft><prod name="ASP.NET" vendor="Microsoft"><vers num="1.1 SP1"/><vers num="1.1"/><vers num="1.0 SP2"/><vers num="1.0 SP1"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0453" published="2005-02-16" seq="2005-0453" severity="Medium" type="CVE"><desc><descript source="cve">The buffer_urldecode function in Lighttpd 1.3.7 and earlier does not properly handle control characters, which allows remote attackers to obtain the source code for CGI and FastCGI scripts via a URL with a %00 (null) character after the file extension.</descript></desc><loss_types><conf/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CONFIRM" url="http://article.gmane.org/gmane.comp.web.lighttpd/1171">http://article.gmane.org/gmane.comp.web.lighttpd/1171</ref><ref adv="1" patch="1" source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200502-21.xml">GLSA-200502-21</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14297">14297</ref></refs><vuln_soft><prod name="lighttpd" vendor="lighttpd"><vers num="1.3.7"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0454" published="2005-05-02" seq="2005-0454" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in DCP-Portal 6.1.1 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the lcat, doc, or uid parameters to index.php, or (2) the mid or bid parameters to forums.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110858497207809&amp;w=2">20050216 [hackgen-2005-#003] - SQL injection bugs in DCP-Portal</ref><ref adv="1" source="MISC" url="http://www.hackgen.org/advisories/hackgen-2005-003.txt">http://www.hackgen.org/advisories/hackgen-2005-003.txt</ref><ref adv="1" source="SECTRACK" url="http://securitytracker.com/id?1013216">1013216</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/419280/100/0/threaded">20051211 [PHP-CHECKER] 99 potential SQL injection vulnerabilities</ref><ref source="" url="http://glide.stanford.edu/yichen/research/sec.pdf"></ref><ref source="BID" url="http://www.securityfocus.com/bid/12573">12573</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19361">dcpportal-multiple-sql-injection(19361)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/108">108</ref></refs><vuln_soft><prod name="DCP-Portal" vendor="Codeworx Technologies"><vers num="6.1.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-01-05" name="CVE-2005-0455" published="2005-05-02" seq="2005-0455" severity="Medium" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in the CSmil1Parser::testAttributeFailed function in smlparse.cpp for RealNetworks RealPlayer 10.5 (6.0.12.1056 and earlier), 10, 8, and RealOne Player V2 and V1 allows remote attackers to execute arbitrary code via a .SMIL file with a large system-screen-size value.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=209&amp;type=vulnerabilities">20050301 RealNetworks RealPlayer .smil Buffer Overflow Vulnerability</ref><ref adv="1" patch="1" source="CONFIRM" url="http://service.real.com/help/faq/security/050224_player">http://service.real.com/help/faq/security/050224_player</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-265.html">RHSA-2005:265</ref><ref adv="1" source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=209&amp;type=vulnerabilities">20050301 RealNetworks RealPlayer .smil Buffer Overflow Vulnerability</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-271.html">RHSA-2005:271</ref></refs><vuln_soft><prod name="RealPlayer" vendor="RealNetworks"><vers edition="Win32" num="8.0"/><vers num="8.0"/><vers num="10.5_6.0.12.1053"/><vers num="10.5_6.0.12.1040"/><vers num="10.5_6.0.12.1016 Beta"/><vers num="10.5"/><vers num="10.0_6.0.12.690"/><vers num="10.0 beta"/><vers num="10.0"/></prod><prod name="RealOne Player" vendor="RealNetworks"><vers num="2.0"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0456" published="2005-01-12" seq="2005-0456" severity="Medium" type="CVE"><desc><descript source="cve">Opera 7.54 and earlier does not properly validate base64 encoded binary data in a data: (RFC 2397) URL, which causes the URL to be obscured in a download dialog, which may allow remote attackers to trick users into executing arbitrary code.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CONFIRM" url="http://www.opera.com/linux/changelogs/754u2/">http://www.opera.com/linux/changelogs/754u2/</ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200502-17.xml">GLSA-200502-17</ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/882926">VU#882926</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/13818/">13818</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18867">opera-data-dialog-spoofing(18867)</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_31_opera.html">SUSE-SA:2005:031</ref></refs><vuln_soft><prod name="Opera Web Browser" vendor="Opera Software"><vers num="7.54"/><vers num="7.53"/><vers num="7.52"/><vers num="7.51"/><vers num="7.50"/><vers num="7.23"/><vers num="7.22"/><vers num="7.21"/><vers num="7.20 Beta1 build2981"/><vers num="7.20"/><vers num="7.11j"/><vers num="7.11b"/><vers num="7.11"/><vers num="7.10"/><vers edition="win32" num="7.0.3"/><vers edition="win32" num="7.0.2"/><vers edition="win32" num="7.0.1"/><vers edition="win32" num="7.0 Beta2"/><vers edition="win32" num="7.0 Beta1"/><vers edition="win32" num="7.0"/><vers edition="Linux" num="6.10"/><vers edition="win32" num="6.0.6"/><vers num="6.0.6"/><vers edition="win32" num="6.0.5"/><vers edition="win32" num="6.0.4"/><vers edition="win32" num="6.0.3"/><vers edition="Linux" num="6.0.3"/><vers edition="win32" num="6.0.2"/><vers edition="Linux" num="6.0.2"/><vers edition="win32" num="6.0.1"/><vers edition="Linux" num="6.0.1"/><vers num="6.0.1"/><vers edition="win32" num="6.0"/><vers num="6.0"/><vers edition="win32" num="5.12"/><vers num="5.12"/><vers edition="win32" num="5.1.1"/><vers edition="win32" num="5.1.0"/><vers edition="Mac" num="5.0"/><vers edition="Linux" num="5.0"/><vers edition="win32" num="5.0.2"/><vers num="9.10"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0457" published="2005-05-02" seq="2005-0457" severity="High" type="CVE"><desc><descript source="cve">Opera 7.54 and earlier on Gentoo Linux uses an insecure path for plugins, which could allow local users to gain privileges by inserting malicious libraries into the PORTAGE_TMPDIR (portage) temporary directory.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200502-17.xml">GLSA-200502-17</ref><ref adv="1" source="CONFIRM" url="http://bugs.gentoo.org/show_bug.cgi?id=81747">http://bugs.gentoo.org/show_bug.cgi?id=81747</ref></refs><vuln_soft><prod name="Opera Web Browser" vendor="Opera Software"><vers num="7.50B1"/><vers num="7.50"/><vers num="7.52"/><vers num="7.53"/><vers num="7.54"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0458" published="2005-05-02" seq="2005-0458" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in contact_us.php in osCommerce 2.2-MS2 allows remote attackers to inject arbitrary web script or HTML via the enquiry parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110851122614995&amp;w=2">20050215 [NOBYTES.COM: #3] osCommerce 2.2-MS2 - XSS Vulnerability</ref></refs><vuln_soft><prod name="osCommerce" vendor="osCommerce"><vers num="2.2 ms2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0459" published="2005-05-02" seq="2005-0459" severity="Medium" type="CVE"><desc><descript source="cve">phpMyAdmin 2.6.2-dev, and possibly earlier versions, allows remote attackers to determine the full path of the web root via a direct request to select_lang.lib.php, which reveals the path in a PHP error message.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="SECTRACK" url="http://securitytracker.com/id?1013210">1013210</ref></refs><vuln_soft><prod name="phpMyAdmin" vendor="phpMyAdmin"><vers num="2.6.2 dev"/><vers num="2.6.0 pl3"/><vers num="2.6.0 pl2"/><vers num="2.6.0 pl1"/><vers num="2.5.7 pl1"/><vers num="2.5.7"/><vers num="2.5.6 rc1"/><vers num="2.5.5 rc2"/><vers num="2.5.5 rc1"/><vers num="2.5.5 pl1"/><vers num="2.5.5"/><vers num="2.5.4"/><vers num="2.5.2"/><vers num="2.5.1"/><vers num="2.5.0"/><vers num="2.4.0"/><vers num="2.3.2"/><vers num="2.3.1"/><vers num="2.2.6"/><vers num="2.2.5"/><vers num="2.2.4"/><vers num="2.2.3"/><vers num="2.2.2"/><vers num="2.2 rc3"/><vers num="2.2 rc2"/><vers num="2.2 rc1"/><vers num="2.2 pre1"/><vers num="2.1.2"/><vers num="2.1.1"/><vers num="2.1"/><vers num="2.0.5"/><vers num="2.0.4"/><vers num="2.0.3"/><vers num="2.0.2"/><vers num="2.0.1"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0460" published="2005-05-02" seq="2005-0460" severity="Medium" type="CVE"><desc><descript source="cve">index.php in MercuryBoard 1.0.x and 1.1.x allows remote attackers to obtain sensitive information by setting the debug parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="MISC" url="http://lostmon.blogspot.com/2005/02/mercuryboard-debug-information.html">http://lostmon.blogspot.com/2005/02/mercuryboard-debug-information.html</ref><ref adv="1" patch="1" source="OSVDB" url="http://www.osvdb.org/13787">13787</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14284">14284</ref></refs><vuln_soft><prod name="MercuryBoard" vendor="MercuryBoard"><vers num="1.1.1"/><vers num="1.1"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0461" published="2005-05-02" seq="2005-0461" severity="Medium" type="CVE"><desc><descript source="cve">Unknown vulnerability in NewsBruiser 2.x before 2.6.1 allows remote attackers to &quot;take actions on comments.&quot;</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="CONFIRM" url="http://newsbruiser.tigris.org/source/browse/newsbruiser/CHANGELOG?rev=1.283&amp;content-type=text/x-cvsweb-markup">http://newsbruiser.tigris.org/source/browse/newsbruiser/CHANGELOG?rev=1.283&amp;content-type=text/x-cvsweb-markup</ref><ref patch="1" source="CONFIRM" url="http://newsbruiser.tigris.org/servlets/NewsItemView?newsItemID=1016">http://newsbruiser.tigris.org/servlets/NewsItemView?newsItemID=1016</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14262">14262</ref></refs><vuln_soft><prod name="NewsBruiser" vendor="Leonard Richardson"><vers num="2.6"/><vers num="2.5"/><vers num="2.4.1"/><vers num="2.4"/><vers num="2.3"/><vers num="2.2"/><vers num="2.1"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0462" published="2005-02-17" seq="2005-0462" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in MercuryBoard 1.0.x and 1.1.x allows remote attackers to inject arbitrary HTML and web script via the f parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MISC" url="http://lostmon.blogspot.com/2005/02/mercuryboard-forumphp-f-variable-xss.html">http://lostmon.blogspot.com/2005/02/mercuryboard-forumphp-f-variable-xss.html</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/13937">13937</ref></refs><vuln_soft><prod name="MercuryBoard" vendor="MercuryBoard"><vers num="1.1.1"/><vers num="1.1"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0463" published="2005-05-02" seq="2005-0463" severity="High" type="CVE"><desc><descript source="cve">Unknown &quot;major security flaws&quot; in Ulog-php before 1.0, related to input validation, have unknown impact and attack vectors, probably related to SQL injection vulnerabilities in (1) host.php, (2) port.php, and (3) index.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CONFIRM" url="http://www.inl.fr/article.php3?id_article=7">http://www.inl.fr/article.php3?id_article=7</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/12610">12610</ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/13853">13853</ref><ref adv="1" patch="1" source="SECTRACK" url="http://securitytracker.com/id?1013220">1013220</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14321">14321</ref></refs><vuln_soft><prod name="Ulog-php" vendor="INL"><vers num="0.8.2"/><vers num="0.8.1"/><vers num="0.8"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0464" published="2005-05-02" seq="2005-0464" severity="Low" type="CVE"><desc><descript source="cve">gr_osview in SGI IRIX 6.5.22, and possibly other 6.5 versions, does not drop privileges when opening description files while in debug mode, which allows local users to read a line from arbitrary files via the -d and -D options, which prints the line as a formatting error.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=226&amp;type=vulnerabilities">20050407 SGI IRIX gr_osview Information Disclosure Vulnerability</ref><ref patch="1" source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20050402-01-P">20050402-01-P</ref><ref source="OSVDB" url="http://www.osvdb.org/15351">15351</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013662">1013662</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14875">14875</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num="6.5.22"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0465" published="2005-05-02" seq="2005-0465" severity="Low" type="CVE"><desc><descript source="cve">gr_osview in SGI IRIX does not drop privileges before opening files, which allows local users to overwrite arbitrary files via the -s option.</descript></desc><loss_types><int/></loss_types><vuln_types><access/><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=225&amp;type=vulnerabilities">20050407 SGI IRIX gr_osview File Overwrite Vulnerability</ref><ref patch="1" source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20050402-01-P">20050402-01-P</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013662">1013662</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14875">14875</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num="6.5.22"/><vers num="6.5.9m"/><vers num="6.5.9f"/><vers num="6.5.9"/><vers num="6.5.8m"/><vers num="6.5.8f"/><vers num="6.5.8"/><vers num="6.5.7m"/><vers num="6.5.7f"/><vers num="6.5.7"/><vers num="6.5.6m"/><vers num="6.5.6f"/><vers num="6.5.6"/><vers num="6.5.5m"/><vers num="6.5.5f"/><vers num="6.5.5"/><vers num="6.5.4m"/><vers num="6.5.4f"/><vers num="6.5.4"/><vers num="6.5.3m"/><vers num="6.5.3f"/><vers num="6.5.3"/><vers num="6.5.21m"/><vers num="6.5.21f"/><vers num="6.5.21"/><vers num="6.5.20m"/><vers num="6.5.20f"/><vers num="6.5.20"/><vers num="6.5.2m"/><vers num="6.5.2f"/><vers num="6.5.2"/><vers num="6.5.19m"/><vers num="6.5.19f"/><vers num="6.5.19"/><vers num="6.5.18m"/><vers num="6.5.18f"/><vers num="6.5.18"/><vers num="6.5.17m"/><vers num="6.5.17f"/><vers num="6.5.17"/><vers num="6.5.16m"/><vers num="6.5.16f"/><vers num="6.5.16"/><vers num="6.5.15m"/><vers num="6.5.15f"/><vers num="6.5.15"/><vers num="6.5.14m"/><vers num="6.5.14f"/><vers num="6.5.14"/><vers num="6.5.13m"/><vers num="6.5.13f"/><vers num="6.5.13"/><vers num="6.5.12m"/><vers num="6.5.12f"/><vers num="6.5.12"/><vers num="6.5.11m"/><vers num="6.5.11f"/><vers num="6.5.11"/><vers num="6.5.10m"/><vers num="6.5.10f"/><vers num="6.5.10"/><vers num="6.5.1"/><vers num="6.5 20"/><vers num="6.5"/><vers num="6.4"/><vers num="6.3"/><vers num="6.2"/><vers num="6.1"/><vers num="6.0.1 XFS"/><vers num="6.0.1"/><vers num="6.0"/><vers num="5.3 XFS"/><vers num="5.3"/><vers num="5.2"/><vers num="5.1.1"/><vers num="5.1"/><vers num="5.0.1"/><vers num="5.0"/><vers num="4.0.5 IPR"/><vers num="4.0.5H"/><vers num="4.0.5G"/><vers num="4.0.5F"/><vers num="4.0.5E"/><vers num="4.0.5B"/><vers num="4.0.5A"/><vers num="4.0.5 IOP"/><vers num="4.0.5"/><vers num="4.0.4T"/><vers num="4.0.4B"/><vers num="4.0.4"/><vers num="4.0.3"/><vers num="4.0.2"/><vers num="4.0.1T"/><vers num="4.0.1"/><vers num="4.0"/><vers num="3.3.3"/><vers num="3.3.2"/><vers num="3.3.1"/><vers num="3.3"/><vers num="3.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0467" published="2005-02-21" seq="2005-0467" severity="High" type="CVE"><desc><descript source="cve">Multiple integer overflows in the (1) sftp_pkt_getstring and (2) fxp_readdir_recv functions in the PSFTP and PSCP clients for PuTTY 0.56, and possibly earlier versions, allow remote malicious web sites to execute arbitrary code via SFTP responses that corrupt the heap after insufficient memory has been allocated.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=201&amp;type=vulnerabilities">20050221 Multiple PuTTY SFTP Client Packet Parsing Integer Overflow Vulnerabilities</ref><ref adv="1" source="CONFIRM" url="http://www.chiark.greenend.org.uk/~sgtatham/putty/wishlist/vuln-sftp-string.html">http://www.chiark.greenend.org.uk/~sgtatham/putty/wishlist/vuln-sftp-string.html</ref><ref adv="1" source="CONFIRM" url="http://www.chiark.greenend.org.uk/~sgtatham/putty/wishlist/vuln-sftp-readdir.html">http://www.chiark.greenend.org.uk/~sgtatham/putty/wishlist/vuln-sftp-readdir.html</ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200502-28.xml">GLSA-200502-28</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14333">14333</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19403">putty-sftppktgetstring-bo(19403)</ref><ref source="" url="http://www-1.ibm.com/support/docview.wss?uid=ssg1S1002414"></ref><ref source="" url="http://www-1.ibm.com/support/docview.wss?uid=ssg1S1002416"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/17214">17214</ref></refs><vuln_soft><prod name="PuTTY" vendor="PuTTY"><vers num="0.56" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-22" name="CVE-2005-0468" published="2005-05-02" seq="2005-0468" severity="High" type="CVE"><desc><descript source="cve">Heap-based buffer overflow in the env_opt_add function in telnet.c for various BSD-based Telnet clients allows remote attackers to execute arbitrary code via responses that contain a large number of characters that require escaping, which consumers more memory than allocated.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=221&amp;type=vulnerabilities">20050328 Multiple Telnet Client env_opt_add() Buffer Overflow Vulnerability</ref><ref adv="1" source="FREEBSD" url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-05:01.telnet.asc">FreeBSD-SA-05:01.telnet</ref><ref adv="1" patch="1" source="CONFIRM" url="http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2005-001-telnet.txt">http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2005-001-telnet.txt</ref><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-703">DSA-703</ref><ref adv="1" patch="1" source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:061">MDKSA-2005:061</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-327.html">RHSA-2005:327</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-330.html">RHSA-2005:330</ref><ref patch="1" source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20050405-01-P">20050405-01-P</ref><ref source="DEBIAN" url="http://www.debian.de/security/2005/dsa-731">DSA-731</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/341908">VU#341908</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14745">14745</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57755-1">57755</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57761-1">57761</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/usn/usn-224-1">USN-224-1</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17899">17899</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000962">CLA-2005:962</ref><ref source="BID" url="http://www.securityfocus.com/bid/12919">12919</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101671-1">101671</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101665-1">101665</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:061">MDKSA-2005:061</ref></refs><vuln_soft><prod name="Telnet" vendor="NCSA"><vers num="c"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-22" name="CVE-2005-0469" published="2005-05-02" seq="2005-0469" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the slc_add_reply function in various BSD-based Telnet clients, when handling LINEMODE suboptions, allows remote attackers to execute arbitrary code via a reply with a large number of Set Local Character (SLC) commands.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=220&amp;type=vulnerabilities">20050328 Multiple Telnet Client slc_add_reply() Buffer Overflow Vulnerability</ref><ref adv="1" source="FREEBSD" url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-05:01.telnet.asc">FreeBSD-SA-05:01.telnet</ref><ref adv="1" patch="1" source="CONFIRM" url="http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2005-001-telnet.txt">http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2005-001-telnet.txt</ref><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-697">DSA-697</ref><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-699">DSA-699</ref><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-703">DSA-703</ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200503-36.xml">GLSA-200503-36</ref><ref adv="1" patch="1" source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:061">MDKSA-2005:061</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-327.html">RHSA-2005:327</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-330.html">RHSA-2005:330</ref><ref patch="1" source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20050405-01-P">20050405-01-P</ref><ref adv="1" patch="1" source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57755-1">57755</ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/291924">VU#291924</ref><ref source="DEBIAN" url="http://www.debian.de/security/2005/dsa-731">DSA-731</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14745">14745</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57761-1">57761</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/usn/usn-224-1">USN-224-1</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17899">17899</ref><ref source="BID" url="http://www.securityfocus.com/bid/12918">12918</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101671-1">101671</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101665-1">101665</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:061">MDKSA-2005:061</ref></refs><vuln_soft><prod name="Telnet" vendor="NCSA"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0470" published="2005-03-14" seq="2005-0470" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in wpa_supplicant before 0.2.7 allows remote attackers to cause a denial of service (segmentation fault) via invalid EAPOL-Key packet data.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Gentoo.org" url="http://www.gentoo.org/security/en/glsa/glsa-200502-22.xml">wpa_supplicant: Buffer overflow vulnerability</ref><ref adv="1" patch="1" source="Secunia.com" url="http://secunia.com/advisories/14313">wpa_supplicant EAPOL-Key Frames Buffer Overflow</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/19357">wpa_supplicant buffer overflow</ref><ref source="MLIST" url="http://lists.shmoo.com/pipermail/hostap/2005-February/009465.html">[HostAP] 20050213 wpa_supplicant - new stable releases v0.3.8 and v0.2.7</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013226">1013226</ref></refs><vuln_soft><prod name="Linux" vendor="Gentoo"><vers num=""/></prod><prod name="SuSE Linux" vendor="SuSE"><vers edition="x86_64" num="9.2"/><vers num="9.2"/></prod><prod name="wpa_supplicant" vendor="wpa_supplicant"><vers num="0.2"/><vers num="0.2.1"/><vers num="0.2.2"/><vers num="0.2.3"/><vers num="0.2.4"/><vers num="0.2.5"/><vers num="0.2.6"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0471" published="2005-03-14" seq="2005-0471" severity="Medium" type="CVE"><desc><descript source="cve">Sun Java JRE 1.1.x through 1.4.x writes temporary files with long filenames that become predictable on a file system that uses 8.3 style short names, which allows remote attackers to write arbitrary files to known locations and facilitates the exploitation of vulnerabilities in applications that rely on unpredictable file names.</descript></desc><loss_types><int/></loss_types><range><network/></range><refs><ref adv="1" source="CERT" url="http://www.kb.cert.org/vuls/id/544392">Sun Java Plugin may create temporary files with predictable names</ref><ref adv="1" source="Secunia.com" url="http://secunia.com/advisories/11070/">Sun Java Plugin Predictable File Location WeaknessSun Java Plugin Predictable File Location Weakness   Sun Java Plugin Predictable File Location Weakness</ref><ref source="MISC" url="http://secunia.com/secunia_research/2004-7/advisory/">http://secunia.com/secunia_research/2004-7/advisory/</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19285">sun-java-create-files(19285)</ref></refs><vuln_soft><prod name="JRE" vendor="Sun"><vers num="1.1"/><vers num="1.2"/><vers num="1.3"/><vers num="1.4"/><vers num="1.5"/></prod><prod name="JDK" vendor="Sun"><vers num="1.1.0"/><vers num="1.2.0"/><vers num="1.3.0"/><vers num="1.4.0"/><vers num="1.5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0472" published="2005-03-14" seq="2005-0472" severity="Medium" type="CVE"><desc><descript source="cve">Gaim before 1.1.3 allows remote attackers to cause a denial of service (infinite loop) via malformed SNAC packets from (1) AIM or (2) ICQ.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/19380">Gaim SNAC packet denial of service</ref><ref adv="1" patch="1" source="CERT" url="http://www.kb.cert.org/vuls/id/839280">Gaim vulnerable to malformed SNAC packet infinite processing loop</ref><ref adv="1" source="Sourceforge.net" url="http://gaim.sourceforge.net/security/index.php?id=10">Gaim Vulnerability</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-716">DSA-716</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200503-03.xml">GLSA-200503-03</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:049">MDKSA-2005:049</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-215.html">RHSA-2005:215</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14322">14322</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-432.html">RHSA-2005:432</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/426078/100/0/threaded">FLSA:158543</ref><ref source="BID" url="http://www.securityfocus.com/bid/12589">12589</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000933">CLA-2005:933</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110935655500670&amp;w=2">20050225 [USN-85-1] Gaim vulnerabilities</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_36_sudo.html">SUSE-SA:2005:036</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:049">MDKSA-2005:049</ref></refs><vuln_soft><prod name="Mandrake Corporate Server" vendor="MandrakeSoft"><vers edition="x86_64" num="3.0"/><vers num="3.0"/></prod><prod name="Desktop" vendor="Red Hat"><vers num="4.0"/></prod><prod name="Gaim" vendor="Rob Flynn"><vers num="1.0"/><vers num="1.0.1"/><vers num="1.1.1"/><vers num="1.1.2"/></prod><prod name="Mandrake Linux" vendor="MandrakeSoft"><vers edition="AMD64" num="10.0"/><vers num="10.0"/><vers edition="x86_64" num="10.1"/><vers num="10.1"/></prod><prod name="Enterprise Linux ES" vendor="Red Hat"><vers edition="Enterprise Server" num="4.0"/></prod><prod name="Enterprise Linux AS" vendor="Red Hat"><vers edition="Advanced Server" num="4.0"/></prod><prod name="Enterprise Linux WS" vendor="Red Hat"><vers edition="Workstation" num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-25" name="CVE-2005-0473" published="2005-03-14" seq="2005-0473" severity="Medium" type="CVE"><desc><descript source="cve">The HTML parsing functions in Gaim before 1.1.3 allow remote attackers to cause a denial of service (application crash) via malformed HTML that causes &quot;an invalid memory access,&quot; a different vulnerability than CVE-2005-0208.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="RedHat" url="http://www.redhat.com/support/errata/RHSA-2005-215.html">Important: gaim security update</ref><ref adv="1" patch="1" source="CERT" url="http://www.kb.cert.org/vuls/id/523888">Gaim vulnerable to HTML processing denial of service</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/19381">Gaim HTML denial of service</ref><ref source="CONFIRM" url="http://gaim.sourceforge.net/security/index.php?id=11">http://gaim.sourceforge.net/security/index.php?id=11</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200503-03.xml">GLSA-200503-03</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:049">MDKSA-2005:049</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14322">14322</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/426078/100/0/threaded">FLSA:158543</ref><ref source="BID" url="http://www.securityfocus.com/bid/12589">12589</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000933">CLA-2005:933</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110935655500670&amp;w=2">20050225 [USN-85-1] Gaim vulnerabilities</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_36_sudo.html">SUSE-SA:2005:036</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:049">MDKSA-2005:049</ref></refs><vuln_soft><prod name="Mandrake Corporate Server" vendor="MandrakeSoft"><vers edition="x86_64" num="3.0"/><vers num="3.0"/></prod><prod name="Desktop" vendor="Red Hat"><vers num="4.0"/></prod><prod name="Gaim" vendor="Rob Flynn"><vers num="1.0"/><vers num="1.0.1"/><vers num="1.1.1"/><vers num="1.1.2"/></prod><prod name="Mandrake Linux" vendor="MandrakeSoft"><vers edition="AMD64" num="10.0"/><vers num="10.0"/><vers edition="x86_64" num="10.1"/><vers num="10.1"/></prod><prod name="Enterprise Linux ES" vendor="Red Hat"><vers edition="Enterprise Server" num="4.0"/></prod><prod name="Enterprise Linux AS" vendor="Red Hat"><vers edition="Advanced Server" num="4.0"/></prod><prod name="Enterprise Linux WS" vendor="Red Hat"><vers edition="Workstation" num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0474" published="2005-03-30" seq="2005-0474" severity="Medium" type="CVE"><desc><descript source="cve">SQL injection vulnerability in the user_valid_crypt function in user.php in WebCalendar 0.9.45 allows remote attackers to execute arbitrary SQL commands via an encoded webcalendar_session cookie.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Scoverttalabs.com" url="http://www.scovettalabs.com/advisory/SCL-2005.001.txt">WebCalendar: SQL Injection from encoded cookie</ref><ref adv="1" patch="1" source="Secunia.com" url="http://secunia.com/advisories/14319">WebCalendar &quot;webcalendar_session&quot; SQL Injection</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/19369">WebCalendar webcalendar_session parameter SQL injection</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110868446431706&amp;w=2">20050217 [ SCL-2005.001 ] - WebCalendar: SQL Injection from encoded cookie</ref><ref source="OSVDB" url="http://www.osvdb.org/13918">13918</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013231">1013231</ref></refs><vuln_soft><prod name="WebCalendar" vendor="WebCalendar"><vers num="0.9.45"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0475" published="2005-03-30" seq="2005-0475" severity="Medium" type="CVE"><desc><descript source="cve">SQL injection vulnerability in paFAQ Beta4, and possibly other versions, allows remote attackers to execute arbitrary SQL code via the (1) offset, (2) limit, (3) order, or (4) orderby parameter to question.php, (5) offset parameter to answer.php, (6) search_item parameter to search.php, (7) cat_id, (8) cid, or (9) id parameter to comment.php.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110868808723487&amp;w=2">paFAQ Beta4 Sql Injection</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/19371">paFAQ SQL injection</ref></refs><vuln_soft><prod name="paFaq" vendor="PHP Arena"><vers num="Beta4"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0476" published="2005-03-30" seq="2005-0476" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in hpm_guestbook.cgi allows remote attackers to inject arbitrary web script or HTML by posting a message.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19372">hpm-guestbook-xss(19372)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110869187805397&amp;w=2">20050217 hpm_guestbook.cgi JavaScript-Injection</ref></refs><vuln_soft><prod name="hpm_guestbook.cgi" vendor="hpm_guestbook.cgi"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0477" published="2005-03-30" seq="2005-0477" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in the SML code for Invision Power Board 1.3.1 FINAL allows remote attackers to inject arbitrary web script via (1) a signature file or (2) a message post containing an IMG tag within a COLOR tag whose style is set to background:url.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110868196922995&amp;w=2">Invision Power Boards 1.3.1 FINAL XSS Exploit</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/12607">bid 12607</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19399">invision-power-board-sml-xss(19399)</ref></refs><vuln_soft><prod name="Invision Power Board" vendor="Invision Power Services"><vers num="1.0"/><vers num="1.0.1"/><vers num="1.1.1"/><vers num="1.1.2"/><vers num="1.2"/><vers num="1.3 Final"/><vers num="1.3"/><vers num="1.3.1 Final"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0478" published="2005-03-30" seq="2005-0478" severity="Medium" type="CVE"><desc><descript source="cve">Multiple buffer overflows in TrackerCam 5.12 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) an HTTP request with a long User-Agent header or (2) a long argument to an arbitrary PHP script.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/390918">Multiple vulnerabilities in TrackerCam 5.12</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/12592">bid 12592</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19411">trackercam-php-bo(19411)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19409">trackercam-useragent-bo(19409)</ref></refs><vuln_soft><prod name="TrackerCam" vendor="TrackerCam"><vers num="5.12" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0479" published="2005-03-30" seq="2005-0479" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in ComGetLogFile.php3 for TrackerCam 5.12 and earlier allows remote attackers to read arbitrary files via &quot;..&quot; sequences and (1) &quot;/&quot; slash), (2) &quot;\&quot; (backslash), or (3) hex-encoded characters in the fn parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/390918">Multiple vulnerabilities in TrackerCam 5.12</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/12592">bid 12592</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19414">trackercam-fn-directory-traversal(19414)</ref></refs><vuln_soft><prod name="TrackerCam" vendor="TrackerCam"><vers num="5.12" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0480" published="2005-03-30" seq="2005-0480" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in TrackerCam 5.12 and earlier allows remote attackers to inject arbitrary HTML or web script via the login request, which is recorded in a log file but not properly handled when the administrator views the log file.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/390918">Multiple vulnerabilities in TrackerCam 5.12</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/12592">bid 12592</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19416">trackercam-xss(19416)</ref></refs><vuln_soft><prod name="TrackerCam" vendor="TrackerCam"><vers num="5.12" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0481" published="2005-03-30" seq="2005-0481" severity="Medium" type="CVE"><desc><descript source="cve">TrackerCam 5.12 and earlier allows remote attackers to read log files via the fn parameter in a direct request to the ComGetLogFile.php3 script.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/390918">Multiple vulnerabilities in TrackerCam 5.12</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/12592">bid 12592</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19415">trackercam-fn-path-disclosure(19415)</ref></refs><vuln_soft><prod name="TrackerCam" vendor="TrackerCam"><vers num="5.12" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0482" published="2005-03-30" seq="2005-0482" severity="Medium" type="CVE"><desc><descript source="cve">TrackerCam 5.12 and earlier allows remote attackers to cause a denial of service (crash) via (1) a large number of connections with a negative Content-Length header, possibly triggering an integer signedness error, or (2) a large amount of data.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/390918">Multiple vulnerabilities in TrackerCam 5.12</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/12592">bid 12592</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19417">trackercam-contentlength-dos(19417)</ref></refs><vuln_soft><prod name="TrackerCam" vendor="TrackerCam"><vers num="5.12" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0483" published="2005-03-30" seq="2005-0483" severity="Medium" type="CVE"><desc><descript source="cve">Multiple directory traversal vulnerabilities in sitenfo.sh, sitezipchk.sh, and siteziplist.sh in Glftpd 1.26 to 2.00 allow remote authenticated users to (1) determine the existence of arbitrary files, (2) list files in restricted directories, or (3) read arbitrary files from within ZIP or gzip files, via .. (dot dot) sequences and globbing (&quot;*&quot;) characters in a SITE NFO command.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/390924">Multiple vulnerabilities in Glftpd v1.26 - v2.00 default zip based plug-ins</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/12586">bid 12586</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19401">glftpd-sitenfosh-directory-traversal(19401)</ref></refs><vuln_soft><prod name="GlFtpd" vendor="GlFtpd"><vers num="1.26"/><vers num="1.27"/><vers num="1.28"/><vers num="1.29.1"/><vers num="1.31"/><vers num="1.32"/><vers num="2.0 RC7"/><vers num="2.0 RC6"/><vers num="2.0 RC5"/><vers num="2.0 RC4"/><vers num="2.0 RC3"/><vers num="2.0 RC2"/><vers num="2.0 RC1"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0484" published="2005-03-30" seq="2005-0484" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in gprostats for GProFTPD before 8.1.9 may allow remote attackers to execute arbitrary code via an FTP transfer with a crafted filename that causes format string specifiers to be inserted into the ProFTPD transfer log.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Gentoo.org" url="http://security.gentoo.org/glsa/glsa-200502-26.xml">GProFTPD: gprostats format string vulnerability</ref><ref adv="1" source="Gentoo.org" url="http://bugs.gentoo.org/show_bug.cgi?id=81894">net-ftp/gproftpd: gprostats format string vulnerability</ref></refs><vuln_soft><prod name="GProFTPD" vendor="GProFTPD"><vers num="8.1.8" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0485" published="2005-03-30" seq="2005-0485" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in comment.php for paNews 2.0b4 for PHP Arena allows remote attackers to inject arbitrary HTML and web script via the showpost parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110863062605906&amp;w=2">paNews v2.0b4 XSS Vulnerability</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/12576">bid 12576</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/19359">paNews comment.php script cross-site scripting</ref></refs><vuln_soft><prod name="paNews" vendor="PHP Arena"><vers num="2.0 b4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0486" published="2005-03-30" seq="2005-0486" severity="Medium" type="CVE"><desc><descript source="cve">Tarantella Secure Global Desktop Enterprise Edition 4.00 and 3.42, and Tarantella Enterprise 3 3.40 and 3.30, when using RSA SecurID and multiple users have the same username, reveals sensitive information during authentication, which allows remote attackers to identify valid usernames and the authentication scheme.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Tarantella.com" url="http://www.tarantella.com/security/bulletin-11.html">Tarantella Security Bulletin #11</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/12591">bid 12591</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19407">tarantella-enterprise-obtain-information(19407)</ref></refs><vuln_soft><prod name="Tarantella Enterprise" vendor="Tarantella"><vers num="3.30"/><vers num="3.40"/></prod><prod name="Secure Global Desktop" vendor="Tarantella"><vers num="Enterprise 3.42"/><vers num="Enterprise 4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0487" published="2005-03-30" seq="2005-0487" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in index.php for Kayako ESupport 2.3.1, and possibly other versions, allows remote attackers to inject arbitrary HTML and web script via the nav parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=110845724029888&amp;w=2">Kayako eSupport v2.3.1 Support Tracker XSS</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/12563">bid 12563</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18571">kayako-index-xss(18571)</ref></refs><vuln_soft><prod name="eSupport" vendor="Kayako"><vers num="2.3.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0488" published="2005-06-14" seq="2005-0488" severity="Medium" type="CVE"><desc><descript source="cve">Certain BSD-based Telnet clients, including those used on Solaris and SuSE Linux, allow remote malicious Telnet servers to read sensitive environment variables via the NEW-ENVIRON option with a SEND ENV_USERVAR command.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="IDEFENSE" url="http://idefense.com/application/poi/display?id=260&amp;type=vulnerabilities">20050614 Multiple Vendor Telnet Client Information Disclosure Vulnerability</ref><ref adv="1" patch="1" source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57755-1">57755</ref><ref adv="1" patch="1" source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57761-1">57761</ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/800829">VU#800829</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-504.html">RHSA-2005:504</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_16_sr.html">SUSE-SR:2005:016</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1139.html">OVAL1139</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014203">1014203</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-562.html">RHSA-2005:562</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17135">17135</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101671-1">101671</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101665-1">101665</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2006//Aug/msg00000.html">APPLE-SA-2006-08-01</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21253">21253</ref><ref source="BID" url="http://www.securityfocus.com/bid/13940">13940</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/3101">ADV-2006-3101</ref><ref source="BID" url="http://www.securityfocus.com/bid/19289">19289</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1139">oval:org.mitre.oval:def:1139</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-214A.html">
TA06-214A</ref></refs><vuln_soft><prod name="Kerberos 5" vendor="MIT"><vers num="1.3.4"/></prod><prod name="Solaris" vendor="Sun"><vers num="5.9"/></prod><prod name="Telnet Client" vendor="Microsoft"><vers num="5.1.2600.2180"/></prod></vuln_soft></entry><entry CVSS_base_score="4.9" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.9" CVSS_score="4.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-31" name="CVE-2005-0489" published="2005-12-31" seq="2005-0489" severity="Medium" type="CVE"><desc><descript source="cve">The /proc handling (proc/base.c) Linux kernel 2.4 before 2.4.17 allows local users to cause a denial of service via unknown vectors that cause an invalid access of free memory.</descript></desc><sols><sol source="nvd">This vulnerability is addressed in the following product release:
Linux, Linux kernel, 2.4.27</sol></sols><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1070">DSA-1070</ref><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1067">DSA-1067</ref><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1069">DSA-1069</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/20163">20163</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/20202">20202</ref><ref patch="1" source="DEBIAN" url="http://kernel.debian.net/debian/pool/main/kernel-source-2.4.17/kernel-source-2.4.17_2.4.17-1woody4_ia64.changes"></ref><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1082">DSA-1082</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/18173">18173</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20338">20338</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.4.26"/><vers num="2.4.25"/><vers num="2.4.24 ow1"/><vers num="2.4.24"/><vers num="2.4.23 -pre9"/><vers num="2.4.23 -ow2"/><vers num="2.4.23"/><vers num="2.4.22"/><vers num="2.4.21 pre7"/><vers num="2.4.21 pre4"/><vers num="2.4.21 pre1"/><vers num="2.4.21"/><vers num="2.4.20"/><vers num="2.4.19 -pre6"/><vers num="2.4.19 -pre5"/><vers num="2.4.19 -pre4"/><vers num="2.4.19 -pre3"/><vers num="2.4.19 -pre2"/><vers num="2.4.19 -pre1"/><vers num="2.4.19"/><vers num="2.4.18 pre-8"/><vers num="2.4.18 pre-7"/><vers num="2.4.18 pre-6"/><vers num="2.4.18 pre-5"/><vers num="2.4.18 pre4"/><vers num="2.4.18 pre3"/><vers num="2.4.18 pre2"/><vers num="2.4.18 pre1"/><vers edition="x86" num="2.4.18"/><vers num="2.4.18"/><vers num="2.4.17"/><vers num="2.4.16"/><vers num="2.4.15"/><vers num="2.4.14"/><vers num="2.4.13"/><vers num="2.4.12"/><vers num="2.4.11"/><vers num="2.4.10"/><vers num="2.4.9"/><vers num="2.4.8"/><vers num="2.4.7"/><vers num="2.4.6"/><vers num="2.4.5"/><vers num="2.4.4"/><vers num="2.4.3"/><vers num="2.4.2"/><vers num="2.4.1"/><vers num="2.4.0 test9"/><vers num="2.4.0 test8"/><vers num="2.4.0 test7"/><vers num="2.4.0 test6"/><vers num="2.4.0 test5"/><vers num="2.4.0 test4"/><vers num="2.4.0 test3"/><vers num="2.4.0 test2"/><vers num="2.4.0 test12"/><vers num="2.4.0 test11"/><vers num="2.4.0 test10"/><vers num="2.4.0 test1"/><vers num="2.4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0490" published="2005-05-02" seq="2005-0490" severity="Medium" type="CVE"><desc><descript source="cve">Multiple stack-based buffer overflows in libcURL and cURL 7.12.1, and possibly other versions, allow remote malicious web servers to execute arbitrary code via base64 encoded replies that exceed the intended buffer lengths when decoded, which is not properly handled by (1) the Curl_input_ntlm function in http_ntlm.c during NTLM authentication or (2) the Curl_krb_kauth and krb4_auth functions in krb4.c during Kerberos authentication.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=202&amp;type=vulnerabilities">20050221 Multiple Unix/Linux Vendor cURL/libcURL NTLM Authentication Buffer Overflow Vulnerability</ref><ref adv="1" source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=203&amp;type=vulnerabilities">20050221 Multiple Unix/Linux Vendor cURL/libcURL Kerberos Authentication Buffer Overflow Vulnerability</ref><ref adv="1" patch="1" source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000940">CLA-2005:940</ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200503-20.xml">GLSA-200503-20</ref><ref adv="1" patch="1" source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:048">MDKSA-2005:048</ref><ref adv="1" patch="1" source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=110959085507755&amp;w=2">20050228 [USN-86-1] cURL vulnerability</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19423">curl-kerberos-bo(19423)</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-340.html">RHSA-2005:340</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_11_curl.html">SUSE-SA:2005:011</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:048">MDKSA-2005:048</ref><ref source="BID" url="http://www.securityfocus.com/bid/12615">12615</ref><ref source="BID" url="http://www.securityfocus.com/bid/12616">12616</ref></refs><vuln_soft><prod name="libcURL" vendor="libcURL"><vers num="7.12.1"/></prod><prod name="cURL" vendor="cURL"><vers num="7.12.1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0491" published="2005-05-02" seq="2005-0491" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in Knox Arkeia Server Backup 5.3.x allows remote attackers to execute arbitrary code via a long type 77 request.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110887325425794&amp;w=2">20050218 Knox Arkeia remote root/system exploit</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/12594">12594</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14327">14327</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19398">arkeia-backup-client-bo(19398)</ref></refs><vuln_soft><prod name="Arkeia Server Backup" vendor="Knox Software"><vers num="5.3.4"/><vers num="5.3.3"/><vers num="5.3.2"/><vers num="5.3.1"/><vers num="5.3.0"/><vers num="5.3.0 rc4"/><vers num="5.3.0 rc3"/><vers num="5.3.0 rc2"/><vers num="5.3.0 rc1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0492" published="2005-05-02" seq="2005-0492" severity="Low" type="CVE"><desc><descript source="cve">Adobe Acrobat Reader 6.0.3 and 7.0.0 allows remote attackers to cause a denial of service (application crash) via a PDF file that contains a negative Count value in the root page node.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110879063511486&amp;w=2">20050218 Adobe Reader invalid root page node Count value DOS</ref><ref patch="1" source="CONFIRM" url="http://www.adobe.com/support/techdocs/331468.html">http://www.adobe.com/support/techdocs/331468.html</ref><ref adv="1" patch="1" source="MISC" url="http://www.frsirt.com/english/advisories/2005/0310">http://www.frsirt.com/english/advisories/2005/0310</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19946">adobe-root-page-node-dos(19946)</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14813">14813</ref></refs><vuln_soft><prod name="Acrobat Reader" vendor="Adobe"><vers num="6.0.3"/><vers num="7.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0493" published="2005-05-02" seq="2005-0493" severity="Medium" type="CVE"><desc><descript source="cve">CRLF injection vulnerability in bizmail.cgi in Biz Mail Form before 2.2 allows remote attackers to bypass the email check and send spam e-mail via CRLF sequences and forged mail headers in the email parameter.</descript></desc><sols><sol source="nvd">Upgrade to newest version.</sol></sols><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110876655521321&amp;w=2">20050218 BizMail 2.1 Spam Exploit</ref></refs><vuln_soft><prod name="Biz Mail Form" vendor="Seth M. Knorr"><vers num="2.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0494" published="2005-02-21" seq="2005-0494" severity="High" type="CVE"><desc><descript source="cve">The RgSecurity form in the HTTP server for the Thomson TCW690 cable modem running firmware 2.1 and software ST42.03.0a does not properly validate the password before performing changes, which allows remote attackers on the LAN to gain access via a direct POST request.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110886937131507&amp;w=2">20050219 Thomson TCW690 POST Password Validation Vulnerability</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/14353">14353</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19387">thomson-tcw690-gain-access(19387)</ref></refs><vuln_soft><prod name="Thomson Cable Modem" vendor="Thomson"><vers num="TCW690"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0495" published="2005-02-19" seq="2005-0495" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in ZeroBoard allows remote attackers to inject arbitrary web script or HTML via the (1) sn1, (2) year, or (3) page parameter to zboard.php or (4) filename to view_image.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110884332105513&amp;w=2">20050219 Multiples vulnerability in ZeroBoard,</ref><ref adv="1" source="MISC" url="http://securitytracker.com/id?1013243">http://securitytracker.com/id?1013243</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19420">zeroboard-xss(19420)</ref></refs><vuln_soft><prod name="Zeroboard" vendor="Zeroboard"><vers num="4.1 pl6"/><vers num="4.1 pl5"/><vers num="4.1 pl4"/><vers num="4.1 pl3"/><vers num="4.1 pl2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0496" published="2005-02-21" seq="2005-0496" severity="High" type="CVE"><desc><descript source="cve">Arkeia Network Backup Client 5.x contains hard-coded credentials that effectively serve as a back door, which allows remote attackers to access the file system and possibly execute arbitrary commands.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110900879826004&amp;w=2">20050220 Arkeia Network Backup Client Remote Access</ref><ref adv="1" source="MISC" url="http://metasploit.com/research/arkeia_agent/">http://metasploit.com/research/arkeia_agent/</ref><ref adv="1" source="MISC" url="http://securitytracker.com/id?1013256">http://securitytracker.com/id?1013256</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20667">arkeia-backup-client-gain-access(20667)</ref></refs><vuln_soft><prod name="Arkeia" vendor="Knox Software"><vers num="5.3"/><vers num="5.2"/><vers num="4.2"/><vers num="4.1"/><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0497" published="2005-05-02" seq="2005-0497" severity="High" type="CVE"><desc><descript source="cve">ADP Elite System Max 9000 allows remote authenticated users to gain privileges by uploading a .profile that sets the ADPROOT environment variable to the root directory.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/><config/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110901051420503&amp;w=2">20050219 ADP Elite System Max 9000 Series Login Vulnerability</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20622">adp-elite-gain-privileges(20622)</ref></refs><vuln_soft><prod name="Elite System Max 9000" vendor="ADP"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-05" name="CVE-2005-0498" published="2005-05-02" seq="2005-0498" severity="High" type="CVE"><desc><descript source="cve">Gigafast router (aka CompUSA router) allows remote attackers to gain sensitive information and bypass the login page via a direct request to backup.cfg, which reveals the administrator password in plaintext.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110900986022760&amp;w=2">20050220 Gigafast/CompUSA router (model EE400-R) vulnerabilities</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19422">gigafast-backupcfg-plaintext-password(19422)</ref></refs><vuln_soft><prod name="Gigafast router" vendor="Gigafast Ethernet"><vers num="EE400-R"/><vers num="EE410-R"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-05" name="CVE-2005-0499" published="2005-02-20" seq="2005-0499" severity="Medium" type="CVE"><desc><descript source="cve">Gigafast router (aka CompUSA router) with the DNS proxy option enabled allows remote attackers to cause a denial of service via malformed DNS queries.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/><exception/><config/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110900986022760&amp;w=2">20050220 Gigafast/CompUSA router (model EE400-R) vulnerabilities</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19426">gigafast-dns-queries-dos(19426)</ref></refs><vuln_soft><prod name="Gigafast router" vendor="Gigafast Ethernet"><vers num="EE400-R"/><vers num="EE410-R"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0500" published="2005-05-02" seq="2005-0500" severity="Medium" type="CVE"><desc><descript source="cve">Internet Explorer 6.0 on Windows XP SP2 allows remote attackers to spoof the domain name of a URL in a titlebar for a script-initiated popup window, which could facilitate phishing attacks.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=110895997201027&amp;w=2">20050221 WindowsXPSP2 script-initiated popup window</ref><ref source="BID" url="http://www.securityfocus.com/bid/12602">12602</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19452">ie-title-bar-spoofing(19452)</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14335">14335</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers edition="for Microsoft Windows Server 2003 SP1.0" num="6"/><vers edition="for Microsoft Windows Server 2003 SP1.0 SP1" num="6"/><vers edition="for Microsoft Windows Server 2003 SP1.0 SP2" num="6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0501" published="2005-05-02" seq="2005-0501" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Bontago 1.1 and earlier allows remote attackers exeucte arbitrary code via a long nickname.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Luigi Auriemma" url="http://aluigi.altervista.org/adv/bontagobof-adv.txt">http://aluigi.altervista.org/adv/bontagobof-adv.txt</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/14350">14350</ref><ref source="BID" url="http://www.securityfocus.com/bid/12603">12603</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19406">bontago-nickname-bo(19406)</ref></refs><vuln_soft><prod name="Bontago" vendor="DigiPen Institute of Technology"><vers num="1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0502" published="2005-02-18" seq="2005-0502" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in Xinkaa 1.0.3 and earlier allows remote attackers to read arbitrary files via (1) ../ and (2) ..\ characters in an HTTP request.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Luigi Auriemma" url="http://aluigi.altervista.org/adv/xinkaa-adv.txt"></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/14349">14349</ref><ref source="BID" url="http://www.securityfocus.com/bid/12606">12606</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/0189">ADV-2005-0189</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19404">xinkaa-web-directory-traversal(19404)</ref></refs><vuln_soft><prod name="Xinkaa WEB Station" vendor="Xinkaa WEB Station"><vers num="1.0.3"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-07-24" name="CVE-2005-0503" published="2005-02-21" seq="2005-0503" severity="Medium" type="CVE"><desc><descript source="cve">uim before 0.4.5.1 trusts certain environment variables when libUIM is used in setuid or setgid applications, which allows local users to gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="MLIST" url="http://lists.freedesktop.org/archives/uim/2005-February/000996.html">[uim] 20050220 uim 0.4.5.1 released</ref><ref adv="1" patch="1" source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:046">MDKSA-2005:046</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/12604">12604</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/13981">13981</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:046">MDKSA-2005:046</ref></refs><vuln_soft><prod name="Uim" vendor="Uim"><vers num="0.4.5"/></prod><prod name="Mandrake Linux" vendor="MandrakeSoft"><vers edition="x86_64" num="10.1"/><vers num="10.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-01-03" name="CVE-2005-0504" published="2005-03-14" seq="2005-0504" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in the MoxaDriverIoctl function for the moxa serial driver (moxa.c) in Linux 2.2.x, 2.4.x, and 2.6.x before 2.6.22 allows local users to execute arbitrary code via a certain modified length value.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="Netsys.com" url="http://lists.netsys.com/pipermail/full-disclosure/2005-January/030660.html"> grsecurity 2.1.0 release / 5 Linux, kernel, advisories</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/12195">bid 12195</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/18821">Linux kernel, MOXA serial driver buffer overflow</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-January/030660.html">20050107 grsecurity 2.1.0 release / 5 Linux kernel advisories</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013273">1013273</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-529.html">RHSA-2005:529</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-551.html">RHSA-2005:551</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-663.html">RHSA-2005:663</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/17002">17002</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1070">DSA-1070</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1067">DSA-1067</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1069">DSA-1069</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/20163">20163</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20202">20202</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1082">DSA-1082</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/1878">ADV-2005-1878</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/20338">20338</ref><ref source="" url="http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.22"></ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-508-1">USN-508-1</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/26651">26651</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2008-0237.html">RHSA-2008:0237</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.2"/><vers num="2.2.1"/><vers num="2.2.2"/><vers num="2.2.3"/><vers num="2.2.4"/><vers num="2.2.5"/><vers num="2.2.6"/><vers num="2.2.7"/><vers num="2.2.8"/><vers num="2.2.9"/><vers num="2.2.10"/><vers num="2.2.11"/><vers num="2.2.12"/><vers num="2.2.13"/><vers num="2.2.14"/><vers num="2.2.15 pre20"/><vers num="2.2.15 pre16"/><vers num="2.2.15"/><vers num="2.2.16 pre6"/><vers num="2.2.16"/><vers num="2.2.17"/><vers num="2.2.18"/><vers num="2.2.19"/><vers num="2.2.20"/><vers num="2.2.21"/><vers num="2.2.22"/><vers num="2.2.23"/><vers num="2.2.24"/><vers num="2.2.25"/><vers num="2.3"/><vers num="2.3.99 pre7"/><vers num="2.3.99 pre6"/><vers num="2.3.99 pre5"/><vers num="2.3.99 pre4"/><vers num="2.3.99 pre3"/><vers num="2.3.99 pre2"/><vers num="2.3.99 pre1"/><vers num="2.3.99"/><vers num="2.4.0 test9"/><vers num="2.4.0 test8"/><vers num="2.4.0 test7"/><vers num="2.4.0 test6"/><vers num="2.4.0 test5"/><vers num="2.4.0 test4"/><vers num="2.4.0 test3"/><vers num="2.4.0 test2"/><vers num="2.4.0 test12"/><vers num="2.4.0 test11"/><vers num="2.4.0 test10"/><vers num="2.4.0 test1"/><vers num="2.4.0"/><vers num="2.4.1"/><vers num="2.4.2"/><vers num="2.4.3"/><vers num="2.4.4"/><vers num="2.4.5"/><vers num="2.4.6"/><vers num="2.4.7"/><vers num="2.4.8"/><vers num="2.4.9"/><vers num="2.4.10"/><vers num="2.4.11"/><vers num="2.4.12"/><vers num="2.4.13"/><vers num="2.4.14"/><vers num="2.4.15"/><vers num="2.4.16"/><vers num="2.4.17"/><vers num="2.4.18 pre8"/><vers num="2.4.18 pre7"/><vers num="2.4.18 pre6"/><vers num="2.4.18 pre5"/><vers num="2.4.18 pre4"/><vers num="2.4.18 pre3"/><vers num="2.4.18 pre2"/><vers num="2.4.18 pre1"/><vers edition="x86" num="2.4.18"/><vers num="2.4.18"/><vers num="2.4.19 pre6"/><vers num="2.4.19 pre5"/><vers num="2.4.19 pre4"/><vers num="2.4.19 pre3"/><vers num="2.4.19 pre2"/><vers num="2.4.19 pre1"/><vers num="2.4.19"/><vers num="2.4.20"/><vers num="2.4.21 pre7"/><vers num="2.4.21 pre4"/><vers num="2.4.21 pre1"/><vers num="2.4.21"/><vers num="2.4.22"/><vers num="2.4.23 pre9"/><vers num="2.4.23 ow2"/><vers num="2.4.23"/><vers num="2.4.24 ow1"/><vers num="2.4.24"/><vers num="2.4.25"/><vers num="2.4.26"/><vers num="2.4.27 pre5"/><vers num="2.4.27 pre4"/><vers num="2.4.27 pre3"/><vers num="2.4.27 pre2"/><vers num="2.4.27 pre1"/><vers num="2.4.27"/><vers num="2.4.28"/><vers num="2.4.29 rc2"/><vers num="2.5.0"/><vers num="2.5.1"/><vers num="2.5.2"/><vers num="2.5.3"/><vers num="2.5.4"/><vers num="2.5.5"/><vers num="2.5.6"/><vers num="2.5.7"/><vers num="2.5.8"/><vers num="2.5.9"/><vers num="2.5.10"/><vers num="2.5.11"/><vers num="2.5.12"/><vers num="2.5.13"/><vers num="2.5.14"/><vers num="2.5.15"/><vers num="2.5.16"/><vers num="2.5.17"/><vers num="2.5.18"/><vers num="2.5.19"/><vers num="2.5.20"/><vers num="2.5.21"/><vers num="2.5.22"/><vers num="2.5.23"/><vers num="2.5.24"/><vers num="2.5.25"/><vers num="2.5.26"/><vers num="2.5.27"/><vers num="2.5.28"/><vers num="2.5.29"/><vers num="2.5.30"/><vers num="2.5.31"/><vers num="2.5.32"/><vers num="2.5.33"/><vers num="2.5.34"/><vers num="2.5.35"/><vers num="2.5.36"/><vers num="2.5.37"/><vers num="2.5.38"/><vers num="2.5.39"/><vers num="2.5.40"/><vers num="2.5.41"/><vers num="2.5.42"/><vers num="2.5.43"/><vers num="2.5.44"/><vers num="2.5.45"/><vers num="2.5.46"/><vers num="2.5.47"/><vers num="2.5.48"/><vers num="2.5.49"/><vers num="2.5.50"/><vers num="2.5.51"/><vers num="2.5.52"/><vers num="2.5.53"/><vers num="2.5.54"/><vers num="2.5.55"/><vers num="2.5.56"/><vers num="2.5.57"/><vers num="2.5.58"/><vers num="2.5.59"/><vers num="2.5.60"/><vers num="2.5.61"/><vers num="2.5.62"/><vers num="2.5.63"/><vers num="2.5.64"/><vers num="2.5.65"/><vers num="2.5.66"/><vers num="2.5.67"/><vers num="2.5.68"/><vers num="2.5.69"/><vers num="2.6.10"/><vers num="2.6 test9 CVS"/><vers num="2.6 test9"/><vers num="2.6 test8"/><vers num="2.6 test7"/><vers num="2.6 test6"/><vers num="2.6 test5"/><vers num="2.6 test4"/><vers num="2.6 test3"/><vers num="2.6 test2"/><vers num="2.6 test11"/><vers num="2.6 test10"/><vers num="2.6 test1"/><vers num="2.6"/><vers num="2.6.1 rc2"/><vers num="2.6.1 rc1"/><vers num="2.6.1"/><vers num="2.6.2"/><vers num="2.6.3"/><vers num="2.6.4"/><vers num="2.6.5"/><vers num="2.6.6 rc1"/><vers num="2.6.6"/><vers num="2.6.7 rc1"/><vers num="2.6.7"/><vers num="2.6.8 rc3"/><vers num="2.6.8 rc2"/><vers num="2.6.8 rc1"/><vers num="2.6.8"/><vers edition="2.6.20" num="2.6.9"/><vers num="2.6.10 rc2"/><vers num="2.6.21_rc7" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0505" published="2005-03-14" seq="2005-0505" severity="High" type="CVE"><desc><descript source="cve">Unknown vulnerability in Information Resource Manager (IRM) before 1.5.2.1 allows remote attackers has &quot;potentially serious&quot; impact, related to LDAP logins.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Sourceforge.net" url="http://sourceforge.net/project/shownotes.php?release_id=306629">Release Name: 1.5.2.1</ref><ref adv="1" patch="1" source="Secunia.com" url="http://secunia.com/advisories/14342">IRM LDAP Login Security Bypass Vulnerability</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/19419">IRM LDAP security bypass</ref></refs><vuln_soft><prod name="Information Resource Manager" vendor="StackWorks Enterprises"><vers num="1.5.1.4"/><vers num="1.5.1"/><vers num="1.5.0"/><vers num="1.4.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0506" published="2005-03-14" seq="2005-0506" severity="Medium" type="CVE"><desc><descript source="cve">The Avaya IP Office Phone Manager, and other products such as the IP Softphone, stores sensitive data in cleartext in a registry key, which allows local and possibly remote users to steal usernames and passwords and impersonate other users via keys such as Avaya\IP400\Generic.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110909733831694&amp;w=2">Avaya IP Office Phone Manager - Sensitive Information Cleartext</ref><ref adv="1" source="Avaya.com" url="http://support.avaya.com/elmodocs2/security/ASA-2005-041_Sensitive_Info_Leak.pdf">Sensitive information leakage</ref><ref adv="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110910486128709&amp;w=2">Re: Avaya IP Office Phone Manager - Sensitive Information Cleartext Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/19438">Avaya IP Softphone plaintext password</ref></refs><vuln_soft><prod name="IP Office Phone Manager" vendor="Avaya"><vers num=""/></prod><prod name="IP Softphone" vendor="Avaya"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0507" published="2005-03-14" seq="2005-0507" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in SD Server 4.0.70 and earlier allows remote attackers to read arbitrary files via .. sequences in an HTTP request.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=110901639709476&amp;w=2">SD Server 4.0.70 Directory Traversal Bug</ref><ref adv="1" patch="1" source="Secunia.com" url="http://secunia.com/advisories/14365">SD Server Directory Traversal Vulnerability</ref><ref source="CONFIRM" url="http://www.gdsoftware.dk/">http://www.gdsoftware.dk/</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110910535122762&amp;w=2">20050222 SD Server 4.0.70 Directory Traversal Bug</ref></refs><vuln_soft><prod name="SD Server" vendor="GD Software"><vers num="4.0.70"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0508" published="2005-03-14" seq="2005-0508" severity="Medium" type="CVE"><desc><descript source="cve">Unknown vulnerability in Squiggle for Batik before 1.5.1 allows attackers to bypass certain access controls via certain features of the Rhino scripting engine due to a &quot;script security issue.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" source="Apache.org" url="http://xml.apache.org/batik/SecurityWarning"></ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/12619">bid 12619</ref><ref adv="1" patch="1" source="Secunia.com" url="http://secunia.com/advisories/14336">Batik Squiggle Browser Unspecified Security Bypass</ref><ref source="CONFIRM" url="http://xml.apache.org/batik/#SecurityWarning">http://xml.apache.org/batik/#SecurityWarning</ref></refs><vuln_soft><prod name="Batik" vendor="Apache Software Foundation"><vers num="1.0"/><vers num="1.1"/><vers num="1.1.1"/><vers num="1.5"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-06-15" name="CVE-2005-0509" published="2005-03-14" seq="2005-0509" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in the Mono 1.0.5 implementation of ASP.NET (.Net) allow remote attackers to inject arbitrary HTML or web script via Unicode representations for ASCII fullwidth characters that are converted to normal ASCII characters, including &quot;&gt;&quot; and &quot;&lt;&quot;.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110867912714913&amp;w=2">XSS vulnerabilty in ASP.Net [with details]</ref><ref adv="1" patch="1" source="Secunia.com" url="http://secunia.com/advisories/14325">Mono ASP.NET Unicode Conversion Cross-Site Scripting</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110867912714913&amp;w=2">20050217 XSS vulnerabilty in ASP.Net [with details]</ref><ref source="MISC" url="http://it-project.ru/andir/docs/aspxvuln/aspxvuln.en.xml">http://it-project.ru/andir/docs/aspxvuln/aspxvuln.en.xml</ref></refs><vuln_soft><prod name=".NET Framework" vendor="Microsoft"><vers num="1.0"/><vers num="1.0 SP1"/><vers num="1.0 SP2"/><vers num="1.1"/><vers num="1.1 SP1"/></prod><prod name="Mono" vendor="Mono Project"><vers num="1.0.5"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0510" published="2005-03-14" seq="2005-0510" severity="Low" type="CVE"><desc><descript source="cve">The daemon for fallback-reboot before 0.995 allows attackers to cause a denial of service (daemon exit), possibly related to verbose debug messages when the daemon is not on a tty.</descript></desc><loss_types><avail/></loss_types><vuln_types><other/></vuln_types><range><local/></range><refs><ref adv="1" source="uci.edu" url="http://dcs.nac.uci.edu/~strombrg/fallback-reboot/"></ref><ref adv="1" patch="1" source="Secunia.com" url="http://secunia.com/advisories/14328">fallback-reboot Daemon Status Denial of Service Vulnerability</ref></refs><vuln_soft><prod name="fallback-reboot" vendor="fallback-reboot"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-28" name="CVE-2005-0511" published="2005-02-21" seq="2005-0511" severity="High" type="CVE"><desc><descript source="cve">misc.php for vBulletin 3.0.6 and earlier, when &quot;Add Template Name in HTML Comments&quot; is enabled, allows remote attackers to execute arbitrary PHP code via nested variables in the template parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110910899415763&amp;w=2">20050222 [SCAN Associates Security Advisory] vbulletin 3.0.6 and below php code injection</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14326">14326</ref><ref source="" url="http://www.vbulletin.com/forum/showthread.php?postid=819562"></ref><ref source="BID" url="http://www.securityfocus.com/bid/12622">12622</ref></refs><vuln_soft><prod name="vBulletin" vendor="Jelsoft"><vers num="3.0.6"/><vers num="3.0.5"/><vers num="3.0.4"/><vers num="3.0.3"/><vers num="3.0.2"/><vers num="3.0.1"/><vers num="3.0.0 RC4"/><vers num="3.0.0 can4"/><vers num="3.0.0 Beta 2"/><vers num="3.0.0"/><vers num="3.0 beta 2"/><vers num="2.3.4"/><vers num="2.3.3"/><vers num="2.3.0"/><vers num="2.2.9 can"/><vers num="2.2.8"/><vers num="2.2.7"/><vers num="2.2.6"/><vers num="2.2.5"/><vers num="2.2.4"/><vers num="2.2.3"/><vers num="2.2.2"/><vers num="2.2.1"/><vers num="2.2.0"/><vers num="2.0.2"/><vers num="2.0.1"/><vers num="2.0 beta 3"/><vers num="2.0 beta 2"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-28" name="CVE-2005-0512" published="2005-02-21" seq="2005-0512" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in Tar.php in Mambo 4.5.2 allows remote attackers to execute arbitrary PHP code by modifying the mosConfig_absolute_path parameter to reference a URL on a remote web server that contains the code, a different vulnerability than CVE-2004-1693.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="CONFIRM" url="http://mamboforge.net/frs/download.php/4043/Patch_4.5.2_to_4.5.2.1.zip">http://mamboforge.net/frs/download.php/4043/Patch_4.5.2_to_4.5.2.1.zip</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14337">14337</ref></refs><vuln_soft><prod name="Mambo" vendor="Mambo"><vers num="4.5.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-28" name="CVE-2005-0513" published="2005-02-19" seq="2005-0513" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in mail_autocheck.php in the Email This Entry add-on for pMachine Pro 2.4, and possibly other versions including pMachine Free, allows remote attackers to execute arbitrary PHP code by directly requesting mail_autocheck.php and modifying the pm_path parameter to reference a URL on a remote web server that contains the code, a different vulnerability than CVE-2003-1086.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=110883604531802&amp;w=2">20050219 pMachine Pro / pMachine Free Remote Code Execution</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/12597">12597</ref><ref source="BID" url="http://www.securityfocus.com/bid/15473">15473</ref></refs><vuln_soft><prod name="PMachine Pro" vendor="PMachine"><vers num="2.4"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0514" published="2005-02-22" seq="2005-0514" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Verity Ultraseek before 5.3.3 allows remote attackers to inject arbitrary HTML and web script via search parameters.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2004-December/030222.html">20041223 Cross-Site Scripting - an industry-wide problem</ref><ref adv="1" patch="1" source="MISC" url="http://www.mikx.de/index.php?p=6">http://www.mikx.de/index.php?p=6</ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/716144">VU#716144</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14367">14367</ref></refs><vuln_soft><prod name="Verity Ultraseek" vendor="Verity"><vers num="5.3.3"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0515" published="2005-05-18" seq="2005-0515" severity="Low" type="CVE"><desc><descript source="cve">Smc.exe in My Firewall Plus 5.0 build 1117, and possibly other versions, does not drop privileges before launching the Log Viewer export functionality, which allows local users to corrupt arbitrary files by saving log files.</descript></desc><loss_types><int/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="MISC" url="http://secunia.com/secunia_research/2004-20/advisory/">http://secunia.com/secunia_research/2004-20/advisory/</ref><ref adv="1" patch="1" source="CONFIRM" url="http://www.webroot.com/services/mfp_advisory.php">http://www.webroot.com/services/mfp_advisory.php</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/12842">12842</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/13577">13577</ref></refs><vuln_soft><prod name="My Firewall Plus" vendor="Webroot Software"><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0516" published="2005-02-23" seq="2005-0516" severity="High" type="CVE"><desc><descript source="cve">The ImageGalleryPlugin (ImageGalleryPlugin.pm) in Twiki allows remote attackers to execute arbitrary commands via certain commands that generate thumbnails.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110918725225288&amp;w=2">20050223 Robustness patch for TWiki, vulnerability in ImageGalleryPlugin</ref><ref adv="1" source="MISC" url="http://www.enyo.de/fw/security/notes/twiki-robustness.html">http://www.enyo.de/fw/security/notes/twiki-robustness.html</ref><ref adv="1" source="MISC" url="http://static.enyo.de/fw/patches/twiki/imagegallery-robustness-20041128.diff">http://static.enyo.de/fw/patches/twiki/imagegallery-robustness-20041128.diff</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14384">14384</ref></refs><vuln_soft><prod name="ImageGalleryPlugin" vendor="Twiki"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0517" published="2005-02-23" seq="2005-0517" severity="Low" type="CVE"><desc><descript source="cve">PeerFTP_5 stores sensitive information such as passwords in plaintext in the PeerFTP.ini files, which allows local users to gain privileges.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="MISC" url="http://securitytracker.com/id?1013263">http://securitytracker.com/id?1013263</ref></refs><vuln_soft><prod name="PeerFTP_5" vendor="PeerFTP_5"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0518" published="2005-02-23" seq="2005-0518" severity="Low" type="CVE"><desc><descript source="cve">eXeem 0.21 stores sensitive information such as passwords in plaintext in the Exeem registry key, which allows local users to gain privileges via the proxy_user and proxy_password values.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="MISC" url="http://securitytracker.com/id?1013266">http://securitytracker.com/id?1013266</ref></refs><vuln_soft><prod name="eXeem" vendor="eXeem"><vers num="0.21"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2007-01-24" name="CVE-2005-0519" published="2005-02-18" seq="2005-0519" severity="High" type="CVE"><desc><descript source="cve">ArGoSoft FTP Server before 1.4.2.7 allows remote attackers to read arbitrary files by uploading a ZIP file containing a shortcut (.LNK) file, using SITE UNZIP to extract the .LNK file onto the server, then accessing the file, a different vulnerability than CVE-2005-0520.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CONFIRM" url="http://www.argosoft.com/ftpserver/changelist.aspx">http://www.argosoft.com/ftpserver/changelist.aspx</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/14172">14172</ref><ref source="BID" url="http://www.securityfocus.com/bid/11589">11589</ref><ref source="OSVDB" url="http://www.osvdb.org/13614">13614</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17939">argosoft-ink-file-upload(17939)</ref><ref source="BID" url="http://www.securityfocus.com/bid/12487">12487</ref></refs><vuln_soft><prod name="FTP Server" vendor="ArGoSoft"><vers num="1.4.2.2"/><vers num="1.4.2.1"/><vers num="1.4.2"/><vers num="1.4.1.9"/><vers num="1.4.1.8"/><vers num="1.4.1.7"/><vers num="1.4.1.6"/><vers num="1.4.1.5"/><vers num="1.4.1.4"/><vers num="1.4.1.3"/><vers num="1.4.1.2"/><vers num="1.4.1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2007-01-24" name="CVE-2005-0520" published="2005-02-23" seq="2005-0520" severity="High" type="CVE"><desc><descript source="cve">ArGoSoft FTP Server before 1.4.2.8 allows remote attackers to read arbitrary files via shortcut (.LNK) files in the SITE COPY command, a different vulnerability than CVE-2005-0519.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CONFIRM" url="http://www.argosoft.com/ftpserver/changelist.aspx">http://www.argosoft.com/ftpserver/changelist.aspx</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14372">14372</ref><ref source="BID" url="http://www.securityfocus.com/bid/12632">12632</ref><ref source="OSVDB" url="http://www.osvdb.org/14061">14061</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19442">argosoft-site-copy-files(19442)</ref></refs><vuln_soft><prod name="FTP Server" vendor="ArGoSoft"><vers num="1.4.2.2"/><vers num="1.4.2.1"/><vers num="1.4.2"/><vers num="1.4.1.9"/><vers num="1.4.1.8"/><vers num="1.4.1.7"/><vers num="1.4.1.6"/><vers num="1.4.1.5"/><vers num="1.4.1.4"/><vers num="1.4.1.3"/><vers num="1.4.1.2"/><vers num="1.4.1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0521" published="2005-02-23" seq="2005-0521" severity="Low" type="CVE"><desc><descript source="cve">SendLink 1.5 stores sensitive information, possibly including passwords, in plaintext in the data.eat file, which allows local users to gain privileges.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="MISC" url="http://securitytracker.com/id?1013269">http://securitytracker.com/id?1013269</ref></refs><vuln_soft><prod name="SendLink" vendor="SendLink"><vers num="1.5"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0522" published="2005-05-02" seq="2005-0522" severity="Medium" type="CVE"><desc><descript source="cve">Chat Anywhere 2.72a stores sensitive information such as passwords in plaintext in the .INI file for a chatroom, which allows local users to gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="MISC" url="http://securitytracker.com/id?1013270">http://securitytracker.com/id?1013270</ref></refs><vuln_soft><prod name="Chat Anywhere" vendor="LionMax Software"><vers num="2.72a"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0523" published="2005-05-02" seq="2005-0523" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in ProZilla 1.3.7.3 and earlier allows remote attackers to execute arbitrary code via format string specifiers in the Location header.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MISC" url="http://www.securiteam.com/exploits/5WP082KEUW.html">http://www.securiteam.com/exploits/5WP082KEUW.html</ref><ref patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-719">DSA-719</ref><ref source="BID" url="http://www.securityfocus.com/bid/12635">12635</ref></refs><vuln_soft><prod name="ProZilla Download Accelerator" vendor="Prozilla"><vers num="1.3.6"/><vers num="1.3.5.2"/><vers num="1.3.5.1"/><vers num="1.3.5"/><vers num="1.3.4"/><vers num="1.3.3"/><vers num="1.3.2"/><vers num="1.3.1"/><vers num="1.3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0524" published="2005-05-02" seq="2005-0524" severity="Medium" type="CVE"><desc><descript source="cve">The php_handle_iff function in image.c for PHP 4.2.2, 4.3.9, 4.3.10 and 5.0.3, as reachable by the getimagesize PHP function, allows remote attackers to cause a denial of service (infinite loop) via a -8 size value.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="IDEFENSE" url="http://www.securityfocus.com/archive/1/394797">20050331 PHP getimagesize() Multiple Denial of Service Vulnerabilities</ref><ref patch="1" source="MISC" url="http://www.frsirt.com/english/advisories/2005/0305">http://www.frsirt.com/english/advisories/2005/0305</ref><ref patch="1" source="MISC" url="http://securitytracker.com/id?1013619">http://securitytracker.com/id?1013619</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/14792">14792</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19920">php-phphandleiff-dos(19920)</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200504-15.xml">GLSA-200504-15</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:072">MDKSA-2005:072</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-405.html">RHSA-2005:405</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-406.html">RHSA-2005:406</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/Jun/msg00000.html">APPLE-SA-2005-06-08</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:072">MDKSA-2005:072</ref><ref source="OSVDB" url="http://www.osvdb.org/15183">15183</ref></refs><vuln_soft><prod name="PHP" vendor="PHP"><vers num="4.2.0.2"/><vers num="4.3.9"/><vers num="4.3.10"/><vers num="5.0.0.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0525" published="2005-05-02" seq="2005-0525" severity="Medium" type="CVE"><desc><descript source="cve">The php_next_marker function in image.c for PHP 4.2.2, 4.3.9, 4.3.10 and 5.0.3, as reachable by the getimagesize PHP function, allows remote attackers to cause a denial of service (infinite loop) via a JPEG image with an invalid marker value, which causes a negative length value to be passed to php_stream_seek.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="IDEFENSE" url="http://www.securityfocus.com/archive/1/394797">20050331 PHP getimagesize() Multiple Denial of Service Vulnerabilities</ref><ref patch="1" source="MISC" url="http://www.frsirt.com/english/advisories/2005/0305">http://www.frsirt.com/english/advisories/2005/0305</ref><ref source="MISC" url="http://securitytracker.com/id?1013619">http://securitytracker.com/id?1013619</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/14792">14792</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200504-15.xml">GLSA-200504-15</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:072">MDKSA-2005:072</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-405.html">RHSA-2005:405</ref><ref patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-708">DSA-708</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-406.html">RHSA-2005:406</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-729">DSA-729</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/Jun/msg00000.html">APPLE-SA-2005-06-08</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:072">MDKSA-2005:072</ref><ref source="OSVDB" url="http://www.osvdb.org/15184">15184</ref></refs><vuln_soft><prod name="PHP" vendor="PHP"><vers num="4.2.0.2"/><vers num="4.3.9"/><vers num="4.3.10"/><vers num="5.0.0.3"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0526" published="2005-05-02" seq="2005-0526" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in PBLang 4.65 allow remote attackers to inject arbitrary web script or HTML via (1) the search string to search.php, (2) the subject of a PM, which is processed by pm.php, or (3) the body of a PM, which is processed by pmpshow.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110917768511595&amp;w=2">20050222 Software PBLang 4.65 pm.php XSS vulnerability</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110917702708589&amp;w=2">20050222 Software PBLang 4.65 pmpshow.php XSS vulnerability</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110917641105486&amp;w=2">20050222 Software PBLang 4.65 search.php XSS vulnerability</ref><ref source="MISC" url="http://securitytracker.com/id?1013277">http://securitytracker.com/id?1013277</ref></refs><vuln_soft><prod name="PBLang" vendor="PBLang"><vers num="4.65"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0527" published="2005-05-02" seq="2005-0527" severity="Medium" type="CVE"><desc><descript source="cve">Firefox 1.0 allows remote attackers to execute arbitrary code via plugins that load &quot;privileged content&quot; into frames, as demonstrated using certain XUL events when a user drags a scrollbar two times, aka &quot;Firescrolling.&quot;</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><access/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110935267500395&amp;w=2">20050225 Firescrolling [Firefox 1.0]</ref><ref source="MISC" url="http://www.mikx.de/?p=11">http://www.mikx.de/?p=11</ref><ref source="CONFIRM" url="http://www.mozilla.org/security/announce/mfsa2005-27.html">http://www.mozilla.org/security/announce/mfsa2005-27.html</ref><ref patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200503-10.xml">GLSA-200503-10</ref><ref patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200503-30.xml">GLSA-200503-30</ref><ref source="MISC" url="http://securitytracker.com/id?1013301">http://securitytracker.com/id?1013301</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval100031.html">OVAL100031</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-176.html">RHSA-2005:176</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-384.html">RHSA-2005:384</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100031">oval:org.mitre.oval:def:100031</ref></refs><vuln_soft><prod name="Firefox" vendor="Mozilla"><vers num="1.0"/></prod></vuln_soft></entry><entry discovered="2004-01-05" modified="2006-06-05" name="CVE-2005-0528" published="2005-12-31" reject="1" seq="2005-0528" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2003-0985.  Reason: This candidate is a duplicate of CVE-2003-0985.  Notes: All CVE users should reference CVE-2003-0985 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript></desc><refs/></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0529" published="2005-05-02" seq="2005-0529" severity="Low" type="CVE"><desc><descript source="cve">Linux kernel 2.6.10 and 2.6.11rc1-bk6 uses different size types for offset arguments to the proc_file_read and locks_read_proc functions, which leads to a heap-based buffer overflow when a signed comparison causes negative integers to be used in a positive context.</descript></desc><loss_types><conf/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref patch="1" source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=110846727602817&amp;w=2">20050215 linux kernel 2.6 fun. windoze is a joke</ref><ref patch="1" source="MISC" url="http://www.guninski.com/where_do_you_want_billg_to_go_today_3.html">http://www.guninski.com/where_do_you_want_billg_to_go_today_3.html</ref><ref source="CONFIRM" url="http://linux.bkbits.net:8080/linux-2.6/cset@4201818eC6aMn0x3GY_9rw3ueb2ZWQ">http://linux.bkbits.net:8080/linux-2.6/cset@4201818eC6aMn0x3GY_9rw3ueb2ZWQ</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/index.php?id=a&amp;anuncio=000930">CLA-2005:930</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_18_kernel.html">SUSE-SA:2005:018</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111091402626556&amp;w=2">20050315 [USN-95-1] Linux kernel vulnerabilities</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-366.html">RHSA-2005:366</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.6.10"/><vers num="2.6.11-rc1-bk6"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0530" published="2005-05-02" seq="2005-0530" severity="Low" type="CVE"><desc><descript source="cve">Signedness error in the copy_from_read_buf function in n_tty.c for Linux kernel 2.6.10 and 2.6.11rc1 allows local users to read kernel memory via a negative argument.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref patch="1" source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=110846727602817&amp;w=2">20050215 linux kernel 2.6 fun. windoze is a joke</ref><ref patch="1" source="MISC" url="http://www.guninski.com/where_do_you_want_billg_to_go_today_3.html">http://www.guninski.com/where_do_you_want_billg_to_go_today_3.html</ref><ref source="CONFIRM" url="http://linux.bkbits.net:8080/linux-2.6/cset@420181322LZmhPTewcCOLkubGwOL3w">http://linux.bkbits.net:8080/linux-2.6/cset@420181322LZmhPTewcCOLkubGwOL3w</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/index.php?id=a&amp;anuncio=000930">CLA-2005:930</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_18_kernel.html">SUSE-SA:2005:018</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111091402626556&amp;w=2">20050315 [USN-95-1] Linux kernel vulnerabilities</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-366.html">RHSA-2005:366</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.6.10"/><vers num="2.6.11-rc1-bk6"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0531" published="2005-05-02" seq="2005-0531" severity="Low" type="CVE"><desc><descript source="cve">The atm_get_addr function in addr.c for Linux kernel 2.6.10 and 2.6.11 before 2.6.11-rc4 may allow local users to trigger a buffer overflow via negative arguments.</descript></desc><loss_types><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=110846727602817&amp;w=2">20050215 linux kernel 2.6 fun. windoze is a joke</ref><ref adv="1" patch="1" source="MISC" url="http://www.guninski.com/where_do_you_want_billg_to_go_today_3.html">http://www.guninski.com/where_do_you_want_billg_to_go_today_3.html</ref><ref patch="1" source="CONFIRM" url="http://linux.bkbits.net:8080/linux-2.6/gnupatch@4208e1fcfccuD-eH2OGM5mBhihmQ3A">http://linux.bkbits.net:8080/linux-2.6/gnupatch@4208e1fcfccuD-eH2OGM5mBhihmQ3A</ref><ref patch="1" source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/index.php?id=a&amp;anuncio=000930">CLA-2005:930</ref><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111091402626556&amp;w=2">20050315 [USN-95-1] Linux kernel vulnerabilities</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-366.html">RHSA-2005:366</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.6.10"/><vers num="2.6.11"/><vers num="2.6.11 -rc1"/><vers num="2.6.11 -rc2"/><vers num="2.6.11 -rc3"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0532" published="2005-05-02" seq="2005-0532" severity="Low" type="CVE"><desc><descript source="cve">The reiserfs_copy_from_user_to_file_region function in reiserfs/file.c for Linux kernel 2.6.10 and 2.6.11 before 2.6.11-rc4, when running on 64-bit architectures, may allow local users to trigger a buffer overflow as a result of casting discrepancies between size_t and int data types.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=110846727602817&amp;w=2">20050215 linux kernel 2.6 fun. windoze is a joke</ref><ref adv="1" patch="1" source="MISC" url="http://www.guninski.com/where_do_you_want_billg_to_go_today_3.html">http://www.guninski.com/where_do_you_want_billg_to_go_today_3.html</ref><ref source="CONFIRM" url="http://linux.bkbits.net:8080/linux-2.6/cset@42018227TkNpHlX6BefnItV_GqMmzQ">http://linux.bkbits.net:8080/linux-2.6/cset@42018227TkNpHlX6BefnItV_GqMmzQ</ref><ref adv="1" patch="1" source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_18_kernel.html">SUSE-SA:2005:018</ref><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111091402626556&amp;w=2">20050315 [USN-95-1] Linux kernel vulnerabilities</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.6.10"/><vers num="2.6.11"/><vers num="2.6.11 -rc1"/><vers num="2.6.11 -rc2"/><vers num="2.6.11 -rc3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-05-01" name="CVE-2005-0533" published="2005-05-02" seq="2005-0533" severity="High" type="CVE"><desc><descript source="cve">Heap-based buffer overflow in Trend Micro AntiVirus Library VSAPI before 7.510, as used in multiple Trend Micro products, allows remote attackers to execute arbitrary code via a crafted ARJ file with long header file names that modify pointers within a structure.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS" url="http://xforce.iss.net/xforce/alerts/id/189">20050224 Trend Micro AntiVirus Library Heap Overflow</ref><ref patch="1" source="CONFIRM" url="http://www.trendmicro.com/vinfo/secadvisories/default6.asp?VName=Vulnerability+in+VSAPI+ARJ+parsing+could+allow+Remote+Code+execution">http://www.trendmicro.com/vinfo/secadvisories/default6.asp?VName=Vulnerability+in+VSAPI+ARJ+parsing+could+allow+Remote+Code+execution</ref><ref adv="1" patch="1" source="MISC" url="http://securitytracker.com/id?1013289">http://securitytracker.com/id?1013289</ref><ref adv="1" patch="1" source="MISC" url="http://securitytracker.com/id?1013290">http://securitytracker.com/id?1013290</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/12643">12643</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14396">14396</ref></refs><vuln_soft><prod name="OfficeScan" vendor="Trend Micro"><vers edition="Windows NT Server" num="Corporate 3.13"/><vers edition="Windows NT Server" num="Corporate 3.11"/><vers edition="Windows NT Server" num="Corporate 3.5"/><vers edition="Windows NT Server" num="Corporate 3.1.1"/><vers edition="Windows NT Server" num="Corporate 3.0"/><vers num="Corporate 6.5"/><vers num="Corporate 5.58"/><vers num="Corporate 5.5"/><vers num="Corporate 5.02"/><vers num="Corporate 3.54"/><vers num="Corporate 3.13"/><vers num="Corporate 3.11"/><vers num="Corporate 3.5"/><vers edition="Corporate" num="3.0"/></prod><prod name="InterScan WebManager" vendor="Trend Micro"><vers num="2.1"/><vers num="2.0"/><vers num="1.2"/></prod><prod name="ServerProtect" vendor="Trend Micro"><vers edition="Linux" num="2.5"/><vers edition="Linux" num="1.3"/><vers edition="Linux" num="1.25_2007-02-16"/><vers num="5.3.1"/></prod><prod name="Control Manager" vendor="Trend Micro"><vers edition="Windows" num="Gold"/><vers edition="Windows NT" num="Gold"/><vers edition="Solaris" num="Gold"/><vers edition="S_390" num="Gold"/><vers num="NetWare"/><vers edition="AS_400" num="Gold"/></prod><prod name="InterScan eManager" vendor="Trend Micro"><vers num="3.51 j"/><vers num="3.51"/><vers edition="Sun" num="3.6"/><vers edition="Linux" num="3.6"/><vers edition="Windows" num="3.5.2"/><vers edition="HP" num="3.5"/></prod><prod name="ScanMail" vendor="Trend Micro"><vers edition="Microsoft Exchange" num="6.1"/><vers edition="Microsoft Exchange" num="3.81"/><vers edition="Microsoft Exchange" num="3.8"/><vers edition="Lotus Domino on Windows" num="Gold"/><vers edition="Lotus Domino on Solaris" num="Gold"/><vers edition="Lotus Domino on S_390" num="Gold"/><vers edition="Lotus Domino on AS_400" num="Gold"/><vers edition="Lotus Domino on AIX" num="Gold"/><vers edition="Domino" num="2.51"/><vers edition="Domino" num="2.6"/></prod><prod name="Client-Server-Messaging Suite SMB" vendor="Trend Micro"><vers edition="Windows" num="Gold"/></prod><prod name="PortalProtect" vendor="Trend Micro"><vers num="1.0"/></prod><prod name="InterScan WebProtect" vendor="Trend Micro"><vers edition="ISA" num="Gold"/></prod><prod name="InterScan VirusWall" vendor="Trend Micro"><vers edition="Windows NT" num="5.1"/><vers edition="Windows NT" num="3.52 build1466"/><vers edition="Windows NT" num="3.52"/><vers edition="Windows NT" num="3.51"/><vers edition="Windows NT" num="3.6"/><vers edition="Windows NT" num="3.5"/><vers edition="Windows NT" num="3.4"/><vers edition="Windows" num="Gold"/><vers edition="Unix" num="3.6"/><vers edition="Unix" num="3.0.1"/><vers edition="Windows NT for SMB" num="Gold"/><vers edition="Linux for SMB" num="Gold"/><vers edition="SMB" num="Gold"/><vers edition="AIX" num="Gold"/><vers edition="Solaris" num="3.6"/><vers edition="Linux" num="3.6.5"/><vers edition="Linux" num="3.0.1"/><vers edition="HP_UX" num="3.6"/></prod><prod name="InterScan Web Security Suite" vendor="Trend Micro"><vers edition="Windows" num="Gold"/><vers edition="Solaris" num="Gold"/><vers edition="Linux" num="Gold"/></prod><prod name="ScanMail eManager" vendor="Trend Micro"><vers num=""/></prod><prod name="InterScan Messaging Security Suite" vendor="Trend Micro"><vers num="5.5"/><vers num="3.81"/><vers edition="Windows" num="Gold"/><vers edition="Solaris" num="Gold"/><vers edition="Linux" num="Gold"/></prod><prod name="Client-Server Suite SMB" vendor="Trend Micro"><vers edition="Windows" num="Gold"/></prod><prod name="PC-cillin" vendor="Trend Micro"><vers num="6.0"/><vers num="2003"/><vers num="2002"/><vers num="2000"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0534" published="2005-05-02" seq="2005-0534" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in MediaWiki 1.3.x before 1.3.11 and 1.4 beta before 1.4 rc1 allow remote attackers to inject arbitrary web script.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="CONFIRM" url="http://sourceforge.net/project/shownotes.php?release_id=307067">http://sourceforge.net/project/shownotes.php?release_id=307067</ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200502-33.xml">GLSA-200502-33</ref><ref adv="1" patch="1" source="MISC" url="http://securitytracker.com/id?1013260">http://securitytracker.com/id?1013260</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14360">14360</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200502-33.xml">GLSA-200502-33</ref></refs><vuln_soft><prod name="MediaWiki" vendor="MediaWiki"><vers num="1.3.10"/><vers num="1.3.9"/><vers num="1.3.8"/><vers num="1.3.7"/><vers num="1.3.6"/><vers num="1.3.5"/><vers num="1.3.4"/><vers num="1.3.3"/><vers num="1.3.2"/><vers num="1.3.1"/><vers num="1.3.0"/><vers num="1.4 beta1"/><vers num="1.4 beta2"/><vers num="1.4 beta3"/><vers num="1.4 beta4"/><vers num="1.4 beta5"/><vers num="1.4 beta6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0535" published="2005-02-22" seq="2005-0535" severity="High" type="CVE"><desc><descript source="cve">Cross-site request forgery (CSRF) vulnerability in MediaWiki 1.3.x before 1.3.11 and 1.4 beta before 1.4 rc1 allows remote attackers to perform unauthorized actions as authenticated MediaWiki users.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200502-33.xml">GLSA-200502-33</ref><ref adv="1" patch="1" source="MISC" url="http://securitytracker.com/id?1013260">http://securitytracker.com/id?1013260</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14360">14360</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200502-33.xml">GLSA-200502-33</ref></refs><vuln_soft><prod name="Linux" vendor="Gentoo"><vers num=""/></prod><prod name="MediaWiki" vendor="MediaWiki"><vers num="1.3.10"/><vers num="1.3.9"/><vers num="1.3.8"/><vers num="1.3.7"/><vers num="1.3.6"/><vers num="1.3.5"/><vers num="1.3.4"/><vers num="1.3.3"/><vers num="1.3.2"/><vers num="1.3.1"/><vers num="1.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0536" published="2005-05-02" seq="2005-0536" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in MediaWiki 1.3.x before 1.3.11 and 1.4 beta before 1.4 rc1 allows remote attackers to delete arbitrary files or determine file existence via a parameter related to image deletion.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="CONFIRM" url="http://sourceforge.net/project/shownotes.php?release_id=307067">http://sourceforge.net/project/shownotes.php?release_id=307067</ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200502-33.xml">GLSA-200502-33</ref><ref adv="1" patch="1" source="MISC" url="http://securitytracker.com/id?1013260">http://securitytracker.com/id?1013260</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14360">14360</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200502-33.xml">GLSA-200502-33</ref></refs><vuln_soft><prod name="MediaWiki" vendor="MediaWiki"><vers num="1.3.10"/><vers num="1.3.9"/><vers num="1.3.8"/><vers num="1.3.7"/><vers num="1.3.6"/><vers num="1.3.5"/><vers num="1.3.4"/><vers num="1.3.3"/><vers num="1.3.2"/><vers num="1.3.1"/><vers num="1.3.0"/><vers num="1.4 beta1"/><vers num="1.4 beta2"/><vers num="1.4 beta3"/><vers num="1.4 beta4"/><vers num="1.4 beta5"/><vers num="1.4 beta6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0537" published="2005-02-21" seq="2005-0537" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in page.php for iGeneric (iG) Shop 1.2 may allow remote attackers to execute arbitrary SQL statements via the (1) cats, (2) l_price, or (3) u_price parameters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110910607229970&amp;w=2">20050221 [NOBYTES.COM: #5] iGeneric eShop 1.2 - Information Disclosure &amp; Possible SQL Injection</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/14369">14369</ref><ref adv="1" source="MISC" url="http://securitytracker.com/id?1013268">http://securitytracker.com/id?1013268</ref></refs><vuln_soft><prod name="Free Shopping Cart" vendor="iGeneric"><vers num="1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0538" published="2005-05-02" seq="2005-0538" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in (1) GinpPictureServlet.java and (2) PicCollection.java in ginp (Java Photo Gallery Web Application) before 0.22 allows remote attackers to read arbitrary files.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="CONFIRM" url="http://sourceforge.net/project/shownotes.php?release_id=307518">http://sourceforge.net/project/shownotes.php?release_id=307518</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/14373">14373</ref></refs><vuln_soft><prod name="ginp" vendor="Ginp"><vers num="0.21"/><vers num="0.20"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0539" published="2005-05-02" seq="2005-0539" severity="Medium" type="CVE"><desc><descript source="cve">Unknown vulnerability in IBM Hardware Management Console (HMC) before 4.4 for POWER5 servers allows local users to gain privileges, related to the Guided Setup Wizard.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref patch="1" source="CONFIRM" url="http://techsupport.services.ibm.com/server/hmc/power5/fixes/ptf_MH00220.html">http://techsupport.services.ibm.com/server/hmc/power5/fixes/ptf_MH00220.html</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14377">14377</ref></refs><vuln_soft><prod name="Hardware Management Console" vendor="IBM"><vers num="4.2"/><vers num="4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0540" published="2005-05-02" seq="2005-0540" severity="Medium" type="CVE"><desc><descript source="cve">Cyclades AlterPath Manager (APM) Console Server 1.2.1 allows remote attackers to obtain sensitive information via a direct request to the /about.html page.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=110924450827137&amp;w=2">20050224 Cyclades AlterPath Manager Vulnerabilities</ref><ref adv="1" source="MISC" url="http://www.cirt.net/advisories/alterpath_disclosure.shtml">http://www.cirt.net/advisories/alterpath_disclosure.shtml</ref><ref source="OSVDB" url="http://www.osvdb.org/14073">14073</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/14378">14378</ref></refs><vuln_soft><prod name="AlterPath Manager" vendor="Cyclades"><vers num="1.2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0541" published="2005-05-02" seq="2005-0541" severity="High" type="CVE"><desc><descript source="cve">consoleConnect.jsp in Cyclades AlterPath Manager (APM) Console Server 1.2.1 allows remote attackers to connect to arbitrary consoles by modifying the consolename parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/><input/></vuln_types><range><network/></range><refs><ref adv="1" source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=110924450827137&amp;w=2">20050224 Cyclades AlterPath Manager Vulnerabilities</ref><ref adv="1" source="MISC" url="http://www.cirt.net/advisories/alterpath_console.shtml">http://www.cirt.net/advisories/alterpath_console.shtml</ref><ref source="OSVDB" url="http://www.osvdb.org/14075">14075</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/14378">14378</ref></refs><vuln_soft><prod name="AlterPath Manager" vendor="Cyclades"><vers num="1.2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0542" published="2005-05-02" seq="2005-0542" severity="Medium" type="CVE"><desc><descript source="cve">saveUser.do in Cyclades AlterPath Manager (APM) Console Server 1.2.1 allows local users to gain privileges by setting the adminUser parameter to true.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=110924450827137&amp;w=2">20050224 Cyclades AlterPath Manager Vulnerabilities</ref><ref adv="1" source="MISC" url="http://www.cirt.net/advisories/alterpath_privesc.shtml">http://www.cirt.net/advisories/alterpath_privesc.shtml</ref><ref source="OSVDB" url="http://www.osvdb.org/14074">14074</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/14378">14378</ref></refs><vuln_soft><prod name="AlterPath Manager" vendor="Cyclades"><vers num="1.2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0543" published="2005-02-24" seq="2005-0543" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in phpMyAdmin 2.6.1 allows remote attackers to inject arbitrary HTML and web script via (1) the strServer, cfg[BgcolorOne], or strServerChoice parameters in select_server.lib.php, (2) the bg_color or row_no parameters in display_tbl_links.lib.php, the left_font_family parameter in theme_left.css.php, or the right_font_family parameter in theme_right.css.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110929725801154&amp;w=2">20050224 [SECURITYREASON.COM] phpMyAdmin 2.6.1 Remote file inclusion and XSS cXIb8O3.4</ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200503-07.xml">GLSA-200503-07</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/12644">12644</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14382">14382</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19462">phpmyadmin-multiple-php-xss(19462)</ref></refs><vuln_soft><prod name="SuSE Linux" vendor="SuSE"><vers edition="x86_64" num="9.2"/><vers num="9.2"/><vers edition="x86_64" num="9.1"/><vers num="9.1"/><vers edition="x86_64" num="9.0"/><vers num="9.0"/><vers num="8.2"/></prod><prod name="phpMyAdmin" vendor="phpMyAdmin"><vers num="2.6.1 rc1"/><vers num="2.6.1"/><vers num="2.6.0 pl3"/><vers num="2.6.0 pl2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0544" published="2005-05-02" seq="2005-0544" severity="Medium" type="CVE"><desc><descript source="cve">phpMyAdmin 2.6.1 allows remote attackers to obtain the full path of the server via direct requests to (1) sqlvalidator.lib.php, (2) sqlparser.lib.php, (3) select_theme.lib.php, (4) select_lang.lib.php, (5) relation_cleanup.lib.php, (6) header_meta_style.inc.php, (7) get_foreign.lib.php, (8) display_tbl_links.lib.php, (9) display_export.lib.php, (10) db_table_exists.lib.php, (11) charset_conversion.lib.php, (12) ufpdf.php, (13) mysqli.dbi.lib.php, (14) setup.php, or (15) cookie.auth.lib.php, which reveals the path in a PHP error message.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14382">14382</ref><ref adv="1" source="CONFIRM" url="http://sourceforge.net/tracker/index.php?func=detail&amp;aid=1149383&amp;group_id=23067&amp;atid=377408">http://sourceforge.net/tracker/index.php?func=detail&amp;aid=1149383&amp;group_id=23067&amp;atid=377408</ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200503-07.xml">GLSA-200503-07</ref></refs><vuln_soft><prod name="phpMyAdmin" vendor="phpMyAdmin"><vers num="2.6.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0545" published="2005-05-02" seq="2005-0545" severity="High" type="CVE"><desc><descript source="cve">Microsoft Windows XP Pro SP2 and Windows 2000 Server SP4 running Active Directory allow local users to bypass group policies that restrict access to hidden drives by using the browse feature in Office 10 applications such as Word or Excel, or using a flash drive.  NOTE: this issue has been disputed in a followup post.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><exception/></vuln_types><range><local/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/391332">20050223 Office 10 applications &amp; flashdrives can be used to browse restricted drives</ref><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110935549821930&amp;w=2">20050225 Re: Office 10 applications &amp; flashdrives can be used to browse restricted</ref><ref source="BID" url="http://www.securityfocus.com/bid/12641">12641</ref></refs><vuln_soft><prod name="Windows XP" vendor="Microsoft"><vers edition="Gold" num="Professional"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num="Server SP4"/><vers num="Server SP3"/><vers num="Server SP2"/><vers num="Server SP1"/><vers num="Server"/><vers num="Professional SP4"/><vers num="Professional SP3"/><vers num="Professional SP2"/><vers num="Professional SP1"/><vers num="Professional"/><vers num="Datacenter Server SP4"/><vers num="Datacenter Server SP3"/><vers num="Datacenter Server SP2"/><vers num="Datacenter Server SP1"/><vers num="Datacenter Server"/><vers num="Advanced Server SP4"/><vers num="Advanced Server SP3"/><vers num="Advanced Server SP2"/><vers num="Advanced Server SP1"/><vers num="Advanced Server"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0546" published="2005-05-02" seq="2005-0546" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in Cyrus IMAPd before 2.2.11 may allow attackers to execute arbitrary code via (1) an off-by-one error in the imapd annotate extension, (2) an off-by-one error in &quot;cached header handling,&quot; (3) a stack-based buffer overflow in fetchnews, or (4) a stack-based buffer overflow in imapd.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref patch="1" source="MLIST" url="http://asg.web.cmu.edu/archive/message.php?mailbox=archive.info-cyrus&amp;msg=33723">[info-cyrus] 20050214 Cyrus IMAPd 2.2.11 Released</ref><ref adv="1" source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000937">CLA-2005:937</ref><ref adv="1" patch="1" source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200502-29.xml">GLSA-200502-29</ref><ref source="CONFIRM" url="http://bugs.gentoo.org/show_bug.cgi?id=82404">http://bugs.gentoo.org/show_bug.cgi?id=82404</ref><ref patch="1" source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:051">MDKSA-2005:051</ref><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110972236203397&amp;w=2">20050228 [USN-87-1] Cyrus IMAP server vulnerability</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14383">14383</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013278">1013278</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-408.html">RHSA-2005:408</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/430294/100/0/threaded">FLSA:156290</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:051">MDKSA-2005:051</ref><ref source="BID" url="http://www.securityfocus.com/bid/12636">12636</ref></refs><vuln_soft><prod name="IMAPd" vendor="Cyrus"><vers num="2.0.17"/><vers num="2.1.16"/><vers num="2.1.17"/><vers num="2.1.18"/><vers num="2.2.10"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0547" published="2005-02-24" seq="2005-0547" severity="Medium" type="CVE"><desc><descript source="cve">Unknown vulnerability in ftpd on HP-UX B.11.00, B.11.04, B.11.11, B.11.22, and B.11.23 allows remote authenticated users to gain &quot;unauthorized access to files.&quot;</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="HP" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110927245211549&amp;w=2">HPSBUX01119</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/12651">12651</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19467">hp-ux-ftpd-gain-access(19467)</ref></refs><vuln_soft><prod name="HP-UX" vendor="HP"><vers edition="IA64 64-bit" num="B.11.23"/><vers num="B.11.22"/><vers num="B.11.11"/><vers num="B.11.04"/><vers num="B.11.00"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0548" published="2005-03-07" seq="2005-0548" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Solaris AnswerBook2 Documentation 1.4.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the Search function.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111205163531628&amp;w=2">20050328 Multiple XSS issues in Sun AnswerBook2</ref><ref adv="1" source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57737-1">57737</ref></refs><vuln_soft><prod name="Solaris AnswerBook2" vendor="Sun"><vers num="1.4.4"/><vers num="1.4.3"/><vers num="1.4.2"/><vers num="1.4.1"/><vers num="1.4"/><vers num="1.3"/><vers num="1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0549" published="2005-05-02" seq="2005-0549" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Solaris AnswerBook2 Documentation 1.4.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the &quot;View Log Files&quot; function.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111205163531628&amp;w=2">20050328 Multiple XSS issues in Sun AnswerBook2</ref><ref adv="1" patch="1" source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57737-1">57737</ref></refs><vuln_soft><prod name="Solaris AnswerBook2 Documentation" vendor="Sun"><vers num="1.4.4" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0550" published="2005-05-02" seq="2005-0550" severity="Low" type="CVE"><desc><descript source="cve">Buffer overflow in Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2003 allows local users to cause a denial of service (i.e., system crash) via a malformed request, aka &quot;Object Management Vulnerability&quot;.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms05-018.mspx">MS05-018</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1271.html">OVAL1271</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval2043.html">OVAL2043</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval4397.html">OVAL4397</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval4832.html">OVAL4832</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1271">oval:org.mitre.oval:def:1271</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2043">oval:org.mitre.oval:def:2043</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4397">oval:org.mitre.oval:def:4397</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4832">oval:org.mitre.oval:def:4832</ref></refs><vuln_soft><prod name="Windows XP" vendor="Microsoft"><vers edition="Tablet PC" num="SP1"/><vers edition="Tablet PC" num="SP2"/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers num="R2"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0551" published="2005-05-02" seq="2005-0551" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in WINSRV.DLL in the Client Server Runtime System (CSRSS) process of Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2003 allows local users to gain privileges via a specially-designed application that provides console window information with a long FaceName value.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms05-018.mspx">MS05-018</ref><ref adv="1" patch="1" source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=230&amp;type=vulnerabilities">20050412 Microsoft Windows CSRSS.EXE Stack Overflow Vulnerability</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1822.html">OVAL1822</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval266.html">OVAL266</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval3544.html">OVAL3544</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval777.html">OVAL777</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1822">oval:org.mitre.oval:def:1822</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:266">oval:org.mitre.oval:def:266</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3544">oval:org.mitre.oval:def:3544</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:777">oval:org.mitre.oval:def:777</ref></refs><vuln_soft><prod name="Windows XP" vendor="Microsoft"><vers edition="Tablet PC" num="SP1"/><vers edition="Tablet PC" num="SP2"/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers num="R2"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0553" published="2005-05-02" seq="2005-0553" severity="Medium" type="CVE"><desc><descript source="cve">Race condition in the memory management routines in the DHTML object processor in Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via a malicious web page or HTML e-mail, aka &quot;DHTML Object Memory Corruption Vulnerability&quot;.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><race/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=228&amp;type=vulnerabilities">20050412 Microsoft Internet Explorer DHTML Engine Race Condition Vulnerability</ref><ref adv="1" patch="1" source="MS" url="http://www.microsoft.com/technet/Security/bulletin/ms05-020.mspx">MS05-020</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14922/">14922</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19831">ie-dhtml-bo(19831)</ref><ref adv="1" patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA05-102A.html">TA05-102A</ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/774338">VU#774338</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1695.html">OVAL1695</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval3100.html">OVAL3100</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval3752.html">OVAL3752</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval4874.html">OVAL4874</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval4985.html">OVAL4985</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1695">oval:org.mitre.oval:def:1695</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3100">oval:org.mitre.oval:def:3100</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3752">oval:org.mitre.oval:def:3752</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4874">oval:org.mitre.oval:def:4874</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4985">oval:org.mitre.oval:def:4985</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="5.01 SP3"/><vers num="5.01 SP4"/><vers num="5.5 SP2"/><vers edition="for Microsoft Windows Server 2003 SP1.0" num="6"/><vers edition="for Microsoft Windows Server 2003 SP1.0 SP1" num="6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0554" published="2005-05-02" seq="2005-0554" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the URL processor of Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a URL with a long hostname, aka &quot;URL Parsing Memory Corruption Vulnerability.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="MS" url="http://www.microsoft.com/technet/Security/bulletin/ms05-020.mspx">MS05-020</ref><ref adv="1" patch="1" source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=229&amp;type=vulnerabilities">20050412 Microsoft Windows Internet Explorer Long Hostname Heap Corruption Vulnerability</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14922/">14922</ref><ref adv="1" patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA05-102A.html">TA05-102A</ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/756122">VU#756122</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1196.html">OVAL1196</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval2253.html">OVAL2253</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval2559.html">OVAL2559</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval3817.html">OVAL3817</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval789.html">OVAL789</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1196">oval:org.mitre.oval:def:1196</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2253">oval:org.mitre.oval:def:2253</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2559">oval:org.mitre.oval:def:2559</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3817">oval:org.mitre.oval:def:3817</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:789">oval:org.mitre.oval:def:789</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="5.01"/><vers num="5.5"/><vers edition="for Microsoft Windows Server 2003 SP1.0" num="6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0555" published="2005-04-12" seq="2005-0555" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the Content Advisor in Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via a crafted Content Advisor file, aka &quot;Content Advisor Memory Corruption Vulnerability.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="MS" url="http://www.microsoft.com/technet/Security/bulletin/ms05-020.mspx">MS05-020</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14922/">14922</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19842">ie-content-advisor-bo(19842)</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA05-102A.html">TA05-102A</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/222050">VU#222050</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval2077.html">OVAL2077</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval2786.html">OVAL2786</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval3157.html">OVAL3157</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval3926.html">OVAL3926</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval4674.html">OVAL4674</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2077">oval:org.mitre.oval:def:2077</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2786">oval:org.mitre.oval:def:2786</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3157">oval:org.mitre.oval:def:3157</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3926">oval:org.mitre.oval:def:3926</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4674">oval:org.mitre.oval:def:4674</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="5.01"/><vers num="5.5"/><vers edition="for Microsoft Windows Server 2003 SP1.0" num="6"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0558" published="2005-05-02" seq="2005-0558" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in Microsoft Word 2000, Word 2002, and Word 2003 allows remote attackers to execute arbitrary code via a crafted document.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="MS" url="http://www.microsoft.com/technet/Security/bulletin/ms05-023.mspx">MS05-023</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19828">word-document-bo(19828)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1236.html">OVAL1236</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval2415.html">OVAL2415</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval2685.html">OVAL2685</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval4234.html">OVAL4234</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1236">oval:org.mitre.oval:def:1236</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2415">oval:org.mitre.oval:def:2415</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2685">oval:org.mitre.oval:def:2685</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4234">oval:org.mitre.oval:def:4234</ref></refs><vuln_soft><prod name="Word" vendor="Microsoft"><vers num="2000"/><vers num="2002"/><vers num="2003"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0560" published="2005-05-02" seq="2005-0560" severity="High" type="CVE"><desc><descript source="cve">Heap-based buffer overflow in the SvrAppendReceivedChunk function in xlsasink.dll in the SMTP service of Exchange Server 2000 and 2003 allows remote attackers to execute arbitrary code via a crafted X-LINK2STATE extended verb request to the SMTP port.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="MS" url="http://www.microsoft.com/technet/Security/bulletin/ms05-021.mspx">MS05-021</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14920/">14920</ref><ref source="OSVDB" url="http://www.osvdb.org/displayvuln.php?osvdb_id=15467">15467</ref><ref source="ISS" url="http://xforce.iss.net/xforce/alerts/id/193">20050412 Microsoft Exchange Remote Compromise</ref><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111393947713420&amp;w=2">20050419 MS05-021 Microsoft Exchange X-LINK2STATE Heap Overflow PoC</ref><ref adv="1" patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA05-102A.html">TA05-102A</ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/275193">VU#275193</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval4032.html">OVAL4032</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4032">oval:org.mitre.oval:def:4032</ref></refs><vuln_soft><prod name="exchange srv" vendor="Microsoft"><vers num="2000"/><vers num="2003"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0562" published="2005-04-12" seq="2005-0562" severity="High" type="CVE"><desc><descript source="cve">GIF file validation error in MSN Messenger 6.2 allows remote attackers in a user&apos;s contact list to execute arbitrary code via a GIF image with an improper height and width.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="MS" url="http://www.microsoft.com/technet/Security/bulletin/ms05-022.mspx">MS05-022</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14915/">14915</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19950">msn-messenger-gif-execute-code (19950)</ref><ref adv="1" patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA05-102A.html">TA05-102A</ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/633446">VU#633446</ref><ref adv="1" patch="1" sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval4927.html">OVAL4927</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4927">oval:org.mitre.oval:def:4927</ref></refs><vuln_soft><prod name="MSN Messenger Service" vendor="Microsoft"><vers num="6.2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-04-07" name="CVE-2005-0563" published="2005-06-14" seq="2005-0563" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Microsoft Outlook Web Access (OWA) component in Exchange Server 5.5 allows remote attackers to inject arbitrary web script or HTML via an email message with an encoded javascript: URL (&quot;jav&amp;#X41sc&amp;#0010;ript:&quot;) in an IMG tag.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=261&amp;type=vulnerabilities">20050614 Microsoft Outlook Web Access Cross-Site Scripting Vulnerability</ref><ref adv="1" patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms05-029.mspx">MS05-029</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15697">15697</ref></refs><vuln_soft><prod name="exchange srv" vendor="Microsoft"><vers num="5.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0564" published="2005-07-12" seq="2005-0564" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in Microsoft Word 2000 and Word 2002, and Microsoft Works Suites 2000 through 2004, might allow remote attackers to execute arbitrary code via a .doc file with long font information.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=281&amp;type=vulnerabilities">20050712 Microsoft Word 2000 and Word 2002 Font Parsing Buffer Overflow Vulnerability</ref><ref adv="1" patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms05-035.mspx">MS05-035</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1190.html">OVAL1190</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1331.html">OVAL1331</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA05-193A.html">TA05-193A</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/218621">VU#218621</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1190">oval:org.mitre.oval:def:1190</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1331">oval:org.mitre.oval:def:1331</ref></refs><vuln_soft><prod name="Word" vendor="Microsoft"><vers num="2000"/><vers num="2002"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0565" published="2005-05-02" seq="2005-0565" severity="High" type="CVE"><desc><descript source="cve">The Announce module in phpWebSite 0.10.0 and earlier allows remote attackers to execute arbitrary PHP code by setting the Image field to reference a PHP file whose name contains a .gif.php extension.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110928565530828&amp;w=2">20050224 phpWebSite-0.10.0_exploit</ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200503-04.xml">GLSA-200503-04</ref><ref adv="1" source="MISC" url="http://securitytracker.com/id?1013298">http://securitytracker.com/id?1013298</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14399">14399</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19482">phpwebsite-announce-execute-code(19482)</ref></refs><vuln_soft><prod name="phpWebSite" vendor="phpWebSite"><vers num="0.10.0"/><vers num="0.9.3.4"/><vers num="0.9.3.3"/><vers num="0.9.3.2"/><vers num="0.9.3.1"/><vers num="0.9.3"/><vers num="0.9.2.1"/><vers num="0.9.2"/><vers num="0.9.1"/><vers num="0.9.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-12-27" name="CVE-2005-0566" published="2005-01-22" seq="2005-0566" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Golden FTP Server Pro (goldenftpd) 2.x allows remote attackers to execute arbitrary code via a long RNTO command.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-January/031098.html">20050122 several BO&apos;s in goldenftpd</ref><ref adv="1" patch="1" source="MISC" url="http://www.goldenftpserver.com">http://www.goldenftpserver.com</ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/620862">VU#620862</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/12333">12333</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/13966/">13966</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19015">golden-ftp-rnto-bo(19015)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1012973">1012973</ref></refs><vuln_soft><prod name="Golden FTP Server" vendor="KMiNT21 Software"><vers num="1.31b"/><vers num="1.30b"/><vers num="1.20b"/><vers num="2.02b"/><vers num="1.00b"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-28" name="CVE-2005-0567" published="2005-05-02" seq="2005-0567" severity="High" type="CVE"><desc><descript source="cve">Multiple PHP remote file inclusion vulnerabilities in phpMyAdmin 2.6.1 allow remote attackers to execute arbitrary PHP code by modifying the (1) theme parameter to phpmyadmin.css.php or (2) cfg[Server][extension] parameter to database_interface.lib.php to reference a URL on a remote web server that contains the code.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110929725801154&amp;w=2">20050224 [SECURITYREASON.COM] phpMyAdmin 2.6.1 Remote file inclusion and XSS cXIb8O3.4</ref><ref adv="1" source="CONFIRM" url="http://www.phpmyadmin.net/home_page/security.php?issue=PMASA-2005-1">http://www.phpmyadmin.net/home_page/security.php?issue=PMASA-2005-1</ref><ref patch="1" source="CONFIRM" url="http://sourceforge.net/tracker/index.php?func=detail&amp;aid=1149381&amp;group_id=23067&amp;atid=377408">http://sourceforge.net/tracker/index.php?func=detail&amp;aid=1149381&amp;group_id=23067&amp;atid=377408</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/12645">12645</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14382/">14382</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19465">phpmyadmin-file-include(19465)</ref></refs><vuln_soft><prod name="phpMyAdmin" vendor="phpMyAdmin"><vers num="2.6.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0568" published="2005-05-02" seq="2005-0568" severity="Medium" type="CVE"><desc><descript source="cve">Soldier of Fortune II 1.03 gold allows remote attackers to cause a denial of service (application crash) via a large cl_guid value, which results in an invalid pointer dereference.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="Luigi Auriemma" url="http://aluigi.altervista.org/adv/sof2guidboom-adv.txt"></ref><ref adv="1" source="SecurityTracker" url="http://securitytracker.com/id?1013291">1013291</ref><ref source="BID" url="http://www.securityfocus.com/bid/12650">12650</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/13289">13289</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110927288423807&amp;w=2">20050224 In-game cl_guid crash in Soldier of Fortune II 1.03</ref></refs><vuln_soft><prod name="Soldier Of Fortune 2" vendor="Raven Software"><vers num="1.0.3"/><vers num="1.0.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0569" published="2005-05-02" seq="2005-0569" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in PunBB 1.2.1 allow remote attackers to execute arbitrary SQL commands via the (1) language parameter to register.php, (2) change email feature in profile.php, (3) posts or (4) topics parameter to moderate.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110927754230666&amp;w=2">20050224 Multiple vulns in punBB</ref><ref source="CONFIRM" url="http://www.punbb.org/changelogs/1.2.1_to_1.2.2.txt">http://www.punbb.org/changelogs/1.2.1_to_1.2.2.txt</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/12652">12652</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14394">14394</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14538">14538</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19473">punbb-multiple-sql-injection(19473)</ref></refs><vuln_soft><prod name="PunBB" vendor="PunBB"><vers num="1.2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0570" published="2005-05-02" seq="2005-0570" severity="Medium" type="CVE"><desc><descript source="cve">profile.php in PunBB 1.2.1 allows remote attackers to cause a denial of service (account lockout) by setting the user&apos;s password to NULL.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110927754230666&amp;w=2">20050224 Multiple vulns in punBB</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/12652">12652</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14394">14394</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19483">punbb-profile-dos(19483)</ref></refs><vuln_soft><prod name="PunBB" vendor="PunBB"><vers num="1.2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0571" published="2005-05-02" seq="2005-0571" severity="Medium" type="CVE"><desc><descript source="cve">admin_loader.php in PunBB 1.2.1 allows remote attackers to read arbitrary files via the plugin parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110927754230666&amp;w=2">20050224 Multiple vulns in punBB</ref><ref source="CONFIRM" url="http://www.punbb.org/changelogs/1.2.1_to_1.2.2.txt">http://www.punbb.org/changelogs/1.2.1_to_1.2.2.txt</ref><ref patch="1" source="CONFIRM" url="http://www.punbb.org/download/patch/punbb-1.2.1_to_1.2.2.patch">http://www.punbb.org/download/patch/punbb-1.2.1_to_1.2.2.patch</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14394">14394</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19478">punbb-file-disclosure(19478)</ref></refs><vuln_soft><prod name="PunBB" vendor="PunBB"><vers num="1.2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0572" published="2005-05-02" seq="2005-0572" severity="Medium" type="CVE"><desc><descript source="cve">index.php in phpWebSite 0.10.0 and earlier allows remote attackers to obtain sensitive information via an invalid SEA_search_module parameter, which reveals the path in a PHP error message.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110935172116369&amp;w=2">20050225 phpWebSite 0.10.0 Full Path disclosure</ref><ref adv="1" source="MISC" url="http://neossecurity.net/Advisories/Advisory-05.txt">http://neossecurity.net/Advisories/Advisory-05.txt</ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200503-04.xml">GLSA-200503-04</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19480">phpwebsite-search-path-disclosure(19480)</ref></refs><vuln_soft><prod name="phpWebSite" vendor="phpWebSite"><vers num="0.10.0"/><vers num="0.9.3.4"/><vers num="0.9.3.3"/><vers num="0.9.3.2"/><vers num="0.9.3.1"/><vers num="0.9.3"/><vers num="0.9.2.1"/><vers num="0.9.2"/><vers num="0.9.1"/><vers num="0.9.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0573" published="2005-05-02" seq="2005-0573" severity="Medium" type="CVE"><desc><descript source="cve">Gaim 1.1.3 on Windows systems allows remote attackers to cause a denial of service (client crash) via a file transfer in which the filename contains &quot;(&quot; or &quot;)&quot; (parenthesis) characters.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=110928380421841&amp;w=2">20050224 GAIM exploit</ref><ref adv="1" source="MISC" url="http://securitytracker.com/id?1013300">http://securitytracker.com/id?1013300</ref></refs><vuln_soft><prod name="Gaim" vendor="Rob Flynn"><vers num="1.1.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0574" published="2005-05-02" seq="2005-0574" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in CIS WebServer 3.5.13 allows remote attackers to read arbitrary files via .. (dot dot) sequences in the URL.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/391560">20050225 CIS WebServer Directory Traversal Bug</ref><ref source="BID" url="http://www.securityfocus.com/bid/12662">12662</ref></refs><vuln_soft><prod name="CIS WebServer" vendor="CIS"><vers num="3.5.13"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0575" published="2005-05-02" seq="2005-0575" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Stormy Studios Knet 1.04c and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long HTTP GET request.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110943766505666&amp;w=2">20050225 Knet &lt;= 1.04c Buffer Overflow Bug</ref><ref source="BID" url="http://www.securityfocus.com/bid/12671">12671</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/14400">14400</ref></refs><vuln_soft><prod name="KNet" vendor="Stormy Studios"><vers num="1.4c"/><vers num="1.4b"/><vers num="1.3"/><vers num="1.2"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="3.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="4.9" CVSS_score="3.6" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0576" published="2005-05-02" seq="2005-0576" severity="Low" type="CVE"><desc><descript source="cve">Unknown vulnerability in Standard Type Services Framework (STSF) Font Server Daemon (stfontserverd) in Solaris 9 allows local users to modify or delete arbitrary files.</descript></desc><loss_types><avail/><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/12656">12656</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14381">14381</ref><ref adv="1" patch="1" source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57738-1">57738</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers edition="x86" num="9.0"/><vers edition="SPARC" num="9.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0577" published="2005-05-02" seq="2005-0577" severity="Medium" type="CVE"><desc><descript source="cve">Format string vulnerability in DNA MKBold-MKItalic 0.06_1 and earlier allows remote attackers to execute arbitrary code via crafted BDF font files.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="CONFIRM" url="http://www.vuxml.org/freebsd/32d4f0f1-85c3-11d9-b6dc-0007e900f747.html">http://www.vuxml.org/freebsd/32d4f0f1-85c3-11d9-b6dc-0007e900f747.html</ref><ref patch="1" source="CONFIRM" url="http://www.freshports.org/x11-fonts/mkbold-mkitalic/">http://www.freshports.org/x11-fonts/mkbold-mkitalic/</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14398">14398</ref></refs><vuln_soft><prod name="MKBold-MKItalic" vendor="DNA"><vers num="0.06_1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0578" published="2005-05-02" seq="2005-0578" severity="Low" type="CVE"><desc><descript source="cve">Firefox before 1.0.1 and Mozilla Suite before 1.7.6 use a predictable filename for the plugin temporary directory, which allows local users to delete arbitrary files of other users via a symlink attack on the plugtmp directory.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="CONFIRM" url="http://www.mozilla.org/security/announce/mfsa2005-28.html">http://www.mozilla.org/security/announce/mfsa2005-28.html</ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200503-10.xml">GLSA-200503-10</ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200503-30.xml">GLSA-200503-30</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-176.html">RHSA-2005:176</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-384.html">RHSA-2005:384</ref><ref source="BID" url="http://www.securityfocus.com/bid/12659">12659</ref></refs><vuln_soft><prod name="Mozilla" vendor="Mozilla"><vers num="1.7.5"/><vers num="1.7.3"/><vers num="1.7.2"/><vers num="1.7.1"/><vers num="1.7 rc3"/><vers num="1.7 rc2"/><vers num="1.7 rc1"/><vers num="1.7 beta"/><vers num="1.7 alpha"/><vers num="1.7"/><vers num="1.6 beta"/><vers num="1.6 alpha"/><vers num="1.6"/><vers num="1.5.1"/><vers num="1.5 rc2"/><vers num="1.5 rc1"/><vers num="1.5 alpha"/><vers num="1.5"/><vers num="1.4a"/><vers num="1.4.1"/><vers num="1.4"/><vers num="1.3"/></prod><prod name="Firefox" vendor="Mozilla"><vers num="1.0"/><vers num="0.9.3"/><vers num="0.9.2"/><vers num="0.9.1"/><vers edition="rc" num="0.9"/><vers num="0.9"/><vers num="0.8"/><vers num="0.10.1"/><vers num="0.10"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0579" published="2005-02-25" seq="2005-0579" severity="Medium" type="CVE"><desc><descript source="cve">nxagent in FreeNX before 0.2.8 does not properly handle when the XAUTHORITY environment variable is not set, which allows local users to access the X server without X authentication.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" source="MLIST" url="http://mail.kde.org/pipermail/freenx-knx/2005-February/000734.html">[FreeNX-kNX] 20050217 Security: Serious bug in authority handling found and fixed</ref><ref adv="1" source="SUSE" url="http://www.linuxcompatible.org/story42495.html">SUSE-SR:2005:006</ref></refs><vuln_soft><prod name="FreeNX" vendor="FreeNX"><vers num="0.2.7"/><vers num="0.2.6"/><vers num="0.2.5"/><vers num="0.2.4"/><vers num="0.2.3"/><vers num="0.2.2"/><vers num="0.2.1"/><vers num="0.2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0580" published="2005-02-25" seq="2005-0580" severity="Low" type="CVE"><desc><descript source="cve">cmd5checkpw, when running setuid, does not properly drop privileges before calling the execvp function, which allows local users to read the poppasswd file.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200502-30.xml">GLSA-200502-30</ref></refs><vuln_soft><prod name="cmd5checkpw" vendor="Krzysztof Dabrowski"><vers num="0.22"/><vers num="0.21"/><vers num="0.20"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0581" published="2005-05-02" seq="2005-0581" severity="Medium" type="CVE"><desc><descript source="cve">Multiple buffer overflows in Computer Associates (CA) License Client and Server 0.1.0.15 allow remote attackers to execute arbitrary code via (1) certain long fields in the Checksum item in a GCR request, (2) a long IP address, hostname, or netmask values in a GCR request, (3) a long last parameter in a GETCONFIG packet, or (4) long values in a request with an invalid format.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=215&amp;type=vulnerabilities">20050302 Computer Associates License Client/Server GCR Checksum Buffer Overflow</ref><ref adv="1" patch="1" source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=214&amp;type=vulnerabilities">20050302 Computer Associates License Client/Server GCR Network Buffer Overflow</ref><ref adv="1" patch="1" source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=213&amp;type=vulnerabilities">20050302 Computer Associates License Client/Server GETCONFIG Buffer Overflow</ref><ref adv="1" patch="1" source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=210&amp;type=vulnerabilities">20050302 Computer Associates License Client and Server Invalid Command Buffer Overflow</ref><ref adv="1" patch="1" source="CONFIRM" url="http://supportconnectw.ca.com/public/ca_common_docs/security_notice.asp">http://supportconnectw.ca.com/public/ca_common_docs/security_notice.asp</ref><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110979326828704&amp;w=2">20050302 License Patches Are Now Available To Address Buffer Overflows</ref></refs><vuln_soft><prod name="License Client and Server" vendor="Computer Associates"><vers num="0.1.0.15"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0582" published="2005-05-02" seq="2005-0582" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Computer Associates (CA) License Client 0.1.0.15 allows remote attackers to execute arbitrary code via a long filename in a PUTOLF request.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=211&amp;type=vulnerabilities">20050302 Computer Associates License Client PUTOLF Buffer Overflow</ref><ref adv="1" patch="1" source="CONFIRM" url="http://supportconnectw.ca.com/public/ca_common_docs/security_notice.asp">http://supportconnectw.ca.com/public/ca_common_docs/security_notice.asp</ref><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110979326828704&amp;w=2">20050302 License Patches Are Now Available To Address Buffer Overflows</ref></refs><vuln_soft><prod name="License Client and Server" vendor="Computer Associates"><vers num="0.1.0.15"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0583" published="2005-05-02" seq="2005-0583" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in Computer Associates (CA) License Client 0.1.0.15 allows remote attackers to create arbitrary files via .. (dot dot) sequences in a PUTOLF request.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=212&amp;type=vulnerabilities">20050302 Computer Associates License Client PUTOLF Directory Traversal</ref><ref adv="1" patch="1" source="CONFIRM" url="http://supportconnectw.ca.com/public/ca_common_docs/security_notice.asp">http://supportconnectw.ca.com/public/ca_common_docs/security_notice.asp</ref><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110979326828704&amp;w=2">20050302 License Patches Are Now Available To Address Buffer Overflows</ref></refs><vuln_soft><prod name="License Client and Server" vendor="Computer Associates"><vers num="0.1.0.15"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0584" published="2005-05-02" seq="2005-0584" severity="Medium" type="CVE"><desc><descript source="cve">Firefox before 1.0.1 and Mozilla before 1.7.6, when displaying the HTTP Authentication dialog, do not change the focus to the tab that generated the prompt, which could facilitate spoofing and phishing attacks.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CONFIRM" url="https://bugzilla.mozilla.org/show_bug.cgi?id=277574">https://bugzilla.mozilla.org/show_bug.cgi?id=277574</ref><ref adv="1" source="CONFIRM" url="http://www.mozilla.org/security/announce/mfsa2005-24.html">http://www.mozilla.org/security/announce/mfsa2005-24.html</ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200503-10.xml">GLSA-200503-10</ref><ref adv="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200503-30.xml">GLSA-200503-30</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval100034.html">OVAL100034</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-176.html">RHSA-2005:176</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-384.html">RHSA-2005:384</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100034">oval:org.mitre.oval:def:100034</ref></refs><vuln_soft><prod name="Mozilla" vendor="Mozilla"><vers num="1.7.5"/><vers num="1.7.3"/><vers num="1.7.2"/><vers num="1.7.1"/><vers num="1.7 rc3"/><vers num="1.7 rc2"/><vers num="1.7 rc1"/><vers num="1.7 beta"/><vers num="1.7 alpha"/><vers num="1.7"/><vers num="1.6 beta"/><vers num="1.6 alpha"/><vers num="1.6"/><vers num="1.5.1"/><vers num="1.5 rc2"/><vers num="1.5 rc1"/><vers num="1.5 alpha"/><vers num="1.5"/><vers num="1.4a"/><vers num="1.4.1"/><vers num="1.4"/><vers num="1.3"/></prod><prod name="Firefox" vendor="Mozilla"><vers num="1.0"/><vers num="0.9.3"/><vers num="0.9.2"/><vers num="0.9.1"/><vers edition="rc" num="0.9"/><vers num="0.9"/><vers num="0.8"/><vers num="0.10.1"/><vers num="0.10"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0585" published="2005-03-25" seq="2005-0585" severity="Low" type="CVE"><desc><descript source="cve">Firefox before 1.0.1 and Mozilla before 1.7.6 truncates long sub-domains or paths for display, which may allow remote malicious web sites to spoof legitimate sites and facilitate phishing attacks.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="MISC" url="http://secunia.com/secunia_research/2004-15/advisory/">http://secunia.com/secunia_research/2004-15/advisory/</ref><ref adv="1" patch="1" source="CONFIRM" url="http://www.mozilla.org/security/announce/mfsa2005-23.html">http://www.mozilla.org/security/announce/mfsa2005-23.html</ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200503-10.xml">GLSA-200503-10</ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200503-30.xml">GLSA-200503-30</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/13599">13599</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval100035.html">OVAL100035</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-176.html">RHSA-2005:176</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-384.html">RHSA-2005:384</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100035">oval:org.mitre.oval:def:100035</ref></refs><vuln_soft><prod name="Mozilla" vendor="Mozilla"><vers num="1.7.5"/><vers num="1.7.3"/><vers num="1.7.2"/><vers num="1.7.1"/><vers num="1.7 rc3"/><vers num="1.7 rc2"/><vers num="1.7 rc1"/><vers num="1.7 beta"/><vers num="1.7 alpha"/><vers num="1.7"/><vers num="1.6 beta"/><vers num="1.6 alpha"/><vers num="1.6"/><vers num="1.5.1"/><vers num="1.5 rc2"/><vers num="1.5 rc1"/><vers num="1.5 alpha"/><vers num="1.5"/><vers num="1.4a"/><vers num="1.4.1"/><vers num="1.4"/><vers num="1.3"/></prod><prod name="Firefox" vendor="Mozilla"><vers num="1.0"/><vers num="0.9.3"/><vers num="0.9.2"/><vers num="0.9.1"/><vers edition="rc" num="0.9"/><vers num="0.9"/><vers num="0.8"/><vers num="0.10.1"/><vers num="0.10"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0586" published="2005-05-02" seq="2005-0586" severity="Low" type="CVE"><desc><descript source="cve">Firefox before 1.0.1 and Mozilla before 1.7.6 allows remote malicious web sites to spoof the extensions of files to download via the Content-Disposition header, which could be used to trick users into downloading dangerous content.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/13258">13258</ref><ref adv="1" source="CONFIRM" url="http://www.mozilla.org/security/announce/mfsa2005-22.html">http://www.mozilla.org/security/announce/mfsa2005-22.html</ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200503-10.xml">GLSA-200503-10</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval100036.html">OVAL100036</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-176.html">RHSA-2005:176</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-384.html">RHSA-2005:384</ref><ref source="BID" url="http://www.securityfocus.com/bid/12659">12659</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100036">oval:org.mitre.oval:def:100036</ref></refs><vuln_soft><prod name="Mozilla" vendor="Mozilla"><vers num="1.7.5"/><vers num="1.7.3"/><vers num="1.7.2"/><vers num="1.7.1"/><vers num="1.7 rc3"/><vers num="1.7 rc2"/><vers num="1.7 rc1"/><vers num="1.7 beta"/><vers num="1.7 alpha"/><vers num="1.7"/><vers num="1.6 beta"/><vers num="1.6 alpha"/><vers num="1.6"/><vers num="1.5.1"/><vers num="1.5 rc2"/><vers num="1.5 rc1"/><vers num="1.5 alpha"/><vers num="1.5"/><vers num="1.4a"/><vers num="1.4.1"/><vers num="1.4"/><vers num="1.3"/></prod><prod name="Firefox" vendor="Mozilla"><vers num="1.0"/><vers num="0.9.3"/><vers num="0.9.2"/><vers num="0.9.1"/><vers edition="rc" num="0.9"/><vers num="0.9"/><vers num="0.8"/><vers num="0.10.1"/><vers num="0.10"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0587" published="2005-03-25" seq="2005-0587" severity="Low" type="CVE"><desc><descript source="cve">Firefox before 1.0.1 and Mozilla before 1.7.6 allows remote malicious web sites to overwrite arbitrary files by tricking the user into downloading a .LNK (link) file twice, which overwrites the file that was referenced in the first .LNK file.</descript></desc><loss_types><int/></loss_types><vuln_types><exception/><other/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="CONFIRM" url="http://www.mozilla.org/security/announce/mfsa2005-21.html">http://www.mozilla.org/security/announce/mfsa2005-21.html</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval100037.html">OVAL100037</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_04_25.html">SUSE-SA:2006:022</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19823">19823</ref><ref source="BID" url="http://www.securityfocus.com/bid/12659">12659</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100037">oval:org.mitre.oval:def:100037</ref></refs><vuln_soft><prod name="Mozilla" vendor="Mozilla"><vers num="1.7.5"/><vers num="1.7.3"/><vers num="1.7.2"/><vers num="1.7.1"/><vers num="1.7 rc3"/><vers num="1.7 rc2"/><vers num="1.7 rc1"/><vers num="1.7 beta"/><vers num="1.7 alpha"/><vers num="1.7"/><vers num="1.6 beta"/><vers num="1.6 alpha"/><vers num="1.6"/><vers num="1.5.1"/><vers num="1.5 rc2"/><vers num="1.5 rc1"/><vers num="1.5 alpha"/><vers num="1.5"/><vers num="1.4a"/><vers num="1.4.1"/><vers num="1.4"/><vers num="1.3"/></prod><prod name="Firefox" vendor="Mozilla"><vers num="1.0"/><vers num="0.9.3"/><vers num="0.9.2"/><vers num="0.9.1"/><vers edition="rc" num="0.9"/><vers num="0.9"/><vers num="0.8"/><vers num="0.10.1"/><vers num="0.10"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0588" published="2005-05-02" seq="2005-0588" severity="Medium" type="CVE"><desc><descript source="cve">Firefox before 1.0.1 and Mozilla before 1.7.6 does not restrict xsl:include and xsl:import tags in XSLT stylesheets to the current domain, which allows remote attackers to determine the existence of files on the local system.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="CONFIRM" url="http://www.mozilla.org/security/announce/mfsa2005-20.html">http://www.mozilla.org/security/announce/mfsa2005-20.html</ref><ref patch="1" source="CONFIRM" url="https://bugzilla.mozilla.org/show_bug.cgi?id=271209">https://bugzilla.mozilla.org/show_bug.cgi?id=271209</ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200503-10.xml">GLSA-200503-10</ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200503-30.xml">GLSA-200503-30</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval100038.html">OVAL100038</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-176.html">RHSA-2005:176</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-384.html">RHSA-2005:384</ref><ref source="BID" url="http://www.securityfocus.com/bid/12659">12659</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100038">oval:org.mitre.oval:def:100038</ref></refs><vuln_soft><prod name="Mozilla" vendor="Mozilla"><vers num="1.7.5"/><vers num="1.7.3"/><vers num="1.7.2"/><vers num="1.7.1"/><vers num="1.7 rc3"/><vers num="1.7 rc2"/><vers num="1.7 rc1"/><vers num="1.7 beta"/><vers num="1.7 alpha"/><vers num="1.7"/><vers num="1.6 beta"/><vers num="1.6 alpha"/><vers num="1.6"/><vers num="1.5.1"/><vers num="1.5 rc2"/><vers num="1.5 rc1"/><vers num="1.5 alpha"/><vers num="1.5"/><vers num="1.4a"/><vers num="1.4.1"/><vers num="1.4"/><vers num="1.3"/></prod><prod name="Firefox" vendor="Mozilla"><vers num="1.0"/><vers num="0.9.3"/><vers num="0.9.2"/><vers num="0.9.1"/><vers edition="rc" num="0.9"/><vers num="0.9"/><vers num="0.8"/><vers num="0.10.1"/><vers num="0.10"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0589" published="2005-05-02" seq="2005-0589" severity="Medium" type="CVE"><desc><descript source="cve">The Form Fill feature in Firefox before 1.0.1 allows remote attackers to steal potentially sensitive information via an input control that monitors the values that are generated by the autocomplete capability.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="CONFIRM" url="http://www.mozilla.org/security/announce/mfsa2005-19.html">http://www.mozilla.org/security/announce/mfsa2005-19.html</ref><ref patch="1" source="CONFIRM" url="https://bugzilla.mozilla.org/show_bug.cgi?id=270697">https://bugzilla.mozilla.org/show_bug.cgi?id=270697</ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200503-10.xml">GLSA-200503-10</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval100039.html">OVAL100039</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-176.html">RHSA-2005:176</ref><ref source="BID" url="http://www.securityfocus.com/bid/12659">12659</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100039">oval:org.mitre.oval:def:100039</ref></refs><vuln_soft><prod name="Firefox" vendor="Mozilla"><vers num="1.0"/><vers num="0.9.3"/><vers num="0.9.2"/><vers num="0.9.1"/><vers edition="rc" num="0.9"/><vers num="0.9"/><vers num="0.8"/><vers num="0.10.1"/><vers num="0.10"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0590" published="2005-05-02" seq="2005-0590" severity="Medium" type="CVE"><desc><descript source="cve">The installation confirmation dialog in Firefox before 1.0.1, Thunderbird before 1.0.1, and Mozilla before 1.7.6 allows remote attackers to use InstallTrigger to spoof the hostname of the host performing the installation via a long &quot;user:pass&quot; sequence in the URL, which appears before the real hostname.</descript></desc><loss_types><int/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref adv="1" source="CONFIRM" url="http://www.mozilla.org/security/announce/mfsa2005-17.html">http://www.mozilla.org/security/announce/mfsa2005-17.html</ref><ref patch="1" source="CONFIRM" url="https://bugzilla.mozilla.org/show_bug.cgi?id=268059">https://bugzilla.mozilla.org/show_bug.cgi?id=268059</ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200503-10.xml">GLSA-200503-10</ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200503-30.xml">GLSA-200503-30</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval100041.html">OVAL100041</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-176.html">RHSA-2005:176</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-384.html">RHSA-2005:384</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_04_25.html">SUSE-SA:2006:022</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19823">19823</ref><ref source="BID" url="http://www.securityfocus.com/bid/12659">12659</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100041">oval:org.mitre.oval:def:100041</ref></refs><vuln_soft><prod name="Mozilla" vendor="Mozilla"><vers num="1.7.5"/><vers num="1.7.3"/><vers num="1.7.2"/><vers num="1.7.1"/><vers num="1.7 rc3"/><vers num="1.7 rc2"/><vers num="1.7 rc1"/><vers num="1.7 beta"/><vers num="1.7 alpha"/><vers num="1.7"/><vers num="1.6 beta"/><vers num="1.6 alpha"/><vers num="1.6"/><vers num="1.5.1"/><vers num="1.5 rc2"/><vers num="1.5 rc1"/><vers num="1.5 alpha"/><vers num="1.5"/><vers num="1.4a"/><vers num="1.4.1"/><vers num="1.4"/><vers num="1.3"/></prod><prod name="Thunderbird" vendor="Mozilla"><vers num="1.0"/><vers num="0.9"/><vers num="0.8"/><vers num="0.7.3"/><vers num="0.7.2"/><vers num="0.7.1"/><vers num="0.7"/><vers num="0.6"/><vers num="0.5"/><vers num="0.4"/><vers num="0.3"/><vers num="0.2"/><vers num="0.1"/></prod><prod name="Firefox" vendor="Mozilla"><vers num="1.0"/><vers num="0.9.3"/><vers num="0.9.2"/><vers num="0.9.1"/><vers edition="rc" num="0.9"/><vers num="0.9"/><vers num="0.8"/><vers num="0.10.1"/><vers num="0.10"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0591" published="2005-05-02" seq="2005-0591" severity="Low" type="CVE"><desc><descript source="cve">Firefox before 1.0.1 allows remote attackers to spoof the (1) security and (2) download modal dialog boxes, which could be used to trick users into executing script or downloading and executing a file, aka &quot;Firespoofing.&quot;</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110547286002188&amp;w=2">20050111 Firespoofing [Firefox 1.0]</ref><ref adv="1" source="MISC" url="http://www.mikx.de/index.php?p=7">http://www.mikx.de/index.php?p=7</ref><ref source="MISC" url="http://www.mikx.de/firespoofing/">http://www.mikx.de/firespoofing/</ref><ref adv="1" source="CONFIRM" url="http://www.mozilla.org/security/announce/mfsa2005-16.html">http://www.mozilla.org/security/announce/mfsa2005-16.html</ref><ref patch="1" source="CONFIRM" url="https://bugzilla.mozilla.org/show_bug.cgi?id=260560">https://bugzilla.mozilla.org/show_bug.cgi?id=260560</ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200503-10.xml">GLSA-200503-10</ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200503-30.xml">GLSA-200503-30</ref><ref source="BID" url="http://www.securityfocus.com/bid/12234">12234</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13786">13786</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18864">web-browser-modal-spoofing(18864)</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-176.html">RHSA-2005:176</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-384.html">RHSA-2005:384</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100042">oval:org.mitre.oval:def:100042</ref></refs><vuln_soft><prod name="Firefox" vendor="Mozilla"><vers num="1.0"/><vers num="0.9.3"/><vers num="0.9.2"/><vers num="0.9.1"/><vers edition="rc" num="0.9"/><vers num="0.9"/><vers num="0.8"/><vers num="0.10.1"/><vers num="0.10"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0592" published="2005-03-25" seq="2005-0592" severity="High" type="CVE"><desc><descript source="cve">Heap-based buffer overflow in the UTF8ToNewUnicode function for Firefox before 1.0.1 and Mozilla before 1.7.6 might allow remote attackers to cause a denial of service (crash) or execute arbitrary code via invalid sequences in a UTF8 encoded string that result in a zero length value.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="CONFIRM" url="http://www.mozilla.org/security/announce/mfsa2005-15.html">http://www.mozilla.org/security/announce/mfsa2005-15.html</ref><ref adv="1" source="CONFIRM" url="https://bugzilla.mozilla.org/show_bug.cgi?id=241440">https://bugzilla.mozilla.org/show_bug.cgi?id=241440</ref><ref adv="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200503-10.xml">GLSA-200503-10</ref><ref adv="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200503-30.xml">GLSA-200503-30</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval100043.html">OVAL100043</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-176.html">RHSA-2005:176</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_04_25.html">SUSE-SA:2006:022</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19823">19823</ref><ref source="BID" url="http://www.securityfocus.com/bid/12659">12659</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100043">oval:org.mitre.oval:def:100043</ref></refs><vuln_soft><prod name="Mozilla" vendor="Mozilla"><vers num="1.7.5"/><vers num="1.7.3"/><vers num="1.7.2"/><vers num="1.7.1"/><vers num="1.7 rc3"/><vers num="1.7 rc2"/><vers num="1.7 rc1"/><vers num="1.7 beta"/><vers num="1.7 alpha"/><vers num="1.7"/><vers num="1.6 beta"/><vers num="1.6 alpha"/><vers num="1.6"/><vers num="1.5.1"/><vers num="1.5 rc2"/><vers num="1.5 rc1"/><vers num="1.5 alpha"/><vers num="1.5"/><vers num="1.4a"/><vers num="1.4.1"/><vers num="1.4"/><vers num="1.3"/></prod><prod name="Firefox" vendor="Mozilla"><vers num="1.0"/><vers num="0.9.3"/><vers num="0.9.2"/><vers num="0.9.1"/><vers edition="rc" num="0.9"/><vers num="0.9"/><vers num="0.8"/><vers num="0.10.1"/><vers num="0.10"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0593" published="2005-03-04" seq="2005-0593" severity="Low" type="CVE"><desc><descript source="cve">Firefox before 1.0.1 and Mozilla before 1.7.6 allows remote attackers to spoof the SSL &quot;secure site&quot; lock icon via (1) a web site that does not finish loading, which shows the lock of the previous site, (2) a non-HTTP server that uses SSL, which causes the lock to be displayed when the SSL handshake is completed, or (3) a URL that generates an HTTP 204 error, which updates the icon and location information but does not change the display of the original site.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/><user_init/></range><refs><ref source="CONFIRM" url="http://www.mozilla.org/security/announce/mfsa2005-14.html">http://www.mozilla.org/security/announce/mfsa2005-14.html</ref><ref adv="1" source="CONFIRM" url="https://bugzilla.mozilla.org/show_bug.cgi?id=258048">https://bugzilla.mozilla.org/show_bug.cgi?id=258048</ref><ref adv="1" source="CONFIRM" url="https://bugzilla.mozilla.org/show_bug.cgi?id=268483">https://bugzilla.mozilla.org/show_bug.cgi?id=268483</ref><ref adv="1" source="CONFIRM" url="https://bugzilla.mozilla.org/show_bug.cgi?id=277564">https://bugzilla.mozilla.org/show_bug.cgi?id=277564</ref><ref adv="1" source="CONFIRM" url="https://bugzilla.mozilla.org/show_bug.cgi?id=276720">https://bugzilla.mozilla.org/show_bug.cgi?id=276720</ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200503-10.xml">GLSA-200503-10</ref><ref adv="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200503-30.xml">GLSA-200503-30</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval100044.html">OVAL100044</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-176.html">RHSA-2005:176</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-384.html">RHSA-2005:384</ref><ref source="BID" url="http://www.securityfocus.com/bid/12659">12659</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100044">oval:org.mitre.oval:def:100044</ref></refs><vuln_soft><prod name="Mozilla" vendor="Mozilla"><vers num="1.7.5"/><vers num="1.7.3"/><vers num="1.7.2"/><vers num="1.7.1"/><vers num="1.7 rc3"/><vers num="1.7 rc2"/><vers num="1.7 rc1"/><vers num="1.7 beta"/><vers num="1.7 alpha"/><vers num="1.7"/><vers num="1.6 beta"/><vers num="1.6 alpha"/><vers num="1.6"/><vers num="1.5.1"/><vers num="1.5 rc2"/><vers num="1.5 rc1"/><vers num="1.5 alpha"/><vers num="1.5"/><vers num="1.4a"/><vers num="1.4.1"/><vers num="1.4"/><vers num="1.3"/></prod><prod name="Firefox" vendor="Mozilla"><vers num="1.0"/><vers num="0.9.3"/><vers num="0.9.2"/><vers num="0.9.1"/><vers edition="rc" num="0.9"/><vers num="0.9"/><vers num="0.8"/><vers num="0.10.1"/><vers num="0.10"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0594" published="2005-05-04" seq="2005-0594" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the Netinfo Setup Tool (NeST) allows local users to execute arbitrary code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/May/msg00001.html">APPLE-SA-2005-05-03</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA05-136A.html">TA05-136A</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/354486">VU#354486</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.3.9"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-08-23" name="CVE-2005-0595" published="2005-05-02" seq="2005-0595" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in ext.dll in BadBlue 2.55 allows remote attackers execute arbitrary code via a long mfcisapicommand parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref patch="1" source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2005-02/0599.html">20050226 Badblue HTTP Server, ext.dll buffer overflow</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/12673">12673</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14405">14405</ref></refs><vuln_soft><prod name="BadBlue" vendor="Working Resources Inc."><vers num="2.55"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0596" published="2005-05-02" seq="2005-0596" severity="Low" type="CVE"><desc><descript source="cve">PHP 4 (PHP4) allows attackers to cause a denial of service (daemon crash) by using the readfile function on a file whose size is a multiple of the page size.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><local/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/12665">12665</ref><ref adv="1" source="SUSE" url="http://www.linuxcompatible.org/story42495.html">SUSE-SR:2005:006</ref></refs><vuln_soft><prod name="PHP" vendor="PHP"><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0597" published="2005-05-02" seq="2005-0597" severity="Medium" type="CVE"><desc><descript source="cve">Cisco devices running Application and Content Networking System (ACNS) 5.0 before 5.0.17.6 and 5.1 before 5.1.11.6 allow remote attackers to cause a denial of service (process restart) via a &quot;crafted TCP connection.&quot;</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-sa-20050224-acnsdos.shtml">20050224 ACNS Denial of Service and Default Admin Password Vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/12648">12648</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/14395">14395</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19466">cisco-tcp-acns-dos(19466)</ref></refs><vuln_soft><prod name="Application &amp; Content Networking Software" vendor="Cisco"><vers num="5.0.17.5" prev="1"/><vers num="5.1.11.5" prev="1"/><vers num="5.0.5"/><vers num="5.0.3"/><vers num="5.0.1"/><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0598" published="2005-02-24" seq="2005-0598" severity="Medium" type="CVE"><desc><descript source="cve">The RealServer RealSubscriber on Cisco devices running Application and Content Networking System (ACNS) 5.1 allow remote attackers to cause a denial of service (CPU consumption) via malformed packets.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/><env/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-sa-20050224-acnsdos.shtml">20050224 ACNS Denial of Service and Default Admin Password Vulnerabilities</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/579240">VU#579240</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/12648">12648</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14395">14395</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19469">cisco-realserver-realsubscriber-dos(19469)</ref></refs><vuln_soft><prod name="Content Delivery Manager" vendor="Cisco"><vers num="4650"/><vers num="4630"/></prod><prod name="Content Router" vendor="Cisco"><vers num="4450"/><vers num="4430 4.1"/><vers num="4430 4.0"/><vers num="4430"/></prod><prod name="Content Engine" vendor="Cisco"><vers num="7325"/><vers num="7320 4.1"/><vers num="7320 4.0"/><vers num="7320 3.1"/><vers num="7320 2.2 .0"/><vers num="7320"/><vers num="590 4.1"/><vers num="590 4.0"/><vers num="590 3.1"/><vers num="590 2.2 .0"/><vers num="590"/><vers num="565"/><vers num="560 4.1"/><vers num="560 4.0"/><vers num="560 3.1"/><vers num="560 2.2 .0"/><vers num="560"/><vers num="510"/><vers num="507 4.1"/><vers num="507 4.0"/><vers num="507 3.1"/><vers num="507 2.2 .0"/><vers num="507"/></prod><prod name="Content Distribution Manager" vendor="Cisco"><vers num="4670"/><vers num="4650 4.1"/><vers num="4650 4.0"/><vers num="4650"/><vers num="4630 4.1"/><vers num="4630 4.0"/><vers num="4630"/></prod><prod name="Application &amp; Content Networking Software" vendor="Cisco"><vers num="(ACNS)"/><vers num="5.1"/><vers num="5.0.5"/><vers num="5.0.3"/><vers num="5.0.1"/><vers num="5.0"/><vers num="4.2.11"/><vers num="4.2.9"/><vers num="4.2"/><vers num="4.1.3"/><vers num="4.1.1"/><vers num="4.0.3"/></prod><prod name="Content Engine Module for Cisco Router" vendor="Cisco"><vers num="3800 Series"/><vers num="3700 Series"/><vers num="3600 Series"/><vers num="2800 Series"/><vers num="2600 Series"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0599" published="2005-05-02" seq="2005-0599" severity="Medium" type="CVE"><desc><descript source="cve">Cisco devices running Application and Content Networking System (ACNS) 4.x, 5.0, or 5.1 before 5.1.11.6 allow remote attackers to cause a denial of service (CPU consumption) via malformed IP packets.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-sa-20050224-acnsdos.shtml">20050224 ACNS Denial of Service and Default Admin Password Vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/12648">12648</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/14395">14395</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19468">cisco-ip-packet-dos(19468)</ref><ref adv="1" source="USCERT" url="http://www.kb.cert.org/vuls/id/360296">Cisco ACNS may be vulnerable to DoS via malformed IP packets</ref></refs><vuln_soft><prod name="Application &amp; Content Networking Software" vendor="Cisco"><vers num="5.0.5"/><vers num="5.0.3"/><vers num="5.0.1"/><vers num="5.0"/><vers num="5.1.11.5" prev="1"/><vers num="4.2.11"/><vers num="4.2.9"/><vers num="4.2"/><vers num="4.1.3"/><vers num="4.1.1"/><vers num="4.0.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0600" published="2005-02-24" seq="2005-0600" severity="Medium" type="CVE"><desc><descript source="cve">Cisco devices running Application and Content Networking System (ACNS) 5.0, 5.1 before 5.1.13.7, or 5.2 before 5.2.3.9 allow remote attackers to cause a denial of service (bandwidth consumption) via &quot;crafted IP packets&quot; that are continuously forwarded.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-sa-20050224-acnsdos.shtml">20050224 ACNS Denial of Service and Default Admin Password Vulnerabilities</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/12648">12648</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14395">14395</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19470">cisco-acns-dos(19470)</ref></refs><vuln_soft><prod name="Content Delivery Manager" vendor="Cisco"><vers num="4650"/><vers num="4630"/></prod><prod name="Content Router" vendor="Cisco"><vers num="4450"/><vers num="4430 4.1"/><vers num="4430 4.0"/><vers num="4430"/></prod><prod name="Content Engine" vendor="Cisco"><vers num="7325"/><vers num="7320 4.1"/><vers num="7320 4.0"/><vers num="7320 3.1"/><vers num="7320 2.2 .0"/><vers num="7320"/><vers num="590 4.1"/><vers num="590 4.0"/><vers num="590 3.1"/><vers num="590 2.2 .0"/><vers num="590"/><vers num="565"/><vers num="560 4.1"/><vers num="560 4.0"/><vers num="560 3.1"/><vers num="560 2.2 .0"/><vers num="560"/><vers num="510"/><vers num="507 4.1"/><vers num="507 4.0"/><vers num="507 3.1"/><vers num="507 2.2 .0"/><vers num="507"/></prod><prod name="Content Distribution Manager" vendor="Cisco"><vers num="4670"/><vers num="4650 4.1"/><vers num="4650 4.0"/><vers num="4650"/><vers num="4630 4.1"/><vers num="4630 4.0"/><vers num="4630"/></prod><prod name="Application &amp; Content Networking Software" vendor="Cisco"><vers num="(ACNS)"/><vers num="5.1"/><vers num="5.0.5"/><vers num="5.0.3"/><vers num="5.0.1"/><vers num="5.0"/><vers num="4.2.11"/><vers num="4.2.9"/><vers num="4.2"/><vers num="4.1.3"/><vers num="4.1.1"/><vers num="4.0.3"/></prod><prod name="Content Engine Module for Cisco Router" vendor="Cisco"><vers num="3800 Series"/><vers num="3700 Series"/><vers num="3600 Series"/><vers num="2800 Series"/><vers num="2600 Series"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0601" published="2005-05-02" seq="2005-0601" severity="High" type="CVE"><desc><descript source="cve">Cisco devices running Application and Content Networking System (ACNS) 4.x, 5.0, 5.1, or 5.2 use a default password when the setup dialog has not been run, which allows remote attackers to gain access.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-sa-20050224-acnsdos.shtml">20050224 ACNS Denial of Service and Default Admin Password Vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/12648">12648</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/14395">14395</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19471">cisco-acns-gain-access(19471)</ref></refs><vuln_soft><prod name="Application &amp; Content Networking Software" vendor="Cisco"><vers num="5.2"/><vers num="5.1"/><vers num="5.0.5"/><vers num="5.0.3"/><vers num="5.0.1"/><vers num="5.0"/><vers num="4.2.11"/><vers num="4.2.9"/><vers num="4.2"/><vers num="4.1.3"/><vers num="4.1.1"/><vers num="4.0.3"/></prod></vuln_soft></entry><entry CVSS_base_score="6.2" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="10.0" CVSS_score="6.2" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0602" published="2005-05-02" seq="2005-0602" severity="Medium" type="CVE"><desc><descript source="cve">Unzip 5.51 and earlier does not properly warn the user when extracting setuid or setgid files, which may allow local users to gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><access/></vuln_types><range><local/><user_init/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110960796331943&amp;w=2">20050228 7a69Adv#22 - UNIX unzip keep setuid and setgid files</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2005:197">MDKSA-2005:197</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2005/0053/">2005-0053</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17045">17045</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17342">17342</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:197">MDKSA-2005:197</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-103150-1">103150</ref><ref source="BID" url="http://www.securityfocus.com/bid/14447">14447</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/3866">ADV-2007-3866</ref><ref source="SECUNIA" url="http://secunia.com/advisories/27684">27684</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-200844-1">200844</ref></refs><vuln_soft><prod name="UnZip" vendor="Info-Zip"><vers num="5.51" prev="1"/><vers num="5.50"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0603" published="2005-02-28" seq="2005-0603" severity="Medium" type="CVE"><desc><descript source="cve">viewtopic.php in phpBB 2.0.12 and earlier allows remote attackers to obtain sensitive information via a highlight parameter containing invalid regular expression syntax, which reveals the path in a PHP error message.</descript></desc><loss_types><conf/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110943646112950&amp;w=2">20050225 -==phpBB 2.0.12 Full path disclosure==-</ref><ref adv="1" patch="1" source="CONFIRM" url="http://www.phpbb.com/phpBB/viewtopic.php?t=267563">http://www.phpbb.com/phpBB/viewtopic.php?t=267563</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14413">14413</ref></refs><vuln_soft><prod name="phpBB" vendor="phpBB Group"><vers num="2.0.11"/><vers num="2.0.10"/><vers num="2.0.9"/><vers num="2.0.8a"/><vers num="2.0.8"/><vers num="2.0.7a"/><vers num="2.0.7"/><vers num="2.0.6d"/><vers num="2.0.6c"/><vers num="2.0.6"/><vers num="2.0.5"/><vers num="2.0.4"/><vers num="2.0.3"/><vers num="2.0.2"/><vers num="2.0.1"/><vers num="2.0.0"/><vers num="2.0 RC4"/><vers num="2.0 RC3"/><vers num="2.0 RC2"/><vers num="2.0 RC1"/><vers num="2.0 Beta1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0604" published="2005-05-02" seq="2005-0604" severity="Medium" type="CVE"><desc><descript source="cve">lnss.exe in GFI Languard Network Security Scanner 5.0 stores the username and password in memory in plaintext, which could allow local administrators to obtain domain administrator credentials.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110961644621528&amp;w=2">20050228 [Hat-Squad] GFI L.N.S.S 5.0 Insecure Credential Storage</ref><ref adv="1" source="MISC" url="http://www.hat-squad.com/en/000160.html">http://www.hat-squad.com/en/000160.html</ref></refs><vuln_soft><prod name="Languard Network Security Scanner" vendor="GFI"><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0605" published="2005-03-02" seq="2005-0605" severity="High" type="CVE"><desc><descript source="cve">scan.c for LibXPM may allow attackers to execute arbitrary code via a negative bitmap_unit value that leads to a buffer overflow.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="CONFIRM" url="https://bugs.freedesktop.org/attachment.cgi?id=1909">https://bugs.freedesktop.org/attachment.cgi?id=1909</ref><ref adv="1" patch="1" source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200503-08.xml">GLSA-200503-08</ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200503-15.xml">GLSA-200503-15</ref><ref adv="1" patch="1" source="CONFIRM" url="http://bugs.gentoo.org/show_bug.cgi?id=83655">http://bugs.gentoo.org/show_bug.cgi?id=83655</ref><ref adv="1" patch="1" source="CONFIRM" url="http://bugs.gentoo.org/show_bug.cgi?id=83598">http://bugs.gentoo.org/show_bug.cgi?id=83598</ref><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111100031032629&amp;w=2">20050316 [USN-97-1] libxpm vulnerability</ref><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111025849723018&amp;w=2">20050307 [USN-92-1] LessTif vulnerabilities</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-331.html">RHSA-2005:331</ref><ref adv="1" patch="1" source="MISC" url="http://securitytracker.com/id?1013339">http://securitytracker.com/id?1013339</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/12714">12714</ref><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-723">DSA-723</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-412.html">RHSA-2005:412</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/Aug/msg00000.html">APPLE-SA-2005-08-15</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2005//Aug/msg00001.html">APPLE-SA-2005-08-17</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-92-1">USN-92-1</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-97-1">USN-97-1</ref><ref source="SCO" url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.57/SCOSA-2005.57.txt">SCOSA-2005.57</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14460">14460</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18049">18049</ref><ref source="SCO" url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2006.5/SCOSA-2006.5.txt">SCOSA-2006.5</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18316">18316</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00001.html">FLSA-2006:152803</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-044.html">RHSA-2005:044</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-198.html">RHSA-2005:198</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-473.html">RHSA-2005:473</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20060403-01-U">20060403-01-U</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19624">
19624</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2008-0261.html">RHSA-2008:0261</ref></refs><vuln_soft><prod name="Mandrake Linux" vendor="MandrakeSoft"><vers edition="x86_64" num="10.2"/><vers num="10.2"/><vers edition="x86_64" num="10.1"/><vers num="10.1"/><vers edition="AMD64" num="10.0"/><vers num="10.0"/></prod><prod name="Enterprise Linux" vendor="Red Hat"><vers edition="Workstation" num="4.0"/><vers edition="Workstation Server" num="3.0"/><vers edition="Enterprise Server" num="4.0"/><vers edition="Enterprise Server" num="3.0"/><vers edition="Advanced Server" num="4.0"/><vers edition="Advanced Server" num="3.0"/></prod><prod name="SuSE Linux" vendor="SuSE"><vers edition="x86_64" num="9.2"/><vers num="9.2"/><vers edition="x86_64" num="9.1"/><vers num="9.1"/><vers edition="x86_64" num="9.0"/><vers num="9.0"/><vers num="8.2"/><vers num="8.1"/><vers edition="i386" num="8.0"/><vers num="8.0"/><vers edition="sparc" num="7.3"/><vers edition="ppc" num="7.3"/><vers edition="i386" num="7.3"/><vers num="7.3"/><vers edition="i386" num="7.2"/><vers num="7.2"/><vers edition="x86" num="7.1"/><vers edition="spa" num="7.1"/><vers edition="sparc" num="7.1"/><vers num="7.1 alpha"/><vers num="7.1"/><vers edition="sparc" num="7.0"/><vers edition="ppc" num="7.0"/><vers edition="i386" num="7.0"/><vers num="7.0 alpha"/><vers num="7.0"/><vers edition="ppc" num="6.4"/><vers edition="i386" num="6.4"/><vers num="6.4 alpha"/><vers num="6.4"/><vers edition="ppc" num="6.3"/><vers num="6.3 alpha"/><vers num="6.3"/><vers num="6.2"/><vers num="6.1 alpha"/><vers num="6.1"/></prod><prod name="X11R6" vendor="X.Org"><vers num="6.8.1"/><vers num="6.8"/><vers num="6.7.0"/></prod><prod name="ALT Linux" vendor="ALTLinux"><vers edition="Junior" num="2.3"/><vers edition="Compact" num="2.3"/></prod><prod name="Lesstif" vendor="Lesstif"><vers num="0.93.94"/></prod><prod name="X11R6" vendor="XFree86 Project"><vers num="4.3.0.2"/><vers num="4.3.0.1"/><vers num="4.3.0"/><vers edition="Errata" num="4.2.1"/><vers num="4.2.1"/><vers num="4.2.0"/><vers num="4.1.0"/><vers num="4.1.12"/><vers num="4.1.11"/><vers num="4.0.3"/><vers num="4.0.2.11"/><vers num="4.0.1"/><vers num="4.0"/><vers num="3.3.6"/><vers num="3.3.5"/><vers num="3.3.4"/><vers num="3.3.3"/><vers num="3.3.2"/><vers num="3.3"/></prod><prod name="Mandrake Corporate Server" vendor="MandrakeSoft"><vers edition="x86_64" num="3.0"/><vers num="3.0"/><vers edition="x86_64" num="2.1"/><vers num="2.1"/></prod><prod name="Desktop" vendor="Red Hat"><vers num="4.0"/><vers num="3.0"/></prod><prod name="Fedora" vendor="Red Hat"><vers num="Core 3.0"/><vers num="Core 2.0"/></prod><prod name="ProPack" vendor="SGI"><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0606" published="2005-05-02" seq="2005-0606" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in settings.inc.php for CubeCart 2.0.0 through 2.0.5, as used in multiple PHP files, allows remote attackers to inject arbitrary HTML or web script via the (1) cat_id, (2) PHPSESSID, (3) view_doc, (4) product, (5) session, (6) catname, (7) search, or (8) page parameters.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MISC" url="http://lostmon.blogspot.com/2005/02/cubecart-20x-multiple-variable-xss.html">http://lostmon.blogspot.com/2005/02/cubecart-20x-multiple-variable-xss.html</ref><ref patch="1" source="CONFIRM" url="http://www.cubecart.com/site/forums/index.php?showtopic=6032">http://www.cubecart.com/site/forums/index.php?showtopic=6032</ref><ref source="MISC" url="http://securitytracker.com/id?1013304">http://securitytracker.com/id?1013304</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/12658">12658</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14416">14416</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20637">cubecart-multiple-xss(20637)</ref></refs><vuln_soft><prod name="CubeCart" vendor="Devellion"><vers num="2.0.5"/><vers num="2.0.3"/><vers num="2.0.2"/><vers num="2.0.1"/><vers num="2.0.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0607" published="2005-05-02" seq="2005-0607" severity="Medium" type="CVE"><desc><descript source="cve">CubeCart 2.0.0 through 2.0.5 allows remote attackers to determine the full path of the server via direct calls without parameters to (1) information.php, (2) language.php, (3) list_docs.php, (4) popular_prod.php, (5) sale.php, (6) subfooter.inc.php, (7) subheader.inc.php, (8) cat_navi.php, or (9) check_sum.php, which reveals the path in a PHP error message.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://lostmon.blogspot.com/2005/02/cubecart-20x-multiple-variable-xss.html">http://lostmon.blogspot.com/2005/02/cubecart-20x-multiple-variable-xss.html</ref><ref patch="1" source="CONFIRM" url="http://www.cubecart.com/site/forums/index.php?showtopic=6032">http://www.cubecart.com/site/forums/index.php?showtopic=6032</ref><ref source="MISC" url="http://securitytracker.com/id?1013304">http://securitytracker.com/id?1013304</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20638">cubecart-multiple-path-disclosure(20638)</ref></refs><vuln_soft><prod name="CubeCart" vendor="Devellion"><vers num="2.0.5"/><vers num="2.0.3"/><vers num="2.0.2"/><vers num="2.0.1"/><vers num="2.0.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0608" published="2005-02-28" seq="2005-0608" severity="High" type="CVE"><desc><descript source="cve">Heap-based buffer overflow in server.cpp for WebMod 0.47 allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a POST request with a Content-Length that is less than the amount of data that is actually sent.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14302">14302</ref><ref adv="1" patch="1" source="CONFIRM" url="http://djeyl.net/forum/index.php?showtopic=41440">http://djeyl.net/forum/index.php?showtopic=41440</ref></refs><vuln_soft><prod name="WebMod" vendor="WebMod"><vers num="0.47"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-05-11" name="CVE-2005-0610" published="2005-04-12" seq="2005-0610" severity="High" type="CVE"><desc><descript source="cve">Multiple symlink vulnerabilities in portupgrade before 20041226_2 in FreeBSD allow local users to (1) overwrite arbitrary files and possibly replace packages to execute arbitrary code via pkg_fetch, (2) overwrite arbitrary files via temporary files when portupgrade upgrades a port or package, or (3) create arbitrary zero-byte files via the pkgdb.fixme temporary file.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="MISC" url="http://www.vuxml.org/freebsd/22f00553-a09d-11d9-a788-0001020eed82.html">http://www.vuxml.org/freebsd/22f00553-a09d-11d9-a788-0001020eed82.html</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/13106">13106</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14903">14903</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="5.4 Release"/><vers num="5.4 pre"/><vers num="5.3 Stable"/><vers num="5.3 Releng"/><vers num="5.3 Release"/><vers num="5.3"/><vers num="5.2.1 Release"/><vers num="5.2 Releng"/><vers num="5.2 Release"/><vers num="5.2"/><vers num="5.1 Releng"/><vers num="5.1 Release Alpha"/><vers num="5.1 p5 Release"/><vers num="5.1 Release"/><vers num="5.1"/><vers num="5.0 Releng"/><vers num="5.0 p14 Release"/><vers num="5.0 alpha"/><vers num="5.0"/><vers num="4.11 Stable"/><vers num="4.10 Releng"/><vers num="4.10 Release"/><vers num="4.10"/><vers num="4.9 Releng"/><vers num="4.9 pre"/><vers num="4.9"/><vers num="4.8 Releng"/><vers num="4.8 p6 Release"/><vers num="4.8 pre"/><vers num="4.8"/><vers num="4.7 Stable"/><vers num="4.7 Releng"/><vers num="4.7 p17 Release"/><vers num="4.7 Release"/><vers num="4.7"/><vers num="4.6.2"/><vers num="4.6 Stable"/><vers num="4.6 Releng"/><vers num="4.6 p20 Release"/><vers num="4.6 Release"/><vers num="4.6"/><vers num="4.5 Stable pre 2002-03-07"/><vers num="4.5 Stable"/><vers num="4.5 Releng"/><vers num="4.5 p32 Release"/><vers num="4.5 Release"/><vers num="4.5"/><vers num="4.4 Stable"/><vers num="4.4 Releng"/><vers num="4.4 p42 Release"/><vers num="4.4"/><vers num="4.3 Stable"/><vers num="4.3 Releng"/><vers num="4.3 p38 Release"/><vers num="4.3 Release"/><vers num="4.3"/><vers num="4.2 Stable pre 2000-12-23"/><vers num="4.2 Stable pre 2001-05-02"/><vers num="4.2 Stable"/><vers num="4.2 Release"/><vers num="4.2"/><vers num="4.1.1 Stable"/><vers num="4.1.1 Release"/><vers num="4.1.1"/><vers num="4.1"/><vers num="4.0 Releng"/><vers num="4.0 alpha"/><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-01-05" name="CVE-2005-0611" published="2005-05-02" seq="2005-0611" severity="Medium" type="CVE"><desc><descript source="cve">Heap-based buffer overflow in RealNetworks RealPlayer 10.5 (6.0.12.1056 and earlier), 10, 8, and RealOne Player V2 and V1, allows remote attackers to execute arbitrary code via .WAV files.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110979465912834&amp;w=2">20050302 RealOne Player / Real .WAV Heap Overflow File Format Vulnerability</ref><ref source="VULNWATCH" url="http://marc.theaimsgroup.com/?l=vulnwatch&amp;m=110977858619314&amp;w=2">20050302 RealOne Player / Real .WAV Heap Overflow File Format Vulnerability</ref><ref source="CONFIRM" url="http://service.real.com/help/faq/security/050224_player/EN/">http://service.real.com/help/faq/security/050224_player/EN/</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-265.html">RHSA-2005:265</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110979465912834&amp;w=2">20050302 RealOne Player / Real .WAV Heap Overflow File Format Vulnerability</ref><ref source="VULNWATCH" url="http://marc.theaimsgroup.com/?l=vulnwatch&amp;m=110977858619314&amp;w=2">20050302 RealOne Player / Real .WAV Heap Overflow File Format Vulnerability</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-271.html">RHSA-2005:271</ref></refs><vuln_soft><prod name="RealPlayer" vendor="RealNetworks"><vers num="10.5"/><vers num="8.0"/><vers edition="Enterprise" num="Any"/><vers num="10.0"/></prod><prod name="Helix Player" vendor="RealNetworks"><vers num=""/></prod><prod name="RealOne Player" vendor="RealNetworks"><vers num="2.0"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0612" published="2005-05-02" seq="2005-0612" severity="High" type="CVE"><desc><descript source="cve">Cisco IP/VC Videoconferencing System 3510, 3520, 3525 and 3530 contain hard-coded default SNMP community strings, which allows remote attackers to gain access, cause a denial of service, and modify configuration.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref patch="1" source="CISCO" url="http://www.cisco.com/public/technotes/cisco-sa-20050202-ipvc.shtml">20050202 Default SNMP Community Strings in Cisco IP/VC Products</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/14122">14122</ref><ref source="BID" url="http://www.securityfocus.com/bid/12424">12424</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013067">1013067</ref></refs><vuln_soft><prod name="IPVC" vendor="Cisco"><vers num="3510-MCU"/><vers num="3520-GW-2B"/><vers num="3520-GW-4B"/><vers num="3520-GW-2V"/><vers num="3520-GW-4V"/><vers num="3520-GW-2B2V"/><vers num="3525-GW-1P"/><vers num="3530-VTA"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0613" published="2005-02-28" seq="2005-0613" severity="Medium" type="CVE"><desc><descript source="cve">Unknown vulnerability in FCKeditor 2.0 RC2, when used with PHP-Nuke, allows remote attackers to upload arbitrary files.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/12676">12676</ref></refs><vuln_soft><prod name="FCKeditor" vendor="FCKeditor"><vers num="2.0 RC2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0614" published="2005-05-02" seq="2005-0614" severity="High" type="CVE"><desc><descript source="cve">sessions.php in phpBB 2.0.12 and earlier allows remote attackers to gain administrator privileges via the autologinid value in a cookie.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110970201920206&amp;w=2">20050301 phpBB &lt;= 2.0.12 UID Exploit</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110999268130739&amp;w=2">20050304 phpBB 2.0.12 Session Handling Administrator Authentication Bypass</ref><ref adv="1" source="CONFIRM" url="http://www.phpbb.com/phpBB/viewtopic.php?t=267563">http://www.phpbb.com/phpBB/viewtopic.php?t=267563</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14413">14413</ref></refs><vuln_soft><prod name="phpBB" vendor="phpBB Group"><vers num="2.0.9"/><vers num="2.0.8a"/><vers num="2.0.8"/><vers num="2.0.7a"/><vers num="2.0.7"/><vers num="2.0.6d"/><vers num="2.0.6c"/><vers num="2.0.6"/><vers num="2.0.5"/><vers num="2.0.4"/><vers num="2.0.3"/><vers num="2.0.2"/><vers num="2.0.12"/><vers num="2.0.11"/><vers num="2.0.10"/><vers num="2.0.1"/><vers num="2.0.0"/><vers num="2.0 RC4"/><vers num="2.0 RC3"/><vers num="2.0 RC2"/><vers num="2.0 RC1"/><vers num="2.0 Beta1"/><vers num="1.4.4"/><vers num="1.4.2"/><vers num="1.4.1"/><vers num="1.4.0"/><vers num="1.2.1"/><vers num="1.2.0"/><vers num="1.0.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-04-07" name="CVE-2005-0615" published="2005-05-02" seq="2005-0615" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in (1) index.php, (2) modules.php, or (3) admin.php in PostNuke 0.760-RC2 allow remote attackers to execute arbitrary SQL code via the catid parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110962819232255&amp;w=2">20050228 [SECURITYREASON.COM] PostNuke Critical SQL Injection 0.760-RC2=&gt;x</ref><ref adv="1" patch="1" source="CONFIRM" url="http://news.postnuke.com/Article2669.html">http://news.postnuke.com/Article2669.html</ref><ref patch="1" source="MISC" url="http://securitytracker.com/id?1013324">http://securitytracker.com/id?1013324</ref></refs><vuln_soft><prod name="PostNuke" vendor="PostNuke Software Foundation"><vers num="0.760 RC2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-04-07" name="CVE-2005-0616" published="2005-02-28" seq="2005-0616" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in the Download module for PostNuke 0.750 and 0.760-RC2 allow remote attackers to inject arbitrary web script or HTML via the (1) Program name, (2) File link, (3) Author name (4) Author e-mail address, (5) File size, (6) Version, or (7) Home page variables.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110962768300373&amp;w=2">20050228 [SECURITYREASON.COM] PostNuke Critical XSS 0.760-RC2=&gt;x cXIb8O3.2</ref><ref adv="1" patch="1" source="CONFIRM" url="http://news.postnuke.com/Article2669.html">http://news.postnuke.com/Article2669.html</ref><ref adv="1" patch="1" source="MISC" url="http://securitytracker.com/id?1013324">http://securitytracker.com/id?1013324</ref></refs><vuln_soft><prod name="PostNuke Phoenix" vendor="PostNuke Software Foundation"><vers num="0.760 RC2"/><vers num="0.750"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-04-07" name="CVE-2005-0617" published="2005-05-02" seq="2005-0617" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in dl-search.php in PostNuke 0.750 and 0.760-RC2 allows remote attackers to execute arbitrary SQL commands via the show parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110962710805864&amp;w=2">20050228 [SECURITYREASON.COM] PostNuke SQL Injection 0.760-RC2=&gt;x cXIb8O3.3</ref><ref adv="1" patch="1" source="CONFIRM" url="http://news.postnuke.com/Article2669.html">http://news.postnuke.com/Article2669.html</ref><ref patch="1" source="MISC" url="http://securitytracker.com/id?1013324">http://securitytracker.com/id?1013324</ref></refs><vuln_soft><prod name="PostNuke" vendor="PostNuke Software Foundation"><vers num="0.750"/><vers num="0.760 RC2"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0618" published="2005-05-02" seq="2005-0618" severity="Medium" type="CVE"><desc><descript source="cve">The SMTP binding function in Symantec Firewall/VPN Appliance 200/200R firmware after 1.5Z and before 1.68, Gateway Security 360/360R and 460/460R firmware before vuild 858, and Nexland Pro800turbo, when configured for load balancing between two WANs, might send SMTP traffic to a trusted network through an untrusted network.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="CONFIRM" url="http://securityresponse.symantec.com/avcenter/security/Content/2005.02.28.html">http://securityresponse.symantec.com/avcenter/security/Content/2005.02.28.html</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14428">14428</ref></refs><vuln_soft><prod name="Pro800turbo" vendor="Nexland"><vers num=""/></prod><prod name="Firewall_VPN Appliance" vendor="Symantec"><vers num="200_200R"/></prod><prod name="Gateway Security 460" vendor="Symantec"><vers num="857" prev="1"/></prod><prod name="Gateway Security 360" vendor="Symantec"><vers num="857" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0619" published="2005-02-28" seq="2005-0619" severity="Low" type="CVE"><desc><descript source="cve">Einstein 1.0.1 stores sensitive information such as usernames and passwords in plaintext in the registry, which allows local users to gain privileges.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="MISC" url="http://www.milw0rm.com/id.php?id=846">http://www.milw0rm.com/id.php?id=846</ref><ref adv="1" source="MISC" url="http://securitytracker.com/id?1013316">http://securitytracker.com/id?1013316</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/14455">14455</ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/14212">14212</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/846">

846</ref></refs><vuln_soft><prod name="Einstein" vendor="bfriendly.com"><vers num="1.0.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0620" published="2005-03-02" seq="2005-0620" severity="Low" type="CVE"><desc><descript source="cve">Einstein 1.0 stores credit card information in plaintext in the world-readable wallets.dat file, which allows local users to steal the information.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/14455">14455</ref></refs><vuln_soft><prod name="Einstein" vendor="bfriendly.com"><vers num="1.0.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0621" published="2005-05-02" seq="2005-0621" severity="Medium" type="CVE"><desc><descript source="cve">Scrapland 1.0 and earlier allows remote attackers to cause a denial of service (server termination) by triggering an error, which is treated as a fatal error by the server, as demonstrated using (1) signed integers for size values, (2) an invalid model, (3) a &quot;newpos&quot; value that is less than or equal to a size value, or (4) partial packets.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="Luigi Auriemma" url="http://aluigi.altervista.org/adv/scrapboom-adv.txt"></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/14435">14435</ref><ref source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=110961578504928&amp;w=2">20050228 Server termination in Scrapland 1.0</ref></refs><vuln_soft><prod name="Scrapland" vendor="Enlight Software"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0622" published="2005-03-01" seq="2005-0622" severity="Medium" type="CVE"><desc><descript source="cve">RaidenHTTPD 1.1.32, and possibly other versions before 1.1.34, allows remote attackers to view the PHP source code via an HTTP GET request for a filename with a trailing (1) . (dot) or (2) space.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110969702013313&amp;w=2">20050301 [SIG^2 G-TEC] RaidenHTTPD Server Buffer Overflow and CGI Source Disclosure Vulnerabilities</ref><ref adv="1" patch="1" source="MISC" url="http://www.security.org.sg/vuln/raidenhttpd1132.html">http://www.security.org.sg/vuln/raidenhttpd1132.html</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14453">14453</ref></refs><vuln_soft><prod name="RaidenHTTPD" vendor="RaidenHTTPD"><vers num="1.1.32"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0623" published="2005-03-01" seq="2005-0623" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in RaidenHTTPD 1.1.32, and possibly other versions before 1.1.34, allows remote attackers to execute arbitrary code via a long URL.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110969702013313&amp;w=2">20050301 [SIG^2 G-TEC] RaidenHTTPD Server Buffer Overflow and CGI Source Disclosure Vulnerabilities</ref><ref adv="1" patch="1" source="MISC" url="http://www.security.org.sg/vuln/raidenhttpd1132.html">http://www.security.org.sg/vuln/raidenhttpd1132.html</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14453">14453</ref></refs><vuln_soft><prod name="RaidenHTTPD" vendor="RaidenHTTPD"><vers num="1.1.32"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0624" published="2005-02-28" seq="2005-0624" severity="Low" type="CVE"><desc><descript source="cve">reportbug before 2.62 creates the .reportbugrc configuration file with world-readable permissions, which allows local users to obtain email smarthost passwords.</descript></desc><loss_types><conf/></loss_types><vuln_types><config/></vuln_types><range><local/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110972153627388&amp;w=2">20050228 [USN-88-1] reportbug information disclosure</ref><ref adv="1" source="CONFIRM" url="https://bugzilla.ubuntu.com/show_bug.cgi?id=6600">https://bugzilla.ubuntu.com/show_bug.cgi?id=6600</ref><ref adv="1" source="CONFIRM" url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=295407">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=295407</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14422/">14422</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19504">reportbug-file-world-readable(19504)</ref></refs><vuln_soft><prod name="reportbug" vendor="Debian"><vers num="2.61"/><vers num="2.60"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0625" published="2005-02-28" seq="2005-0625" severity="Low" type="CVE"><desc><descript source="cve">reportbug 3.2 includes settings from .reportbugrc in bug reports, which exposes sensitive information such as smtpuser and smtppasswd.</descript></desc><loss_types><conf/></loss_types><vuln_types><config/></vuln_types><range><local/></range><refs><ref adv="1" source="ubuntu" url="https://bugzilla.ubuntu.com/show_bug.cgi?id=6600">6600: </ref><ref adv="1" source="Debian" url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=295407">295407: reportbug: config files are world readable</ref><ref adv="1" source="CONFIRM" url="https://bugzilla.ubuntu.com/show_bug.cgi?id=6717">https://bugzilla.ubuntu.com/show_bug.cgi?id=6717</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14422/">14422</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19520">reportbug-smtppasswd-information-disclosure(19520)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110972153627388&amp;w=2">20050228 [USN-88-1] reportbug information disclosure</ref></refs><vuln_soft><prod name="reportbug" vendor="Debian"><vers num="3.2"/><vers num="2.61"/><vers num="2.60"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0626" published="2005-03-08" seq="2005-0626" severity="Low" type="CVE"><desc><descript source="cve">Race condition in Squid 2.5.STABLE7 to 2.5.STABLE9, when using the Netscape Set-Cookie recommendations for handling cookies in caches, may cause Set-Cookie headers to be sent to other users, which allows attackers to steal the related cookies.</descript></desc><loss_types><conf/></loss_types><vuln_types><race/></vuln_types><range><network/></range><refs><ref adv="1" source="CONFIRM" url="http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE9-setcookie">http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE9-setcookie</ref><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111032213012823&amp;w=2">20050308 [USN-93-1] Squid vulnerability</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19581">squid-set-cookie-race-condition(19581)</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-415.html">RHSA-2005:415</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-93-1">USN-93-1</ref><ref source="FEDORA" url="http://fedoranews.org/updates/FEDORA--.shtml">FLSA-2006:152809</ref><ref source="BID" url="http://www.securityfocus.com/bid/12716">12716</ref></refs><vuln_soft><prod name="Squid" vendor="Squid"><vers num="2.5.STABLE7"/><vers num="2.5.STABLE6"/><vers num="2.5.STABLE5"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0627" published="2005-05-02" seq="2005-0627" severity="Medium" type="CVE"><desc><descript source="cve">Qt before 3.3.4 searches the BUILD_PREFIX directory, which could be world-writable, to load shared libraries regardless of the LD_LIBRARY_PATH environment variable, which allows local users to execute arbitrary programs.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200503-01.xml">GLSA-200503-01</ref><ref patch="1" source="MISC" url="http://bugs.gentoo.org/show_bug.cgi?id=75181">http://bugs.gentoo.org/show_bug.cgi?id=75181</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/12695">12695</ref></refs><vuln_soft><prod name="Qt" vendor="Trolltech"><vers num="3.3.3"/><vers num="3.3.2"/><vers num="3.3.1"/><vers num="3.3.0"/><vers num="3.2.3"/><vers num="3.2.1"/><vers num="3.1.2"/><vers num="3.1.1"/><vers num="3.1"/><vers num="3.0.5"/><vers num="3.0.3"/><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0628" published="2005-03-01" seq="2005-0628" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Forumwa 1.0 allow remote attackers to inject arbitrary web script or HTML via (1) the keyword parameter in search.php or the (2) body or (3) subject of a forum message.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110971101826900&amp;w=2">20050301 Forumwa search.php xss vulnerability</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/12689">12689</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/14418">14418</ref></refs><vuln_soft><prod name="Forumwa" vendor="Demof"><vers num="v1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0629" published="2005-03-01" seq="2005-0629" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in profile.php in 427BB 2.2 allow remote attackers to inject arbitrary web script or HTML via the (1) user or (2) Avatar parameters.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110970911514167&amp;w=2">20050301 427BB profile.php XSS vulnerability.</ref><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110970474726113&amp;w=2">20050301 427BB profile.php XSS vulnerability.</ref><ref adv="1" source="MISC" url="http://securitytracker.com/id?1013337">http://securitytracker.com/id?1013337</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/12693">12693</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/14434">14434</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19546">427bb-profile-xss(19546)</ref></refs><vuln_soft><prod name="fourtwosevenbb" vendor="427BB"><vers num="2.2.1"/><vers num="2.2"/><vers num="2.1.3"/><vers num="2.1.2"/><vers num="2.1.1"/><vers num="2.1"/><vers num="2.0.1"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0630" published="2005-03-01" seq="2005-0630" severity="Low" type="CVE"><desc><descript source="cve">sendpm.php in PBLang 4.63 allows remote authenticated users to read arbitrary files via a full pathname in the orig parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110971002211589&amp;w=2">20050301 Software PBLang 4.63 sendpm.php reply file read vulnerability</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/12690">12690</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19544">pblang-sendpm-obtain-information(19544)</ref><ref source="" url="http://pblforum.drmartinus.de/post.php?cat=2&amp;fid=2&amp;pid=40&amp;page=1"></ref></refs><vuln_soft><prod name="PBLang" vendor="PBLang"><vers num="4.63"/><vers num="4.56 4.5 RC2"/><vers num="4.6"/><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0631" published="2005-03-01" seq="2005-0631" severity="Low" type="CVE"><desc><descript source="cve">delpm.php in PBLang 4.63 allows remote authenticated users to delete arbitrary PM files by modifying the &quot;id&quot; and &quot;a&quot; parameters.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110970738214608&amp;w=2">20050301 Software PBLang 4.63 delpm.php authentication vulnerability</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/12694">12694</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19552">pblang-delpm-delete-messages(19552)</ref><ref source="" url="http://pblforum.drmartinus.de/post.php?cat=2&amp;fid=2&amp;pid=42&amp;page=1"></ref></refs><vuln_soft><prod name="PBLang" vendor="PBLang"><vers num="4.63"/><vers num="4.56 4.5 RC2"/><vers num="4.6"/><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0632" published="2005-03-01" seq="2005-0632" severity="Medium" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in auth.php in PHPNews 1.2.4 and possibly 1.2.3, allows remote attackers to execute arbitrary PHP code via the path parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110971663824719&amp;w=2">20050301 PHP News &lt;= 1.2.4 - Remote File Inclusion (VXSfx)</ref><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110989169008570&amp;w=2">20050303 PHP News &lt;= 1.2.4 - Remote File Inclusion Exploit</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/12696">12696</ref><ref adv="1" patch="1" source="MISC" url="http://securitytracker.com/id?1013345">http://securitytracker.com/id?1013345</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14449">14449</ref></refs><vuln_soft><prod name="PHPNews" vendor="PHPNews"><vers num="1.2.4"/><vers num="1.2.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0633" published="2005-03-02" seq="2005-0633" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Trillian 3.0 and Pro 3.0 allows remote attackers to execute arbitrary code via a crafted PNG image file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111023000624809&amp;w=2">20050306 See-security advisory: Trillian Basic 3.0 PNG Processing Buffer overflow</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/12703">12703</ref><ref adv="1" patch="1" source="MISC" url="http://www.frsirt.com/english/advisories/2005/0221">http://www.frsirt.com/english/advisories/2005/0221</ref><ref adv="1" patch="1" source="MISC" url="http://www.securiteam.com/exploits/5KP030KF5E.html">http://www.securiteam.com/exploits/5KP030KF5E.html</ref></refs><vuln_soft><prod name="Trillian Pro" vendor="Cerulean Studios"><vers num="3.0"/></prod><prod name="Trillian" vendor="Cerulean Studios"><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0634" published="2005-05-02" seq="2005-0634" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Golden FTP Server 1.92 allows remote attackers to execute arbitrary code via a long USER command.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/391987">20050302 Golden Ftp server 1.29 Username remote Buffer Overflow</ref><ref source="BID" url="http://www.securityfocus.com/bid/12704">12704</ref><ref source="" url="http://retrogod.altervista.org/golden_heap.html"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/4936">ADV-2006-4936</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23323">23323</ref></refs><vuln_soft><prod name="Golden FTP Server" vendor="KMiNT21 Software"><vers num="1.92"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0635" published="2005-05-02" seq="2005-0635" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Foxmail Server 2.0 allows remote attackers to execute arbitrary code via a long USER command.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/391960">20050302 Foxmail server </ref><ref adv="1" source="MISC" url="http://securitytracker.com/id?1013356">http://securitytracker.com/id?1013356</ref><ref source="BID" url="http://www.securityfocus.com/bid/12711">12711</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/14145">14145</ref></refs><vuln_soft><prod name="Foxmail Email Server" vendor="Foxmail"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0636" published="2005-03-02" seq="2005-0636" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in Foxmail Server 2.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format strings in the USER command.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/391960">20050302 Foxmail server </ref><ref adv="1" source="MISC" url="http://securitytracker.com/id?1013356">http://securitytracker.com/id?1013356</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/12711">12711</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/14145">14145</ref></refs><vuln_soft><prod name="Foxmail Email Server" vendor="Foxmail"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0637" published="2005-05-02" seq="2005-0637" severity="Medium" type="CVE"><desc><descript source="cve">The copy functions in locore.s such as copyout in OpenBSD 3.5 and 3.6, and possibly other BSD based operating systems, may allow attackers to exceed certain address boundaries and modify kernel memory.</descript></desc><loss_types><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="MISC" url="http://securitytracker.com/id?1013333">http://securitytracker.com/id?1013333</ref><ref patch="1" source="OPENBSD" url="http://www.openbsd.org/errata35.html#locore">20050228 028: SECURITY FIX: February 28, 2005</ref><ref patch="1" source="OPENBSD" url="http://www.openbsd.org/errata.html#copy">20050316 012: SECURITY FIX: March 16, 2005   amd64 only</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/12825">12825</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14432">14432</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19531">openbsd-copy-functions(19531)</ref></refs><vuln_soft><prod name="OpenBSD" vendor="OpenBSD"><vers num="3.5"/><vers num="3.6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0638" published="2005-03-02" seq="2005-0638" severity="High" type="CVE"><desc><descript source="cve">xloadimage before 4.1-r2, and xli before 1.17, allows attackers to execute arbitrary commands via shell metacharacters in filenames for compressed images, which are not properly quoted when calling the gunzip command.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-695">DSA-695</ref><ref adv="1" source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200503-05.xml">GLSA-200503-05</ref><ref adv="1" source="CONFIRM" url="http://bugs.gentoo.org/show_bug.cgi?id=79762">http://bugs.gentoo.org/show_bug.cgi?id=79762</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14459">14459</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/14462">14462</ref><ref source="OSVDB" url="http://www.osvdb.org/14365">14365</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-332.html">RHSA-2005:332</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2005-134_RHSA-2005-332.pdf"></ref><ref source="BID" url="http://www.securityfocus.com/bid/12712">12712</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/433935/30/5010/threaded">
FLSA-2006:152923</ref></refs><vuln_soft><prod name="SuSE Linux" vendor="SuSE"><vers num="9.3"/><vers edition="x86_64" num="9.2"/><vers num="9.2"/><vers edition="x86_64" num="9.1"/><vers num="9.1"/><vers edition="x86_64" num="9.0"/><vers num="9.0"/><vers num="8.2"/><vers num="8.1"/><vers edition="i386" num="8.0"/><vers num="8.0"/><vers edition="sparc" num="7.3"/><vers edition="ppc" num="7.3"/><vers edition="i386" num="7.3"/><vers num="7.3"/><vers edition="i386" num="7.2"/><vers num="7.2"/><vers edition="x86" num="7.1"/><vers edition="spa" num="7.1"/><vers edition="sparc" num="7.1"/><vers num="7.1 alpha"/><vers num="7.1"/><vers edition="sparc" num="7.0"/><vers edition="ppc" num="7.0"/><vers edition="i386" num="7.0"/><vers num="7.0 alpha"/><vers num="7.0"/><vers edition="ppc" num="6.4"/><vers edition="i386" num="6.4"/><vers num="6.4 alpha"/><vers num="6.4"/><vers edition="ppc" num="6.3"/><vers num="6.3 alpha"/><vers num="6.3"/><vers num="6.2"/><vers num="6.1 alpha"/><vers num="6.1"/><vers num="6.0"/><vers num="5.3"/><vers num="5.2"/><vers num="5.1"/><vers num="5.0"/><vers num="4.4.1"/><vers num="4.4"/><vers num="4.3"/><vers num="4.2"/><vers num="4.0"/><vers num="3.0"/><vers num="2.0"/><vers num="1.0"/></prod><prod name="ALT Linux" vendor="ALTLinux"><vers edition="Junior" num="2.3"/><vers edition="Compact" num="2.3"/></prod><prod name="xli" vendor="xli"><vers num="1.17"/><vers num="1.16"/><vers num="1.15"/><vers num="1.14"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0639" published="2005-03-02" seq="2005-0639" severity="High" type="CVE"><desc><descript source="cve">Multiple vulnerabilities in xli before 1.17 may allow remote attackers to execute arbitrary code via &quot;buffer management errors&quot; from certain image properties, some of which may be related to integer overflows in PPM files.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-695">DSA-695</ref><ref adv="1" source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200503-05.xml">GLSA-200503-05</ref><ref adv="1" source="CONFIRM" url="http://bugs.gentoo.org/show_bug.cgi?id=79762">http://bugs.gentoo.org/show_bug.cgi?id=79762</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14459">14459</ref></refs><vuln_soft><prod name="SuSE Linux" vendor="SuSE"><vers num="9.3"/><vers edition="x86_64" num="9.2"/><vers num="9.2"/><vers edition="x86_64" num="9.1"/><vers num="9.1"/><vers edition="x86_64" num="9.0"/><vers num="9.0"/><vers num="8.2"/><vers num="8.1"/><vers edition="i386" num="8.0"/><vers num="8.0"/><vers edition="sparc" num="7.3"/><vers edition="ppc" num="7.3"/><vers edition="i386" num="7.3"/><vers num="7.3"/><vers edition="i386" num="7.2"/><vers num="7.2"/><vers edition="x86" num="7.1"/><vers edition="spa" num="7.1"/><vers edition="sparc" num="7.1"/><vers num="7.1 alpha"/><vers num="7.1"/><vers edition="sparc" num="7.0"/><vers edition="ppc" num="7.0"/><vers edition="i386" num="7.0"/><vers num="7.0 alpha"/><vers num="7.0"/><vers edition="ppc" num="6.4"/><vers edition="i386" num="6.4"/><vers num="6.4 alpha"/><vers num="6.4"/><vers edition="ppc" num="6.3"/><vers num="6.3 alpha"/><vers num="6.3"/><vers num="6.2"/><vers num="6.1 alpha"/><vers num="6.1"/><vers num="6.0"/><vers num="5.3"/><vers num="5.2"/><vers num="5.1"/><vers num="5.0"/><vers num="4.4.1"/><vers num="4.4"/><vers num="4.3"/><vers num="4.2"/><vers num="4.0"/><vers num="3.0"/><vers num="2.0"/><vers num="1.0"/></prod><prod name="ALT Linux" vendor="ALTLinux"><vers edition="Junior" num="2.3"/><vers edition="Compact" num="2.3"/></prod><prod name="xli" vendor="xli"><vers num="1.17"/><vers num="1.16"/><vers num="1.15"/><vers num="1.14"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0640" published="2005-03-02" seq="2005-0640" severity="Medium" type="CVE"><desc><descript source="cve">Computer Associates (CA) Unicenter Asset Management (UAM) 4.0 does not properly initialize the &quot;Change Credentials for Database&quot; window, which allows local users to recover the SQL Admin password via certain methods.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CONFIRM" url="http://supportconnect.ca.com/sc/solcenter/solresults.jsp?aparno=Qo64323">http://supportconnect.ca.com/sc/solcenter/solresults.jsp?aparno=Qo64323</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14454">14454</ref></refs><vuln_soft><prod name="Unicenter Asset Management" vendor="Computer Associates"><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0641" published="2005-03-02" seq="2005-0641" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in the Reporter for Computer Associates (CA) Unicenter Asset Management (UAM) 4.0 allows remote attackers to inject arbitrary HTML or web script via the (1) name or (2) description in a report template.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="CONFIRM" url="http://supportconnect.ca.com/sc/solcenter/solresults.jsp?aparno=Qo64323">http://supportconnect.ca.com/sc/solcenter/solresults.jsp?aparno=Qo64323</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14454">14454</ref></refs><vuln_soft><prod name="Unicenter Asset Management" vendor="Computer Associates"><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0642" published="2005-05-02" seq="2005-0642" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in the Query Designer for Computer Associates (CA) Unicenter Asset Management (UAM) 4.0 allows remote attackers to execute arbitrary SQL via an imported file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="CONFIRM" url="http://supportconnect.ca.com/sc/solcenter/solresults.jsp?aparno=Qo64323">http://supportconnect.ca.com/sc/solcenter/solresults.jsp?aparno=Qo64323</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14454">14454</ref></refs><vuln_soft><prod name="Unicenter Asset Management" vendor="Computer Associates"><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-08-16" name="CVE-2005-0643" published="2005-05-02" seq="2005-0643" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in McAfee Scan Engine 4320 with DAT version before 4357 allows remote attackers to execute arbitrary code via crafted LHA files.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="CONFIRM" url="http://images.mcafee.com/misc/McAfee_Security_Bulletin_05-march-17.pdf">http://images.mcafee.com/misc/McAfee_Security_Bulletin_05-march-17.pdf</ref><ref source="BID" url="http://www.securityfocus.com/bid/10243">10243</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14628">14628</ref><ref adv="1" source="USCERT" url="http://www.kb.cert.org/vuls/id/361180">McAfee Scan Engine vulnerable to buffer overflow in LHA decoder</ref></refs><vuln_soft><prod name="McAfee Antivirus Engine" vendor="McAfee"><vers num="4.3.20"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-08-16" name="CVE-2005-0644" published="2005-05-02" seq="2005-0644" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in McAfee Scan Engine 4320 with DAT version before 4436 allows remote attackers to execute arbitrary code via a malformed LHA file with a type 2 header file name field, a variant of CVE-2005-0643.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS" url="http://xforce.iss.net/xforce/alerts/id/190">20050317 McAfee AntiVirus Library Stack Overflow</ref><ref adv="1" source="CONFIRM" url="http://images.mcafee.com/misc/McAfee_Security_Bulletin_05-march-17.pdf">http://images.mcafee.com/misc/McAfee_Security_Bulletin_05-march-17.pdf</ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/361180">VU#361180</ref><ref source="MISC" url="http://securitytracker.com/id?1013463">http://securitytracker.com/id?1013463</ref><ref source="BID" url="http://www.securityfocus.com/bid/10243">10243</ref><ref source="BID" url="http://www.securityfocus.com/bid/12832">12832</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14628">14628</ref></refs><vuln_soft><prod name="McAfee Antivirus Engine" vendor="McAfee"><vers num="4.3.20"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0645" published="2005-05-02" seq="2005-0645" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in show.inc.php in cuteNews 1.3.6 allows remote attackers to inject arbitrary HTML, web script, and PHP code via the (1) CLIENT-IP or (2) X-FORWARDED-FOR header in an HTTP POST request to show_news.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110969774502370&amp;w=2">20050301 Kernelpanik Labs Digest 2005-2</ref><ref source="MISC" url="http://www.kernelpanik.org/docs/kernelpanik/cutenews.txt">http://www.kernelpanik.org/docs/kernelpanik/cutenews.txt</ref></refs><vuln_soft><prod name="cuteNews" vendor="cutePHP"><vers num="1.3.6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0646" published="2005-05-02" seq="2005-0646" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in auth.php in paNews 2.0.4b allows remote attackers to execute arbitrary SQL via the mysql_prefix parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110969774502370&amp;w=2">20050301 Kernelpanik Labs Digest 2005-2</ref><ref source="MISC" url="http://www.kernelpanik.org/docs/kernelpanik/panews.txt">http://www.kernelpanik.org/docs/kernelpanik/panews.txt</ref></refs><vuln_soft><prod name="paNews" vendor="PHP Arena"><vers num="2.0.4b"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0647" published="2005-05-02" seq="2005-0647" severity="Medium" type="CVE"><desc><descript source="cve">admin_setup.php in paNews 2.0.4b allows remote attackers to inject arbitrary PHP code via the (1) $form[comments] or (2) $form[autoapprove] parameters, which are written to config.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110969774502370&amp;w=2">20050301 Kernelpanik Labs Digest 2005-2</ref><ref source="MISC" url="http://www.kernelpanik.org/docs/kernelpanik/panews.txt">http://www.kernelpanik.org/docs/kernelpanik/panews.txt</ref></refs><vuln_soft><prod name="paNews" vendor="PHP Arena"><vers num="2.0.4b"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-08-23" name="CVE-2005-0648" published="2005-05-02" seq="2005-0648" severity="Medium" type="CVE"><desc><descript source="cve">Multiple vulnerabilities in Pixel-Apes SafeHTML before 1.3.0 allow remote attackers to bypass cross-site scripting (XSS) protection via (1) &quot;decimal HTML entities&quot; or (2) &quot;the \x00 symbol.&quot;</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="CONFIRM" url="http://pixel-apes.com/safehtml/feed">http://pixel-apes.com/safehtml/feed</ref><ref source="MISC" url="http://securitytracker.com/id?1013315">http://securitytracker.com/id?1013315</ref></refs><vuln_soft><prod name="SafeHTML" vendor="Pixel-Apes Group"><vers num="1.3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-08-23" name="CVE-2005-0649" published="2005-05-02" seq="2005-0649" severity="Medium" type="CVE"><desc><descript source="cve">Pixel-Apes SafeHTML before 1.2.1 allows remote attackers to bypass cross-site scripting (XSS) protection via &quot;hexadecimal HTML entities.&quot;</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="CONFIRM" url="http://pixel-apes.com/safehtml/feed">http://pixel-apes.com/safehtml/feed</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13869">13869</ref></refs><vuln_soft><prod name="SafeHTML" vendor="Pixel-Apes Group"><vers num="1.2.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0650" published="2005-05-02" seq="2005-0650" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in ProjectBB 0.4.5.1 allow remote attackers to inject arbitrary web script or HTML via (1) the pages parameter to divers.php (incorrectly referred to as &quot;drivers.php&quot; by some sources), (2) in the search feature text area, (3) forum name, (4) site name or (5) the maximum avatar size in the option section, (5) new category or (6) new forum fields in the forum section.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111031893610270&amp;w=2">20050308 failles dans ProjectBB v0.4.5.1</ref><ref source="MISC" url="http://securitytracker.com/id?1013332">http://securitytracker.com/id?1013332</ref><ref source="MISC" url="http://www.frsirt.com/english/advisories/2005/0223">http://www.frsirt.com/english/advisories/2005/0223</ref><ref source="BID" url="http://www.securityfocus.com/bid/12709">12709</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14533">14533</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19556">projectbb-multiple-xss(19556)</ref></refs><vuln_soft><prod name="ProjectBB" vendor="ProjectBB"><vers num="0.4.5.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0651" published="2005-05-02" seq="2005-0651" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in ProjectBB 0.4.5.1 allow remote attackers to execute arbitrary SQL commands via (1) liste or (2) desc parameters to divers.php (incorrectly referred to as &quot;drivers.php&quot; by some sources), (3) the search feature text area, (4) post name in the post creation feature, (5) City, (6) Homepage, (7) ICQ, (8) AOL, (9) Yahoo!, (10) MSN, or (11) e-mail fields in the profile feature or (12) the new field in the moderator section.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111031893610270&amp;w=2">20050308 failles dans ProjectBB v0.4.5.1</ref><ref source="MISC" url="http://securitytracker.com/id?1013332">http://securitytracker.com/id?1013332</ref><ref source="MISC" url="http://www.frsirt.com/english/advisories/2005/0223">http://www.frsirt.com/english/advisories/2005/0223</ref><ref source="BID" url="http://www.securityfocus.com/bid/12710">12710</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14533">14533</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19557">projectbb-mulitple-sql-injection(19557)</ref></refs><vuln_soft><prod name="ProjectBB" vendor="ProjectBB"><vers num="0.4.5.1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-05" name="CVE-2005-0652" published="2005-05-02" seq="2005-0652" severity="Low" type="CVE"><desc><descript source="cve">Unknown vulnerability in HP OpenVMS VAX 7.x and 6.x and OpenVMS Alpha 7.x or 6.x allows local users to access privileged files.</descript></desc><loss_types><conf/></loss_types><vuln_types><other/></vuln_types><range><local/></range><refs><ref source="HP" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110980700101451&amp;w=2">SSRT4866</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14444">14444</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19566">openvms-gain-access(19566)</ref></refs><vuln_soft><prod name="HP OpenVMS VAX" vendor="HP"><vers num="6.2"/><vers num="7.3"/></prod><prod name="HP OpenVMS Alpha" vendor="HP"><vers num="6.2"/><vers num="7.3_1"/><vers num="7.3_2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0653" published="2005-05-02" seq="2005-0653" severity="Medium" type="CVE"><desc><descript source="cve">phpMyAdmin 2.6.1 does not properly grant permissions on tables with an underscore in the name, which grants remote authenticated users more privileges than intended.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200503-07.xml">GLSA-200503-07</ref><ref patch="1" source="MISC" url="http://bugs.gentoo.org/show_bug.cgi?id=83792">http://bugs.gentoo.org/show_bug.cgi?id=83792</ref></refs><vuln_soft><prod name="phpMyAdmin" vendor="phpMyAdmin"><vers num="2.6.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0654" published="2005-05-02" seq="2005-0654" severity="Medium" type="CVE"><desc><descript source="cve">gifload.exe in GIMP 2.0.5, 2.2.3, and possibly 2.2.4 allows remote attackers or local users to cause a denial of service (application crash) via the image descriptor (1) height or (2) width fields set to zero.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110995346018830&amp;w=2">20050304 GIMP gifload.exe GIF file (image width)*(image height)==0 DOS vulnerability</ref></refs><vuln_soft><prod name="GIMP" vendor="The GIMP Team"><vers num="2.0.5"/><vers num="2.2.3"/><vers num="2.2.4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0655" published="2005-05-02" seq="2005-0655" severity="Medium" type="CVE"><desc><descript source="cve">auraCMS 1.5 allows remote attackers to obtain sensitive information via an HTTP request with an invalid id parameter to (1) teman.php, (2) hal.php, or (3) arsip.php, which reveals the path in a PHP error message.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110979842315750&amp;w=2">20050302 Vulnerabilities in Aura CMS</ref><ref source="MISC" url="http://securitytracker.com/id?1013357">http://securitytracker.com/id?1013357</ref></refs><vuln_soft><prod name="auraCMS" vendor="Arif Supriyanto"><vers num="1.5"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0656" published="2005-05-02" seq="2005-0656" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in auraCMS 1.5 allow remote attackers to inject arbitrary web script or HTML via the (1) hits parameter to hits.php, (2) query parameter to index.php, or (3) theCount parameter to counter.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110979842315750&amp;w=2">20050302 Vulnerabilities in Aura CMS</ref><ref source="MISC" url="http://securitytracker.com/id?1013357">http://securitytracker.com/id?1013357</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14458">14458</ref></refs><vuln_soft><prod name="auraCMS" vendor="Arif Supriyanto"><vers num="1.5"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0657" published="2005-05-02" seq="2005-0657" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in Computalynx CProxy 3.3.x and 3.4.x through 3.4.4 allows remote attackers to read arbitrary files or cause a denial of service (application crash) via a .. (dot dot) in an HTTP request.</descript></desc><loss_types><avail/><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110980096304013&amp;w=2">20050302 Security Advisory: Computalynx CProxy Server Multiple Remote Vulnerabilities</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14461">14461</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19573">computalynx-cproxy-directory-traversal(19573)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19574">computalynx-cproxy-get-dos(19574)</ref></refs><vuln_soft><prod name="CProxy" vendor="Computalynx"><vers num="3.3"/><vers num="3.4"/><vers num="3.4.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0658" published="2005-05-02" seq="2005-0658" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in a third party extension to TYPO3 allows remote attackers to execute arbitrary SQL commands via the category_uid parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110987892618892&amp;w=2">20050303 TYPO3 SQL Injection vunerabilitie</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110995289619649&amp;w=2">20050304 RE: TYPO3 SQL Injection vunerabilitie</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110996536620069&amp;w=2">20050304 Re: TYPO3 SQL Injection vunerabilitie</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/14465">14465</ref></refs><vuln_soft><prod name="CMW Linklist" vendor="CMW Linklist"><vers num="1.4.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0659" published="2005-05-02" seq="2005-0659" severity="Medium" type="CVE"><desc><descript source="cve">phpBB 2.0.13 and earlier allows remote attackers to obtain sensitive information via a direct request to oracle.php, which reveals the path in a PHP error message.</descript></desc><loss_types><conf/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110996579900134&amp;w=2">20050304 -==phpBB 2.0.13 Full path disclosure==-</ref><ref source="MISC" url="http://neosecurityteam.net/Advisories/Advisory-09.txt">http://neosecurityteam.net/Advisories/Advisory-09.txt</ref><ref source="MISC" url="http://securitytracker.com/id?1013377">http://securitytracker.com/id?1013377</ref></refs><vuln_soft><prod name="phpBB" vendor="phpBB Group"><vers num="2.0.9"/><vers num="2.0.8a"/><vers num="2.0.8"/><vers num="2.0.7a"/><vers num="2.0.7"/><vers num="2.0.6d"/><vers num="2.0.6c"/><vers num="2.0.6"/><vers num="2.0.5"/><vers num="2.0.4"/><vers num="2.0.3"/><vers num="2.0.2"/><vers num="2.0.13"/><vers num="2.0.12"/><vers num="2.0.11"/><vers num="2.0.10"/><vers num="2.0.1"/><vers num="2.0 RC4"/><vers num="2.0 RC3"/><vers num="2.0 RC2"/><vers num="2.0 RC1"/><vers num="2.0 Beta1"/><vers num="2.0.0"/><vers num="1.4.4"/><vers num="1.4.2"/><vers num="1.4.1"/><vers num="1.4.0"/><vers num="1.2.1"/><vers num="1.2.0"/><vers num="1.0.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0660" published="2005-05-02" seq="2005-0660" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in D-Forum 1.11 allows remote attackers to inject arbitrary web script or HTML via certain fields, as demonstrated using the page parameter in nav.php3.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MISC" url="http://securitytracker.com/id?1013349">http://securitytracker.com/id?1013349</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14464">14464</ref></refs><vuln_soft><prod name="D-Forum" vendor="Adalis"><vers num="1.11"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0661" published="2005-05-02" seq="2005-0661" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in the getwbbuserdata function in session.php for Woltlab Burning Board 2.0.3 through 2.3.0 allows remote attackers to execute arbitrary SQL commands via the (1) userid or (2) lastvisit cookie.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MISC" url="http://securitytracker.com/id?1013351">http://securitytracker.com/id?1013351</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/14450">14450</ref></refs><vuln_soft><prod name="Burning Board" vendor="Woltlab"><vers num="2.0.3"/><vers num="2.1.5"/><vers num="2.2.1"/><vers num="2.3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0662" published="2005-05-02" seq="2005-0662" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in index.php for MercuryBoard 1.1.2 allows remote attackers to inject arbitrary web script or HTML via the Avatar field.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="OSVDB" url="http://www.osvdb.org/14308">14308</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/14414">14414</ref></refs><vuln_soft><prod name="MercuryBoard" vendor="MercuryBoard"><vers num="1.1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0663" published="2005-05-02" seq="2005-0663" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in index.php for MercuryBoard 1.1.2 allows remote attackers to inject arbitrary SQL commands via the f parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="OSVDB" url="http://www.osvdb.org/14308">14308</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/14414">14414</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19051">mercuryboard-index-sql-injection(19051)</ref></refs><vuln_soft><prod name="MercuryBoard" vendor="MercuryBoard"><vers num="1.1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-06-15" name="CVE-2005-0664" published="2005-05-02" seq="2005-0664" severity="Low" type="CVE"><desc><descript source="cve">Buffer overflow in the EXIF library (libexif) 0.6.9 does not properly validate the structure of the EXIF tags, which allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a JPEG image with a crafted EXIF tag.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-709">DSA-709</ref><ref patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200503-17.xml">GLSA-200503-17</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:064">MDKSA-2005:064</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111022284403377&amp;w=2">20050307 [USN-91-1] EXIF library vulnerability</ref><ref patch="1" source="MISC" url="https://bugzilla.ubuntu.com/show_bug.cgi?id=7152">https://bugzilla.ubuntu.com/show_bug.cgi?id=7152</ref><ref patch="1" source="MISC" url="http://securitytracker.com/id?1013398">http://securitytracker.com/id?1013398</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-91-1">USN-91-1</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102041-1">102041</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/0240">ADV-2005-0240</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/2565">ADV-2005-2565</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17705">17705</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-300.html">RHSA-2005:300</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:064">MDKSA-2005:064</ref></refs><vuln_soft><prod name="libexif" vendor="libexif"><vers num="0.6.9"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0665" published="2005-05-02" seq="2005-0665" severity="Medium" type="CVE"><desc><descript source="cve">Format string vulnerability in xv before 3.10a allows remote attackers to execute arbitrary code via format string specifiers in a filename.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200503-09.xml">GLSA-200503-09</ref><ref source="MISC" url="http://bugs.gentoo.org/show_bug.cgi?id=83686">http://bugs.gentoo.org/show_bug.cgi?id=83686</ref></refs><vuln_soft><prod name="XV" vendor="John Bradley"><vers num="3.10a"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0666" published="2005-05-02" seq="2005-0666" severity="Medium" type="CVE"><desc><descript source="cve">Unknown vulnerability in PaX from the September 2003 release to 2.2 before 2005.03.05, related to SEGMEXEC or RANDEXEC and VMA mirroring, allows local users and possibly remote attackers to bypass intended access restrictions and execute arbitrary code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><other/></vuln_types><range><local/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/392348">20050305 PaX privilege elevation security bug</ref><ref source="BID" url="http://www.securityfocus.com/bid/12729">12729</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14489">14489</ref></refs><vuln_soft><prod name="PaX linux" vendor="The PaX Team"><vers num="2.6.5"/><vers num="2.4.28"/><vers num="2.4.27"/><vers num="2.4.26"/><vers num="2.4.25"/><vers num="2.4.24"/><vers num="2.4.23"/><vers num="2.4.22"/><vers num="2.4.21"/><vers num="2.4.20"/><vers num="2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-22" name="CVE-2005-0667" published="2005-03-07" seq="2005-0667" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in Sylpheed before 1.0.3 and other versions before 1.9.5 allows remote attackers to execute arbitrary code via an e-mail message with certain headers containing non-ASCII characters that are not properly handled when the user replies to the message.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="CONFIRM" url="http://sylpheed.good-day.net/changelog.html.en">http://sylpheed.good-day.net/changelog.html.en</ref><ref adv="1" patch="1" source="CONFIRM" url="http://sylpheed.good-day.net/changelog-devel.html.en">http://sylpheed.good-day.net/changelog-devel.html.en</ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200503-26.xml">GLSA-200503-26</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-303.html">RHSA-2005:303</ref><ref adv="1" source="MISC" url="http://securitytracker.com/id?1013376">http://securitytracker.com/id?1013376</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14491">14491</ref></refs><vuln_soft><prod name="Enterprise Linux AS" vendor="Red Hat"><vers edition="Advanced Server" num="2.1"/><vers edition="Advanced Server" num="2.1"/></prod><prod name="Sylpheed-Claws" vendor="Sylpheed-Claws"><vers num="1.0.2"/></prod><prod name="Sylpheed" vendor="Sylpheed"><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0.0"/><vers num="0.9.99"/><vers num="0.9.12"/><vers num="0.9.11"/><vers num="0.9.10"/><vers num="0.9.9"/><vers num="0.9.8"/><vers num="0.9.7"/><vers num="0.9.6"/><vers num="0.9.5"/><vers num="0.9.4"/><vers num="0.8.11"/></prod><prod name="ALT Linux" vendor="ALTLinux"><vers edition="Junior" num="2.3"/><vers edition="Compact" num="2.3"/></prod><prod name="Enterprise Linux WS" vendor="Red Hat"><vers edition="Workstation" num="2.1"/><vers edition="Workstation" num="2.1"/></prod><prod name="Enterprise Linux ES" vendor="Red Hat"><vers edition="Enterprise Server" num="2.1"/><vers edition="Enterprise Server" num="2.1"/></prod><prod name="Fedora" vendor="Red Hat"><vers num="Core 3.0"/></prod><prod name="Advanced Workstation Itanium Processor" vendor="Red Hat"><vers edition="IA64" num="2.1"/><vers num="2.1"/></prod><prod name="Linux" vendor="Gentoo"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0668" published="2005-03-04" seq="2005-0668" severity="High" type="CVE"><desc><descript source="cve">Unknown vulnerability in HTTP Anti Virus Proxy (HAVP) before 0.51 prevents viruses from being properly detected in certain files such as (1) .CAB or (2) .ZIP files.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CONFIRM" url="http://www.bemberg.de/server-side/index.htm">http://www.bemberg.de/server-side/index.htm</ref><ref adv="1" patch="1" source="MISC" url="http://securitytracker.com/id?1013370">http://securitytracker.com/id?1013370</ref></refs><vuln_soft><prod name="HTTP Anti Virus Proxy (HAVP)" vendor="Christian Hilgers"><vers num="0.50" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-03-29" name="CVE-2005-0669" published="2005-05-02" seq="2005-0669" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in mod.php for phpCOIN 1.2.0 through 1.2.1b allow remote attackers to execute arbitrary SQL commands via the (1) the faq_id in the faq mod, (2) the id parameter in the pages mod, (3) the id parameter in the siteinfo module, (4) the topic_id parameter in the articles module, (5) the ord_id in the orders module, (6) the dom_id parameter in the domains module, or (7) the invd_id parameter in the invoices module.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MISC" url="http://lostmon.blogspot.com/2005/03/phpcoin-posible-sql-injection-comands.html">http://lostmon.blogspot.com/2005/03/phpcoin-posible-sql-injection-comands.html</ref><ref source="CONFIRM" url="http://forums.phpcoin.com/index.php?showtopic=4118">http://forums.phpcoin.com/index.php?showtopic=4118</ref><ref patch="1" source="CONFIRM" url="http://forums.phpcoin.com/index.php?showtopic=4116">http://forums.phpcoin.com/index.php?showtopic=4116</ref><ref source="CONFIRM" url="http://forums.phpcoin.com/index.php?showtopic=4101">http://forums.phpcoin.com/index.php?showtopic=4101</ref><ref source="BID" url="http://www.securityfocus.com/bid/12686">12686</ref><ref source="MISC" url="http://securitytracker.com/id?1013329">http://securitytracker.com/id?1013329</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/14439">14439</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19571">phpcoin-id-sql-injection(19571)</ref></refs><vuln_soft><prod name="phpCOIN" vendor="COINSoft Technologies"><vers num="1.2.1b"/><vers num="1.2.1"/><vers num="1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-03-29" name="CVE-2005-0670" published="2005-05-02" seq="2005-0670" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in phpCOIN 1.2.0 through 1.2.1b allows remote attackers to inject arbitrary web script or HTML via (1) the new parameter to mod.php, (2) the w parameter to mod.php, (3) the e parameter to login.php, (4) the o parameter to login.php, and possibly other scripts.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MISC" url="http://lostmon.blogspot.com/2005/03/phpcoin-posible-sql-injection-comands.html">http://lostmon.blogspot.com/2005/03/phpcoin-posible-sql-injection-comands.html</ref><ref source="CONFIRM" url="http://forums.phpcoin.com/index.php?showtopic=4118">http://forums.phpcoin.com/index.php?showtopic=4118</ref><ref patch="1" source="CONFIRM" url="http://forums.phpcoin.com/index.php?showtopic=4116">http://forums.phpcoin.com/index.php?showtopic=4116</ref><ref source="CONFIRM" url="http://forums.phpcoin.com/index.php?showtopic=4101">http://forums.phpcoin.com/index.php?showtopic=4101</ref><ref source="BID" url="http://www.securityfocus.com/bid/12686">12686</ref><ref source="MISC" url="http://securitytracker.com/id?1013329">http://securitytracker.com/id?1013329</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/14439">14439</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19572">phpcoin-xss(19572)</ref></refs><vuln_soft><prod name="phpCOIN" vendor="COINSoft Technologies"><vers num="1.2.1b"/><vers num="1.2.1"/><vers num="1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0671" published="2005-03-03" seq="2005-0671" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in Carsten&apos;s 3D Engine (Ca3DE), March 2004 version and earlier, allows remote attackers to execute arbitrary code via format string specifiers in a command.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Luigi Auriemma" url="http://aluigi.altervista.org/adv/ca3dex-adv.txt">http://aluigi.altervista.org/adv/ca3dex-adv.txt</ref><ref adv="1" source="SecurityTracker" url="http://securitytracker.com/id?1013361">http://securitytracker.com/id?1013361</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/12727">12727</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14483">14483</ref></refs><vuln_soft><prod name="Ca3DE" vendor="Ca3DE"><vers num="March 2004" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0672" published="2005-05-02" seq="2005-0672" severity="High" type="CVE"><desc><descript source="cve">Carsten&apos;s 3D Engine (Ca3DE), March 2004 version and earlier, allows remote attackers to execute arbitrary code via text strings that are not null terminated, which triggers a null dereference.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref source="Luigi Auriemma" url="http://aluigi.altervista.org/adv/ca3dex-adv.txt">http://aluigi.altervista.org/adv/ca3dex-adv.txt</ref><ref source="SecurityTracker" url="http://securitytracker.com/id?1013361">http://securitytracker.com/id?1013361</ref><ref source="BID" url="http://www.securityfocus.com/bid/12727">12727</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14483">14483</ref></refs><vuln_soft><prod name="Ca3DE" vendor="Ca3DE"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0673" published="2005-05-02" seq="2005-0673" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in usercp_register.php for phpBB 2.0.13 allows remote attackers to inject arbitrary web script or HTML by setting the (1) allowhtml, (2) allowbbcode, or (3) allowsmilies parameters to inject HTML into signatures for personal messages, possibly when they are processed by privmsg.php or viewtopic.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MISC" url="http://securitytracker.com/id?1013362">http://securitytracker.com/id?1013362</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/14475">14475</ref></refs><vuln_soft><prod name="phpBB" vendor="phpBB Group"><vers num="2.0.13"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0674" published="2005-03-03" seq="2005-0674" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in the News module for paBox 1.6 allows remote attackers to inject arbitrary web script or HTML via the text hidden parameter in an HTTP POST request.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110987537431541&amp;w=2">20050303 [XSS] paBox 1.6</ref><ref adv="1" source="MISC" url="http://securitytracker.com/id?1013363">http://securitytracker.com/id?1013363</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/12719">12719</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/14474">14474</ref></refs><vuln_soft><prod name="paBox" vendor="PHP Arena"><vers num="1.6"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0675" published="2005-05-02" seq="2005-0675" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in index.php for Zorum 3.5 allows remote attackers to inject arbitrary web script or HTML via the (1) list or (2) frommethod parameters.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MISC" url="http://securitytracker.com/id?1013365">http://securitytracker.com/id?1013365</ref><ref source="SECUNIA" url="http://secunia.com/advisories/9497">9497</ref></refs><vuln_soft><prod name="Zorum" vendor="PHPOutsourcing"><vers num="3.5"/><vers num="3.4"/><vers num="3.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0676" published="2005-05-04" seq="2005-0676" severity="High" type="CVE"><desc><descript source="cve">index.php in Zorum 3.5 allows remote attackers to trigger an SQL error, and possibly inject arbitrary SQL commands, via the search capability.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://securitytracker.com/id?1013365">http://securitytracker.com/id?1013365</ref></refs><vuln_soft><prod name="Zorum" vendor="PhpOutsourcing"><vers num="3.5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0677" published="2005-05-02" seq="2005-0677" severity="Medium" type="CVE"><desc><descript source="cve">index.php for Zorum 3.5 allows remote attackers to perform certain actions as other users by modifying the id parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MISC" url="http://securitytracker.com/id?1013365">http://securitytracker.com/id?1013365</ref></refs><vuln_soft><prod name="Zorum" vendor="PHPOutsourcing"><vers num="3.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-28" name="CVE-2005-0678" published="2005-05-02" seq="2005-0678" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in formmail.inc.php for Form Mail Script 2.3 and earlier allows remote attackers to execute arbitrary PHP code by modifying the script_root to reference a URL on a remote web server that contains the code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110996489800035&amp;w=2">20050304 PHP Form Mail Script (2.3) - Arbitrary File Inclusion (VXSfx)</ref><ref source="MISC" url="http://securitytracker.com/id?1013378">http://securitytracker.com/id?1013378</ref><ref patch="1" source="CONFIRM" url="http://www.stadtaus.com/forum/t-1579.html">http://www.stadtaus.com/forum/t-1579.html</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/14505">14505</ref></refs><vuln_soft><prod name="Form Mail Script" vendor="STADTAUS"><vers num="2.3" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-01-03" name="CVE-2005-0679" published="2005-05-02" seq="2005-0679" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in tell_a_friend.inc.php for Tell A Friend Script 2.7 before 20050305 allows remote attackers to execute arbitrary PHP code by modifying the script_root parameter to reference a URL on a remote web server that contains the code.  NOTE: it was later reported that 2.4 is also affected.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CONFIRM" url="http://www.stadtaus.com/forum/t-1579.html">http://www.stadtaus.com/forum/t-1579.html</ref><ref patch="1" source="MISC" url="http://securitytracker.com/id?1013390">http://securitytracker.com/id?1013390</ref><ref source="OSVDB" url="http://www.osvdb.org/14628">14628</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/474954/100/0/threaded">20070727 Friend Script 2.5 - 2.4 Remote File Include</ref><ref source="" url="http://arfis.wordpress.com/2007/09/13/rfi-02-openelibrary/"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19630">tellafriend-scriptroot-file-include(19630)</ref></refs><vuln_soft><prod name="Tell A Friend Script" vendor="stadtaus"><vers num="2.7" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-28" name="CVE-2005-0680" published="2005-03-07" seq="2005-0680" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in download_center_lite.inc.php for Download Center Lite 1.6 allows remote attackers to execute arbitrary PHP code by modifying the script_root parameter to reference a URL on a remote web server that contains the code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110996056601719&amp;w=2">20050304 Download Center Lite (DCL) - Arbitrary File Inclusion (VXSfx)</ref><ref adv="1" patch="1" source="CONFIRM" url="http://www.stadtaus.com/forum/t-1579.html">http://www.stadtaus.com/forum/t-1579.html</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14513">14513</ref></refs><vuln_soft><prod name="Download Center Lite" vendor="STADTAUS"><vers num="1.5" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0681" published="2005-03-06" seq="2005-0681" severity="Medium" type="CVE"><desc><descript source="cve">Nokia Symbian 60 allows remote attackers to cause a denial of service (phone restart) via a Bluetooth nickname.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://securitytracker.com/id?1013380">http://securitytracker.com/id?1013380</ref><ref source="" url="http://www.securiteam.com/securitynews/5PP0V00G1S.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/12743">12743</ref><ref source="OSVDB" url="http://www.osvdb.org/14574">14574</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19594">nokia-symbian-dos(19594)</ref></refs><vuln_soft><prod name="Series" vendor="Nokia"><vers num="60"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0682" published="2005-05-02" seq="2005-0682" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in common.inc in Drupal before 4.5.2 allows remote attackers to inject arbitrary web script or HTML via certain inputs.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CONFIRM" url="http://drupal.org/drupal-4.5.2">http://drupal.org/drupal-4.5.2</ref><ref patch="1" source="CONFIRM" url="http://drupal.org/files/drupal-4.5-xss-fix.patch">http://drupal.org/files/drupal-4.5-xss-fix.patch</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14515">14515</ref></refs><vuln_soft><prod name="Drupal" vendor="Drupal"><vers num="4.5.1"/><vers num="4.5.0"/><vers num="4.4.2"/><vers num="4.4.1"/><vers num="4.4.0"/></prod></vuln_soft></entry><entry modified="2005-10-25" name="CVE-2005-0683" published="2005-05-02" reject="1" seq="2005-0683" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2005-0659.  Reason: This candidate is a duplicate of CVE-2005-0659.  Notes: All CVE users should reference CVE-2005-0659 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript></desc><refs/></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-03-28" name="CVE-2005-0684" published="2005-04-25" seq="2005-0684" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in the web tool for MySQL MaxDB before 7.5.00.26 allows remote attackers to execute arbitrary code via (1) an HTTP GET request with a long file parameter after a percent (&quot;%&quot;) sign or (2) a long Lock-Token string to the WebDAV functionality, which is not properly handled by the getLockTokenHeader function in WDVHandler_CommonUtils.c.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=234&amp;type=vulnerabilities">20050425 MySQL MaxDB Webtool Remote Stack Overflow Vulnerability</ref><ref adv="1" patch="1" source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=235&amp;type=vulnerabilities">20050425 MySQL MaxDB Webtool Remote Lock-Token Stack Overflow Vulnerability</ref><ref adv="1" patch="1" source="CONFIRM" url="http://dev.mysql.com/doc/maxdb/changes/changes_7.5.00.26.html#WebDAV">http://dev.mysql.com/doc/maxdb/changes/changes_7.5.00.26.html#WebDAV</ref><ref source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=234&amp;type=vulnerabilities">20050425 MySQL MaxDB Webtool Remote Stack Overflow Vulnerability</ref><ref source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=235&amp;type=vulnerabilities">20050425 MySQL MaxDB Webtool Remote Lock-Token Stack Overflow Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/13368">13368</ref></refs><vuln_soft><prod name="MaxDB" vendor="MySQL"><vers num="7.5.00.23"/><vers num="7.5.00.19"/><vers num="7.5.00.18"/><vers num="7.5.00.16"/><vers num="7.5.00.15"/><vers num="7.5.00.14"/><vers num="7.5.00.12"/><vers num="7.5.00.11"/><vers num="7.5.00.08"/><vers num="7.5.00"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0685" published="2005-03-08" seq="2005-0685" severity="High" type="CVE"><desc><descript source="cve">Multiple access validation errors in OutStart Participate Enterprise (PE) allow remote attackers to (1) browse arbitrary directory trees by modifying the rootFolder parameter to displaynavigator.jsp, (2) rename arbitrary directory objects by modifying the selectedObject parameter to renamepopup.jsp, (3) delete arbitrary directory objects by modifying the selectedObjectsCSV parameter to displaydeletenavigator.jsp, and conduct other unauthorized activities via the (4) showDeleteView, (5) showWebFolderView, (6) showLibraryView, (7) showMyLibraryView, (8) singleSelectObject, (9) processRadioSelection, (10) processCheckboxSelection, (11) singleSelectObject, (12) addToSelectedObjects, or (13) removeFromSelectedObjects commands.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/392623">20050308 PE Multiple Remote Access Validation Vulnerabilities (Participate Systems Inc. / Outstart Inc.)</ref><ref adv="1" patch="1" source="MISC" url="http://security.honour.ca/outstartpsi.txt">http://security.honour.ca/outstartpsi.txt</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/12752">12752</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14542">14542</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19632">pe-access-validation-dos(19632)</ref></refs><vuln_soft><prod name="Participate Enterprise" vendor="OutStart"><vers num="3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0686" published="2005-03-07" seq="2005-0686" severity="High" type="CVE"><desc><descript source="cve">Integer overflow in mlterm 2.5.0 through 2.9.1, with gdk-pixbuf support enabled, allows remote attackers to execute arbitrary code via a large image file that is used as a background.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200503-13.xml">GLSA-200503-13</ref><ref adv="1" patch="1" source="CONFIRM" url="https://sourceforge.net/project/shownotes.php?release_id=310416">https://sourceforge.net/project/shownotes.php?release_id=310416</ref></refs><vuln_soft><prod name="mlterm" vendor="mlterm"><vers num="2.9.1"/><vers num="2.9"/><vers num="2.8"/><vers num="2.7"/><vers num="2.6.3"/><vers num="2.6.2"/><vers num="2.6.1"/><vers num="2.6"/><vers num="2.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0687" published="2005-03-06" seq="2005-0687" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in Hashcash 1.16 allows remote attackers to cause a denial of service (memory consumption) and possibly execute arbitrary code via format string specifiers in a reply address, which is not properly handled when printing the header.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200503-12.xml">GLSA-200503-12</ref><ref adv="1" patch="1" source="MISC" url="http://bugs.gentoo.org/show_bug.cgi?id=83541">http://bugs.gentoo.org/show_bug.cgi?id=83541</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14487">14487</ref></refs><vuln_soft><prod name="Hashcash" vendor="Hashcash"><vers num="1.16"/><vers num="1.15"/><vers num="1.14"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0688" published="2005-03-05" seq="2005-0688" severity="Medium" type="CVE"><desc><descript source="cve">Windows Server 2003 and XP SP2, with Windows Firewall turned off, allows remote attackers to cause a denial of service (CPU consumption) via a TCP packet with the SYN flag set and the same destination and source address and port, aka a reoccurrence of the &quot;Land&quot; vulnerability (CVE-1999-0016).</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111005099504081&amp;w=2">20050305 Windows Server 2003 and XP SP2 LAND attack vulnerability</ref><ref adv="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms05-019.mspx">MS05-019</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1288.html">OVAL1288</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1685.html">OVAL1685</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval4978.html">OVAL4978</ref><ref source="MS" url="http://www.microsoft.com/technet/security/Bulletin/MS06-064.mspx">MS06-064</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/3983">ADV-2006-3983</ref><ref source="SECUNIA" url="http://secunia.com/advisories/22341">22341</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/449179/100/0/threaded">HPSBST02161</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1288">oval:org.mitre.oval:def:1288</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1685">oval:org.mitre.oval:def:1685</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4978">oval:org.mitre.oval:def:4978</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:482">oval:org.mitre.oval:def:482</ref></refs><vuln_soft><prod name="Windows XP" vendor="Microsoft"><vers edition="Tablet PC" num="SP2"/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers num="R2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0689" published="2005-03-07" seq="2005-0689" severity="High" type="CVE"><desc><descript source="cve">includer.cgi in The Includer allows remote attackers to execute arbitrary commands via shell metacharacters in (1) the URL or (2) the template parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111021730710779&amp;w=2">20050307 Remote Command Execution</ref><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111030957413411&amp;w=2">20050308 Re: Remote Command Execution</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/12738">12738</ref></refs><vuln_soft><prod name="The Includer" vendor="Jimmy"><vers num="1.1"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0690" published="2005-03-07" seq="2005-0690" severity="Low" type="CVE"><desc><descript source="cve">Gene6 FTP Server does not properly restrict access to the control console, which allows local users to modify the server configuration and gain privileges, as demonstrated by defining a SITE command.</descript></desc><loss_types><int/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111022496826680&amp;w=2">20050307 Gene6 FTP Server Local Privilege Escalation Vulnerability</ref><ref adv="1" source="MISC" url="http://secway.org/Advisory/ad20050303.txt">http://secway.org/Advisory/ad20050303.txt</ref><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111026585431080&amp;w=2">20050308 Re: Gene6 FTP Server Local Privilege Escalation Vulnerability</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/12739">12739</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/14436">14436</ref></refs><vuln_soft><prod name="G6 FTP Server" vendor="Gene6"><vers num="3.4"/><vers num="3.3.1"/><vers num="3.3"/><vers num="3.2"/><vers num="3.1"/><vers num="3.0.2"/><vers num="3.0.1"/><vers num="3.0"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-28" name="CVE-2005-0691" published="2005-03-06" seq="2005-0691" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in article mode for modules.php in SocialMPN allows remote attackers to execute arbitrary PHP code by modifying the name parameter to reference a URL on a remote web server that contains the code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111022633903239&amp;w=2">20050307 Remote Testing SocialMPN Remote File Inclusion by y3dips</ref><ref adv="1" source="MISC" url="http://waraxe.us/ftopic-542-0-days0-orderasc-.html">http://waraxe.us/ftopic-542-0-days0-orderasc-.html</ref></refs><vuln_soft><prod name="SocialMPN" vendor="SocialMPN"><vers num="1.2.5"/><vers num="1.2.4"/><vers num="1.2.3"/><vers num="1.2.2"/><vers num="1.2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0692" published="2005-03-06" seq="2005-0692" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in fusion_core.php for PHP-Fusion 5.x allows remote attackers to inject arbitrary web script or HTML via a message with IMG bbcode containing character-encoded Javascript.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111022851900028&amp;w=2">20050306 PHP-FUSION 5.* XSS VULNERABILITY</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14492">14492</ref><ref source="" url="http://www.php-fusion.co.uk/news.php?readmore=183"></ref></refs><vuln_soft><prod name="PHP_Fusion" vendor="PHP_Fusion"><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0693" published="2005-03-07" seq="2005-0693" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in JoWood Chaser 1.50 and earlier allows remote attackers to cause a denial of service (client or server crash) and execute arbitrary code via a long nickname.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Luigi Auriemma" url="http://aluigi.altervista.org/adv/chasercool-adv.txt">http://aluigi.altervista.org/adv/chasercool-adv.txt</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/12733">12733</ref></refs><vuln_soft><prod name="Chaser" vendor="JoWood Productions"><vers num="1.50"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0694" published="2005-03-07" seq="2005-0694" severity="Medium" type="CVE"><desc><descript source="cve">Hosting Controller 6.1 Hotfix 1.7 and earlier stores log files under the web root, which allows remote attackers to obtain sensitive information via a direct request to HCDiskQuotaService.csv.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111026083314947&amp;w=2">20050307 Hosting Controller Multiple Unauthenticated information disclose</ref><ref adv="1" patch="1" source="MISC" url="http://isun.shabgard.org/hc2.txt">http://isun.shabgard.org/hc2.txt</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14522">14522</ref></refs><vuln_soft><prod name="Hosting Controller" vendor="Hosting Controller"><vers num="6.1 Hotfix 1.7"/><vers num="6.1 Hotfix 1.4"/><vers num="6.1"/><vers num="1.4.1"/><vers num="1.4b"/><vers num="1.3"/><vers num="1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0695" published="2005-03-07" seq="2005-0695" severity="Medium" type="CVE"><desc><descript source="cve">The password recovery feature (forgotpassword.asp) in Hosting Controller 6.1 Hotfix 1.7 and earlier allows remote attackers to determine the owner&apos;s e-mail address by providing a portion of the domain name to the &quot;login ID&quot; field.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111026083314947&amp;w=2">20050307 Hosting Controller Multiple Unauthenticated information disclose</ref><ref adv="1" patch="1" source="MISC" url="http://isun.shabgard.org/hc2.txt">http://isun.shabgard.org/hc2.txt</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14522">14522</ref></refs><vuln_soft><prod name="Hosting Controller" vendor="Hosting Controller"><vers num="6.1 Hotfix 1.7"/><vers num="6.1 Hotfix 1.4"/><vers num="6.1"/><vers num="1.4.1"/><vers num="1.4b"/><vers num="1.3"/><vers num="1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-06-15" name="CVE-2005-0696" published="2005-03-08" seq="2005-0696" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in ArGoSoft FTP Server 1.4.2.8 allows remote authenticated users to execute arbitrary code via a long DELE command. NOTE: this issue was later reported to also affect 1.4.3.5.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/392653">20050308 ArGoSoft FTP Server 1.4.2.8 Buffer Overflow</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/12755">12755</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14526">14526</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426081/100/0/threaded">20060225 ArGoSoft FTP server remote heap overflow</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-February/042523.html">20060225 ArGoSoft FTP server remote heap overflow</ref><ref source="" url="https://www.securinfos.info/english/security-advisories-alerts/20060225_ArGoSoft.FTP.Server_Heap.Overflow.html"></ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015681">1015681</ref><ref source="SREASON" url="http://securityreason.com/securityalert/494">494</ref></refs><vuln_soft><prod name="FTP Server" vendor="ArGoSoft"><vers num="1.4.2.8"/><vers num="1.4.2.29"/><vers num="1.4.3.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0697" published="2005-03-07" seq="2005-0697" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in the process_picture function xp_publish.php in CopperExport 0.2.1 allows remote attackers to execute arbitrary SQL commands, possibly via the (1) title, (2) caption, or (3) keywords parameters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CONFIRM" url="http://www.zzamboni.org/copperexport/">http://www.zzamboni.org/copperexport/</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14401">14401</ref></refs><vuln_soft><prod name="CopperExport" vendor="BrT"><vers num="0.2"/><vers num="0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-28" name="CVE-2005-0698" published="2005-03-07" seq="2005-0698" severity="Medium" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in PHPWebLog 0.5.3 and earlier allows remote attackers to execute arbitrary PHP code by modifying the (1) G_PATH parameter to init.inc.php or the (2) PATH parameter to index.php to reference a URL on a remote web server that contains the code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/392552">20050307 phpWebLog &lt;= 0.5.3 arbitrary file inclusion (VXSfx)</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/12747">12747</ref></refs><vuln_soft><prod name="phpWebLog" vendor="Jason Hines"><vers num="0.5.3"/><vers num="0.5.2"/><vers num="0.5.1"/><vers num="0.5"/><vers num="0.4.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0699" published="2005-03-08" seq="2005-0699" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in the dissect_a11_radius function in the CDMA A11 (3G-A11) dissector (packet-3g-a11.c) for Ethereal 0.10.9 and earlier allow remote attackers to execute arbitrary code via RADIUS authentication packets with large length values.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/392659">20050308 Ethereal remote buffer overflow</ref><ref adv="1" patch="1" source="CONFIRM" url="http://www.ethereal.com/appnotes/enpa-sa-00018.html">http://www.ethereal.com/appnotes/enpa-sa-00018.html</ref><ref adv="1" patch="1" source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200503-16.xml">GLSA-200503-16</ref><ref adv="1" patch="1" source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:053">MDKSA-2005:053</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-306.html">RHSA-2005:306</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/12759">12759</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00003.html">FLSA-2006:152922</ref><ref source="" url="http://security.lss.hr/en/index.php?page=details&amp;ID=LSS-2005-03-04"></ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111038641832400&amp;w=2">20050309 RE: Ethereal remote buffer overflow - addon</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111083125521813&amp;w=2">20050314 Ethereal 0.10.9 and below remote root exploit</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:053">MDKSA-2005:053</ref></refs><vuln_soft><prod name="ALT Linux" vendor="ALTLinux"><vers num="Junior 2.3"/><vers num="Compact 2.3"/></prod><prod name="Desktop" vendor="Red Hat"><vers num="4.0"/><vers num="3.0"/></prod><prod name="Advanced Workstation Itanium Processor" vendor="Red Hat"><vers edition="IA64" num="2.1"/><vers num="2.1"/></prod><prod name="Conectiva Linux" vendor="Conectiva"><vers num="10.0"/><vers num="9.0"/></prod><prod name="Ethereal" vendor="Ethereal Group"><vers num="0.10.9"/><vers num="0.10.8"/><vers num="0.10.7"/><vers num="0.10.6"/><vers num="0.10.5"/><vers num="0.10.4"/><vers num="0.10.3"/></prod><prod name="Enterprise Linux" vendor="Red Hat"><vers edition="Workstation" num="4.0"/><vers edition="Workstation Server" num="3.0"/><vers edition="Workstation" num="2.1"/><vers edition="Workstation" num="2.1"/><vers edition="Enterprise Server" num="4.0"/><vers edition="Enterprise Server" num="3.0"/><vers edition="Enterprise Server" num="2.1"/><vers edition="Enterprise Server" num="2.1"/><vers edition="Advanced Server" num="4.0"/><vers edition="Advanced Server" num="3.0"/><vers edition="Advanced Server" num="2.1"/><vers edition="Advanced Server" num="2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0700" published="2005-03-07" seq="2005-0700" severity="Medium" type="CVE"><desc><descript source="cve">The export_index action in myadmin.php for Aztek Forum 4.0 allows remote attackers to obtain database files, possibly by setting the ATK_ADMIN cookie.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://www.frsirt.com/exploits/20050307.aztek.c.php">http://www.frsirt.com/exploits/20050307.aztek.c.php</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/12745">12745</ref></refs><vuln_soft><prod name="Aztek Forum" vendor="Aztek Forum"><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0701" published="2005-03-07" seq="2005-0701" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in Oracle Database Server 8i and 9i allows remote attackers to read or rename arbitrary files via &quot;\\.\\..&quot;  (modified dot dot backslash) sequences to UTL_FILE functions such as (1) UTL_FILE.FOPEN or (2) UTL_FILE.frename.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111023635928211&amp;w=2">20050307 - Argeniss - Oracle Database Server Directory transversal</ref><ref adv="1" patch="1" source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-March/032273.html">20050307 - Argeniss - Oracle Database Server Directory transversal</ref><ref adv="1" patch="1" source="MISC" url="http://www.argeniss.com/research/ARGENISS-ADV-030501.txt">http://www.argeniss.com/research/ARGENISS-ADV-030501.txt</ref></refs><vuln_soft><prod name="Oracle9i Database Server" vendor="Oracle"><vers num=""/></prod><prod name="Oracle8i Database Server" vendor="Oracle"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0702" published="2005-03-07" seq="2005-0702" severity="Medium" type="CVE"><desc><descript source="cve">SQL injection vulnerability in phpMyFAQ 1.4 and 1.5 allows remote attackers to add FAQ records to the database via the username field in forum messages.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CONFIRM" url="http://www.phpmyfaq.de/advisory_2005-03-06.php">http://www.phpmyfaq.de/advisory_2005-03-06.php</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14516">14516</ref></refs><vuln_soft><prod name="phpMyFAQ" vendor="phpMyFAQ"><vers num="1.5"/><vers num="1.4a"/><vers num="1.4 alpha2"/><vers num="1.4 alpha1"/><vers num="1.4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-25" name="CVE-2005-0703" published="2005-03-07" seq="2005-0703" severity="Medium" type="CVE"><desc><descript source="cve">Xerox MicroServer Web Server for various WorkCentre products including M35/M45/M55 2.028.11.000 through 2.97.20.032 and 4.84.16.000 through 4.97.20.032, Pro 35/45/55 3.028.11.000 through 3.97.20.032, Pro 65/75/90 1.001.00.060 through 1.001.02.084, and others, has an &quot;unauthenticated account,&quot; which allows remote attackers to modify system configuration, a different vulnerability than CVE-2005-1179.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CONFIRM" url="http://www.xerox.com/downloads/usa/en/c/cert_XRX05_005.pdf">http://www.xerox.com/downloads/usa/en/c/cert_XRX05_005.pdf</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14507">14507</ref></refs><vuln_soft><prod name="WorkCentre Pro" vendor="Xerox"><vers num="90 1.001.02.084"/><vers num="90 1.001.00.060"/><vers num="90"/><vers num="75 1.001.02.084"/><vers num="75 1.001.00.060"/><vers num="75"/><vers num="65 1.001.02.084"/><vers num="65 1.001.00.060"/><vers num="65"/><vers num="55 3.97.20.032"/><vers num="55 3.028.11.000"/><vers num="55"/><vers num="45 3.97.20.032"/><vers num="45 3.028.11.000"/><vers num="45"/><vers num="40 Color"/><vers num="40 0.001.02.081"/><vers num="40 0.001.00.060"/><vers num="35 3.97.20.032"/><vers num="35 3.028.11.000"/><vers num="35"/><vers num="32 Color"/><vers num="32 0.001.02.081"/><vers num="32 0.001.00.060"/><vers num="175 7.47.33.008"/><vers num="175 7.47.30.000"/><vers num="175"/><vers num="165 7.47.33.008"/><vers num="165 7.47.30.000"/><vers num="165"/></prod><prod name="WorkCentre Pro Color" vendor="Xerox"><vers num="3545 0.001.04.044"/><vers num="3545"/><vers num="2636 0.001.04.044"/><vers num="2636"/><vers num="2128 0.001.04.044"/><vers num="2128"/></prod><prod name="WorkCentre" vendor="Xerox"><vers num="M55 4.84.16.000"/><vers num="M55 2.97.20.032"/><vers num="M55 2.28.11.000"/><vers num="M55"/><vers num="M45 4.84.16.000"/><vers num="M45 2.97.20.032"/><vers num="M45 2.28.11.000"/><vers num="M45"/><vers num="M35 4.84.16.000"/><vers num="M35 2.97.20.032"/><vers num="M35 2.28.11.000"/><vers num="M35"/><vers num="M175 8.47.33.008"/><vers num="M175 8.47.30.000"/><vers num="M175 6.47.33.008"/><vers num="M175 6.47.30.000"/><vers num="M175"/><vers num="M165 8.47.33.008"/><vers num="M165 8.47.30.000"/><vers num="M165 6.47.33.008"/><vers num="M165 6.47.30.000"/><vers num="M165"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0704" published="2005-05-02" seq="2005-0704" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the Etheric dissector in Ethereal 0.10.7 through 0.10.9 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="CONFIRM" url="http://www.ethereal.com/appnotes/enpa-sa-00018.html">http://www.ethereal.com/appnotes/enpa-sa-00018.html</ref><ref patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200503-16.xml">GLSA-200503-16</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:053">MDKSA-2005:053</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-306.html">RHSA-2005:306</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00003.html">FLSA-2006:152922</ref><ref source="BID" url="http://www.securityfocus.com/bid/12762">12762</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:053">MDKSA-2005:053</ref></refs><vuln_soft><prod name="Ethereal" vendor="Ethereal Group"><vers num="0.10.7"/><vers num="0.10.8"/><vers num="0.10.9"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0705" published="2005-05-02" seq="2005-0705" severity="Medium" type="CVE"><desc><descript source="cve">The GPRS-LLC dissector in Ethereal 0.10.7 through 0.10.9, with the &quot;ignore cipher bit&quot; option enabled. allows remote attackers to cause a denial of service (application crash).</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="CONFIRM" url="http://www.ethereal.com/appnotes/enpa-sa-00018.html">http://www.ethereal.com/appnotes/enpa-sa-00018.html</ref><ref patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200503-16.xml">GLSA-200503-16</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:053">MDKSA-2005:053</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-306.html">RHSA-2005:306</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00003.html">FLSA-2006:152922</ref><ref source="BID" url="http://www.securityfocus.com/bid/12762">12762</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:053">MDKSA-2005:053</ref></refs><vuln_soft><prod name="Ethereal" vendor="Ethereal Group"><vers num="0.10.7"/><vers num="0.10.8"/><vers num="0.10.9"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0706" published="2005-05-02" seq="2005-0706" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in discdb.c for grip 3.1.2 allows attackers to cause a denial of service (crash) and possibly execute arbitrary code by causing the cddb lookup to return more matches than expected.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://sourceforge.net/tracker/index.php?func=detail&amp;aid=834724&amp;group_id=3714&amp;atid=103714">http://sourceforge.net/tracker/index.php?func=detail&amp;aid=834724&amp;group_id=3714&amp;atid=103714</ref><ref source="CONFIRM" url="http://sourceforge.net/tracker/index.php?func=detail&amp;aid=1160134&amp;group_id=3714&amp;atid=303714">http://sourceforge.net/tracker/index.php?func=detail&amp;aid=1160134&amp;group_id=3714&amp;atid=303714</ref><ref patch="1" source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200503-21.xml">GLSA-200503-21</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-304.html">RHSA-2005:304</ref><ref source="BID" url="http://www.securityfocus.com/bid/12770">12770</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19648">grip-cddb-bo(19648)</ref><ref source="FEDORA" url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=152919">FLSA:152919</ref><ref source="" url="http://rpmfind.net/linux/RPM/suse/9.3/i386/suse/i586/gnome-vfs-1.0.5-816.2.i586.html"></ref></refs><vuln_soft><prod name="Grip" vendor="Grip"><vers num="3.1.2"/><vers num="3.2.0"/><vers num="3.1.4"/><vers num="2.9.6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-08-30" name="CVE-2005-0707" published="2005-05-02" seq="2005-0707" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the IMAP daemon (IMAP4d32.exe) for Ipswitch Collaboration Suite (ICS) before 8.15 Hotfix 1 allows remote authenticated users to execute arbitrary code via a long EXAMINE command.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=216&amp;type=vulnerabilities">20050310 Ipswitch Collaboration Suite IMAP EXAMINE Buffer Overflow Vulnerability</ref><ref patch="1" source="MISC" url="http://securitytracker.com/id?1013410">http://securitytracker.com/id?1013410</ref><ref source="BID" url="http://www.securityfocus.com/bid/12780">12780</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/14546">14546</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19655">ipswitch-imail-imapexamine-bo(19655)</ref></refs><vuln_soft><prod name="IPSwitch Collaboration Suite" vendor="IPSwitch"><vers num="8.15" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-05-11" name="CVE-2005-0708" published="2005-05-02" seq="2005-0708" severity="High" type="CVE"><desc><descript source="cve">The sendfile system call in FreeBSD 4.8 through 4.11 and 5 through 5.4 can transfer portions of kernel memory if a file is truncated while it is being sent, which could allow remote attackers to obtain sensitive information.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref patch="1" source="Security Focus" url="http://securityfocus.com/bid/12993">FreeBSD Kernel SendFile System Call Local Information Disclosure Vulnerability</ref><ref adv="1" patch="1" source="AusCERT" url="http://www.auscert.org.au/render.html?it=4963">ESB-2005.0273 -- FreeBSD-SA-05:02.sendfile -- sendfile kernel memory disclosure </ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="5.4 pre"/><vers num="5.3 Stable"/><vers num="5.3 Release"/><vers num="5.3"/><vers num="5.2.1 Release"/><vers num="5.2 Releng"/><vers num="5.2 Release"/><vers num="5.2"/><vers num="5.1 Releng"/><vers num="5.1 Release Alpha"/><vers num="5.1 p5 Release"/><vers num="5.1 Release"/><vers num="5.1"/><vers num="5.0 Releng"/><vers num="5.0 p14 Release"/><vers num="5.0 alpha"/><vers num="5.0"/><vers num="4.11 Stable"/><vers num="4.10 Releng"/><vers num="4.10 Release"/><vers num="4.10"/><vers num="4.9 Releng"/><vers num="4.9 pre"/><vers num="4.9"/><vers num="4.8 Releng"/><vers num="4.8 p6 Release"/><vers num="4.8 pre"/><vers num="4.8"/><vers num="4.7 Stable"/><vers num="4.7 Releng"/><vers num="4.7 p17 Release"/><vers num="4.7 Release"/><vers num="4.7"/><vers num="4.6.2"/><vers num="4.6 Stable"/><vers num="4.6 Releng"/><vers num="4.6 p20 Release"/><vers num="4.6 Release"/><vers num="4.6"/><vers num="4.5 Stable pre 2002-03-07"/><vers num="4.5 Stable"/><vers num="4.5 Releng"/><vers num="4.5 p32 Release"/><vers num="4.5 Release"/><vers num="4.5"/><vers num="4.4 Stable"/><vers num="4.4 Releng"/><vers num="4.4 p42 Release"/><vers num="4.4"/><vers num="4.3 Stable"/><vers num="4.3 Releng"/><vers num="4.3 p38 Release"/><vers num="4.3 Release"/><vers num="4.3"/><vers num="4.2 Stable pre 2000-12-23"/><vers num="4.2 Stable pre 2001-05-02"/><vers num="4.2 Stable"/><vers num="4.2 Release"/><vers num="4.2"/><vers num="4.1.1 Stable"/><vers num="4.1.1 Release"/><vers num="4.1.1"/><vers num="4.1"/><vers num="4.0 Releng"/><vers num="4.0 alpha"/><vers num="4.0"/></prod><prod name="DragonFlyBSD" vendor="DragonFlyBSD"><vers num="1.1"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-06-15" name="CVE-2005-0709" published="2005-05-02" seq="2005-0709" severity="Medium" type="CVE"><desc><descript source="cve">MySQL 4.0.23 and earlier, and 4.1.x up to 4.1.10, allows remote authenticated users with INSERT and DELETE privileges to execute arbitrary code by using CREATE FUNCTION to access libc calls, as demonstrated by using strcat, on_exit, and exit.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111066115808506&amp;w=2">20050310 Mysql CREATE FUNCTION libc arbitrary code execution.</ref><ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2005-q1/0084.html">20050310 Mysql CREATE FUNCTION libc arbitrary code execution.</ref><ref patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-707">DSA-707</ref><ref patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200503-19.xml">GLSA-200503-19</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:060">MDKSA-2005:060</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-334.html">RHSA-2005:334</ref><ref patch="1" source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_19_mysql.html">SUSE-SA:2005:019</ref><ref patch="1" source="TRUSTIX" url="http://www.trustix.org/errata/2005/0009/">2005-0009</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111100791920597&amp;w=2">20050316 [USN-96-1] mySQL vulnerabilities</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/12781">12781</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111066115808506&amp;w=2">20050310 Mysql CREATE FUNCTION libc arbitrary code execution.</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-96-1">USN-96-1</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/Aug/msg00000.html">APPLE-SA-2005-08-15</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2005//Aug/msg00001.html">APPLE-SA-2005-08-17</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-348.html">RHSA-2005:348</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101864-1">101864</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:060">MDKSA-2005:060</ref></refs><vuln_soft><prod name="MySQL" vendor="MySQL"><vers num="4.1.10"/><vers num="4.1.5"/><vers num="4.1.4"/><vers num="4.1.3 beta"/><vers num="4.1.3.0"/><vers num="4.1.2 alpha"/><vers num="4.1.0 alpha"/><vers num="4.1.0.0"/><vers num="4.0.23"/><vers num="4.0.21"/><vers num="4.0.20"/><vers num="4.0.18"/><vers num="4.0.15"/><vers num="4.0.14"/><vers num="4.0.13"/><vers num="4.0.12"/><vers num="4.0.11 gamma"/><vers num="4.0.11"/><vers num="4.0.10"/><vers num="4.0.9 gamma"/><vers num="4.0.9"/><vers num="4.0.8 gamma"/><vers num="4.0.8"/><vers num="4.0.7 gamma"/><vers num="4.0.7"/><vers num="4.0.6"/><vers num="4.0.5a"/><vers num="4.0.5"/><vers num="4.0.4"/><vers num="4.0.3"/><vers num="4.0.2"/><vers num="4.0.1"/><vers num="4.0.0"/><vers num="3.23.49"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-03-28" name="CVE-2005-0710" published="2005-05-02" seq="2005-0710" severity="Medium" type="CVE"><desc><descript source="cve">MySQL 4.0.23 and earlier, and 4.1.x up to 4.1.10, allows remote authenticated users with INSERT and DELETE privileges to bypass library path restrictions and execute arbitrary libraries by using INSERT INTO to modify the mysql.func table, which is processed by the udf_init function.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111065974004648&amp;w=2">20050310 Mysql CREATE FUNCTION mysql.func table arbitrary library injection</ref><ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2005-q1/0083.html">20050310 Mysql CREATE FUNCTION mysql.func table arbitrary library injection</ref><ref patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-707">DSA-707</ref><ref patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200503-19.xml">GLSA-200503-19</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:060">MDKSA-2005:060</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-334.html">RHSA-2005:334</ref><ref patch="1" source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_19_mysql.html">SUSE-SA:2005:019</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2005/0009/">2005-0009</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111100791920597&amp;w=2">20050316 [USN-96-1] mySQL vulnerabilities</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/12781">12781</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19658">mysql-udfinit-gain-access(19658)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111065974004648&amp;w=2">20050310 Mysql CREATE FUNCTION mysql.func table arbitrary library injection</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-96-1">USN-96-1</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/Aug/msg00000.html">APPLE-SA-2005-08-15</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2005//Aug/msg00001.html">APPLE-SA-2005-08-17</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-348.html">RHSA-2005:348</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101864-1">101864</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:060">MDKSA-2005:060</ref></refs><vuln_soft><prod name="MySQL" vendor="MySQL"><vers num="4.1.10"/><vers num="4.1.5"/><vers num="4.1.4"/><vers num="4.1.3 beta"/><vers num="4.1.3.0"/><vers num="4.1.2 alpha"/><vers num="4.1.0 alpha"/><vers num="4.1.0.0"/><vers num="4.0.23"/><vers num="4.0.21"/><vers num="4.0.20"/><vers num="4.0.18"/><vers num="4.0.15"/><vers num="4.0.14"/><vers num="4.0.13"/><vers num="4.0.12"/><vers num="4.0.11 gamma"/><vers num="4.0.11"/><vers num="4.0.10"/><vers num="4.0.9 gamma"/><vers num="4.0.9"/><vers num="4.0.8 gamma"/><vers num="4.0.8"/><vers num="4.0.7 gamma"/><vers num="4.0.7"/><vers num="4.0.6"/><vers num="4.0.5a"/><vers num="4.0.5"/><vers num="4.0.4"/><vers num="4.0.3"/><vers num="4.0.2"/><vers num="4.0.1"/><vers num="4.0.0"/><vers num="3.23.49"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-03-28" name="CVE-2005-0711" published="2005-05-02" seq="2005-0711" severity="Low" type="CVE"><desc><descript source="cve">MySQL 4.0.23 and earlier, and 4.1.x up to 4.1.10, uses predictable file names when creating temporary tables, which allows local users with CREATE TEMPORARY TABLE privileges to overwrite arbitrary files via a symlink attack.</descript></desc><loss_types><int/></loss_types><vuln_types><exception/><env/></vuln_types><range><local/></range><refs><ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2005-q1/0082.html">20050310 Mysql insecure temporary file creation with CREATE TEMPORARY TABLE privilege escalation</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-707">DSA-707</ref><ref patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200503-19.xml">GLSA-200503-19</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:060">MDKSA-2005:060</ref><ref patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-334.html">RHSA-2005:334</ref><ref patch="1" source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_19_mysql.html">SUSE-SA:2005:019</ref><ref patch="1" source="TRUSTIX" url="http://www.trustix.org/errata/2005/0009/">2005-0009</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111100791920597&amp;w=2">20050316 [USN-96-1] mySQL vulnerabilities</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/12781">12781</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-96-1">USN-96-1</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/Aug/msg00000.html">APPLE-SA-2005-08-15</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2005//Aug/msg00001.html">APPLE-SA-2005-08-17</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-348.html">RHSA-2005:348</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101864-1">101864</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:060">MDKSA-2005:060</ref></refs><vuln_soft><prod name="MySQL" vendor="MySQL"><vers num="4.1.10"/><vers num="4.1.5"/><vers num="4.1.4"/><vers num="4.1.3 beta"/><vers num="4.1.3.0"/><vers num="4.1.2 alpha"/><vers num="4.1.0 alpha"/><vers num="4.1.0.0"/><vers num="4.0.23"/><vers num="4.0.21"/><vers num="4.0.20"/><vers num="4.0.18"/><vers num="4.0.15"/><vers num="4.0.14"/><vers num="4.0.13"/><vers num="4.0.12"/><vers num="4.0.11 gamma"/><vers num="4.0.11"/><vers num="4.0.10"/><vers num="4.0.9 gamma"/><vers num="4.0.9"/><vers num="4.0.8 gamma"/><vers num="4.0.8"/><vers num="4.0.7 gamma"/><vers num="4.0.7"/><vers num="4.0.6"/><vers num="4.0.5a"/><vers num="4.0.5"/><vers num="4.0.4"/><vers num="4.0.3"/><vers num="4.0.2"/><vers num="4.0.1"/><vers num="4.0.0"/><vers num="3.23.49"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0712" published="2005-05-02" seq="2005-0712" severity="Medium" type="CVE"><desc><descript source="cve">Mac OS X before 10.3.8 users world-writable permissions for certain directories, which may allow local users to gain privileges, possibly via the receipt cache or ColorSync profiles.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><exception/></vuln_types><range><local/></range><refs><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/Mar/msg00000.html">APPLE-SA-2005-03-21</ref><ref source="Security Tracker" url="http://www.securitytracker.com/alerts/2005/Mar/1013503.html">Apple Mac OS X Unsafe Directory Permissions May Let Local Users Gain Elevated Privileges</ref></refs><vuln_soft><prod name="Mac OS X" vendor="Apple"><vers num="10.3.4"/><vers num="10.2"/><vers num="10.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0713" published="2005-03-21" seq="2005-0713" severity="Medium" type="CVE"><desc><descript source="cve">The Bluetooth Setup Assistant for Mac OS X before 10.3.8 can be launched without a keyboard or Bluetooth device, which allows local users to bypass access restrictions and gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/Mar/msg00000.html">APPLE-SA-2005-03-21</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.3.7"/><vers num="10.3.6"/><vers num="10.3.5"/><vers num="10.3.4"/><vers num="10.3.3"/><vers num="10.3.2"/><vers num="10.3.1"/><vers num="10.3"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.3.8"/><vers num="10.3.7"/><vers num="10.3.6"/><vers num="10.3.5"/><vers num="10.3.4"/><vers num="10.3.3"/><vers num="10.3.2"/><vers num="10.3.1"/><vers num="10.3"/></prod></vuln_soft></entry><entry modified="2005-10-25" name="CVE-2005-0714" published="2005-05-02" reject="1" seq="2005-0714" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2005-0340.  Reason: This candidate is a reservation duplicate of CVE-2005-0340.  Notes: All CVE users should reference CVE-2005-0340 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript></desc><refs/></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0715" published="2005-03-21" seq="2005-0715" severity="Low" type="CVE"><desc><descript source="cve">AFP Server in Mac OS X before 10.3.8 uses insecure permissions for &quot;Drop Boxes,&quot; which allows local users to read the contents of a Drop Box.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/Mar/msg00000.html">APPLE-SA-2005-03-21</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.3.7"/><vers num="10.3.6"/><vers num="10.3.5"/><vers num="10.3.4"/><vers num="10.3.3"/><vers num="10.3.2"/><vers num="10.3.1"/><vers num="10.3"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.3.8"/><vers num="10.3.7"/><vers num="10.3.6"/><vers num="10.3.5"/><vers num="10.3.4"/><vers num="10.3.3"/><vers num="10.3.2"/><vers num="10.3.1"/><vers num="10.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0716" published="2005-03-21" seq="2005-0716" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in the Core Foundation Library in Mac OS X 10.3.5 and 10.3.6, and possibly earlier versions, allows local users to execute arbitrary code via a long CF_CHARSET_PATH environment variable.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=219&amp;type=vulnerabilities">20050321 Mac OS X CF_CHARSET_PATH Buffer Overflow Vulnerability</ref><ref adv="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/Mar/msg00000.html">APPLE-SA-2005-03-21</ref><ref source="BID" url="http://www.securityfocus.com/bid/13224">13224</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.3.6"/><vers num="10.3.5"/><vers num="10.3.4"/><vers num="10.3.3"/><vers num="10.3.2"/><vers num="10.3.1"/><vers num="10.3"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.3.8"/><vers num="10.3.7"/><vers num="10.3.6"/><vers num="10.3.5"/><vers num="10.3.4"/><vers num="10.3.3"/><vers num="10.3.2"/><vers num="10.3.1"/><vers num="10.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0718" published="2005-04-14" seq="2005-0718" severity="Medium" type="CVE"><desc><descript source="cve">Squid 2.5.STABLE7 and earlier allows remote attackers to cause a denial of service (segmentation fault) by aborting the connection during a (1) PUT or (2) POST request, which causes Squid to access previously freed memory.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="CONFIRM" url="http://www.squid-cache.org/bugs/show_bug.cgi?id=1224">http://www.squid-cache.org/bugs/show_bug.cgi?id=1224</ref><ref adv="1" source="CONFIRM" url="http://www1.uk.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE7-post">http://www1.uk.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE7-post</ref><ref adv="1" source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000931">CLA-2005:931</ref><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111352541329027&amp;w=2">20050414 [USN-111-1] Squid vulnerability</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-111-1">USN-111-1</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-415.html">RHSA-2005:415</ref><ref source="FEDORA" url="http://fedoranews.org/updates/FEDORA--.shtml">FLSA-2006:152809</ref><ref source="BID" url="http://www.securityfocus.com/bid/13166">13166</ref><ref source="SECUNIA" url="http://secunia.com/advisories/12508">12508</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19919">squid-put-post-dos(19919)</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-489.html">RHSA-2005:489</ref></refs><vuln_soft><prod name="Squid" vendor="Squid"><vers num="2.5.STABLE7"/><vers num="2.5.STABLE6"/><vers num="2.5.STABLE5"/><vers num="2.5.STABLE4"/><vers num="2.5.STABLE3"/><vers num="2.5.STABLE2"/><vers num="2.5.STABLE1"/><vers num="2.5.6"/><vers num="2.5 Stable9"/><vers num="2.5 STABLE4"/><vers num="2.5 STABLE3"/><vers num="2.5 .STABLE6"/><vers num="2.5 .STABLE5"/><vers num="2.5 .STABLE4"/><vers num="2.5 .STABLE3"/><vers num="2.5 .STABLE1"/><vers num="2.4.STABLE7"/><vers num="2.4.STABLE6"/><vers num="2.4.STABLE4"/><vers num="2.4.STABLE3"/><vers num="2.4.STABLE2"/><vers num="2.4.STABLE1"/><vers num="2.4 STABLE7"/><vers num="2.4 .STABLE7"/><vers num="2.4 .STABLE6"/><vers num="2.4 .STABLE2"/><vers num="2.4"/><vers num="2.3.STABLE5"/><vers num="2.3.STABLE4"/><vers num="2.3.STABLE3"/><vers num="2.3.STABLE2"/><vers num="2.3.STABLE1"/><vers num="2.3.DEVEL3"/><vers num="2.3.DEVEL2"/><vers num="2.3 STABLE5"/><vers num="2.3 .STABLE5"/><vers num="2.3 .STABLE4"/><vers num="2.2.STABLE5"/><vers num="2.2.STABLE4"/><vers num="2.2.STABLE3"/><vers num="2.2.STABLE2"/><vers num="2.2.STABLE1"/><vers num="2.2.PRE2"/><vers num="2.2.PRE1"/><vers num="2.2.DEVEL4"/><vers num="2.2.DEVEL3"/><vers num="2.1.RELEASE"/><vers num="2.1.PRE4"/><vers num="2.1.PRE3"/><vers num="2.1.PRE1"/><vers num="2.1.PATCH2"/><vers num="2.1.PATCH1"/><vers num="2.1 PATCH2"/><vers num="2.0.RELEASE"/><vers num="2.0.PRE1"/><vers num="2.0.PATCH2"/><vers num="2.0.PATCH1"/><vers num="2.0 PATCH2"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0719" published="2005-03-09" seq="2005-0719" severity="Low" type="CVE"><desc><descript source="cve">Unknown vulnerability in the systems message queue in HP Tru64 Unix 4.0F PK8 through 5.1B-2/PK4 allows local users to cause a denial of service (process crash) for processes such as nfsstat, pfstat, arp, ogated, rarpd, route, sendmail, srconfig, strsetup, trpt, netstat, and xntpd.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="HP" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111040492127482&amp;w=2">HPSBTU01109</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/12768">12768</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14549/">14549</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19642">tru64-system-message-dos(19642)</ref></refs><vuln_soft><prod name="Tru64" vendor="HP"><vers num="5.1B1 PK4"/><vers num="5.1B1 PK3"/><vers num="5.1 A PK6"/><vers num="4.0G PK4"/><vers num="4.0F PK8"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-01-03" name="CVE-2005-0720" published="2005-03-08" seq="2005-0720" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in admin/header.php in PHP mcNews 1.3 allows remote attackers to execute arbitrary PHP code by modifying the skinfile parameter to reference a URL on a remote web server that contains the code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111025679324892&amp;w=2">20050307 PHP mcNews &lt;= 1.3 arbitrary file inclusion (VXSfx)</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/14528">14528</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19616">mcnews-skinfile-file-include(19616)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/476277/100/0/threaded">20070811 mcNews (skinfile) Remote File Include Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/12776">12776</ref></refs><vuln_soft><prod name="McNews" vendor="McNews"><vers num="1.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-28" name="CVE-2005-0721" published="2005-05-02" seq="2005-0721" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in modules.php in eXPerience2 allows remote attackers to execute arbitrary PHP code by modifying the file parameter to reference a URL on a remote web server that contains the code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111030766324600&amp;w=2">20050307 Multiples Vulnerabilities</ref><ref source="" url="http://xforce.iss.net/xforce/xfdb/19913"></ref></refs><vuln_soft><prod name="eXperience2" vendor="GameArena"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0722" published="2005-03-07" seq="2005-0722" severity="Medium" type="CVE"><desc><descript source="cve">eXPerience2 allows remote attackers to obtain the full path for the web root via a direct request to modules.php without any parameters, which leaks the path in a PHP error message.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111030766324600&amp;w=2">20050307 Multiples Vulnerabilities</ref></refs><vuln_soft><prod name="eXPerience2" vendor="eXPerience2"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0723" published="2005-03-08" seq="2005-0723" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in the jumpmenu function in functions.php for paFileDB 3.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the URL parameters, which is not properly cleansed in the $pageurl variable, as demonstrated using pafiledb.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111031801802851&amp;w=2">20050308 Multiple vulnerabilities in paFileDB</ref></refs><vuln_soft><prod name="paFileDB" vendor="PHP Arena"><vers num="3.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0724" published="2005-05-02" seq="2005-0724" severity="Medium" type="CVE"><desc><descript source="cve">paFileDB 3.1 and earlier allows remote attackers to obtain sensitive information via (1) an invalid str parameter to pafiledb.php, or a direct request to (2) viewall.php, (3) stats.php, (4) search.php, (5) rate.php, (6) main.php, (7) license.php, (8) category.php, (9) download.php, (10) file.php, (11) email.php, or (12) admin.php, which reveals the path in a PHP error message.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111031801802851&amp;w=2">20050308 Multiple vulnerabilities in paFileDB</ref></refs><vuln_soft><prod name="paFileDB" vendor="PHP Arena"><vers num="3.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0725" published="2005-03-08" seq="2005-0725" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in the getAllbyArticle function in wfsfiles.php for WF-Sections (wfsections) 1.07 allows remote attackers to execute arbitrary SQL commands via the articleid parameter to article.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111049618519821&amp;w=2">20050308 Wfsection 1.07 vulnerabilities</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19660">wfsections-wfsfiles-sql-injection(19660)</ref></refs><vuln_soft><prod name="WF-Sections" vendor="WF-Sections"><vers num="1.07"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0726" published="2005-05-02" seq="2005-0726" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in editpost.php in UBB.threads 6.0 allows remote attackers to execute arbitrary SQL commands via the Number parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111056135818279&amp;w=2">20050311 UBB.threads 6 SQL Injection</ref></refs><vuln_soft><prod name="UBB.threads" vendor="UBBCentral"><vers num="6.0"/></prod></vuln_soft></entry><entry modified="2005-10-25" name="CVE-2005-0727" published="2005-05-02" reject="1" seq="2005-0727" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2005-0735.  Reason: This candidate is a duplicate of CVE-2005-0735.  Notes: All CVE users should reference CVE-2005-0727 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript></desc><refs/></entry><entry modified="2005-10-25" name="CVE-2005-0728" published="2005-05-02" reject="1" seq="2005-0728" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2005-0736.  Reason: This candidate is a duplicate of CVE-2005-0736.  Notes: All CVE users should reference CVE-2005-0736 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript></desc><refs/></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0729" published="2005-05-02" seq="2005-0729" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in Xpand Rally 1.1.0.0 and earlier allows remote attackers to execute arbitrary code via format string specifiers in a message.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="Luigi Auriemma" url="http://aluigi.altervista.org/adv/xprallyfs-adv.txt"></ref><ref source="SecuriTeam" url="http://www.securiteam.com/windowsntfocus/5DP0G00F5Q.html">Xpand Rally Format String Vulnerability</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/14545">14545</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19649">xpandrally-message-format-string(19649)</ref></refs><vuln_soft><prod name="XPand Rally" vendor="Techland"><vers num="1.1"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0730" published="2005-05-02" seq="2005-0730" severity="Medium" type="CVE"><desc><descript source="cve">PY Software Active Webcam WebServer (webcam.exe) 5.5 allows remote attackers to cause a denial of service via a request to a file on the floppy drive, as demonstrated using A:\a.txt.</descript></desc><loss_types><avail/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2005-03/0216.html">20050310 Multiple Vulnerabilities of PY Software Active Webcam WebServer</ref><ref source="MISC" url="http://secway.org/advisory/ad20050104.txt">http://secway.org/advisory/ad20050104.txt</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14553">14553</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19647">active-webcam-dos(19647)</ref></refs><vuln_soft><prod name="Active WebCam" vendor="PY Software"><vers num="5.5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0731" published="2005-03-10" seq="2005-0731" severity="Medium" type="CVE"><desc><descript source="cve">PY Software Active Webcam WebServer (webcam.exe) 5.5 allows remote attackers to cause a denial of service (CPU consumption) via a direct request to Filelist.html.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2005-03/0216.html">20050310 Multiple Vulnerabilities of PY Software Active Webcam WebServer</ref><ref adv="1" source="MISC" url="http://secway.org/advisory/ad20050104.txt">http://secway.org/advisory/ad20050104.txt</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/14553">14553</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19650">active-webcam-filelist-dos(19650)</ref></refs><vuln_soft><prod name="Active WebCam" vendor="PY Software"><vers num="5.5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0732" published="2005-05-02" seq="2005-0732" severity="Medium" type="CVE"><desc><descript source="cve">PY Software Active Webcam WebServer (webcam.exe) 5.5 allows remote attackers to obtain the full path of the web server via a request for a non-existent filename, which leaks the full path in an error message.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2005-03/0216.html">20050310 Multiple Vulnerabilities of PY Software Active Webcam WebServer</ref><ref source="MISC" url="http://secway.org/advisory/ad20050104.txt">http://secway.org/advisory/ad20050104.txt</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14553">14553</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19652">active-webcam-path-disclosure(19652)</ref></refs><vuln_soft><prod name="Active Webcam" vendor="PY Software"><vers num="5.5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0733" published="2005-05-02" seq="2005-0733" severity="Medium" type="CVE"><desc><descript source="cve">PY Software Active Webcam WebServer (webcam.exe) 5.5 allows remote attackers to determine the existence of files via an HTTP request with a full pathname, which produces different messages whether the file exists or not.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2005-03/0216.html">20050310 Multiple Vulnerabilities of PY Software Active Webcam WebServer</ref><ref source="MISC" url="http://secway.org/advisory/ad20050104.txt">http://secway.org/advisory/ad20050104.txt</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14553">14553</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19654">active-webcam-file-disclosure(19654)</ref></refs><vuln_soft><prod name="Active Webcam" vendor="PY Software"><vers num="5.5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0734" published="2005-05-02" seq="2005-0734" severity="Medium" type="CVE"><desc><descript source="cve">PY Software Active Webcam WebServer (webcam.exe) 5.5 allows remote attackers to cause a denial of service (memory exhaustion and process crash) via a large number of HTTP requests.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2005-03/0216.html">20050310 Multiple Vulnerabilities of PY Software Active Webcam WebServer</ref><ref source="MISC" url="http://secway.org/advisory/ad20050104.txt">http://secway.org/advisory/ad20050104.txt</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14553">14553</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19653">active-webcam-memory-dos(19653)</ref></refs><vuln_soft><prod name="Active Webcam" vendor="PY Software"><vers num="5.5"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0735" published="2005-05-02" seq="2005-0735" severity="High" type="CVE"><desc><descript source="cve">newsscript.pl for NewsScript allows remote attachers to gain privileges by setting the mode parameter to admin.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/12761">12761</ref><ref source="xforce.iss.net" url="http://xforce.iss.net/xforce/xfdb/19912">newsscript-script-security-bypass </ref></refs><vuln_soft><prod name="NewsScript" vendor="NewsScript.co.uk"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0736" published="2005-03-09" seq="2005-0736" severity="Low" type="CVE"><desc><descript source="cve">Integer overflow in sys_epoll_wait in eventpoll.c for Linux kernel 2.6 to 2.6.11 allows local users to overwrite kernel memory via a large number of events.</descript></desc><loss_types><int/></loss_types><vuln_types><input bound="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-March/032314.html">20050309 overwriting low kernel memory</ref><ref adv="1" source="CONFIRM" url="http://linux.bkbits.net:8080/linux-2.6/cset@422dd06a1p5PsyFhoGAJseinjEq3ew?nav=index.html%7CChangeSet@-1d">http://linux.bkbits.net:8080/linux-2.6/cset@422dd06a1p5PsyFhoGAJseinjEq3ew?nav=index.html|ChangeSet@-1d</ref><ref adv="1" source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_18_kernel.html">SUSE-SA:2005:018</ref><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111091402626556&amp;w=2">20050315 [USN-95-1] Linux kernel vulnerabilities</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/12763">12763</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-95-1">USN-95-1</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-293.html">RHSA-2005:293</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-366.html">RHSA-2005:366</ref></refs><vuln_soft><prod name="Desktop" vendor="Red Hat"><vers num="4.0"/></prod><prod name="Conectiva Linux" vendor="Conectiva"><vers num="10.0"/></prod><prod name="Kernel" vendor="Linux"><vers num="2.6.11"/><vers num="2.6.10"/><vers edition="2.6.20" num="2.6.9"/><vers num="2.6.8"/><vers num="2.6.7"/><vers num="2.6.6"/><vers num="2.6.5"/><vers num="2.6.4"/><vers num="2.6.3"/><vers num="2.6.2"/><vers num="2.6.1"/><vers num="2.6"/></prod><prod name="Enterprise Linux" vendor="Red Hat"><vers edition="Workstation" num="4.0"/><vers edition="Enterprise Server" num="4.0"/><vers edition="Advanced Server" num="4.0"/></prod><prod name="Fedora" vendor="Red Hat"><vers num="Core 3.0"/><vers num="Core 2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0737" published="2005-05-02" seq="2005-0737" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Yahoo! Messenger allows remote attackers to execute arbitrary code via the offline mode.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/12750">12750</ref><ref source="FULLDISC" url="http://seclists.org/lists/fulldisclosure/2005/Mar/0284.html">20050308 Yahoo! Messenger Offline Mode Status Remote Buffer Overflow Vulnerability</ref></refs><vuln_soft><prod name="Messenger" vendor="Yahoo"><vers num="6.0.0.1921"/><vers num="6.0.0.1750"/><vers num="6.0.0.1643"/><vers num="6.0"/><vers num="5.6.0.1358"/><vers num="5.6.0.1356"/><vers num="5.6.0.1355"/><vers num="5.6.0.1351"/><vers num="5.6.0.1347"/><vers num="5.6"/><vers num="5.5.1249"/><vers num="5.5"/><vers num="5.0.1232"/><vers num="5.0.1065"/><vers num="5.0.1046"/><vers num="5.0"/><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0738" published="2005-05-02" seq="2005-0738" severity="Medium" type="CVE"><desc><descript source="cve">Stack overflow in Microsoft Exchange Server 2003 SP1 allows users to cause a denial of service (hang) by deleting or moving a folder with deeply nested subfolders, which causes Microsoft Exchange Information Store service (Store.exe) to hang as a result of a large number of recursive calls.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/><exception/></vuln_types><range><network/></range><refs><ref patch="1" source="MSKB" url="http://support.microsoft.com/?kbid=891504">891504</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14543">14543</ref></refs><vuln_soft><prod name="exchange srv" vendor="Microsoft"><vers num="2003 SP1"/><vers num="2003"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0739" published="2005-05-02" seq="2005-0739" severity="Medium" type="CVE"><desc><descript source="cve">The IAPP dissector (packet-iapp.c) for Ethereal 0.9.1 to 0.10.9 does not properly use certain routines for formatting strings, which could leave it vulnerable to buffer overflows, as demonstrated using modified length values that are not properly handled by the the dissect_pdus and pduval_to_str functions.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref patch="1" source="CONFIRM" url="http://www.ethereal.com/appnotes/enpa-sa-00018.html">http://www.ethereal.com/appnotes/enpa-sa-00018.html</ref><ref patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-718">DSA-718</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200503-16.xml">GLSA-200503-16</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:053">MDKSA-2005:053</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-306.html">RHSA-2005:306</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00003.html">FLSA-2006:152922</ref><ref source="BID" url="http://www.securityfocus.com/bid/12762">12762</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111066805726551&amp;w=2">20050312 Ethereal remote buffer overflow #2</ref><ref source="" url="http://security.lss.hr/index.php?page=details&amp;ID=LSS-2005-03-05"></ref><ref source="" url="http://anonsvn.ethereal.com/viewcvs/viewcvs.py?view=rev&amp;rev=13707"></ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:053">MDKSA-2005:053</ref></refs><vuln_soft><prod name="Ethereal" vendor="Ethereal Group"><vers num="0.10.9" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0740" published="2005-01-13" seq="2005-0740" severity="Medium" type="CVE"><desc><descript source="cve">The TCP stack (tcp_input.c) in OpenBSD 3.5 and 3.6 allows remote attackers to cause a denial of service (system panic) via crafted values in the TCP timestamp option, which causes invalid arguments to be used when calculating the retransmit timeout.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="OPENBSD" url="http://www.openbsd.org/errata35.html">20050111 027: RELIABILITY FIX: January 11, 2005</ref><ref adv="1" patch="1" source="MISC" url="http://securitytracker.com/id?1012861">http://securitytracker.com/id?1012861</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/12250">12250</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13819">13819</ref></refs><vuln_soft><prod name="OpenBSD" vendor="OpenBSD"><vers num="3.6"/><vers num="3.5"/><vers num="3.4"/><vers num="3.3"/><vers num="3.2"/><vers num="3.1"/><vers num="3.0"/><vers num="2.9"/><vers num="2.8"/><vers num="2.7"/><vers num="2.6"/><vers num="2.5"/><vers num="2.4"/><vers num="2.3"/><vers num="2.2"/><vers num="2.1"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0741" published="2005-03-08" seq="2005-0741" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in YaBB.pl for YaBB 2.0 RC1 allows remote attackers to inject arbitrary web script or HTML via the username parameter in a usersrecentposts action.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://securitytracker.com/id?1013420">http://securitytracker.com/id?1013420</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/12756">12756</ref></refs><vuln_soft><prod name="YaBB" vendor="YaBB"><vers num="2.0 RC1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0742" published="2005-05-02" seq="2005-0742" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Sun Java System Application Server 7 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/12775">12775</ref><ref patch="1" source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57742-1">57742</ref></refs><vuln_soft><prod name="Java System Application Server" vendor="Sun"><vers num="7.0 UR4"/><vers edition="Standard" num="7.0 2004Q2 R1"/><vers edition="Enterprise" num="7.0 2004Q2 R1"/><vers num="7.0 2004Q2"/><vers edition="Standard" num="7.0 UR5"/><vers edition="Platform" num="7.0 UR5"/><vers edition="Standard" num="7.0"/><vers edition="Platform" num="7.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0743" published="2005-05-02" seq="2005-0743" severity="High" type="CVE"><desc><descript source="cve">The custom avatar uploading feature (uploader.php) for XOOPS 2.0.9.2 and earlier allows remote attackers to upload arbitrary PHP scripts, whose file extensions are not filtered.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/392626">20050308 [SCAN Associates Security Advisory] xoops 2.0.9.2 and below weak file extension validation</ref><ref patch="1" source="CONFIRM" url="http://www.xoops.org/modules/news/article.php?storyid=2114">http://www.xoops.org/modules/news/article.php?storyid=2114</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/12754">12754</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14520">14520</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19634">xoops-uploader-file-upload(19634)</ref></refs><vuln_soft><prod name="XOOPS" vendor="XOOPS"><vers num="2.0.9.2"/><vers num="2.0.5.2"/><vers num="2.0.5.1"/><vers num="2.0.5"/><vers num="2.0.3"/><vers num="2.0.2"/><vers num="2.0.1"/><vers num="2.0"/><vers num="1.3.10"/><vers num="1.3.9"/><vers num="1.3.8"/><vers num="1.3.7"/><vers num="1.3.6"/><vers num="1.3.5"/><vers num="1.0 RC3.0.5"/><vers num="1.0 RC3"/><vers num="1.0 RC1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0744" published="2005-05-02" seq="2005-0744" severity="High" type="CVE"><desc><descript source="cve">The web GUI for Novell iChain 2.2 and 2.3 SP2 and SP3 allows attackers to hijack sessions and gain administrator privileges by (1) sniffing the connection on TCP port 51100 and replaying the authentication information or (2) obtaining and replaying the PCZQX02 authentication cookie from the browser.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref patch="1" source="CONFIRM" url="http://support.novell.com/cgi-bin/search/searchtid.cgi?/10096885.htm">http://support.novell.com/cgi-bin/search/searchtid.cgi?/10096885.htm</ref><ref source="MISC" url="http://securitytracker.com/id?1013406">http://securitytracker.com/id?1013406</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14527">14527</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19646">ichain-gain-access(19646)</ref></refs><vuln_soft><prod name="iChain" vendor="Novell"><vers num="2.2"/><vers num="2.3"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0745" published="2005-03-09" seq="2005-0745" severity="Medium" type="CVE"><desc><descript source="cve">UTStarcom iAN-02EX VoIP Analog Terminal Adaptor (ATA) allows local users to bypass ATA access restrictions by dialing &quot;*#26845#&quot; and causing a device reset.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/><design/></vuln_types><range><local/></range><refs><ref adv="1" source="BUGTRAQ" url="http://seclists.org/lists/bugtraq/2005/Mar/0168.html">20050307 Re: Lingo VoIP ATA / UTStarcom iAN-02EX remote access vulnerability</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/14544">14544</ref></refs><vuln_soft><prod name="iAN-02EX VoIP ATA" vendor="UTStarcom"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0746" published="2005-05-02" seq="2005-0746" severity="Medium" type="CVE"><desc><descript source="cve">The Mini FTP server in Novell iChain 2.2 and 2.3 SP2 and earlier allows remote unauthenticated attackers to obtain the full path of the server via the PWD command.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111091102023359&amp;w=2">20050315 [ISR] - Novell iChain Mini FTP Server Unauthorized Remote Path Disclosure Vulnerability</ref><ref source="MISC" url="http://www.infobyte.com.ar/adv/ISR-03.html">http://www.infobyte.com.ar/adv/ISR-03.html</ref><ref source="CONFIRM" url="http://support.novell.com/cgi-bin/search/searchtid.cgi?/10096886.htm">http://support.novell.com/cgi-bin/search/searchtid.cgi?/10096886.htm</ref><ref source="MISC" url="http://securitytracker.com/id?1013407">http://securitytracker.com/id?1013407</ref><ref source="BID" url="http://www.securityfocus.com/bid/12766">12766</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14537">14537</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19643">ichain-path-disclosure(19643)</ref></refs><vuln_soft><prod name="iChain" vendor="Novell"><vers num="2.3 SP2"/><vers num="2.3"/><vers num="2.2.113"/><vers num="2.2 SP3"/><vers num="2.2 SP2"/><vers num="2.2 SP1"/><vers num="2.2 FP1a"/><vers num="2.2 FP1"/><vers num="2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0747" published="2005-03-08" seq="2005-0747" severity="Medium" type="CVE"><desc><descript source="cve">ApplyYourself i-Class allows remote attackers to obtain sensitive information about their own applications by reusing the hidden ID field, as demonstrated using the id parameter to ApplicantDecision.asp.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="MISC" url="http://securitytracker.com/id?1013400">http://securitytracker.com/id?1013400</ref></refs><vuln_soft><prod name="i-Class" vendor="ApplyYourself"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-28" name="CVE-2005-0748" published="2005-03-10" seq="2005-0748" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in initdb.php for WEBInsta Mailing list manager 1.3d allows remote attackers to execute arbitrary PHP code by modifying the absolute_path parameter to reference a URL on a remote web server that contains the code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://www.frsirt.com/english/advisories/2005/0248">http://www.frsirt.com/english/advisories/2005/0248</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/12773">12773</ref><ref adv="1" source="SECTRACK" url="http://securitytracker.com/id?1013409">1013409</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/14550">14550</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19651">webinsta-initdb-file-include(19651)</ref></refs><vuln_soft><prod name="WEBInsta Mailing Manager" vendor="WEBInsta"><vers num="1.3d"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-05-16" name="CVE-2005-0749" published="2005-04-01" seq="2005-0749" severity="High" type="CVE"><desc><descript source="cve">The load_elf_library in the Linux kernel before 2.6.11.6 allows local users to cause a denial of service (kernel crash) via a crafted ELF library or executable, which causes a free of an invalid pointer.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111238412403118&amp;w=2">20050401 [USN-103-1] Linux kernel vulnerabilities</ref><ref adv="1" source="CONFIRM" url="http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.11.6">http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.11.6</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14713/">14713</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19867">kernel-loadelflibrary-dos(19867)</ref><ref source="FEDORA" url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=152532">FLSA:152532</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-103-1">USN-103-1</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-293.html">RHSA-2005:293</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-366.html">RHSA-2005:366</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-529.html">RHSA-2005:529</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-551.html">RHSA-2005:551</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20060402-01-U">20060402-01-U</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19607">19607</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.6.11.5" prev="1"/><vers num="2.6.11.4"/><vers num="2.6.11.3"/><vers num="2.6.11.2"/><vers num="2.6.11.1"/><vers num="2.6.11 rc4"/><vers num="2.6.11 rc3"/><vers num="2.6.11 rc2"/><vers num="2.6.11 rc1"/><vers num="2.6.11.8"/><vers num="2.6.11.7"/><vers num="2.6.11.6"/><vers num="2.6.11"/><vers num="2.6.10 rc2"/><vers num="2.6.10"/><vers num="2.6.1 rc2"/><vers num="2.6.1 rc1"/><vers num="2.6.1"/><vers num="2.6.0"/><vers num="2.6 test9 CVS"/><vers num="2.6 test9"/><vers num="2.6 test8"/><vers num="2.6 test7"/><vers num="2.6 test6"/><vers num="2.6 test5"/><vers num="2.6 test4"/><vers num="2.6 test3"/><vers num="2.6 test2"/><vers num="2.6 test11"/><vers num="2.6 test10"/><vers num="2.6 test1"/><vers num="2.6"/><vers num="2.5.9"/><vers num="2.5.8"/><vers num="2.5.7"/><vers num="2.5.69"/><vers num="2.5.68"/><vers num="2.5.67"/><vers num="2.5.66"/><vers num="2.5.65"/><vers num="2.5.64"/><vers num="2.5.63"/><vers num="2.5.62"/><vers num="2.5.61"/><vers num="2.5.60"/><vers num="2.5.6"/><vers num="2.5.59"/><vers num="2.5.58"/><vers num="2.5.57"/><vers num="2.5.56"/><vers num="2.5.55"/><vers num="2.5.54"/><vers num="2.5.53"/><vers num="2.5.52"/><vers num="2.5.51"/><vers num="2.5.50"/><vers num="2.5.5"/><vers num="2.5.49"/><vers num="2.5.48"/><vers num="2.5.47"/><vers num="2.5.46"/><vers num="2.5.45"/><vers num="2.5.44"/><vers num="2.5.43"/><vers num="2.5.42"/><vers num="2.5.41"/><vers num="2.5.40"/><vers num="2.5.4"/><vers num="2.5.39"/><vers num="2.5.38"/><vers num="2.5.37"/><vers num="2.5.36"/><vers num="2.5.35"/><vers num="2.5.34"/><vers num="2.5.33"/><vers num="2.5.32"/><vers num="2.5.31"/><vers num="2.5.30"/><vers num="2.5.3"/><vers num="2.5.29"/><vers num="2.5.28"/><vers num="2.5.27"/><vers num="2.5.26"/><vers num="2.5.25"/><vers num="2.5.24"/><vers num="2.5.23"/><vers num="2.5.22"/><vers num="2.5.21"/><vers num="2.5.20"/><vers num="2.5.2"/><vers num="2.5.19"/><vers num="2.5.18"/><vers num="2.5.17"/><vers num="2.5.16"/><vers num="2.5.15"/><vers num="2.5.14"/><vers num="2.5.13"/><vers num="2.5.12"/><vers num="2.5.11"/><vers num="2.5.10"/><vers num="2.5.1"/><vers num="2.5.0"/><vers num="2.4.9"/><vers num="2.4.8"/><vers num="2.4.7"/><vers num="2.4.6"/><vers num="2.4.5"/><vers num="2.4.4"/><vers num="2.4.3 pre3"/><vers num="2.4.31 pre1"/><vers num="2.4.30 rc3"/><vers num="2.4.30 rc2"/><vers num="2.4.30"/><vers num="2.4.3"/><vers num="2.4.29 rc2"/><vers num="2.4.29 rc1"/><vers num="2.4.29"/><vers num="2.4.28"/><vers num="2.4.27 pre5"/><vers num="2.4.27 pre4"/><vers num="2.4.27 pre3"/><vers num="2.4.27 pre2"/><vers num="2.4.27 pre1"/><vers num="2.4.27"/><vers num="2.4.26"/><vers num="2.4.25"/><vers num="2.4.24 ow1"/><vers num="2.4.24"/><vers num="2.4.23 pre9"/><vers num="2.4.23 ow2"/><vers num="2.4.23"/><vers num="2.4.22 pre10"/><vers num="2.4.22"/><vers num="2.4.21 pre7"/><vers num="2.4.21 pre4"/><vers num="2.4.21 pre1"/><vers num="2.4.21"/><vers num="2.4.20"/><vers num="2.4.2"/><vers num="2.4.19 pre6"/><vers num="2.4.19 pre5"/><vers num="2.4.19 pre4"/><vers num="2.4.19 pre3"/><vers num="2.4.19 pre2"/><vers num="2.4.19 pre1"/><vers num="2.4.19"/><vers edition="x86" num="2.4.18"/><vers num="2.4.18 pre8"/><vers num="2.4.18 pre7"/><vers num="2.4.18 pre6"/><vers num="2.4.18 pre5"/><vers num="2.4.18 pre4"/><vers num="2.4.18 pre3"/><vers num="2.4.18 pre2"/><vers num="2.4.18 pre1"/><vers num="2.4.18"/><vers num="2.4.17"/><vers num="2.4.16"/><vers num="2.4.15"/><vers num="2.4.14"/><vers num="2.4.13"/><vers num="2.4.12"/><vers num="2.4.11"/><vers num="2.4.10"/><vers num="2.4.1"/><vers num="2.4.0 test9"/><vers num="2.4.0 test8"/><vers num="2.4.0 test7"/><vers num="2.4.0 test6"/><vers num="2.4.0 test5"/><vers num="2.4.0 test4"/><vers num="2.4.0 test3"/><vers num="2.4.0 test2"/><vers num="2.4.0 test12"/><vers num="2.4.0 test11"/><vers num="2.4.0 test10"/><vers num="2.4.0 test1"/><vers num="2.4.0"/><vers num="2.3.99 pre7"/><vers num="2.3.99 pre6"/><vers num="2.3.99 pre5"/><vers num="2.3.99 pre4"/><vers num="2.3.99 pre3"/><vers num="2.3.99 pre2"/><vers num="2.3.99 pre1"/><vers num="2.3.99"/><vers num="2.3"/><vers num="2.2.9"/><vers num="2.2.8"/><vers num="2.2.7"/><vers num="2.2.6"/><vers num="2.2.5"/><vers num="2.2.4"/><vers num="2.2.3"/><vers num="2.2.27 rc2"/><vers num="2.2.25"/><vers num="2.2.24"/><vers num="2.2.23"/><vers num="2.2.22"/><vers num="2.2.21"/><vers num="2.2.20"/><vers num="2.2.2"/><vers num="2.2.19"/><vers num="2.2.18"/><vers num="2.2.17"/><vers num="2.2.16 pre6"/><vers num="2.2.16"/><vers num="2.2.15 pre20"/><vers num="2.2.15 pre16"/><vers num="2.2.15"/><vers num="2.2.14"/><vers num="2.2.13"/><vers num="2.2.12"/><vers num="2.2.11"/><vers num="2.2.10"/><vers num="2.2.1"/><vers num="2.2"/><vers num="2.1.89"/><vers num="2.1"/><vers num="2.0.9.9"/><vers num="2.0.9"/><vers num="2.0.8"/><vers num="2.0.7"/><vers num="2.0.6"/><vers num="2.0.5"/><vers num="2.0.4"/><vers num="2.0.39"/><vers num="2.0.38"/><vers num="2.0.37"/><vers num="2.0.36"/><vers num="2.0.35"/><vers num="2.0.34"/><vers num="2.0.33"/><vers num="2.0.32"/><vers num="2.0.31"/><vers num="2.0.30"/><vers num="2.0.3"/><vers num="2.0.29"/><vers num="2.0.28"/><vers num="2.0.27"/><vers num="2.0.26"/><vers num="2.0.25"/><vers num="2.0.24"/><vers num="2.0.23"/><vers num="2.0.22"/><vers num="2.0.21"/><vers num="2.0.20"/><vers num="2.0.2"/><vers num="2.0.19"/><vers num="2.0.18"/><vers num="2.0.17"/><vers num="2.0.16"/><vers num="2.0.15"/><vers num="2.0.14"/><vers num="2.0.13"/><vers num="2.0.12"/><vers num="2.0.11"/><vers num="2.0.10"/><vers num="2.0.1"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0750" published="2005-03-27" seq="2005-0750" severity="High" type="CVE"><desc><descript source="cve">The bluez_sock_create function in the Bluetooth stack for Linux kernel 2.4.6 through 2.4.30-rc1 and 2.6 through 2.6.11.5 allows local users to gain privileges via (1) socket or (2) socketpair call with a negative protocol value.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111204562102633&amp;w=2">20050327 local root security bug in linux &gt;= 2.4.6 &lt;= 2.4.30-rc1 and 2.6.x.y &lt;= 2.6.11.5</ref><ref adv="1" source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-March/032913.html">20050327 local root security bug in linux &gt;= 2.4.6 &lt;= 2.4.30-rc1 and 2.6.x.y &lt;= 2.6.11.5</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19844">kernel-bluezsockcreate-integer-underflow(19844)</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-283.html">RHSA-2005:283</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-284.html">RHSA-2005:284</ref><ref source="FEDORA" url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=152532">FLSA:152532</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-293.html">RHSA-2005:293</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-366.html">RHSA-2005:366</ref><ref source="BID" url="http://www.securityfocus.com/bid/12911">12911</ref></refs><vuln_soft><prod name="Enterprise Linux" vendor="Red Hat"><vers edition="Workstation" num="4.0"/><vers edition="Enterprise Server" num="4.0"/><vers edition="Advanced Server" num="4.0"/></prod><prod name="SuSE Linux" vendor="SuSE"><vers num="9.3"/></prod><prod name="Ubuntu Linux" vendor="Ubuntu"><vers edition="ppc" num="4.1"/><vers edition="ia64" num="4.1"/><vers edition="ia64" num="4.1"/></prod><prod name="Conectiva Linux" vendor="Conectiva"><vers num="10.0"/></prod><prod name="Desktop" vendor="Red Hat"><vers num="4.0"/></prod><prod name="Fedora" vendor="Red Hat"><vers num="Core 3.0"/><vers num="Core 2.0"/><vers num="Core 1.0"/></prod><prod name="SuSE Linux Desktop" vendor="SuSE"><vers num="1.0"/></prod><prod name="Kernel" vendor="Linux"><vers num="2.6.11"/><vers num="2.6.10"/><vers edition="2.6.20" num="2.6.9"/><vers num="2.6.8"/><vers num="2.6.7"/><vers num="2.6.6"/><vers num="2.6.5"/><vers num="2.6.4"/><vers num="2.6.3"/><vers num="2.6.2"/><vers num="2.6.1"/><vers num="2.6"/><vers num="2.4.29"/><vers num="2.4.28"/><vers num="2.4.27"/><vers num="2.4.26"/><vers num="2.4.25"/><vers num="2.4.24"/><vers num="2.4.23"/><vers num="2.4.22"/><vers num="2.4.21"/><vers num="2.4.20"/><vers num="2.4.19"/><vers num="2.4.18"/><vers num="2.4.17"/><vers num="2.4.16"/><vers num="2.4.15"/><vers num="2.4.14"/><vers num="2.4.13"/><vers num="2.4.12"/><vers num="2.4.11"/><vers num="2.4.10"/><vers num="2.4.9"/><vers num="2.4.8"/><vers num="2.4.7"/><vers num="2.4.6"/></prod><prod name="Linux" vendor="Red Hat"><vers edition="i386" num="9.0"/><vers edition="i686" num="7.3"/><vers edition="i386" num="7.3"/><vers num="7.3"/></prod></vuln_soft></entry><entry modified="2005-10-20" name="CVE-2005-0751" published="2005-06-09" reject="1" seq="2005-0751" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: none.  Reason: This candidate has been revoked by its Candidate Numbering Authority (CNA) because it was initially assigned to a problem that was not a security issue.  Notes: none.</descript></desc><refs/></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0752" published="2005-04-18" seq="2005-0752" severity="High" type="CVE"><desc><descript source="cve">The Plugin Finder Service (PFS) in Firefox before 1.0.3 allows remote attackers to execute arbitrary code via a javascript: URL in the PLUGINSPAGE attribute of an EMBED tag.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CONFIRM" url="http://www.mozilla.org/security/announce/mfsa2005-34.html">http://www.mozilla.org/security/announce/mfsa2005-34.html</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-383.html">RHSA-2005:383</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14938">14938</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval100024.html">OVAL100024</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100024">oval:org.mitre.oval:def:100024</ref><ref source="BID" url="http://www.securityfocus.com/bid/13228">
13228</ref></refs><vuln_soft><prod name="Firefox" vendor="Mozilla"><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0"/><vers num="0.9.3"/><vers num="0.9.2"/><vers num="0.9.1"/><vers edition="rc" num="0.9"/><vers num="0.9"/><vers num="0.8"/><vers num="0.10.1"/><vers num="0.10"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0753" published="2005-04-18" seq="2005-0753" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in CVS before 1.11.20 allows remote attackers to execute arbitrary code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200504-16.xml">GLSA-200504-16</ref><ref adv="1" patch="1" source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_24_cvs.html">SuSE-SA:2005:024</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14976/">14976</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/20148">cvs-bo(20148)</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-387.html">RHSA-2005:387</ref><ref adv="1" source="Gentoo" url="http://bugs.gentoo.org/attachment.cgi?id=54352&amp;action=view">54352</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-742">DSA-742</ref></refs><vuln_soft><prod name="CVS" vendor="CVS"><vers num="1.11.6"/><vers num="1.11.5"/><vers num="1.11.4"/><vers num="1.11.3"/><vers num="1.11.2"/><vers num="1.11.16"/><vers num="1.11.15"/><vers num="1.11.14"/><vers num="1.11.11"/><vers num="1.11.10"/><vers num="1.11.1 p1"/><vers num="1.11.1"/><vers num="1.11"/><vers num="1.10.8"/><vers num="1.10.7"/><vers num="1.10.6"/><vers num="1.10"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0754" published="2005-04-22" seq="2005-0754" severity="High" type="CVE"><desc><descript source="cve">Kommander in KDE 3.2 through KDE 3.4.0 executes data files without confirmation from the user, which allows remote attackers to execute arbitrary code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111419664411051&amp;w=2">20050422 [KDE Security Advisory]: Kommander untrusted code execution</ref><ref adv="1" patch="1" source="CONFIRM" url="http://www.kde.org/info/security/advisory-20050420-1.txt">http://www.kde.org/info/security/advisory-20050420-1.txt</ref><ref adv="1" source="CONFIRM" url="ftp://ftp.kde.org/pub/kde/security_patches/post-3.4.0-kdewebdev-kommander.diff">ftp://ftp.kde.org/pub/kde/security_patches/post-3.4.0-kdewebdev-kommander.diff</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/15060">15060</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/13313">13313</ref></refs><vuln_soft><prod name="Linux" vendor="Gentoo"><vers num=""/></prod><prod name="KDE" vendor="KDE"><vers num="3.4"/><vers num="3.3.2"/><vers num="3.3.1"/><vers num="3.3"/><vers num="3.2.3"/><vers num="3.2.2"/><vers num="3.2.1"/><vers num="3.2"/></prod><prod name="Conectiva Linux" vendor="Conectiva"><vers num="10.0"/><vers num="9.0"/></prod><prod name="Fedora" vendor="Red Hat"><vers num="Core 3.0"/></prod><prod name="Ubuntu Linux" vendor="Ubuntu"><vers edition="powerpc" num="5.04"/><vers edition="i386" num="5.04"/><vers edition="amd64" num="5.04"/><vers edition="ppc" num="4.1"/><vers edition="ia64" num="4.1"/><vers edition="ia64" num="4.1"/></prod><prod name="Quanta" vendor="KDE"><vers num="3.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-01-05" name="CVE-2005-0755" published="2005-04-19" seq="2005-0755" severity="Medium" type="CVE"><desc><descript source="cve">Heap-based buffer overflow in RealPlayer 10 and earlier, Helix Player before 10.0.4, and RealOne Player v1 and v2 allows remote attackers to execute arbitrary code via a long hostname in a RAM file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="CONFIRM" url="http://service.real.com/help/faq/security/050419_player/EN/">http://service.real.com/help/faq/security/050419_player/EN/</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-363.html">RHSA-2005:363</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-392.html">RHSA-2005:392</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-394.html">RHSA-2005:394</ref><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111401615202987&amp;w=2">20050420 RealNetworks RealPlayer/RealOne Player/Helix Player Remote Heap Overflow</ref><ref adv="1" patch="1" source="MISC" url="http://pb.specialised.info/all/adv/real-ram-adv.txt">http://pb.specialised.info/all/adv/real-ram-adv.txt</ref><ref adv="1" patch="1" source="FEDORA" url="http://www.redhat.com/archives/fedora-announce-list/2005-April/msg00040.html">FEDORA-2005-329</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111401615202987&amp;w=2">20050420 RealNetworks RealPlayer/RealOne Player/Helix Player Remote Heap Overflow</ref></refs><vuln_soft><prod name="RealPlayer" vendor="RealNetworks"><vers edition="Win32" num="8.0"/><vers edition="Unix" num="8.0"/><vers edition="Mac OS" num="8.0"/><vers num="8.0"/><vers num="10.0_6.0.12.690"/><vers num="10.0 beta"/><vers num="10.0"/><vers edition="Japanese" num="10.0"/><vers edition="German" num="10.0"/><vers edition="English" num="10.0"/></prod><prod name="Helix Player" vendor="RealNetworks"><vers num="10.0.3" prev="1"/></prod><prod name="RealOne Player" vendor="RealNetworks"><vers num="2.0"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-06-15" name="CVE-2005-0756" published="2005-06-08" seq="2005-0756" severity="Low" type="CVE"><desc><descript source="cve">ptrace in Linux kernel 2.6.8.1 does not properly verify addresses on the amd64 platform, which allows local users to cause a denial of service (kernel crash).</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-137-1">USN-137-1</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-922">DSA-922</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-921">DSA-921</ref><ref source="BID" url="http://www.securityfocus.com/bid/13891">13891</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18056">18056</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18059">18059</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-514.html">RHSA-2005:514</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-663.html">RHSA-2005:663</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/428058/100/0/threaded">FLSA:157459-2</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/427980/100/0/threaded">FLSA:157459-3</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17073">17073</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17002">17002</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/1878">ADV-2005-1878</ref></refs><vuln_soft><prod name="SuSE Linux" vendor="SuSE"><vers edition="x86_64" num="9.3"/><vers edition="x86_64" num="9.1"/><vers edition="x86_64" num="9.0"/></prod><prod name="Kernel" vendor="Linux"><vers num="2.6.10"/><vers num="2.6.8"/></prod><prod name="Ubuntu Linux" vendor="Ubuntu"><vers edition="amd64" num="5.04"/><vers edition="ia64" num="4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0757" published="2005-05-18" seq="2005-0757" severity="Low" type="CVE"><desc><descript source="cve">The xattr file system code, as backported in Red Hat Enterprise Linux 3 on 64-bit systems, does not properly handle certain offsets, which allows local users to cause a denial of service (system crash) via certain actions on an ext3 file system with extended attributes enabled.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-294.html">RHSA-2005:294</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-922">DSA-922</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-921">DSA-921</ref><ref source="BID" url="http://www.securityfocus.com/bid/13680">13680</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18056">18056</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18059">18059</ref></refs><vuln_soft><prod name="Desktop" vendor="Red Hat"><vers num="3.0"/></prod><prod name="Enterprise Linux WS" vendor="Red Hat"><vers edition="Workstation" num="3.0"/></prod><prod name="Enterprise Linux ES" vendor="Red Hat"><vers edition="Enterprise Server" num="3.0"/></prod><prod name="Enterprise Linux AS" vendor="Red Hat"><vers edition="Advanced Servers" num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-05" name="CVE-2005-0758" published="2005-05-13" seq="2005-0758" severity="Medium" type="CVE"><desc><descript source="cve">zgrep in gzip before 1.3.5 does not properly sanitize arguments, which allows local users to execute arbitrary commands via filenames that are injected into a sed script.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200505-05.xml">GLSA-200505-05</ref><ref adv="1" source="MISC" url="http://bugs.gentoo.org/show_bug.cgi?id=90626">http://bugs.gentoo.org/show_bug.cgi?id=90626</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1081.html">OVAL1081</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1107.html">OVAL1107</ref><ref source="FEDORA" url="http://www.fedoralegacy.org/updates/FC2/2005-11-14-FLSA_2005_158801__Updated_bzip2_packages_fix_security_issues.html">FLSA:158801</ref><ref source="SCO" url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.58/SCOSA-2005.58.txt">SCOSA-2005.58</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18100">18100</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:026">MDKSA-2006:026</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:027">MDKSA-2006:027</ref><ref source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2005-357.html">RHSA-2005:357</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-158-1">USN-158-1</ref><ref source="BID" url="http://www.securityfocus.com/bid/13582">13582</ref><ref source="OSVDB" url="http://www.osvdb.org/16371">16371</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013928">1013928</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20539">gzip-zgrep-file-installation(20539)</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-474.html">RHSA-2005:474</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20060301-01.U.asc">20060301-01-U</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19183">19183</ref><ref source="SLACKWARE" url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2006&amp;m=slackware-security.555852">SSA:2006-262</ref><ref source="SECUNIA" url="http://secunia.com/advisories/22033">22033</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1081">oval:org.mitre.oval:def:1081</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1107">oval:org.mitre.oval:def:1107</ref><ref source="OPENPKG" url="http://www.openpkg.com/security/advisories/OpenPKG-SA-2007.002.html">OpenPKG-SA-2007.002</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=306172"></ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce//2007/Jul/msg00004.html">APPLE-SA-2007-07-31</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:026">MDKSA-2006:026</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:027">MDKSA-2006:027</ref><ref source="BID" url="http://www.securityfocus.com/bid/25159">25159</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/2732">ADV-2007-2732</ref><ref source="SECUNIA" url="http://secunia.com/advisories/26235">26235</ref></refs><vuln_soft><prod name="gzip" vendor="GNU"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0759" published="2005-03-23" seq="2005-0759" severity="Medium" type="CVE"><desc><descript source="cve">ImageMagick before 6.0 allows remote attackers to cause a denial of service (application crash) via a TIFF image with an invalid tag.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="REDHAT" url="https://rhn.redhat.com/errata/RHSA-2005-070.html">RHSA-2005:070</ref><ref adv="1" patch="1" source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_17_imagemagick.html">SUSE-SA:2005:017</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/12875">12875</ref><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-702">DSA-702</ref><ref adv="1" patch="1" source="MISC" url="http://securitytracker.com/id?1013550">http://securitytracker.com/id?1013550</ref></refs><vuln_soft><prod name="ImageMagick" vendor="ImageMagick"><vers num="5.5.7"/><vers num="5.5.6.0 2003-04-09"/><vers num="5.5.6"/><vers num="5.5.4"/><vers num="5.5.3.2.1.2.0"/><vers num="5.4.8.2.1.1.0"/><vers num="5.4.8"/><vers num="5.4.7"/><vers num="5.4.4.5"/><vers num="5.4.3"/><vers num="5.3.8"/><vers num="5.3.3"/></prod><prod name="ProPack" vendor="SGI"><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0760" published="2005-05-02" seq="2005-0760" severity="Medium" type="CVE"><desc><descript source="cve">The TIFF decoder in ImageMagick before 6.0 allows remote attackers to cause a denial of service (crash) via a crafted TIFF file.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref patch="1" source="REDHAT" url="https://rhn.redhat.com/errata/RHSA-2005-070.html">RHSA-2005:070</ref><ref patch="1" source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_17_imagemagick.html">SUSE-SA:2005:017</ref><ref source="MISC" url="http://securitytracker.com/id?1013550">http://securitytracker.com/id?1013550</ref><ref patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-702">DSA-702</ref></refs><vuln_soft><prod name="ImageMagick" vendor="ImageMagick"><vers num="5.5.7"/><vers num="5.5.6.0 2003-04-09"/><vers num="5.5.6"/><vers num="5.5.4"/><vers num="5.5.3.2.1.2.0"/><vers num="5.4.8.2.1.1.0"/><vers num="5.4.8"/><vers num="5.4.7"/><vers num="5.4.4.5"/><vers num="5.4.3"/><vers num="5.3.8"/><vers num="5.3.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0761" published="2005-03-23" seq="2005-0761" severity="Medium" type="CVE"><desc><descript source="cve">Unknown vulnerability in ImageMagick before 6.1.8 allows remote attackers to cause a denial of service (application crash) via a crafted PSD file.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2005-070.html">RHSA-2005:070</ref><ref adv="1" patch="1" source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_17_imagemagick.html">SuSE-SA:2005:017</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/12876">12876</ref><ref adv="1" patch="1" source="MISC" url="http://securitytracker.com/id?1013550">http://securitytracker.com/id?1013550</ref></refs><vuln_soft><prod name="ImageMagick" vendor="ImageMagick"><vers num="6.1.7"/><vers num="6.1.6"/><vers num="6.1.5"/><vers num="6.1.4"/><vers num="6.1.3"/><vers num="6.1.2"/><vers num="6.1.1.6"/><vers num="6.1"/><vers num="6.0.8"/><vers num="6.0.7"/><vers num="6.0.6"/><vers num="6.0.5"/><vers num="6.0.4"/><vers num="6.0.3"/><vers num="6.0.2.5"/><vers num="6.0.2"/><vers num="6.0.1"/><vers num="6.0"/><vers num="5.5.7"/><vers num="5.5.6.0 2003-04-09"/><vers num="5.5.6"/><vers num="5.5.4"/><vers num="5.5.3.2.1.2.0"/><vers num="5.4.8.2.1.1.0"/><vers num="5.4.8"/><vers num="5.4.7"/><vers num="5.4.4.5"/><vers num="5.4.3"/><vers num="5.3.8"/><vers num="5.3.3"/></prod><prod name="ProPack" vendor="SGI"><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0762" published="2005-05-02" seq="2005-0762" severity="High" type="CVE"><desc><descript source="cve">Heap-based buffer overflow in the SGI parser in ImageMagick before 6.0 allows remote attackers to execute arbitrary code via a crafted SGI image file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref patch="1" source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2005-070.html">RHSA-2005:070</ref><ref patch="1" source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_17_imagemagick.html">SuSE-SA:2005:017</ref><ref patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-702">DSA-702</ref><ref source="MISC" url="http://securitytracker.com/id?1013550">http://securitytracker.com/id?1013550</ref></refs><vuln_soft><prod name="ImageMagick" vendor="ImageMagick"><vers num="6.0.1"/><vers num="6.0"/><vers num="5.5.7"/><vers num="5.5.6.0 2003-04-09"/><vers num="5.5.6"/><vers num="5.5.4"/><vers num="5.5.3.2.1.2.0"/><vers num="5.4.8.2.1.1.0"/><vers num="5.4.8"/><vers num="5.4.7"/><vers num="5.4.4.5"/><vers num="5.4.3"/><vers num="5.3.8"/><vers num="5.3.3"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0763" published="2005-05-02" seq="2005-0763" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in Midnight Commander (mc) 4.5.55 and earlier may allow attackers to execute arbitrary code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-698">DSA-698</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-512.html">RHSA-2005:512</ref></refs><vuln_soft><prod name="Midnight Commander" vendor="Midnight Commander"><vers num="4.5.55" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0764" published="2005-05-02" seq="2005-0764" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in command.C for rxvt-unicode before 5.3 allows remote attackers to execute arbitrary code via a crafted file containing long escape sequences.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200503-23.xml">GLSA-200503-23</ref><ref patch="1" source="MISC" url="http://bugs.gentoo.org/show_bug.cgi?id=84680">http://bugs.gentoo.org/show_bug.cgi?id=84680</ref></refs><vuln_soft><prod name="RXVT-Unicode" vendor="Marc Lehmann"><vers num="5.2"/><vers num="5.1"/><vers num="5.0"/><vers num="4.9"/><vers num="4.8"/><vers num="4.7"/><vers num="4.6"/><vers num="4.5"/><vers num="4.4"/><vers num="4.3"/><vers num="4.2"/><vers num="4.1"/><vers num="4.0"/><vers num="3.9"/><vers num="3.8"/><vers num="3.7"/><vers num="3.6"/><vers num="3.5"/><vers num="3.4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0765" published="2005-03-12" seq="2005-0765" severity="Medium" type="CVE"><desc><descript source="cve">Unknown vulnerability in the JXTA dissector in Ethereal 0.10.9 allows remote attackers to cause a denial of service (application crash).</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref adv="1" source="CONFIRM" url="http://www.ethereal.com/appnotes/enpa-sa-00018.html">http://www.ethereal.com/appnotes/enpa-sa-00018.html</ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200503-16.xml">GLSA-200503-16</ref><ref adv="1" patch="1" source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:053">MDKSA-2005:053</ref><ref source="BID" url="http://www.securityfocus.com/bid/12762">12762</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:053">MDKSA-2005:053</ref></refs><vuln_soft><prod name="Ethereal" vendor="Ethereal Group"><vers num="0.10.9"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0766" published="2005-05-02" seq="2005-0766" severity="Medium" type="CVE"><desc><descript source="cve">Unknown vulnerability in the sFlow dissector in Ethereal 0.9.14 through 0.10.9 allows remote attackers to cause a denial of service (application crash).</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref patch="1" source="CONFIRM" url="http://www.ethereal.com/appnotes/enpa-sa-00018.html">http://www.ethereal.com/appnotes/enpa-sa-00018.html</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200503-16.xml">GLSA-200503-16</ref><ref patch="1" source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:053">MDKSA-2005:053</ref><ref source="BID" url="http://www.securityfocus.com/bid/12762">12762</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:053">MDKSA-2005:053</ref></refs><vuln_soft><prod name="Ethereal" vendor="Ethereal Group"><vers num="0.10.9" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.9" CVSS_exploit_subscore="3.4" CVSS_impact_subscore="10.0" CVSS_score="6.9" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2007-02-08" name="CVE-2005-0767" published="2005-03-15" seq="2005-0767" severity="Medium" type="CVE"><desc><descript source="cve">Race condition in the Radeon DRI driver for Linux kernel 2.6.8.1 allows local users with DRI privileges to execute arbitrary code as root.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><race/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111091402626556&amp;w=2">20050315 [USN-95-1] Linux kernel vulnerabilities</ref><ref adv="1" source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000945">CLA-2005:945</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-95-1">USN-95-1</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-366.html">RHSA-2005:366</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.6.8.1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0768" published="2005-05-02" seq="2005-0768" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the administration web server for GoodTech Telnet Server 4.0 and 5.0, and possibly all versions before 5.0.7, allows remote attackers to execute arbitrary code via a long string to port 2380.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111092012415193&amp;w=2">20050315 GoodTech Telnet Server Buffer Overflow Vulnerability</ref><ref source="MISC" url="http://unsecure.altervista.org/security/goodtechtelnet.htm">http://unsecure.altervista.org/security/goodtechtelnet.htm</ref></refs><vuln_soft><prod name="GoodTech Telnet Server" vendor="GoodTech Systems"><vers edition="Windows NT" num="5.0"/><vers edition="Windows NT" num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0769" published="2005-05-02" seq="2005-0769" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in OpenSLP before 1.1.5 allow remote attackers to have an unknown impact via malformed SLP packets.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200503-25.xml">GLSA-200503-25</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:055">MDKSA-2005:055</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_15_openslp.html">SUSE-SA:2005:015</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111109121919869&amp;w=2">20050317 [USN-98-1] OpenSLP vulnerabilities</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/12792">12792</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14561">14561</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19683">openslp-slp-bo(19683)</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-98-1">USN-98-1</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/447537/100/0/threaded">HPSBUX02129</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/3879">ADV-2006-3879</ref><ref source="SECUNIA" url="http://secunia.com/advisories/22128">22128</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:055">MDKSA-2005:055</ref></refs><vuln_soft><prod name="OpenSLP" vendor="OpenSLP"><vers num="1.2.1"/><vers num="1.2 .0"/><vers num="1.1.5"/><vers num="1.0.11"/><vers num="1.0.10"/><vers num="1.0.9 a"/><vers num="1.0.8 a"/><vers num="1.0.7"/><vers num="1.0.6"/><vers num="1.0.5"/><vers num="1.0.4"/><vers num="1.0.3"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0 .0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0770" published="2005-05-02" seq="2005-0770" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in DataRescue Interactive Disassembler and Debugger (IDA) Pro 4.7.0.830 allows remote attackers or local users to cause a denial of service (CPU consumption or application crash) and possibly execute arbitrary code via format string specifiers in a dynamic link library (DLL) name.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111100269512216&amp;w=2">20050316 ADVISORY: DataRescue Interactive Disassembler Pro Debugger Format String Vulnerability</ref><ref source="MISC" url="http://pb.specialised.info/all/adv/ida-debugger-adv.txt">http://pb.specialised.info/all/adv/ida-debugger-adv.txt</ref><ref source="CONFIRM" url="http://www.datarescue.com/cgi-local/ultimatebb.cgi?ubb=get_topic;f=2;t=000155;p=0">http://www.datarescue.com/cgi-local/ultimatebb.cgi?ubb=get_topic;f=2;t=000155;p=0</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14610">14610</ref><ref source="securityfocus" url="http://www.securityfocus.com/bid/12819">12819</ref></refs><vuln_soft><prod name="IDA Pro" vendor="DataRescue"><vers num="4.7.0.830"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-03-27" name="CVE-2005-0771" published="2005-06-23" seq="2005-0771" severity="High" type="CVE"><desc><descript source="cve">VERITAS Backup Exec Server (beserver.exe) 9.0 through 10.0 for Windows allows remote unauthenticated attackers to modify the registry by calling methods to the RPC interface on TCP port 6106.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=269&amp;type=vulnerabilities&amp;flashstatus=true">20050623 Veritas Backup Exec Server Remote Registry Access Vulnerability</ref><ref adv="1" patch="1" source="" url="http://seer.support.veritas.com/docs/276605.htm">http://seer.support.veritas.com/docs/276605.htm</ref><ref patch="1" source="" url="http://seer.support.veritas.com/docs/277429.htm">http://seer.support.veritas.com/docs/277429.htm</ref><ref adv="1" patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA05-180A.html">TA05-180A</ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/584505">VU#584505</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1014273">1014273</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/15789">15789</ref><ref source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=269&amp;type=vulnerabilities&amp;flashstatus=true">20050623 Veritas Backup Exec Server Remote Registry Access Vulnerability</ref></refs><vuln_soft><prod name="Backup Exec" vendor="Symantec Veritas"><vers num="10.0 rev.5484"/><vers num="9.1 rev.4691"/><vers num="9.0 rev.4454"/><vers num="9.0 rev.4367"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-03-27" name="CVE-2005-0772" published="2005-06-28" seq="2005-0772" severity="Medium" type="CVE"><desc><descript source="cve">VERITAS Backup Exec 9.0 through 10.0 for Windows Servers, and 9.0.4019 through 9.1.307 for Netware, allows remote attackers to cause a denial of service (Remote Agent crash) via (1) a crafted packet in NDMLSRVR.DLL or (2) a request packet with an invalid (non-0) &quot;Error Status&quot; value, which triggers a null dereference.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=270&amp;type=vulnerabilities&amp;flashstatus=true">20050623 Veritas Backup Exec Remote Agent NDMLSRVR.DLL DoS Vulnerability</ref><ref source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=270&amp;type=vulnerabilities&amp;flashstatus=true">20050623 Veritas Backup Exec Remote Agent NDMLSRVR.DLL DoS Vulnerability</ref><ref source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=271&amp;type=vulnerabilities">20050623 Veritas Backup Exec Agent Error Status Remote DoS Vulnerability</ref><ref source="" url="http://seer.support.veritas.com/docs/276533.htm">http://seer.support.veritas.com/docs/276533.htm</ref><ref source="" url="http://seer.support.veritas.com/docs/277485.htm">http://seer.support.veritas.com/docs/277485.htm</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014273">1014273</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15789">15789</ref></refs><vuln_soft><prod name="Backup Exec" vendor="Symantec Veritas"><vers num="10.0"/><vers num="10.0 SP1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-03-27" name="CVE-2005-0773" published="2005-06-18" seq="2005-0773" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in VERITAS Backup Exec Remote Agent 9.0 through 10.0 for Windows, and 9.0.4019 through 9.1.307 for Netware allows remote attackers to execute arbitrary code via a CONNECT_CLIENT_AUTH request with authentication method type 3 (Windows credentials) and a long password argument.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=272&amp;type=vulnerabilities&amp;flashstatus=true">20050623 Veritas Backup Exec Agent CONNECT_CLIENT_AUTH Buffer Overflow Vulnerability</ref><ref adv="1" patch="1" source="" url="http://seer.support.veritas.com/docs/276604.htm">http://seer.support.veritas.com/docs/276604.htm</ref><ref patch="1" source="" url="http://seer.support.veritas.com/docs/277429.htm">http://seer.support.veritas.com/docs/277429.htm</ref><ref adv="1" patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA05-180A.html">TA05-180A</ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/492105">VU#492105</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/14022">14022</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1014273">1014273</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/15789">15789</ref><ref source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=272&amp;type=vulnerabilities&amp;flashstatus=true">20050623 Veritas Backup Exec Agent CONNECT_CLIENT_AUTH Buffer Overflow Vulnerability</ref><ref source="OSVDB" url="http://www.osvdb.org/17624">17624</ref></refs><vuln_soft><prod name="Backup Exec" vendor="Symantec Veritas"><vers num="9.1.1154"/><vers num="9.1.1152.4"/><vers num="9.1.1152"/><vers num="9.1.1151.1"/><vers num="9.1.1127.1"/><vers num="9.1.1067.3"/><vers num="9.1.1067.2"/><vers num="9.1.307"/><vers num="9.1.306"/><vers num="9.0.4202"/><vers num="9.0.4174"/><vers num="9.0.4172"/><vers num="9.0.4170"/><vers num="9.0.4019"/><vers num="10.0 rev.5484 SP1"/><vers num="10.0 rev.5484"/><vers num="9.1 rev.4691 SP2"/><vers num="9.1 rev.4691"/><vers num="9.0 rev.4454 SP1"/><vers num="9.0 rev.4454"/><vers num="9.0 rev.4367 SP1"/><vers num="9.0 rev.4367"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-27" name="CVE-2005-0774" published="2005-03-10" seq="2005-0774" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in member.php and possibly other scripts in PhotoPost PHP 5.0 RC3 allows remote attackers to execute arbitrary SQL commands via the uid parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111065868402859&amp;w=2">20050311 PhotoPost PHP 5.0 RC3, and later, multiple vulnerabilities</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/12779">12779</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14576">14576</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19675">photopost-uid-sql-injection(19675)</ref></refs><vuln_soft><prod name="PhotoPost PHP Pro" vendor="PhotoPost"><vers num="5.0 RC3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-27" name="CVE-2005-0775" published="2005-05-02" seq="2005-0775" severity="High" type="CVE"><desc><descript source="cve">The reportpost action in misc.php for PhotoPost PHP 5.0 RC3 does not limit the logging data that is sent to the admistrator, which allows remote attackers to send large amounts of email to the admistrator.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111065868402859&amp;w=2">20050311 PhotoPost PHP 5.0 RC3, and later, multiple vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/12779">12779</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14576">14576</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19676">photopost-email-security-bypass(19676)</ref></refs><vuln_soft><prod name="PhotoPost PHP Pro" vendor="PhotoPost"><vers num="5.0 RC3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-27" name="CVE-2005-0776" published="2005-05-02" seq="2005-0776" severity="Medium" type="CVE"><desc><descript source="cve">adm-photo.php in PhotoPost PHP 5.0 RC3 does not properly verify administrative privileges before manipulating photos, which could allow remote attackers to manipulate other users&apos; photos.</descript></desc><loss_types><int/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111065868402859&amp;w=2">20050311 PhotoPost PHP 5.0 RC3, and later, multiple vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/12779">12779</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14576">14576</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19677">photopost-image-modification(19677)</ref></refs><vuln_soft><prod name="PhotoPost PHP Pro" vendor="PhotoPost"><vers num="5.0 RC3"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-27" name="CVE-2005-0777" published="2005-05-02" seq="2005-0777" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in PhotoPost PHP 5.0 RC3 allow remote attackers to inject arbitrary web script or HTML via (1) the check_tags function or (2) the editbio field in the user profile.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111065868402859&amp;w=2">20050311 PhotoPost PHP 5.0 RC3, and later, multiple vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/12779">12779</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14576">14576</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19678">photopost-editbio-xss(19678)</ref></refs><vuln_soft><prod name="PhotoPost PHP Pro" vendor="PhotoPost"><vers num="5.0 RC3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-27" name="CVE-2005-0778" published="2005-05-02" seq="2005-0778" severity="Medium" type="CVE"><desc><descript source="cve">PhotoPost PHP 5.0 RC3 does not fully verify that an uploaded file is an image file, which allows remote attackers to inject arbitrary Javascript by uploading non-image files with an image extension such as .gif.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111065868402859&amp;w=2">20050311 PhotoPost PHP 5.0 RC3, and later, multiple vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/12779">12779</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14576">14576</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19679">photopost-file-upload(19679)</ref></refs><vuln_soft><prod name="PhotoPost PHP Pro" vendor="PhotoPost"><vers num="5.0 RC3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0779" published="2005-05-02" seq="2005-0779" severity="Medium" type="CVE"><desc><descript source="cve">PlatinumFTP 1.0.18, and possibly earlier versions, allows remote attackers to cause a denial of service (server crash) via multiple connection attempts with a \ (backslash) in the username.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111066232415249&amp;w=2">20050312 PlatinumFTP 1.0.18 remote DoS</ref><ref source="BID" url="http://www.securityfocus.com/bid/12790">12790</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19674">platinumftp-username-dos(19674)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/455609/100/0/threaded">20070101 Re: PlatinumFTP 1.0.18 remote DoS</ref></refs><vuln_soft><prod name="PlatinumFTPserver" vendor="PlatinumFTP"><vers num="1.0.18"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0780" published="2005-03-12" seq="2005-0780" severity="Medium" type="CVE"><desc><descript source="cve">paFileDB 3.1 and earlier allows remote attackers to obtain sensitive information via a direct request to (1) auth.php, (2) login.php, (3) category.php, (4) file.php, (5) team.php, (6) license.php, (7) custom.php, (8) admins.php, or (9) backupdb.php, which reveal the path in a PHP error message.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111066293914977&amp;w=2">20050312 [SECURITYREASON.COM]  Mass Full Path Disclosure in paFileDB</ref></refs><vuln_soft><prod name="paFileDB" vendor="PHP Arena"><vers num="3.1"/><vers num="3.0 Beta 3.1"/><vers num="3.0"/><vers num="2.1.1"/><vers num="1.1.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0781" published="2005-05-02" seq="2005-0781" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in (1) viewall.php and (2) category.php in paFileDB 3.1 and earlier allows remote attackers to execute arbitrary SQL commands via the start parameter to pafiledb.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111065796525043&amp;w=2">20050312 [SECURITYREASON.COM]  SQL injection and XSS in paFileDB</ref><ref source="BID" url="http://www.securityfocus.com/bid/12788">12788</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19688">pafiledb-viewall-category-sql-injection(19688)</ref></refs><vuln_soft><prod name="paFileDB" vendor="PHP Arena"><vers num="3.1"/><vers num="3.0 Beta 3.1"/><vers num="3.0"/><vers num="2.1.1"/><vers num="1.1.3"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0782" published="2005-05-02" seq="2005-0782" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in (1) viewall.php and (2) category.php for paFileDB 3.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the start parameter to pafiledb.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111065796525043&amp;w=2">20050312 [SECURITYREASON.COM]  SQL injection and XSS in paFileDB</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111221940107161&amp;w=2">20050330 PaFileDB Version 3.1 and below are exploitable via a XSS and a SQL injection vulnerability</ref><ref source="MISC" url="http://digitalparadox.org/advisories/pafdb.txt">http://digitalparadox.org/advisories/pafdb.txt</ref><ref source="BID" url="http://www.securityfocus.com/bid/12788">12788</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19690">pafiledb-viewall-category-xss(19690)</ref></refs><vuln_soft><prod name="paFileDB" vendor="PHP Arena"><vers num="3.1"/><vers num="3.0 Beta 3.1"/><vers num="3.0"/><vers num="2.1.1"/><vers num="1.1.3"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0783" published="2005-05-02" seq="2005-0783" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Phorum before 5.0.14a allows remote attackers to inject arbitrary web script or HTML via the filename of an attached file.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111083279031544&amp;w=2">20050313 3 XSS Vulnerabilities in Phorum &lt;= 5.0.14</ref><ref source="BID" url="http://www.securityfocus.com/bid/12800">12800</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/14554">14554</ref></refs><vuln_soft><prod name="Phorum" vendor="Phorum"><vers num="5.0.14"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0784" published="2005-05-02" seq="2005-0784" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Phorum before 5.0.15 allow remote attackers to inject arbitrary web script or HTML via (1) the subject line to follow.php or (2) the subject line in the user&apos;s personal control panel.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111083279031544&amp;w=2">20050313 3 XSS Vulnerabilities in Phorum &lt;= 5.0.14</ref><ref source="BID" url="http://www.securityfocus.com/bid/12800">12800</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/14554">14554</ref></refs><vuln_soft><prod name="Phorum" vendor="Phorum"><vers num="5.0.14"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0785" published="2005-05-02" seq="2005-0785" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in usersrecentposts in YaBB 2.0 rc1 allows remote attackers to inject arbitrary web script or HTML via the username parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111083400601759&amp;w=2">20050313 YaBB2 rc1 XSS</ref><ref source="MISC" url="http://www.securitytracker.com/alerts/2005/Mar/1013420.html">http://www.securitytracker.com/alerts/2005/Mar/1013420.html</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/12756">12756</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19671">yabb-usersrecentposts-xss(19671)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013420">1013420</ref></refs><vuln_soft><prod name="YaBB" vendor="YaBB"><vers num="2.0 RC1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0786" published="2005-03-14" seq="2005-0786" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in gb_new.inc in SimpGB allows remote attackers to execute arbitrary SQL commands via the quote parameter to guestbook.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111082702422979&amp;w=2">20050313 SimpGB SQL Injection Vulnerability</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/12801">12801</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14583">14583</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19694">simpgb-gbnew-sql-injection(19694)</ref></refs><vuln_soft><prod name="SimpGB" vendor="SimpGB"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-22" name="CVE-2005-0787" published="2005-05-02" seq="2005-0787" severity="Low" type="CVE"><desc><descript source="cve">Wine 20050211 and earlier creates temp files with world readable permissions and predictable file names, which allows local users to obtain sensitive information, such as passwords.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111082537009842&amp;w=2">20050314 [ZH2005-02SA] Insecure tmp file creation in Wine</ref><ref patch="1" source="MISC" url="http://bugs.winehq.org/show_bug.cgi?id=2715">http://bugs.winehq.org/show_bug.cgi?id=2715</ref><ref patch="1" source="MISC" url="http://www.zone-h.org/advisories/read/id=7300">http://www.zone-h.org/advisories/read/id=7300</ref><ref source="BID" url="http://www.securityfocus.com/bid/12791">12791</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013428">1013428</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19697">wine-registry-information-disclosure(19697)</ref></refs><vuln_soft><prod name="Wine" vendor="Wine"><vers num="2005-03-10"/><vers num="2005-03-05"/><vers num="2005-02-11"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0788" published="2005-03-14" seq="2005-0788" severity="Medium" type="CVE"><desc><descript source="cve">LimeWire 4.1.2 through 4.5.6 allows remote attackers to read arbitrary files by specifying the full pathname in a Gnutella GET request.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111082448213238&amp;w=2">20050314 LimeWire Gnutella client two vulnerabilities</ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200503-37.xml">GLSA-200503-37</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14555/">14555</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19693">limewire-client-information-disclosure(19693)</ref></refs><vuln_soft><prod name="LimeWire" vendor="LimeWire"><vers num="4.1.2"/><vers num="4.5.6"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0789" published="2005-03-14" seq="2005-0789" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in LimeWire 3.9.6 through 4.6.0 allows remote attackers to read arbitrary files via a .. (dot dot) in a magnet request.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111082448213238&amp;w=2">20050314 LimeWire Gnutella client two vulnerabilities</ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200503-37.xml">GLSA-200503-37</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14555/">14555</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19695">limewire-magnet-directory-traversal(19695)</ref></refs><vuln_soft><prod name="LimeWire" vendor="LimeWire"><vers num="3.9.6"/><vers num="4.6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0790" published="2005-03-14" seq="2005-0790" severity="Medium" type="CVE"><desc><descript source="cve">phpAdsNew 2.0.4 allows remote attackers to obtain sensitive information via a direct request to (1) lib-xmlrpcs.inc.php, (2) maintenance-activation.php, (3) maintenance-cleantables.php, (4) maintenance-autotargeting.php, (5) maintenance-reports.php, (6) phpads.php, (7) remotehtmlview.php, (8) click.php, (9) adcontent.php, which reveal the path in a PHP error message.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111083286926490&amp;w=2">20050314 [SECURITYREASON.COM] phpAdsNew 2.0.4-pr1 Multiple vulnerabilities cXIb8O3.9</ref><ref adv="1" source="MISC" url="http://securityreason.com/adv/%5BphpAdsNew%202.0.4-pr1%20Multiple%20vulnerabilities%20cXIb8O3.9%5D.asc">http://securityreason.com/adv/%5BphpAdsNew%202.0.4-pr1%20Multiple%20vulnerabilities%20cXIb8O3.9%5D.asc</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013429">1013429</ref></refs><vuln_soft><prod name="phpAdsNew" vendor="phpAdsNew"><vers num="2.0.4 pr1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0791" published="2005-03-14" seq="2005-0791" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in adframe.php in phpAdsNew 2.0.4-pr1, when register_globals is enabled, allows remote attackers to inject arbitrary web script or HTML via the refresh parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111083286926490&amp;w=2">20050314 [SECURITYREASON.COM] phpAdsNew 2.0.4-pr1 Multiple vulnerabilities cXIb8O3.9</ref><ref adv="1" patch="1" source="MISC" url="http://securityreason.com/adv/%5BphpAdsNew%202.0.4-pr1%20Multiple%20vulnerabilities%20cXIb8O3.9%5D.asc">http://securityreason.com/adv/%5BphpAdsNew%202.0.4-pr1%20Multiple%20vulnerabilities%20cXIb8O3.9%5D.asc</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/12803">12803</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14592">14592</ref><ref source="OSVDB" url="http://www.osvdb.org/14787">14787</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013429">1013429</ref></refs><vuln_soft><prod name="phpAdsNew" vendor="phpAdsNew"><vers num="2.0.4 pr1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0792" published="2005-03-15" seq="2005-0792" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in ZPanel 2.0 allows remote attackers to execute arbitrary SQL commands via the (1) uname parameter to index.php or (2) page parameter to zpanel.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111090324111053&amp;w=2">20050315 Few remote bugs in zPanel</ref><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111142323616309&amp;w=2">20050320 Re: Few remote bugs in zPanel</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/12809">12809</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14602">14602</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19709">zpanel-index-sql-injection(19709)</ref></refs><vuln_soft><prod name="ZPanel" vendor="ZPanel"><vers num="2.5 beta9"/><vers num="2.5 beta10"/><vers num="2.5 beta"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-28" name="CVE-2005-0793" published="2005-03-15" seq="2005-0793" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in zpanel.php in ZPanel allows remote attackers to (1) execute arbitrary PHP code in ZPanel 2.0 or (2) include local files in ZPanel 2.5 beta 10 and earlier by modifying the page parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111090324111053&amp;w=2">20050315 Few remote bugs in zPanel</ref><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111142323616309&amp;w=2">20050320 Re: Few remote bugs in zPanel</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/12809">12809</ref></refs><vuln_soft><prod name="ZPanel" vendor="ZPanel"><vers num="2.5 Beta9"/><vers num="2.5 Beta10"/><vers num="2.5 Beta"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0794" published="2005-03-15" seq="2005-0794" severity="Medium" type="CVE"><desc><descript source="cve">ZPanel 2.0 and 2.5 beta 10 does not remove or protect installation scripts after they have been used, which allows remote attackers to reinstall the software and possibly cause a denial of service via a direct request to install.php.</descript></desc><loss_types><avail/><int/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111090324111053&amp;w=2">20050315 Few remote bugs in zPanel</ref><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111142323616309&amp;w=2">20050320 Re: Few remote bugs in zPanel</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14602">14602</ref></refs><vuln_soft><prod name="ZPanel" vendor="ZPanel"><vers num="2.5 beta10"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0795" published="2005-03-14" seq="2005-0795" severity="Medium" type="CVE"><desc><descript source="cve">HolaCMS 1.4.9 does not restrict file access to the holaDB/votes directory, which allows remote attackers to overwrite arbitrary files via a modified vote_filename parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2005-03/0210.html">20050315 Virginity Security Advisory 2005-001 : Hola CMS - File destruction and System access</ref><ref adv="1" patch="1" source="CONFIRM" url="http://www.holacms.de/?content=changelog">http://www.holacms.de/?content=changelog</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14566">14566</ref></refs><vuln_soft><prod name="HolaCMS" vendor="Hola"><vers num="1.4.9_1"/><vers num="1.4.9"/><vers num="1.4.8"/><vers num="1.4.7"/><vers num="1.4.6"/><vers num="1.4.5"/><vers num="1.4.4"/><vers num="1.4.3"/><vers num="1.4.2a"/><vers num="1.4.2"/><vers num="1.4.1"/><vers num="1.4"/><vers num="1.2.10"/><vers num="1.2.9"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0796" published="2005-05-02" seq="2005-0796" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in HolaCMS 1.4.9-1 allows remote attackers to overwrite arbitrary files via a &quot;holaDB/votes&quot; followed by a .. (dot dot) in the vote_filename parameter, which bypasses the check by HolaCMS to ensure that the file is in the holaDB/votes directory.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="CONFIRM" url="http://www.holacms.de/?content=changelog">http://www.holacms.de/?content=changelog</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/14566">14566</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111090966815089&amp;w=2">20050315 Virginity Security Advisory 2005-002 : Hola CMS - Another File destruction and System access</ref></refs><vuln_soft><prod name="HolaCMS" vendor="Hola"><vers num="1.4.9" prev="1"/><vers num="1.4.9_1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2008-04-04" name="CVE-2005-0797" published="2005-03-15" seq="2005-0797" severity="Medium" type="CVE"><desc><descript source="cve">Novell iChain Mini FTP Server 2.3 displays different error messages if a user exists or not, which allows remote attackers to obtain sensitive information and facilitates brute force attacks.</descript></desc><loss_types><conf/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111091027000721&amp;w=2">20050315 [ISR] - Novell iChain Mini FTP Server Valid User Disclosure Vulnerability</ref><ref adv="1" source="MISC" url="http://www.infobyte.com.ar/adv/ISR-04.html">http://www.infobyte.com.ar/adv/ISR-04.html</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/12811">12811</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/14607">14607</ref></refs><vuln_soft><prod name="iChain" vendor="Novell"><vers num="2.3 SP2"/><vers num="2.3"/><vers num="2.2.113"/><vers num="2.2 SP3"/><vers num="2.2 SP2"/><vers num="2.2 SP1"/><vers num="2.2 FP1a"/><vers num="2.2 FP1"/><vers num="2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0798" published="2005-03-15" seq="2005-0798" severity="High" type="CVE"><desc><descript source="cve">Novell iChain Mini FTP Server 2.3, and possibly earlier versions, does not limit the number of incorrect logins, which makes it easier for remote attackers to conduct brute force login attacks.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111091517007681&amp;w=2">20050315 [ISR] - Novell iChain Mini FTP Server Bruteforce Problem</ref><ref adv="1" source="MISC" url="http://www.infobyte.com.ar/adv/ISR-05.html">http://www.infobyte.com.ar/adv/ISR-05.html</ref><ref adv="1" source="CONFIRM" url="http://support.novell.com/cgi-bin/search/searchtid.cgi?/10096887.htm">http://support.novell.com/cgi-bin/search/searchtid.cgi?/10096887.htm</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/14607">14607</ref><ref source="OSVDB" url="http://www.osvdb.org/14648">14648</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013408">1013408</ref></refs><vuln_soft><prod name="iChain Server" vendor="Novell"><vers num="2.2 FP1"/><vers num="2.2"/></prod><prod name="iChain" vendor="Novell"><vers num="2.3 SP2"/><vers num="2.3"/><vers num="2.2.113"/><vers num="2.2 SP3"/><vers num="2.2 SP2"/><vers num="2.2 SP1"/><vers num="2.2 FP1a"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-03-28" name="CVE-2005-0799" published="2005-03-15" seq="2005-0799" severity="Medium" type="CVE"><desc><descript source="cve">MySQL 4.1.9, and possibly earlier versions, allows remote attackers with certain privileges to cause a denial of service (application crash) via a use command followed by an MS-DOS device name such as (1) LPT1 or (2) PRN.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="CONFIRM" url="http://bugs.mysql.com/bug.php?id=9148">http://bugs.mysql.com/bug.php?id=9148</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/14564">14564</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111091250923281&amp;w=2">20050315 Denial of Service Vulnerability in MySQL Server for Windows</ref></refs><vuln_soft><prod name="MySQL" vendor="MySQL"><vers num="4.1.9"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-28" name="CVE-2005-0800" published="2005-05-02" seq="2005-0800" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in install.php in mcNews 1.3 and earlier allows remote attackers to execute arbitrary PHP code by modifying the l parameter to reference a URL on a remote web server that contains the code, a different vulnerability than CVE-2005-0720.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111108900102438&amp;w=2">20050317 PHP mcNews arbitrary file inclusion</ref><ref source="BID" url="http://www.securityfocus.com/bid/12835">12835</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14528">14528</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19726">mcnews-install-file-include(19726)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/445606/100/0/threaded">20060906 mcNews v1.3 - Remote File Include</ref></refs><vuln_soft><prod name="McNews" vendor="McNews"><vers num="1.3"/><vers num="1.2"/><vers num="1.1a"/><vers num="1.1"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0801" published="2005-05-02" seq="2005-0801" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in includer.cgi in The Includer allows remote attackers to read arbitrary files via (1) a .. (dot dot) or (2) a full pathname in the URL.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111109052121557&amp;w=2">20050317 Another includer.cgi problem?</ref></refs><vuln_soft><prod name="includer.cgi" vendor="includer.cgi"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0802" published="2005-05-02" seq="2005-0802" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in search.asp in ACS Blog 0.8 through 1.1b allows remote attackers to execute arbitrary web script or HTML via the search parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/12836">12836</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013470">1013470</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14625/">14625</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19728">acs-blog-search-xss(19728)</ref><ref source="OSVDB" url="http://www.osvdb.org/14861">14861</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111108840811698&amp;w=2">20050317 XSS in ACS blog</ref></refs><vuln_soft><prod name="ACS Blog" vendor="ASP Press"><vers num="0.8"/><vers num="0.9"/><vers num="1.0"/><vers num="1.1b"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-06-15" name="CVE-2005-0803" published="2005-05-02" seq="2005-0803" severity="Medium" type="CVE"><desc><descript source="cve">The GetEnhMetaFilePaletteEntries API in GDI32.DLL in Windows 2000 allows remote attackers to cause a denial of service (application crash) via a crafted Enhanced Metafile (EMF) file that causes invalid (1) end, (2) emreof, or (3) palent offsets to be used, aka &quot;Enhanced Metafile Vulnerability.&quot;</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/12834">12834</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14631">14631</ref><ref source="MS" url="http://www.microsoft.com/technet/security/Bulletin/MS05-053.mspx">MS05-053</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1121.html">OVAL1121</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1152.html">OVAL1152</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1215.html">OVAL1215</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1240.html">OVAL1240</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval671.html">OVAL671</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015168">1015168</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/134756">VU#134756</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/2348">ADV-2005-2348</ref><ref source="OSVDB" url="http://www.osvdb.org/20580">20580</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19727">win-2000-gdi32dll-dos(19727)</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2005-228.pdf"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/17461">17461</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17223">17223</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111108743527497&amp;w=2">20050317 Windows 2000 GDI32.DLL GetEnhMetaFilePaletteEntries() API specially crafted EMF file DOS vulnerability</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1121">oval:org.mitre.oval:def:1121</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1152">oval:org.mitre.oval:def:1152</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1215">oval:org.mitre.oval:def:1215</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1240">oval:org.mitre.oval:def:1240</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:671">oval:org.mitre.oval:def:671</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA05-312A.html">TA05-312A</ref></refs><vuln_soft><prod name="Windows 2000" vendor="Microsoft"><vers num="Server SP4"/><vers num="Server SP3"/><vers num="Server SP2"/><vers num="Server SP1"/><vers num="Server"/><vers num="Professional SP4"/><vers num="Professional SP3"/><vers num="Professional SP2"/><vers num="Professional SP1"/><vers num="Professional"/><vers num="Datacenter Server SP4"/><vers num="Datacenter Server SP3"/><vers num="Datacenter Server SP2"/><vers num="Datacenter Server SP1"/><vers num="Datacenter Server"/><vers num="Advanced Server SP4"/><vers num="Advanced Server SP3"/><vers num="Advanced Server SP2"/><vers num="Advanced Server SP1"/><vers num="Advanced Server"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2007-07-24" name="CVE-2005-0804" published="2005-05-02" seq="2005-0804" severity="Medium" type="CVE"><desc><descript source="cve">Format string vulnerability in MailEnable 1.8 allows remote attackers to cause a denial of service (application crash) via format string specifiers in the mailto field.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/12833">12833</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/14627">14627</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111108519331738&amp;w=2">20050317 See-security Advisory: Format string vulnerability in MailEnable 1.8</ref></refs><vuln_soft><prod name="MailEnable Standard" vendor="MailEnable"><vers num="1.8"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0805" published="2005-05-02" seq="2005-0805" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in index.php in Subdreamer Light, when magic_quotes_gpc is enabled, allows remote attackers to execute arbitrary SQL commands via certain parameters that are used as global variables, as demonstrated using the imageid parameter, which is not properly handled by imagegallery.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/12839">12839</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111116479910230&amp;w=2">20050318 possible SQL injection in Subdreamer</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/437983/100/200/threaded">20060621 Re: possible SQL injection in Subdreamer</ref><ref source="" url="http://www.subdreamer.com/forum/showthread.php?t=2501"></ref></refs><vuln_soft><prod name="Subdreamer Light" vendor="Subdreamer"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0806" published="2005-05-02" seq="2005-0806" severity="Medium" type="CVE"><desc><descript source="cve">Evolution 2.0.3 allows remote attackers to cause a denial of service (application crash or hang) via crafted messages, possibly involving charsets in attachment filenames.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref source="CONFIRM" url="http://bugzilla.ximian.com/show_bug.cgi?id=72609">http://bugzilla.ximian.com/show_bug.cgi?id=72609</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:059">MDKSA-2005:059</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-397.html">RHSA-2005:397</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-166-1">USN-166-1</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:059">MDKSA-2005:059</ref></refs><vuln_soft><prod name="Evolution" vendor="Ximian"><vers num="2.0.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-04-07" name="CVE-2005-0807" published="2005-05-02" seq="2005-0807" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in Cain &amp; Abel before 2.67 allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via (1) an IKE packet with a large ID field that is not properly handled by the PSK sniffer filter, (2) the HTTP sniffer filter, or the (3) POP3, (4) SMTP, (5) IMAP, (6) NNTP, or (7) TDS sniffer filters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="CONFIRM" url="http://www.oxid.it/">http://www.oxid.it/</ref><ref source="BID" url="http://www.securityfocus.com/bid/12840">12840</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013476">1013476</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/14630">14630</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19742">cain-abel-ikepsk-bo(19742)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19744">cain-abel-http-filter-bo(19744)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111116097313427&amp;w=2">20050318 Cain &amp; Abel PSK Sniffer Heap overflow</ref></refs><vuln_soft><prod name="Cain &amp; Abel" vendor="oxid"><vers num="2.65"/><vers num="2.5"/><vers num="2.5 beta65"/><vers num="2.5 beta59"/><vers num="2.5 beta56"/><vers num="2.5 beta51"/><vers num="2.5 beta47"/><vers num="2.5 beta41"/><vers num="2.5 beta40"/><vers num="2.5 beta36"/><vers num="2.5 beta34"/><vers num="2.5 beta29"/><vers num="2.5 beta21"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0808" published="2005-05-02" seq="2005-0808" severity="Medium" type="CVE"><desc><descript source="cve">Apache Tomcat before 5.x allows remote attackers to cause a denial of service (application crash) via a crafted AJP12 packet to TCP port 8007.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="CONFIRM" url="http://www.kb.cert.org/vuls/id/JGEI-6A2LEF">http://www.kb.cert.org/vuls/id/JGEI-6A2LEF</ref><ref source="CONFIRM" url="http://www.hitachi-support.com/security_e/vuls_e/HS05-006_e/index-e.html">http://www.hitachi-support.com/security_e/vuls_e/HS05-006_e/index-e.html</ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/204710">VU#204710</ref><ref source="BID" url="http://www.securityfocus.com/bid/12795">12795</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19681">tomcat-manager-ajp12-dos(19681)</ref></refs><vuln_soft><prod name="Tomcat" vendor="Apache Software Foundation"><vers num="3.3.1a"/><vers num="3.3.1"/><vers num="3.3"/><vers num="3.2.4"/><vers num="3.2.3"/><vers num="3.2.2 Beta2"/><vers num="3.2.1"/><vers num="3.2"/><vers num="3.1.1"/><vers num="3.1"/><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0809" published="2005-05-02" seq="2005-0809" severity="High" type="CVE"><desc><descript source="cve">NotifyLink, when configured for client key retrieval, allows remote attackers to obtain AES keys via a direct request to /hwp/get.asp, then uses a weak encryption scheme (fixed byte reordering) to protect the key, which allows remote attackers to obtain the key via a brute force attack.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/581068">VU#581068</ref><ref source="BID" url="http://www.securityfocus.com/bid/12843">12843</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14617">14617</ref></refs><vuln_soft><prod name="NotifyLink" vendor="Notify Technology"><vers num="Enterprise Server"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0810" published="2005-05-02" seq="2005-0810" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in NotifyLink before 3.0 allows remote attackers to execute arbitrary SQL commands via the URL.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/264097">VU#264097</ref><ref source="BID" url="http://www.securityfocus.com/bid/12843">12843</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14617">14617</ref></refs><vuln_soft><prod name="NotifyLink" vendor="Notify Technology"><vers num="Enterprise Server"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0811" published="2005-05-02" seq="2005-0811" severity="Medium" type="CVE"><desc><descript source="cve">The web interface in NotifyLink 3.0 does not properly restrict access to functions that have been disabled in the GUI, which allows remote authenticated users to bypass intended restrictions via a direct request to certain URLs.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/131828">VU#131828</ref><ref source="BID" url="http://www.securityfocus.com/bid/12843">12843</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14617">14617</ref></refs><vuln_soft><prod name="NotifyLink" vendor="Notify Technology"><vers num="Enterprise Server"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0812" published="2005-05-02" seq="2005-0812" severity="Medium" type="CVE"><desc><descript source="cve">The web interface in NotifyLink 3.0 displays passwords in cleartext on the administrative page, which could allow remote attackers or local users to obtain sensitive information.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/770532">VU#770532</ref><ref source="BID" url="http://www.securityfocus.com/bid/12843">12843</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14617">14617</ref></refs><vuln_soft><prod name="NotifyLink" vendor="Notify Technology"><vers num="Enterprise Server"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0813" published="2005-05-02" seq="2005-0813" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in Initial Redirect (ir) Squid Proxy Plug-In 0.1 and 0.2 may allow attackers to cause a denial of service and execute arbitrary code via unknown vectors.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="CONFIRM" url="http://www.vanheusden.com/ir/">http://www.vanheusden.com/ir/</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/12827">12827</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/13674">13674</ref><ref source="OSVDB" url="http://www.osvdb.org/14832">14832</ref></refs><vuln_soft><prod name="Initial Redirect Squid Proxy Plug-In" vendor="Initial Redirect"><vers num="0.2"/><vers num="0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0814" published="2005-05-02" seq="2005-0814" severity="Medium" type="CVE"><desc><descript source="cve">Unknown vulnerability in lshd in Lysator LSH 1.x and 2.x before 2.0.1 allows remote attackers to cause a denial of service via unknown vectors.</descript></desc><loss_types><avail/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="MLIST" url="http://lists.lysator.liu.se/pipermail/lsh-bugs/2005q1/000328.html">[lsh-bugs] 20050316 ANNOUNCE: LSH-2.0.1, fix for denial of service bug</ref><ref patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-717">DSA-717</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/14609">14609</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19724">lsh-lshd-dos(19724)</ref></refs><vuln_soft><prod name="LSH" vendor="Lysator"><vers num="1.0.1"/><vers num="1.0.2"/><vers num="1.0.3"/><vers num="1.0.4"/><vers num="1.0.5"/><vers num="1.0.6"/><vers num="1.0.7"/><vers num="1.0"/><vers num="1.1.0"/><vers num="1.1.1"/><vers num="1.1.2"/><vers num="1.1.3"/><vers num="1.1.4"/><vers num="1.1.5"/><vers num="1.1.6"/><vers num="1.1.7"/><vers num="1.1.8"/><vers num="1.1.9"/><vers num="1.2.1"/><vers num="1.2.2"/><vers num="1.2.3"/><vers num="1.2.4"/><vers num="1.2.5"/><vers num="1.2"/><vers num="1.3.0"/><vers num="1.3.1"/><vers num="1.3.2"/><vers num="1.3.3"/><vers num="1.3.4"/><vers num="1.3.5"/><vers num="1.3.6"/><vers num="1.3.7"/><vers num="1.4.1"/><vers num="1.4.2"/><vers num="1.4.3"/><vers num="1.4"/><vers num="1.5.1"/><vers num="1.5.2"/><vers num="1.5.3"/><vers num="1.5.4"/><vers num="1.5.5"/><vers num="1.5"/><vers num="2.0.1"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0815" published="2005-05-02" seq="2005-0815" severity="Medium" type="CVE"><desc><descript source="cve">Multiple &quot;range checking flaws&quot; in the ISO9660 filesystem handler in Linux 2.6.11 and earlier may allow attackers to cause a denial of service or corrupt memory via a crafted filesystem.</descript></desc><loss_types><avail/><int/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/393590">20050317 Linux ISO9660 handling flaws</ref><ref source="CONFIRM" url="http://kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.12-rc1">http://kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.12-rc1</ref><ref source="BID" url="http://www.securityfocus.com/bid/12837">12837</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19741">kernel-iso9660-filesystem(19741)</ref><ref source="FEDORA" url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=152532">FLSA:152532</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0190.html">RHSA-2006:0190</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0191.html">RHSA-2006:0191</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18684">18684</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-366.html">RHSA-2005:366</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-663.html">RHSA-2005:663</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17002">17002</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:072">MDKSA-2006:072</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/1878">ADV-2005-1878</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:072">MDKSA-2006:072</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.6.11"/><vers num="2.6.10 rc2"/><vers num="2.6.10"/><vers num="2.6.1 rc2"/><vers num="2.6.1 rc1"/><vers num="2.6.1"/><vers num="2.6.0"/><vers num="2.6 test9 CVS"/><vers num="2.6 test9"/><vers num="2.6 test8"/><vers num="2.6 test7"/><vers num="2.6 test6"/><vers num="2.6 test5"/><vers num="2.6 test4"/><vers num="2.6 test3"/><vers num="2.6 test2"/><vers num="2.6 test11"/><vers num="2.6 test10"/><vers num="2.6 test1"/><vers num="2.6"/><vers num="2.5.9"/><vers num="2.5.8"/><vers num="2.5.7"/><vers num="2.5.69"/><vers num="2.5.68"/><vers num="2.5.67"/><vers num="2.5.66"/><vers num="2.5.65"/><vers num="2.5.64"/><vers num="2.5.63"/><vers num="2.5.62"/><vers num="2.5.61"/><vers num="2.5.60"/><vers num="2.5.6"/><vers num="2.5.59"/><vers num="2.5.58"/><vers num="2.5.57"/><vers num="2.5.56"/><vers num="2.5.55"/><vers num="2.5.54"/><vers num="2.5.53"/><vers num="2.5.52"/><vers num="2.5.51"/><vers num="2.5.50"/><vers num="2.5.5"/><vers num="2.5.49"/><vers num="2.5.48"/><vers num="2.5.47"/><vers num="2.5.46"/><vers num="2.5.45"/><vers num="2.5.44"/><vers num="2.5.43"/><vers num="2.5.42"/><vers num="2.5.41"/><vers num="2.5.40"/><vers num="2.5.4"/><vers num="2.5.39"/><vers num="2.5.38"/><vers num="2.5.37"/><vers num="2.5.36"/><vers num="2.5.35"/><vers num="2.5.34"/><vers num="2.5.33"/><vers num="2.5.32"/><vers num="2.5.31"/><vers num="2.5.30"/><vers num="2.5.3"/><vers num="2.5.29"/><vers num="2.5.28"/><vers num="2.5.27"/><vers num="2.5.26"/><vers num="2.5.25"/><vers num="2.5.24"/><vers num="2.5.23"/><vers num="2.5.22"/><vers num="2.5.21"/><vers num="2.5.20"/><vers num="2.5.2"/><vers num="2.5.19"/><vers num="2.5.18"/><vers num="2.5.17"/><vers num="2.5.16"/><vers num="2.5.15"/><vers num="2.5.14"/><vers num="2.5.13"/><vers num="2.5.12"/><vers num="2.5.11"/><vers num="2.5.10"/><vers num="2.5.1"/><vers num="2.5.0"/><vers num="2.4.9"/><vers num="2.4.8"/><vers num="2.4.7"/><vers num="2.4.6"/><vers num="2.4.5"/><vers num="2.4.4"/><vers num="2.4.3 pre3"/><vers num="2.4.31 pre1"/><vers num="2.4.30 rc3"/><vers num="2.4.30 rc2"/><vers num="2.4.30"/><vers num="2.4.3"/><vers num="2.4.29 rc2"/><vers num="2.4.29 rc1"/><vers num="2.4.29"/><vers num="2.4.28"/><vers num="2.4.27 pre5"/><vers num="2.4.27 pre4"/><vers num="2.4.27 pre3"/><vers num="2.4.27 pre2"/><vers num="2.4.27 pre1"/><vers num="2.4.27"/><vers num="2.4.26"/><vers num="2.4.25"/><vers num="2.4.24 ow1"/><vers num="2.4.24"/><vers num="2.4.23 pre9"/><vers num="2.4.23 ow2"/><vers num="2.4.23"/><vers num="2.4.22 pre10"/><vers num="2.4.22"/><vers num="2.4.21 pre7"/><vers num="2.4.21 pre4"/><vers num="2.4.21 pre1"/><vers num="2.4.21"/><vers num="2.4.20"/><vers num="2.4.2"/><vers num="2.4.19 pre6"/><vers num="2.4.19 pre5"/><vers num="2.4.19 pre4"/><vers num="2.4.19 pre3"/><vers num="2.4.19 pre2"/><vers num="2.4.19 pre1"/><vers num="2.4.19"/><vers edition="x86" num="2.4.18"/><vers num="2.4.18 pre8"/><vers num="2.4.18 pre7"/><vers num="2.4.18 pre6"/><vers num="2.4.18 pre5"/><vers num="2.4.18 pre4"/><vers num="2.4.18 pre3"/><vers num="2.4.18 pre2"/><vers num="2.4.18 pre1"/><vers num="2.4.18"/><vers num="2.4.17"/><vers num="2.4.16"/><vers num="2.4.15"/><vers num="2.4.14"/><vers num="2.4.13"/><vers num="2.4.12"/><vers num="2.4.11"/><vers num="2.4.10"/><vers num="2.4.1"/><vers num="2.4.0 test9"/><vers num="2.4.0 test8"/><vers num="2.4.0 test7"/><vers num="2.4.0 test6"/><vers num="2.4.0 test5"/><vers num="2.4.0 test4"/><vers num="2.4.0 test3"/><vers num="2.4.0 test2"/><vers num="2.4.0 test12"/><vers num="2.4.0 test11"/><vers num="2.4.0 test10"/><vers num="2.4.0 test1"/><vers num="2.4.0"/><vers num="2.3.99 pre7"/><vers num="2.3.99 pre6"/><vers num="2.3.99 pre5"/><vers num="2.3.99 pre4"/><vers num="2.3.99 pre3"/><vers num="2.3.99 pre2"/><vers num="2.3.99 pre1"/><vers num="2.3.99"/><vers num="2.3"/><vers num="2.2.9"/><vers num="2.2.8"/><vers num="2.2.7"/><vers num="2.2.6"/><vers num="2.2.5"/><vers num="2.2.4"/><vers num="2.2.3"/><vers num="2.2.27 rc2"/><vers num="2.2.25"/><vers num="2.2.24"/><vers num="2.2.23"/><vers num="2.2.22"/><vers num="2.2.21"/><vers num="2.2.20"/><vers num="2.2.2"/><vers num="2.2.19"/><vers num="2.2.18"/><vers num="2.2.17"/><vers num="2.2.16 pre6"/><vers num="2.2.16"/><vers num="2.2.15 pre20"/><vers num="2.2.15 pre16"/><vers num="2.2.15"/><vers num="2.2.14"/><vers num="2.2.13"/><vers num="2.2.12"/><vers num="2.2.11"/><vers num="2.2.10"/><vers num="2.2.1"/><vers num="2.2"/><vers num="2.1.89"/><vers num="2.1"/><vers num="2.0.9.9"/><vers num="2.0.9"/><vers num="2.0.8"/><vers num="2.0.7"/><vers num="2.0.6"/><vers num="2.0.5"/><vers num="2.0.4"/><vers num="2.0.39"/><vers num="2.0.38"/><vers num="2.0.37"/><vers num="2.0.36"/><vers num="2.0.35"/><vers num="2.0.34"/><vers num="2.0.33"/><vers num="2.0.32"/><vers num="2.0.31"/><vers num="2.0.30"/><vers num="2.0.3"/><vers num="2.0.29"/><vers num="2.0.28"/><vers num="2.0.27"/><vers num="2.0.26"/><vers num="2.0.25"/><vers num="2.0.24"/><vers num="2.0.23"/><vers num="2.0.22"/><vers num="2.0.21"/><vers num="2.0.20"/><vers num="2.0.2"/><vers num="2.0.19"/><vers num="2.0.18"/><vers num="2.0.17"/><vers num="2.0.16"/><vers num="2.0.15"/><vers num="2.0.14"/><vers num="2.0.13"/><vers num="2.0.12"/><vers num="2.0.11"/><vers num="2.0.10"/><vers num="2.0.1"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0816" published="2005-05-02" seq="2005-0816" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in newgrp in Solaris 7 through 9 allows local users to gain root privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57710-1">57710</ref><ref source="BID" url="http://www.securityfocus.com/bid/12838">12838</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013462">1013462</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19729">solaris-newgrp-bo(19729)</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers edition="x86" num="9.0"/><vers edition="SPARC" num="9.0"/><vers edition="x86" num="8.0"/><vers num="8.0"/><vers edition="x86" num="7.0"/><vers num="7.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0817" published="2005-05-02" seq="2005-0817" severity="Medium" type="CVE"><desc><descript source="cve">Unknown vulnerability in the DNSd proxy, as used in Symantec Gateway Security 5400 2.x and 5300 1.x, Enterprise Firewall 7.0.x and 8.x, and VelociRaptor 1100/1200/1300 1.5, allows remote attackers to poison the DNS cache and redirect users to malicious sites.</descript></desc><loss_types><int/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref source="MISC" url="http://www.isc.sans.org/diary.php?date=2005-03-04">http://www.isc.sans.org/diary.php?date=2005-03-04</ref><ref adv="1" source="CONFIRM" url="http://securityresponse.symantec.com/avcenter/security/Content/2005.03.15.html">http://securityresponse.symantec.com/avcenter/security/Content/2005.03.15.html</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013451">1013451</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14595">14595</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/16423">sef-dns-spoofing(16423)</ref></refs><vuln_soft><prod name="VelociRaptor" vendor="Symantec"><vers num="Model 1300"/></prod><prod name="Enterprise Firewall" vendor="Symantec"><vers num="7.0"/><vers num="8.0"/></prod><prod name="Gateway Security 5300" vendor="Symantec"><vers num="1.0"/></prod><prod name="Gateway Security 5400" vendor="Symantec"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0818" published="2005-05-02" seq="2005-0818" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in PunBB 1.2.3 allows remote attackers to inject arbitrary web script or HTML via the (1) email or (2) Jabber parameters.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="SECTRACK" url="http://securitytracker.com/id?1013446">1013446</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19725">punbb-email-jabber-xss(19725)</ref></refs><vuln_soft><prod name="PunBB" vendor="PunBB"><vers num="1.2.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0819" published="2005-05-02" seq="2005-0819" severity="Medium" type="CVE"><desc><descript source="cve">The xvesa code in Novell Netware 6.5 SP2 and SP3 allows remote attackers to redirect the xsession without authentication via a direct request to GUIMirror/Start.</descript></desc><loss_types><int/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="CONFIRM" url="http://support.novell.com/cgi-bin/search/searchtid.cgi?/2971038.htm">http://support.novell.com/cgi-bin/search/searchtid.cgi?/2971038.htm</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/12831">12831</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013460">1013460</ref></refs><vuln_soft><prod name="Netware" vendor="Novell"><vers num="6.5 SP2"/><vers num="6.5 SP3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0820" published="2005-05-02" seq="2005-0820" severity="Medium" type="CVE"><desc><descript source="cve">Microsoft Office InfoPath 2003 SP1 includes sensitive information in the Manifest.xsf file in a custom .xsn form, which allows attackers to obtain printer and network information, obtain the database name, username, and password, or obtain the internal web server name.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="MSKB" url="http://support.microsoft.com/kb/867443">867443</ref><ref source="BID" url="http://www.securityfocus.com/bid/12824">12824</ref><ref source="OSVDB" url="http://www.osvdb.org/14882">14882</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013454">1013454</ref></refs><vuln_soft><prod name="Office InfoPath" vendor="Microsoft"><vers num="2003 SP1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0821" published="2005-05-02" seq="2005-0821" severity="High" type="CVE"><desc><descript source="cve">Unknown vulnerability in Citrix MetaFrame Conferencing Manager 3.0 allows conference members to bypass organizer restrictions to control the keyboard and mouse.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CONFIRM" url="http://support.citrix.com/kb/entry.jspa?externalID=CTX105574">http://support.citrix.com/kb/entry.jspa?externalID=CTX105574</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/12821">12821</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1013457">1013457</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19723">metaframe-conferencing-gain-access(19723)</ref></refs><vuln_soft><prod name="MetaFrame Conferencing Manager" vendor="Citrix"><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0822" published="2005-05-02" seq="2005-0822" severity="Low" type="CVE"><desc><descript source="cve">Citrix Metaframe Password Manager 2.5 and earlier stores a password in cleartext although it is obfuscated when presented to a user, which allows users to view their secondary passwords even if it is not allowed by policy.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CONFIRM" url="http://support.citrix.com/kb/entry.jspa?externalID=CTX105762">http://support.citrix.com/kb/entry.jspa?externalID=CTX105762</ref><ref adv="1" source="CONFIRM" url="http://support.citrix.com/kb/entry.jspa?entryID=5970&amp;categoryID=254">http://support.citrix.com/kb/entry.jspa?entryID=5970&amp;categoryID=254</ref><ref source="" url="http://support.citrix.com/article/CTX105800"></ref><ref source="BID" url="http://www.securityfocus.com/bid/24041">
24041</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1018077">
1018077</ref></refs><vuln_soft><prod name="Metaframe Password Manager" vendor="Citrix"><vers num="2.5"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0823" published="2005-05-02" seq="2005-0823" severity="Medium" type="CVE"><desc><descript source="cve">ThePoolClub (1) iPool and (2) iSnooker 1.6.81 and earlier stores usernames and passwords in cleartext in the MyDetails.txt file, which allows local users to gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/12830">12830</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013458">1013458</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013459">1013459</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14629">14629</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19717">ipool-mydetails-plaintext-password(19717)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19718">isnooker-mydetails-plaintext-password(19718)</ref></refs><vuln_soft><prod name="iPool" vendor="ThePoolClub"><vers num="1.6.81" prev="1"/></prod><prod name="iSnooker" vendor="ThePoolClub"><vers num="1.6.8" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0824" published="2005-05-02" seq="2005-0824" severity="Low" type="CVE"><desc><descript source="cve">The internal_dump function in Mathopd before 1.5p5, and 1.6x before 1.6b6 BETA, when Mathopd is running with the -n option, allows local users to overwrite arbitrary files via a symlink attack on dump files that are triggered by a SIGWINCH signal.</descript></desc><loss_types><int/></loss_types><vuln_types><design/><env/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14524">14524</ref><ref source="CONFIRM" url="http://www.mail-archive.com/mathopd%40mathopd.org/msg00272.html">http://www.mail-archive.com/mathopd%40mathopd.org/msg00272.html</ref></refs><vuln_soft><prod name="Mathopd" vendor="Mathopd"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0825" published="2005-05-02" seq="2005-0825" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in LTris before 1.0.10 allows local users to execute arbitrary code via a crafted highscores file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="CONFIRM" url="http://lgames.sourceforge.net/index.php?action=show_news&amp;news_action=show_item&amp;item_id=108">http://lgames.sourceforge.net/index.php?action=show_news&amp;news_action=show_item&amp;item_id=108</ref><ref patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200503-24.xml">GLSA 200503-24</ref><ref source="MISC" url="http://bugs.gentoo.org/show_bug.cgi?id=85770">http://bugs.gentoo.org/show_bug.cgi?id=85770</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/14635">14635</ref></refs><vuln_soft><prod name="LTris" vendor="LGames"><vers num="1.0.9"/><vers num="1.0.8" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0826" published="2005-05-02" seq="2005-0826" severity="Medium" type="CVE"><desc><descript source="cve">OllyDbg 1.10 and earlier allows remote attackers to cause a denial of service (application crash) via a dynamic link library (DLL) with a long filename.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111125734701262&amp;w=2">20050319 OllyDbg long process Module debug Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/12850">12850</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013478">1013478</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19750">ollydbg-long-filename-do(19750)</ref></refs><vuln_soft><prod name="OllyDbg" vendor="OllyDbg"><vers num="1.10"/><vers num="1.09"/><vers num="1.08b"/><vers num="1.06"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0827" published="2005-05-02" seq="2005-0827" severity="Medium" type="CVE"><desc><descript source="cve">Viewcat.php in (1) RUNCMS 1.1A, (2) Ciamos 0.9.2 RC1, e-Xoops 1.05 Rev3, and possibly other products based on e-Xoops (exoops), allow remote attackers to obtain sensitive information via an invalid parameter to the convertorderbytrans function, which reveals the path in a PHP error message.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111125588920928&amp;w=2">20050319 Ciamos Installation path(IHS)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111117182417422&amp;w=2">20050318 runcms installation path</ref><ref adv="1" source="MISC" url="http://www.ihsteam.com/download/sections/runcms%20advisory%20-%20eng.pdf">http://www.ihsteam.com/download/sections/runcms%20advisory%20-%20eng.pdf</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/14641">14641</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19755">ciamos-viewcat-path-disclosure(19755)</ref></refs><vuln_soft><prod name="e-Xoops" vendor="e-Xoops"><vers num="1.05 Rev3"/></prod><prod name="RunCMS" vendor="RunCMS"><vers num="1.1a"/></prod><prod name="Ciamos" vendor="Ciamos"><vers num="0.9.2 RC1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0828" published="2005-05-02" seq="2005-0828" severity="Medium" type="CVE"><desc><descript source="cve">highlight.php in (1) RUNCMS 1.1A, (2) CIAMOS 0.9.2 RC1, (3) e-Xoops 1.05 Rev3, and possibly other products based on e-Xoops (exoops), allows remote attackers to read arbitrary PHP files by specifying the pathname in the file parameter, as demonstrated by reading database configuration information from mainfile.php.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111117241923006&amp;w=2">20050318 runcms highlight.php hole</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111125645312693&amp;w=2">20050319 Ciamos Highlight.php Security Hole(IHS)</ref><ref adv="1" source="MISC" url="http://www.ihsteam.com/download/sections/runcms%20advisory%20-%20eng.pdf">http://www.ihsteam.com/download/sections/runcms%20advisory%20-%20eng.pdf</ref><ref source="MISC" url="http://www.ihsteam.com/download/advisory/Exoops%20highlight%20hole.txt">http://www.ihsteam.com/download/advisory/Exoops%20highlight%20hole.txt</ref><ref source="BID" url="http://www.securityfocus.com/bid/12848">12848</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/14648">14648</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14641">14641</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19754">ciamos-file-information-disclosure(19754)</ref><ref source="OSVDB" url="http://www.osvdb.org/14890">14890</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013485">1013485</ref></refs><vuln_soft><prod name="E-Xoops" vendor="E-Xoops"><vers num="1.05r3"/></prod><prod name="RunCMS" vendor="RunCMS"><vers num="1.1a"/></prod><prod name="Ciamos" vendor="Ciamos"><vers num="0.9.2 RC1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0829" published="2005-05-02" seq="2005-0829" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in setuser.php of the Digitanium addon to PHP-Fusion 5.01 allows remote attackers to inject arbitrary web script or HTML via the (1) user_name or (2) user_pass parameters.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111125692513645&amp;w=2">20050319 [PersianHacker.NET 200503-10]PHP-Fusion v5.01 Html Injection</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111142752220155&amp;w=2">20050319 Fw: [PersianHacker.NET 200503-10]PHP-Fusion v5.01 Html Injection    Vulnerability</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111142918711745&amp;w=2">20050319 Re: [PersianHacker.NET 200503-10]PHP-Fusion v5.01 Html Injection</ref></refs><vuln_soft><prod name="PHP_Fusion" vendor="PHP_Fusion"><vers num="5.01"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0830" published="2005-05-02" seq="2005-0830" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in Xzabite DYNDNSUpdate 0.6.15 and earlier, including the ipcheck function in dyndnsupdate.c, allow remote attackers who spoof a dyndns.org server to execute arbitrary code via unknown vectors.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200503-27.xml">GLSA-200503-27</ref><ref adv="1" source="MISC" url="http://bugs.gentoo.org/show_bug.cgi?id=84659">http://bugs.gentoo.org/show_bug.cgi?id=84659</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/14663">14663</ref></refs><vuln_soft><prod name="DYNDNSUpdate" vendor="Xzabite"><vers num="0.6.15"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-22" name="CVE-2005-0831" published="2005-05-02" seq="2005-0831" severity="Medium" type="CVE"><desc><descript source="cve">PHP-Post allows remote attackers to spoof the names of other users by registering with a username containing hex-encoded characters.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/393695">20050318 PHP-Post Exploit</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/12845">12845</ref></refs><vuln_soft><prod name="PHP-Post Web Forum" vendor="PHP-Post"><vers num="0.32"/><vers num="0.22"/><vers num="0.21"/><vers num="0.3"/><vers num="0.2"/><vers num="0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-22" name="CVE-2005-0832" published="2005-05-02" seq="2005-0832" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in PHP-Post before 0.33 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="CONFIRM" url="http://www.php-post.co.uk/index.php?s=content&amp;p=download">http://www.php-post.co.uk/index.php?s=content&amp;p=download</ref><ref source="BID" url="http://www.securityfocus.com/bid/12845">12845</ref></refs><vuln_soft><prod name="PHP-Post Web Forum" vendor="PHP-Post"><vers num="0.32"/><vers num="0.22"/><vers num="0.21"/><vers num="0.3"/><vers num="0.2"/><vers num="0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0833" published="2005-05-02" seq="2005-0833" severity="High" type="CVE"><desc><descript source="cve">Belkin 54G (F5D7130) wireless router allows remote attackers to access restricted resources by sniffing URIs from UPNP datagrams, then accessing those URIs, which do not require authentication.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/12846">12846</ref></refs><vuln_soft><prod name="Belkin 54G Wireless Router" vendor="Belkin"><vers num="F5D7130"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0834" published="2005-05-02" seq="2005-0834" severity="Medium" type="CVE"><desc><descript source="cve">Belkin 54G (F5D7130) wireless router enables SNMP by default in a manner that allows remote attackers to obtain sensitive information.</descript></desc><loss_types><conf/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/12846">12846</ref></refs><vuln_soft><prod name="Belkin 54G Wireless Router" vendor="Belkin"><vers num="F5D7130"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0835" published="2005-05-02" seq="2005-0835" severity="Medium" type="CVE"><desc><descript source="cve">The SNMP service in the Belkin 54G (F5D7130) wireless router allows remote attackers to cause a denial of service via unknown vectors.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/12846">12846</ref></refs><vuln_soft><prod name="54G Wireless Router" vendor="Belkin"><vers num="F5D7130"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0836" published="2005-05-02" seq="2005-0836" severity="High" type="CVE"><desc><descript source="cve">Argument injection vulnerability in Java Web Start for J2SE 1.4.2 up to 1.4.2_06 allows untrusted applications to gain privileges via the value parameter of a property tag in a JNLP file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=111117284323657&amp;w=2">20050318 Java Web Start argument injection vulnerability</ref><ref source="MISC" url="http://jouko.iki.fi/adv/ws.html">http://jouko.iki.fi/adv/ws.html</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57740-1">57740</ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200503-28.xml">GLSA-200503-28</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/12847">12847</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/14640">14640</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_32_java2.html">SUSE-SA:2005:032</ref></refs><vuln_soft><prod name="J2SE" vendor="Sun"><vers num="1.4.2"/><vers num="1.4.2_01"/><vers num="1.4.2_02"/><vers num="1.4.2_03"/><vers num="1.4.2_04"/><vers num="1.4.2_05"/><vers num="1.4.2_06"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0837" published="2005-05-02" seq="2005-0837" severity="Medium" type="CVE"><desc><descript source="cve">IceCast 2.20 allows remote attackers to bypass the XSL parser and obtain the source for XSL files via a request for a .xsl file with a trailing . (dot).</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/393705">20050318 IceCast up to v2.20 multiple vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/12849">12849</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013475">1013475</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/14644">14644</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19760">icecast-get-bypass-security(19760)</ref></refs><vuln_soft><prod name="Icecast" vendor="Icecast"><vers num="2.2"/><vers num="2.1.0"/><vers num="2.0.2"/><vers num="2.0.1"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0838" published="2005-05-02" seq="2005-0838" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in the XSL parser for IceCast 2.20 may allow attackers to cause a denial of service and possibly execute arbitrary code via (1) a long test value in an xsl:when tag, (2) a long test value in an xsl:if tag, or (3) a long select value in an xsl:value-of tag.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/393705">20050318 IceCast up to v2.20 multiple vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/12849">12849</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013475">1013475</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19753">icecast-xsl-gain-pivileges(19753)</ref></refs><vuln_soft><prod name="IceCast" vendor="IceCast"><vers num="2.20"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0839" published="2005-05-02" seq="2005-0839" severity="High" type="CVE"><desc><descript source="cve">Linux kernel 2.6 before 2.6.11 does not restrict access to the N_MOUSE line discipline for a TTY, which allows local users to gain privileges by injecting mouse or keyboard events into other user sessions.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" source="MLIST" url="http://www.mail-archive.com/linux-kernel@vger.kernel.org/msg64704.html">[linux-kernel] 20050301 Re: Breakage from patch: Only root should be able to set the N_MOUSE line discipline.</ref><ref source="MISC" url="http://linux.bkbits.net:8080/linux-2.6/cset@41fa6464E1UuGu6zmketEYxm73KSyQ">http://linux.bkbits.net:8080/linux-2.6/cset@41fa6464E1UuGu6zmketEYxm73KSyQ</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-366.html">RHSA-2005:366</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/427980/100/0/threaded">FLSA:157459-3</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.6.0"/><vers num="2.6.1"/><vers num="2.6.1-rc1"/><vers num="2.6.1-rc2"/><vers num="2.6.10"/><vers num="2.6.10-rc2"/><vers num="2.6.2"/><vers num="2.6.3"/><vers num="2.6.4"/><vers num="2.6.5"/><vers num="2.6.6"/><vers num="2.6.7"/><vers num="2.6.8"/><vers num="2.6.8.1"/><vers num="2.6.9"/></prod></vuln_soft></entry><entry modified="2005-10-25" name="CVE-2005-0840" published="2005-05-02" reject="1" seq="2005-0840" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2005-0706.  Reason: This candidate is a duplicate of CVE-2005-0706.  Notes: All CVE users should reference CVE-2005-0706 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript></desc><refs/></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0841" published="2005-05-02" seq="2005-0841" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in (1) people.php, (2) track.php, (3) edit.php, (4) document.php, (5) census.php, (6) passthru.php and possibly other php files in phpMyFamily 1.4.0 allows remote attackers to execute arbitrary SQL commands, as demonstrated via (1) the person parameter to people.php or (2) the Login field.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111143649730845&amp;w=2">20050321 phpMyFamily 1.4.0 SQL vulnerabilities</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013493">1013493</ref><ref source="BID" url="http://www.securityfocus.com/bid/12860">12860</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14642">14642</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19787">phpmyfamily-multiple-scripts-sql-injection(19787)</ref></refs><vuln_soft><prod name="phpmyfamily" vendor="phpmyfamily"><vers num="1.4"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0842" published="2005-05-02" seq="2005-0842" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in Kayako eSupport 2.3 allows remote attackers to inject arbitrary web script or HTML via the (1) _i or (2) _c parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111151292704335&amp;w=2">20050322 Kayako eSupport Cross Site Scripting</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13563">13563</ref></refs><vuln_soft><prod name="eSupport" vendor="Kayako"><vers num="2.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0843" published="2005-05-02" seq="2005-0843" severity="Medium" type="CVE"><desc><descript source="cve">CRLF injection vulnerability in search.php in Phorum 5.0.14a allows remote attackers to perform HTTP Response Splitting attacks via the body parameter, which is included in the resulting Location header.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111151651621097&amp;w=2">20050322 [ Positive Technologies #SA] Phorum </ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14680">14680</ref></refs><vuln_soft><prod name="Phorum" vendor="Phorum"><vers num="5.0.14a"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-08-30" name="CVE-2005-0844" published="2005-05-02" seq="2005-0844" severity="Medium" type="CVE"><desc><descript source="cve">Nortel VPN client 5.01 stores the cleartext password in the memory or the Extranet.exe process, which could allow local users to obtain sensitive information.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111151589203707&amp;w=2">20050322 Nortel VPN Client Issue: Clear-text password stored in memory</ref><ref adv="1" source="MISC" url="http://www.nta-monitor.com/news/vpn-flaws/nortel/nortel-client/">http://www.nta-monitor.com/news/vpn-flaws/nortel/nortel-client/</ref><ref adv="1" source="SECTRACK" url="http://securitytracker.com/id?1013512">1013512</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19791">nortel-contivity-information-disclosure(19791)</ref></refs><vuln_soft><prod name="Contivity" vendor="Nortel Networks"><vers num="5.01"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-22" name="CVE-2005-0845" published="2005-05-02" seq="2005-0845" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in the Webmail interface in SurgeMail 2.2g3 allows remote authenticated users to write arbritrary files or directories via a .. (dot dot) in the attach_id parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111159967417903&amp;w=2">20050323 [SIG^2 G-TEC] SurgeMail Webmail Attachment Upload and XSS</ref><ref source="MISC" url="http://www.security.org.sg/vuln/surgemail22g3.html">http://www.security.org.sg/vuln/surgemail22g3.html</ref><ref patch="1" source="CONFIRM" url="http://netwinsite.com/cgi/dnewsweb.cgi?cmd=article&amp;group=netwin.surgemail&amp;item=8814&amp;utag=">http://netwinsite.com/cgi/dnewsweb.cgi?cmd=article&amp;group=netwin.surgemail&amp;item=8814&amp;utag=</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14658">14658</ref></refs><vuln_soft><prod name="SurgeMail" vendor="NetWin"><vers num="2.2g3"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-22" name="CVE-2005-0846" published="2005-05-02" seq="2005-0846" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in the email auto-reply message in SurgeMail 2.2g3 allow remote attackers to inject arbitrary web script or HTML via the (1) message subject or (2) message header field.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111159967417903&amp;w=2">20050323 [SIG^2 G-TEC] SurgeMail Webmail Attachment Upload and XSS</ref><ref source="MISC" url="http://www.security.org.sg/vuln/surgemail22g3.html">http://www.security.org.sg/vuln/surgemail22g3.html</ref><ref patch="1" source="CONFIRM" url="http://netwinsite.com/cgi/dnewsweb.cgi?cmd=article&amp;group=netwin.surgemail&amp;item=8814&amp;utag=">http://netwinsite.com/cgi/dnewsweb.cgi?cmd=article&amp;group=netwin.surgemail&amp;item=8814&amp;utag=</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14658">14658</ref></refs><vuln_soft><prod name="SurgeMail" vendor="NetWin"><vers num="2.2g3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0847" published="2005-05-02" seq="2005-0847" severity="Medium" type="CVE"><desc><descript source="cve">Code Ocean FTP server 1.0 allows remote attackers to cause a denial of service via a large number of connections.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="MISC" url="http://www.milw0rm.com/id.php?id=893">http://www.milw0rm.com/id.php?id=893</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14662">14662</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/12859">12859</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19777">ocean-ftp-connection-dos(19777)</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/893">

893</ref></refs><vuln_soft><prod name="Ocean FTP Server" vendor="Code Ocean"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0848" published="2005-05-02" seq="2005-0848" severity="Medium" type="CVE"><desc><descript source="cve">Multiple games developed by FUN labs, including 4X4 Off-road Adventure III, Big Game Hunter, Dangerous Hunts, Deer Hunt, Revolution, Secret Service, Shadow Force, and US Most Wanted, allow remote attackers to cause a denial of service via an empty UDP packet to the server, which cannot detect that a new packet has arrived using the socket ioctl.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="Luigi Auriemma" url="http://aluigi.altervista.org/adv/funlabsboom-adv.txt"></ref><ref adv="1" source="SECTRACK" url="http://securitytracker.com/id?1013492">1013492</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/14638">14638</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19762">funlabs-games-upd-dos(19762)</ref></refs><vuln_soft><prod name="Cabela&apos;s Deer Hunt 2005 Season" vendor="FunLabs"><vers num=""/></prod><prod name="Cabela&apos;s Big Game Hunter 2005" vendor="FunLabs"><vers num=""/></prod><prod name="Revolution" vendor="FunLabs"><vers num=""/></prod><prod name="Secret Service In Harm&apos;s Way" vendor="FunLabs"><vers num=""/></prod><prod name="4X4 Off-road Adventure III" vendor="FunLabs"><vers num=""/></prod><prod name="Shadow Force Razor Unit" vendor="FunLabs"><vers num=""/></prod><prod name="Cabela&apos;s Dangerous Hunts" vendor="FunLabs"><vers num=""/></prod><prod name="Cabela&apos;s Big Game Hunter 2004 Season" vendor="FunLabs"><vers num=""/></prod><prod name="US Most Wanted Nowhere To Hide" vendor="FunLabs"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0849" published="2005-05-02" seq="2005-0849" severity="Medium" type="CVE"><desc><descript source="cve">Multiple games developed by FUN labs, including 4X4 Off-road Adventure III, Big Game Hunter, Dangerous Hunts, Deer Hunt, Revolution, Secret Service, Shadow Force, and US Most Wanted, allow remote attackers to cause a denial of service (crash from invalid memory access) via a malformed join packet with values that cause the server to copy more memory than was actually provided in the packet.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="Luigi Auriemma" url="http://aluigi.altervista.org/adv/funlabsboom-adv.txt"></ref><ref adv="1" source="SECTRACK" url="http://securitytracker.com/id?1013492">1013492</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/14638">14638</ref></refs><vuln_soft><prod name="Cabela&apos;s Deer Hunt 2005 Season" vendor="FunLabs"><vers num=""/></prod><prod name="Cabela&apos;s Big Game Hunter 2005" vendor="FunLabs"><vers num=""/></prod><prod name="Revolution" vendor="FunLabs"><vers num=""/></prod><prod name="Secret Service In Harm&apos;s Way" vendor="FunLabs"><vers num=""/></prod><prod name="4X4 Off-road Adventure III" vendor="FunLabs"><vers num=""/></prod><prod name="Shadow Force Razor Unit" vendor="FunLabs"><vers num=""/></prod><prod name="Cabela&apos;s Dangerous Hunts" vendor="FunLabs"><vers num=""/></prod><prod name="Cabela&apos;s Big Game Hunter 2004 Season" vendor="FunLabs"><vers num=""/></prod><prod name="US Most Wanted Nowhere To Hide" vendor="FunLabs"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0850" published="2005-05-02" seq="2005-0850" severity="Medium" type="CVE"><desc><descript source="cve">FileZilla FTP server before 0.9.6 allows remote attackers to cause a denial of service via a request for a filename containing an MS-DOS device name such as CON, NUL, COM1, LPT1, and others.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref patch="1" source="CONFIRM" url="http://sourceforge.net/project/shownotes.php?group_id=21558&amp;release_id=314473">http://sourceforge.net/project/shownotes.php?group_id=21558&amp;release_id=314473</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/12865">12865</ref></refs><vuln_soft><prod name="FileZilla Server" vendor="FileZilla"><vers num="0.9.5"/><vers num="0.9.4e"/><vers num="0.9.4d"/><vers num="0.9.3"/><vers num="0.9.2"/><vers num="0.9.1b"/><vers num="0.9.0"/><vers num="0.8.9"/><vers num="0.8.8"/><vers num="0.8.7"/><vers num="0.8.6a"/><vers num="0.8.5"/><vers num="0.8.4"/><vers num="0.8.3"/><vers num="0.8.2"/><vers num="0.8.1"/><vers num="0.7.1"/><vers num="0.7"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0851" published="2005-05-02" seq="2005-0851" severity="Medium" type="CVE"><desc><descript source="cve">FileZilla FTP server before 0.9.6, when using MODE Z (zlib compression), allows remote attackers to cause a denial of service (infinite loop) via certain file uploads or directory listings.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref patch="1" source="CONFIRM" url="http://sourceforge.net/project/shownotes.php?group_id=21558&amp;release_id=314473">http://sourceforge.net/project/shownotes.php?group_id=21558&amp;release_id=314473</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/12865">12865</ref></refs><vuln_soft><prod name="FileZilla Server" vendor="FileZilla"><vers num="0.9.5"/><vers num="0.9.4e"/><vers num="0.9.4d"/><vers num="0.9.3"/><vers num="0.9.2"/><vers num="0.9.1b"/><vers num="0.9.0"/><vers num="0.8.9"/><vers num="0.8.8"/><vers num="0.8.7"/><vers num="0.8.6a"/><vers num="0.8.5"/><vers num="0.8.4"/><vers num="0.8.3"/><vers num="0.8.2"/><vers num="0.8.1"/><vers num="0.7.1"/><vers num="0.7"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0852" published="2005-05-02" seq="2005-0852" severity="Low" type="CVE"><desc><descript source="cve">Microsoft Windows XP SP1 allows local users to cause a denial of service (system crash) via an empty datagram to a raw IP over IP socket (IP protocol 4), as originally demonstrated using code in Python 2.3.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><local/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/393956">20050322 Possible windows+python bug</ref><ref source="BID" url="http://www.securityfocus.com/bid/12870">12870</ref></refs><vuln_soft><prod name="Windows XP" vendor="Microsoft"><vers edition="Gold" num="Professional"/><vers edition="SP1" num="Home"/><vers edition="SP2" num="Tablet PC"/><vers edition="SP1" num="Media Center"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0853" published="2005-05-02" seq="2005-0853" severity="Medium" type="CVE"><desc><descript source="cve">betaparticle blog (bp blog) stores the database under the web root, which allows remote attackers to obtain sensitive information via a direct request to (1) dbBlogMX.mdb for versions before 3.0, or (2) Blog.mdb for versions 3.0 and later.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/12861">12861</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14668">14668</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19779">betaparticle-web-root-information-disclosure(19779)</ref></refs><vuln_soft><prod name="betaparticle blog" vendor="betaparticle"><vers num="3.0"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-06-15" name="CVE-2005-0854" published="2005-05-02" seq="2005-0854" severity="High" type="CVE"><desc><descript source="cve">betaparticle blog (bp blog), posisbly before version 4, allows remote attackers to bypass authentication and (1) upload files via a direct request to upload.asp or (2) delete files via a direct request to myFiles.asp.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/12861">12861</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14668">14668</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19781">betaparticle-blog-authentication-bypass(19781)</ref><ref source="" url="http://blog.betaparticle.com/template_permalink.asp?id=68"></ref></refs><vuln_soft><prod name="Betaparticle blog" vendor="Betaparticle"><vers num="3.0"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2007-01-24" name="CVE-2005-0855" published="2005-05-02" seq="2005-0855" severity="High" type="CVE"><desc><descript source="cve">CoolForum 0.8.1 beta and earlier allows remote attackers to obtain sensitive path information via direct requests to (1) entete.php, (2) profile_accueil.php, (3) profile_mdp.php, (4) profile_notify.php, (5) profile_options.php, (6) profile_perso.php, (7) profile_pm.php, or (8) readannonce.php, which leaks the full pathname in a PHP error message.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1013474">1013474</ref></refs><vuln_soft><prod name="CoolForum" vendor="CoolForum"><vers num="0.8.1 Beta" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0856" published="2005-05-02" seq="2005-0856" severity="High" type="CVE"><desc><descript source="cve">CoolForum 0.8.1 beta and earlier allows remote attackers to manipulate SQL commands via certain requests to (1) alert.php or (2) viewip.php, possibly due to a SQL injection vulnerability.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1013474">1013474</ref></refs><vuln_soft><prod name="CoolForum" vendor="CoolForum"><vers num="0.8.1 beta" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0857" published="2005-05-02" seq="2005-0857" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in avatar.php for CoolForum 0.8 and earlier allows remote attackers to inject arbitrary web script or HTML via the img parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/12852">12852</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1013474">1013474</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19758">coolforum-avatar-xss(19758)</ref></refs><vuln_soft><prod name="CoolForum" vendor="CoolForum"><vers num="0.8" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0858" published="2005-05-02" seq="2005-0858" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in CoolForum 0.8 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the pseudo parameter to entete.php or (2) the login parameter to register.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/12852">12852</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1013474">1013474</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19759">coolforum-adminentete-sql-injection(19759)</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19761">coolforum-register-sql-injection(19761)</ref></refs><vuln_soft><prod name="CoolForum" vendor="CoolForum"><vers num="0.8" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-28" name="CVE-2005-0859" published="2005-05-02" seq="2005-0859" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in CzarNews 1.13b allows remote attackers to execute arbitrary PHP code via the tpath parameter to (1) headlines.php or (2) news.php.  NOTE: some sources have reported the &quot;dir&quot; parameter as being affected; however, this is likely a cut-and-paste error from the wrong section of the original vulnerability report.  Also, the news.php version was later reported to be in 1.12 through 1.14.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/12857">12857</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013486">1013486</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14670">14670</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19765">czarnews-multiple-scripts-file-include(19765)</ref><ref source="OSVDB" url="http://www.osvdb.org/14925">14925</ref><ref source="OSVDB" url="http://www.osvdb.org/14926">14926</ref><ref source="BID" url="http://www.securityfocus.com/bid/18411">18411</ref><ref source="" url="http://milw0rm.com/exploits/2009"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/27733">czarnews-news-config-file-include(27733)</ref></refs><vuln_soft><prod name="CzarNews" vendor="Czaries Network"><vers num="1.13b"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-28" name="CVE-2005-0860" published="2005-05-02" seq="2005-0860" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in TRG News Script 3.0 allows remote attackers to execute arbitrary PHP code via the dir parameter to (1) article.php, (2) authorall.php, (3) comment.php, (4) display.php, or (5) displayall.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/12855">12855</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013487">1013487</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/14669">14669</ref></refs><vuln_soft><prod name="TRG News" vendor="The Rusted Gate"><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0861" published="2005-05-02" seq="2005-0861" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in DeleGate before 8.11.1 may allow attackers to cause a denial of service or execute arbitrary code, possibly due to &quot;overflows on arrays.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref patch="1" source="MISC" url="http://www.delegate.org/mail-lists/delegate-en/2840">http://www.delegate.org/mail-lists/delegate-en/2840</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/14649">14649</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19775">delegate-bo(19775)</ref></refs><vuln_soft><prod name="Delegate" vendor="Delegate"><vers num="8.11.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-28" name="CVE-2005-0862" published="2005-05-02" seq="2005-0862" severity="High" type="CVE"><desc><descript source="cve">Multiple PHP remote file inclusion vulnerabilities in PHPOpenChat 3.0.1 and earlier allow remote attackers to execute arbitrary PHP code via the phpbb_root_path parameter to (1) poc_loginform.php or (2) phpbb/poc.php, the poc_root_path parameter to (3) phpbb/poc.php, (4) phpnuke/ENGLISH_poc.php, (5) phpnuke/poc.php, or (6) yabbse/poc.php, or (7) the sourcedir parameter to yabbse/poc.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://www.zone-h.org/advisories/read/id=7310">http://www.zone-h.org/advisories/read/id=7310</ref><ref source="BID" url="http://www.securityfocus.com/bid/12817">12817</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013434">1013434</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/14600">14600</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19721">phpopenchat-file-include(19721)</ref><ref source="OSVDB" url="http://www.osvdb.org/14807">14807</ref><ref source="OSVDB" url="http://www.osvdb.org/14808">14808</ref><ref source="OSVDB" url="http://www.osvdb.org/14809">14809</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/465237/100/0/threaded">

20070410 PhpOpenChat &lt;= 3.0.1 (poc.php) Multiple Remote File Include Vulnerabilities</ref></refs><vuln_soft><prod name="PHPOpenChat" vendor="PHPOpenChat"><vers num="3.0.1"/><vers num="2.3.4"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0863" published="2005-05-02" seq="2005-0863" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in PHPOpenChat v3.x allows remote attackers to inject arbitrary web script or HTML via (1) the chatter parameter to regulars.php or (2) the chatter, chatter1, chatter2, chatter3, or chatter4 parameters to register.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/12841">12841</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14651">14651</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19748">phpopenchat-regulars-register-xss(19748)</ref></refs><vuln_soft><prod name="PHPOpenChat" vendor="PHPOpenChat"><vers num="3.0.2"/><vers num="3.0.1"/><vers num="3.0.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0864" published="2005-05-02" seq="2005-0864" severity="Medium" type="CVE"><desc><descript source="cve">The Boa web server, as used in Samsung ADSL Modem SMDK8947v1.2 and possibly other products, allows remote attackers to read arbitrary files via a full pathname in the HTTP request.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://exploitlabs.com/files/advisories/EXPL-A-2005-002-samsung-adsl.txt">http://exploitlabs.com/files/advisories/EXPL-A-2005-002-samsung-adsl.txt</ref><ref adv="1" source="MISC" url="http://zone-h.org/en/advisories/read/id=7339/">http://zone-h.org/en/advisories/read/id=7339/</ref><ref source="BID" url="http://www.securityfocus.com/bid/12864">12864</ref></refs><vuln_soft><prod name="Samsung ADSL Modem" vendor="secure computing"><vers num="SMDK8947v1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0865" published="2005-05-02" seq="2005-0865" severity="High" type="CVE"><desc><descript source="cve">Samsung ADSL Modem SMDK8947v1.2 uses default passwords for the (1) root, (2) admin, or (3) user users, which allows remote attackers to gain privileges via Telnet or an HTTP request to adsl.cgi.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://exploitlabs.com/files/advisories/EXPL-A-2005-002-samsung-adsl.txt">http://exploitlabs.com/files/advisories/EXPL-A-2005-002-samsung-adsl.txt</ref><ref adv="1" source="MISC" url="http://zone-h.org/en/advisories/read/id=7339/">http://zone-h.org/en/advisories/read/id=7339/</ref><ref source="BID" url="http://www.securityfocus.com/bid/12864">12864</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013615">1013615</ref></refs><vuln_soft><prod name="Samsung ADSL Modem" vendor="secure computing"><vers num="SMDK8947v1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0866" published="2005-05-02" seq="2005-0866" severity="Low" type="CVE"><desc><descript source="cve">cdrecord before 4:2.0, when DEBUG is enabled, allows local users to overwrite arbitrary files via a symlink attack on temporary files.</descript></desc><loss_types><int/></loss_types><vuln_types><input/><env/></vuln_types><range><local/></range><refs><ref patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111170604206805&amp;w=2">20050324 [USN-100-1] cdrecord vulnerability</ref><ref source="CONFIRM" url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=291376">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=291376</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-100-1">USN-100-1</ref></refs><vuln_soft><prod name="CDRecord" vendor="CDRTools"><vers num="2.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0867" published="2005-05-02" seq="2005-0867" severity="High" type="CVE"><desc><descript source="cve">Integer overflow in Linux kernel 2.6 allows local users to overwrite kernel memory by writing to a sysfs file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_18_kernel.html">SuSE-SA:2005:018</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-366.html">RHSA-2005:366</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/427980/100/0/threaded">FLSA:157459-3</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0868" published="2005-05-02" seq="2005-0868" severity="High" type="CVE"><desc><descript source="cve">AS/400 Telnet 5250 terminal emulation clients, as implemented by (1) IBM client access, (2) Bosanova, (3) PowerTerm, (4) Mochasoft, and possibly other emulations, allows malicious AS/400 servers to execute arbitrary commands via a STRPCO (Start PC Organizer) command followed by STRPCCMD (Start PC command), as demonstrated by creating a backdoor account using REXEC.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111160242803070&amp;w=2">20050323 Backdoors in AS/400 emulations allow the server to attack connected PC workstations</ref><ref source="MISC" url="http://www.venera.com/downloads/Attack_5250_terminal_emulations_from_iSeries_server.pdf">http://www.venera.com/downloads/Attack_5250_terminal_emulations_from_iSeries_server.pdf</ref></refs><vuln_soft><prod name="InterConnect" vendor="PowerTerm"><vers num=""/></prod><prod name="Launcher400" vendor="BOSaNOVA"><vers num=""/></prod><prod name="TN5250" vendor="Mochasoft"><vers num=""/></prod><prod name="Client Access" vendor="IBM"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0869" published="2005-05-02" seq="2005-0869" severity="Medium" type="CVE"><desc><descript source="cve">phpSysInfo 2.3 allows remote attackers to obtain sensitive information via a direct request to (1) class.OpenBSD.inc.php, (2) class.NetBSD.inc.php, (3) class.FreeBSD.inc.php, (4) class.Darwin.inc.php, (5) XPath.class.php, (6) system_header.php, or (7) system_footer.php, which reveal the path in a PHP error message.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111161017209422&amp;w=2">20050323 [SECURITYREASON.COM] phpSysInfo 2.3 Multiple vulnerabilities</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/14690/">14690</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19808">phpsysinfo-path-disclosure(19808)</ref></refs><vuln_soft><prod name="phpSysInfo" vendor="phpSysInfo"><vers num="2.3"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0870" published="2005-05-02" seq="2005-0870" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in phpSysInfo 2.3, when register_globals is enabled, allow remote attackers to inject arbitrary web script or HTML via the (1) sensor_program parameter to index.php, (2) text[language], (3) text[template], or (4) hide_picklist parameter to system_footer.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111161017209422&amp;w=2">20050323 [SECURITYREASON.COM] phpSysInfo 2.3 Multiple vulnerabilities</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/14690/">14690</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19807">phpsysinfo-sensor-program-xss(19807)</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-724">DSA-724</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-898">DSA-898</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/416543">20051115 Advisory 22/2005: Multiple vulnerabilities in phpSysInfo</ref><ref source="" url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=301118"></ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-899">DSA-899</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2005:212">MDKSA-2005:212</ref><ref source="BID" url="http://www.securityfocus.com/bid/15414">15414</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-897">DSA-897</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17616">17616</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17643">17643</ref><ref source="BID" url="http://www.securityfocus.com/bid/12887">12887</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:212">MDKSA-2005:212</ref></refs><vuln_soft><prod name="phpSysInfo" vendor="phpSysInfo"><vers num="2.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0871" published="2005-05-02" seq="2005-0871" severity="Medium" type="CVE"><desc><descript source="cve">calendar_scheduler.php in Topic Calendar 1.0.1 module for phpBB, when running on a Microsoft IIS server, allows remote attackers to obtain sensitive information via invalid parameters, which reveal the path in an error message.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/><env/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111168190630576&amp;w=2">20050324 Multiple vulnerabilities in Topic Calendar 1.0.1 for phpBB</ref><ref source="MISC" url="http://www.securitytracker.com/alerts/2005/Mar/1013554.html">http://www.securitytracker.com/alerts/2005/Mar/1013554.html</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14659">14659</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19824">topic-calendar-path-disclosure(19824)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013554">1013554</ref></refs><vuln_soft><prod name="phpBB" vendor="phpBB Group"><vers num="1.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0872" published="2005-05-02" seq="2005-0872" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in calendar_scheduler.php in the Topic Calendar 1.0.1 module for phpBB allows remote attackers to inject arbitrary web script or HTML via the start parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MISC" url="http://www.securitytracker.com/alerts/2005/Mar/1013554.html">http://www.securitytracker.com/alerts/2005/Mar/1013554.html</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14659">14659</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19821">topic-calendar-start-xss(19821)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013554">1013554</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111168190630576&amp;w=2">20050324 Multiple vulnerabilities in Topic Calendar 1.0.1 for phpBB</ref></refs><vuln_soft><prod name="phpbb" vendor="phpBB Group"><vers num="1.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0873" published="2005-05-02" seq="2005-0873" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in test.jsp in Oracle Reports Server 10g (9.0.4.3.3) allow remote attackers to inject arbitrary web script or HTML via the (1) desname or (2) repprod parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111168323804203&amp;w=2">20050324 Oracle Reports Server 10g Vulnerable to  XSS</ref><ref source="BID" url="http://www.securityfocus.com/bid/12892">12892</ref><ref source="" url="http://www.oracle.com/technology/deploy/security/pdf/cpuoct2005.html"></ref><ref source="" url="http://www.oracle.com/technology/deploy/security/pdf/public_vuln_to_advisory_mapping.html"></ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA05-292A.html">TA05-292A</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/210524">VU#210524</ref><ref source="BID" url="http://www.securityfocus.com/bid/15134">15134</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17250">17250</ref></refs><vuln_soft><prod name="Oracle10g Reports Server" vendor="Oracle"><vers num="9.0.4.3.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0874" published="2005-05-02" seq="2005-0874" severity="Medium" type="CVE"><desc><descript source="cve">Multiple buffer overflows in the (1) AIM, (2) MSN, (3) RSS, and other plug-ins for Trillian 2.0 allow remote web servers to cause a denial of service (application crash) via a long string in an HTTP 1.1 response header.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111171416802350&amp;w=2">20050324 LogicLibrary BugScan VSR,Trillian 2.0, 3.0 and 3.1</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/14689">14689</ref><ref source="OSVDB" url="http://www.osvdb.org/15004">15004</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013557">1013557</ref></refs><vuln_soft><prod name="Trillian" vendor="Cerulean Studios"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0875" published="2005-05-02" seq="2005-0875" severity="Medium" type="CVE"><desc><descript source="cve">Multiple buffer overflows in the Yahoo plug-in for Trillian 2.0, 3.0, and 3.1 allow remote web servers to cause a denial of service (application crash) via a long string in an HTTP 1.1 response header.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111171416802350&amp;w=2">20050324 LogicLibrary BugScan VSR,Trillian 2.0, 3.0 and 3.1</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/14689">14689</ref></refs><vuln_soft><prod name="Trillian" vendor="Cerulean Studios"><vers num="2.0"/><vers num="3.0"/><vers num="3.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0876" published="2005-05-02" seq="2005-0876" severity="Medium" type="CVE"><desc><descript source="cve">Off-by-one buffer overflow in Dnsmasq before 2.21 may allow attackers to execute arbitrary code via the DHCP lease file.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="CONFIRM" url="http://www.thekelleys.org.uk/dnsmasq/CHANGELOG">http://www.thekelleys.org.uk/dnsmasq/CHANGELOG</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/12897">12897</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14691">14691</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19825">dnsmasq-dhcp-offbyone-bo(19825)</ref></refs><vuln_soft><prod name="Dnsmasq" vendor="Dnsmasq"><vers num="2.20"/><vers num="2.19"/><vers num="2.18"/><vers num="2.17"/><vers num="2.16"/><vers num="2.15"/><vers num="2.14"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0877" published="2005-05-02" seq="2005-0877" severity="Medium" type="CVE"><desc><descript source="cve">Dnsmasq before 2.21 allows remote attackers to poison the DNS cache via answers to queries that were not made by Dnsmasq.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="CONFIRM" url="http://www.thekelleys.org.uk/dnsmasq/CHANGELOG">http://www.thekelleys.org.uk/dnsmasq/CHANGELOG</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/12897">12897</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14691">14691</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19826">dnsmasq-dns-cache-poisoning(19826)</ref></refs><vuln_soft><prod name="Dnsmasq" vendor="Dnsmasq"><vers num="2.20"/><vers num="2.19"/><vers num="2.18"/><vers num="2.17"/><vers num="2.16"/><vers num="2.15"/><vers num="2.14"/><vers num="2.13"/><vers num="2.12"/><vers num="2.11"/><vers num="2.10"/><vers num="2.9"/><vers num="2.8"/><vers num="2.7"/><vers num="2.6"/><vers num="2.5"/><vers num="2.4"/><vers num="2.3"/><vers num="2.2"/><vers num="2.1"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-10-06" name="CVE-2005-0878" published="2005-03-23" seq="2005-0878" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in MercuryBoard before 1.1.3 allows remote attackers to inject arbitrary web script or HTML via the title field of a PM (private message).</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/12872">12872</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14679">14679</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19797">mercuryboard-title-pm-xss(19797)</ref></refs><vuln_soft><prod name="MercuryBoard Message Board" vendor="MercuryBoard"><vers num="1.1.2"/><vers num="1.1.1"/><vers num="1.1"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-06-15" name="CVE-2005-0879" published="2005-05-02" seq="2005-0879" severity="High" type="CVE"><desc><descript source="cve">PHP remote file include vulnerability in (1) content.php and (2) index.php for Vortex Portal allows remote attackers to execute arbitrary PHP code via a URL in the act parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2005-03/0405.html">20050323 Vortex Portal</ref><ref source="BID" url="http://www.securityfocus.com/bid/12878">12878</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/14707">14707</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19809">vortexportal-act-file-include(19809)</ref><ref source="OSVDB" url="http://www.osvdb.org/14958">14958</ref><ref source="OSVDB" url="http://www.osvdb.org/14959">14959</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013545">1013545</ref></refs><vuln_soft><prod name="Vortex Portal" vendor="Vortex Portal"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0880" published="2005-05-02" seq="2005-0880" severity="Medium" type="CVE"><desc><descript source="cve">content.php in Vortex Portal allows remote attackers to obtain sensitive information via an invalid act parameter, which leaks the full pathname in a PHP error message.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2005-03/0405.html">20050323 Vortex Portal</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19811">vortex-portal-path-disclosure(19811)</ref></refs><vuln_soft><prod name="Vortex Portal" vendor="Vortex Portal"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0881" published="2005-03-23" seq="2005-0881" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in articles.newcomment for Interspire ArticleLive 2005 allows remote attackers to inject arbitrary web script or HTML via the Articleld parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/394069">20050323 Interspire ArticleLive 2005 (php version) is vulnerable to XSS</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/12879">12879</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14708">14708</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19817">articlelive-articleid-xss(19817)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112483966331737&amp;w=2">20050823 Re: Interspire ArticleLive 2005 (php version) is vulnerable to XSS</ref></refs><vuln_soft><prod name="ArticleLive" vendor="Interspire"><vers num="2005"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0882" published="2005-05-02" seq="2005-0882" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in admincore.php in BirdBlog before 1.2.0 allows remote attackers to execute arbitrary SQL commands via the (1) userid or (2) userpw parameters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="CONFIRM" url="http://birdblog.sourceforge.net/ChangeLog">http://birdblog.sourceforge.net/ChangeLog</ref><ref source="CONFIRM" url="http://cvs.sourceforge.net/viewcvs.py/birdblog/birdblog/admin/admincore.php?r1=1.4&amp;r2=1.5">http://cvs.sourceforge.net/viewcvs.py/birdblog/birdblog/admin/admincore.php?r1=1.4&amp;r2=1.5</ref><ref patch="1" source="MISC" url="http://securitytracker.com/id?1013548">http://securitytracker.com/id?1013548</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/12880">12880</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14676">14676</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19799">birdblog-admincore-sql-injection(19799)</ref></refs><vuln_soft><prod name="BirdBlog" vendor="BirdBlog"><vers num="1.1.0"/><vers num="1.0.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0883" published="2005-03-23" seq="2005-0883" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in base.php for DigitalHive 2.0 allow remote attackers to inject arbitrary web script or HTML via (1) the mt parameter to the membres.php page or (2) the -afs-1- query string to the msg.php page.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://securitytracker.com/id?1013516">http://securitytracker.com/id?1013516</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/12883">12883</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/14702">14702</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19803">digitalhive-basephp-xss(19803)</ref></refs><vuln_soft><prod name="DigitalHive" vendor="DigitalHive"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0884" published="2005-05-02" seq="2005-0884" severity="High" type="CVE"><desc><descript source="cve">DigitalHive 2.0 allows remote attackers to re-install the product by directly accessing the install script.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/><input/></vuln_types><range><network/></range><refs><ref source="MISC" url="http://securitytracker.com/id?1013516">http://securitytracker.com/id?1013516</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19802">digitalhive-reinstall(19802)</ref></refs><vuln_soft><prod name="DigitalHive" vendor="DigitalHive"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0885" published="2005-05-02" seq="2005-0885" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in XMB Forum 1.9.1 allow remote attackers to inject arbitrary web script or HTML via the (1) Mood or (2) &quot;Send To&quot; fields.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MISC" url="http://securitytracker.com/id?1013515">http://securitytracker.com/id?1013515</ref><ref source="BID" url="http://www.securityfocus.com/bid/12886">12886</ref></refs><vuln_soft><prod name="XMB" vendor="XMB Forum"><vers num="1.9.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0886" published="2005-05-02" seq="2005-0886" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Invision Power Board 2.0.2 and earlier allows remote attackers to inject arbitrary web script or HTML via an HTTP POST request.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/12888">12888</ref></refs><vuln_soft><prod name="Invision Board" vendor="Invision Power Services"><vers num="2.0.2"/><vers num="2.0.1"/><vers num="2.0 PF2"/><vers num="2.0 PF1"/><vers num="2.0 PDR3"/><vers num="2.0 Alpha 3"/><vers num="2.0"/><vers num="1.3.1 Final"/><vers num="1.3 Final"/><vers num="1.3"/><vers num="1.2"/><vers num="1.1.2"/><vers num="1.1.1"/><vers num="1.0.1"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-06-15" name="CVE-2005-0887" published="2005-03-24" seq="2005-0887" severity="High" type="CVE"><desc><descript source="cve">Eval injection vulnerability in Double Choco Latte before 0.9.4.3 allows remote attackers to execute arbitrary PHP code via the menuAction variable in (1) functions.inc.php or (2) main.php, which causes code to be injected into an eval statement.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CONFIRM" url="http://sourceforge.net/project/shownotes.php?release_id=315144">http://sourceforge.net/project/shownotes.php?release_id=315144</ref><ref adv="1" patch="1" source="MISC" url="http://securitytracker.com/id?1013559">http://securitytracker.com/id?1013559</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14688">14688</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19806">dcl-file-include(19806)</ref></refs><vuln_soft><prod name="Double Choco Latte" vendor="Michael Dean"><vers num="0.9.4.3"/><vers num="0.9.4.2"/><vers num="0.9.4"/><vers num="0.9.3"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0888" published="2005-05-02" seq="2005-0888" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in functions.inc.php for Double Choco Latte 0.9.4.3 allow remote attackers to inject arbitrary web script or HTML via the (1) class or (2) method name.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="CONFIRM" url="http://sourceforge.net/project/shownotes.php?release_id=315160">http://sourceforge.net/project/shownotes.php?release_id=315160</ref><ref patch="1" source="MISC" url="http://securitytracker.com/id?1013559">http://securitytracker.com/id?1013559</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14688">14688</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19805">dcl-xss(19805)</ref></refs><vuln_soft><prod name="Double Choco Latte" vendor="Michael Dean"><vers num="0.9.4.3"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-20" name="CVE-2005-0889" published="2005-03-24" seq="2005-0889" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in index.php for Dream4 Koobi CMS 4.2.3 allows remote attackers to inject arbitrary web script or HTML via the area parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://securitytracker.com/id?1013558">http://securitytracker.com/id?1013558</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/12895">12895</ref></refs><vuln_soft><prod name="Koobi CMS" vendor="Dream4"><vers num="4.2.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0890" published="2005-05-02" seq="2005-0890" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in Dream4 Koobi CMS 4.2.3 allows remote attackers to execute arbitrary SQL commands via the area parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MISC" url="http://securitytracker.com/id?1013558">http://securitytracker.com/id?1013558</ref><ref source="BID" url="http://www.securityfocus.com/bid/12896">12896</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/14696">14696</ref></refs><vuln_soft><prod name="Koobi CMS" vendor="Dream4"><vers num="4.2.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2008-02-26" name="CVE-2005-0891" published="2005-05-02" seq="2005-0891" severity="Medium" type="CVE"><desc><descript source="cve">Double free vulnerability in gtk 2 (gtk2) before 2.2.4 allows remote attackers to cause a denial of service (crash) via a crafted BMP image.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-344.html">RHSA-2005:344</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/419771/100/0/threaded">FLSA-2005:155510</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2005:214">MDKSA-2005:214</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/17657">17657</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-343.html">RHSA-2005:343</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000958">CLSA-2005:958</ref><ref source="BID" url="http://www.securityfocus.com/bid/12950">12950</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:214">MDKSA-2005:214</ref></refs><vuln_soft><prod name="GTK+" vendor="GTK"><vers num="2.0.2"/><vers num="2.0.6"/><vers num="2.2.1"/><vers num="2.2.3"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0892" published="2005-03-28" seq="2005-0892" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in smail 3.2.0.120 allows remote attackers or local users to execute arbitrary code via a long string in the MAIL FROM command and possibly other SMTP commands.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111177045217717&amp;w=2">20050325 smail remote and local root holes</ref><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-722">DSA-722</ref></refs><vuln_soft><prod name="Smail" vendor="Smail"><vers num="3.2.0.120"/></prod></vuln_soft></entry><entry CVSS_base_score="7.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="10.0" CVSS_score="7.6" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0893" published="2005-05-02" seq="2005-0893" severity="High" type="CVE"><desc><descript source="cve">modes.c in smail 3.2.0.120 implements signal handlers with certain unsafe library calls, which may allow attackers to execute arbitrary code via signal handler race conditions, possibly using xmalloc.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><race/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111177045217717&amp;w=2">20050325 smail remote and local root holes</ref></refs><vuln_soft><prod name="smail" vendor="smail"><vers num="3.2.0.120"/></prod></vuln_soft></entry><entry CVSS_base_score="3.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="4.9" CVSS_score="3.6" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0894" published="2005-05-02" seq="2005-0894" severity="Low" type="CVE"><desc><descript source="cve">OpenmosixCollector and OpenMosixView in OpenMosixView 1.5 allow local users to overwrite or delete arbitrary files via a symlink attack on (1) temporary files in the openmosixcollector directory or (2) nodes.tmp.</descript></desc><loss_types><avail/><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111176899423078&amp;w=2">20050325 RX250305 - OpenMosixView : Multiple Race conditions - advisory and exploit</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/12902">12902</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/14693">14693</ref></refs><vuln_soft><prod name="OpenMosixView" vendor="OpenMosixView"><vers num="1.5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0895" published="2005-05-02" seq="2005-0895" severity="Medium" type="CVE"><desc><descript source="cve">Netcomm 1300NB DSL Modem allows remote attackers to cause a denial of service (device hang) via a large number of ping packets.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111177093020587&amp;w=2">20050325 Netcomm 1300NB DSL Modem Denial of Service</ref><ref source="BID" url="http://www.securityfocus.com/bid/12901">12901</ref></refs><vuln_soft><prod name="NB1300" vendor="NetComm"><vers num="4.4.1"/><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0896" published="2005-05-02" seq="2005-0896" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in review.php in phpMyDirectory 10.1.3-rel allow remote attackers to inject arbitrary web script or HTML via the (1) subcat, (2) page, or (3) subsubcat parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111176904423360&amp;w=2">20050325 phpMyDirectory 10.1.3-rel Cross site scripting</ref><ref source="BID" url="http://www.securityfocus.com/bid/12900">12900</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/14692">14692</ref></refs><vuln_soft><prod name="phpMyDirectory" vendor="phpMyDirectory"><vers num="10.1.3 rel"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-28" name="CVE-2005-0897" published="2005-05-02" seq="2005-0897" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in catalog.php in E-Store Kit-2 PayPal Edition allows remote attackers to execute arbitrary PHP code by modifying the menu and main parameters to reference a URL on a remote web server that contains the code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111186424600509&amp;w=2">20050325 File inclusion and XSS vulnerability in E-Store Kit-2 PayPal Edition</ref><ref source="BID" url="http://www.securityfocus.com/bid/12910">12910</ref></refs><vuln_soft><prod name="E-Store Kit-2" vendor="MagicScripts"><vers num="PayPal"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0898" published="2005-03-26" seq="2005-0898" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in downloadform.php in E-Store Kit-2 PayPal Edition allows remote attackers to inject arbitrary web script or HTML via the txn_id parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111186424600509&amp;w=2">20050325 File inclusion and XSS vulnerability in E-Store Kit-2 PayPal Edition</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/12909">12909</ref></refs><vuln_soft><prod name="E-Store Kit-2" vendor="MagicScripts"><vers num="PayPal"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0899" published="2005-05-02" seq="2005-0899" severity="Low" type="CVE"><desc><descript source="cve">AS/400 running OS400 5.2 installs and enables LDAP by default, which allows remote authenticated users to obtain OS/400 user profiles by performing a search.</descript></desc><loss_types><conf/></loss_types><vuln_types><config/></vuln_types><range><local/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111186209318029&amp;w=2">20050325 AS/400 LDAP user accounts disclosure</ref></refs><vuln_soft><prod name="OS_400" vendor="IBM"><vers num="5.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0900" published="2005-03-26" seq="2005-0900" severity="Medium" type="CVE"><desc><descript source="cve">marks.php in NukeBookmarks 0.6 for PHP-Nuke allows remote attackers to obtain sensitive information via an invalid (1) file or (2) category parameter, which reveal the path in an error message.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111186145609320&amp;w=2">20050325 ZH2005-03SA -- multiple vulnerabilities in NukeBookmarks .6</ref><ref adv="1" source="MISC" url="http://zone-h.org/advisories/read/id=7356">http://zone-h.org/advisories/read/id=7356</ref><ref source="CONFIRM" url="http://nukebookmarks.sourceforge.net/">http://nukebookmarks.sourceforge.net/</ref></refs><vuln_soft><prod name="NukeBookmarks" vendor="NukeBookmarks"><vers num="0.6"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0901" published="2005-05-02" seq="2005-0901" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in NukeBookmarks 0.6 for PHP-Nuke allow remote attackers to inject arbitrary web script or HTML via the (1) catname, (2) markname, (3) comment, or (4) category parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111186145609320&amp;w=2">20050325 ZH2005-03SA -- multiple vulnerabilities in NukeBookmarks .6</ref><ref source="MISC" url="http://zone-h.org/advisories/read/id=7356">http://zone-h.org/advisories/read/id=7356</ref><ref source="CONFIRM" url="http://nukebookmarks.sourceforge.net/">http://nukebookmarks.sourceforge.net/</ref></refs><vuln_soft><prod name="NukeBookmarks" vendor="NukeBookmarks"><vers num="0.6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0902" published="2005-05-02" seq="2005-0902" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in marks.php in NukeBookmarks 0.6 for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the category parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111186145609320&amp;w=2">20050325 ZH2005-03SA -- multiple vulnerabilities in NukeBookmarks .6</ref><ref adv="1" source="MISC" url="http://zone-h.org/advisories/read/id=7356">http://zone-h.org/advisories/read/id=7356</ref><ref source="CONFIRM" url="http://nukebookmarks.sourceforge.net/">http://nukebookmarks.sourceforge.net/</ref></refs><vuln_soft><prod name="NukeBookmarks" vendor="NukeBookmarks"><vers num="0.6"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0903" published="2005-05-02" seq="2005-0903" severity="Low" type="CVE"><desc><descript source="cve">Buffer overflow in QuickTime PictureViewer 6.5.1 allows remote attackers to cause a denial of service (application crash) via a JPEG file with crafted Huffman Table (marker DHT) data.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111186277521713&amp;w=2">20050326 QuickTime malformed JPEG buffer overflow</ref><ref source="BID" url="http://www.securityfocus.com/bid/12905">12905</ref></refs><vuln_soft><prod name="QuickTime PictureViewer" vendor="Apple"><vers num="6.5.1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0904" published="2005-05-02" seq="2005-0904" severity="Low" type="CVE"><desc><descript source="cve">Remote Desktop in Windows XP SP1 does not verify the &quot;Force shutdown from a remote system&quot; setting, which allows remote attackers to shut down the system by executing TSShutdn.exe.</descript></desc><loss_types><avail/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref source="MISC" url="http://securitytracker.com/id?1013552">http://securitytracker.com/id?1013552</ref><ref source="MSKB" url="http://support.microsoft.com/kb/889323">889323</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19819">windows-desktop-tsshutdnexe-dos(19819)</ref></refs><vuln_soft><prod name="Windows XP" vendor="Microsoft"><vers edition="Tablet PC" num="SP1"/></prod><prod name="Remote Desktop" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0905" published="2005-05-02" seq="2005-0905" severity="Low" type="CVE"><desc><descript source="cve">Maxthon 1.2.0 allows remote malicious web sites to obtain potentially sensitive data from the search bar via the m2_search_text property.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/><design/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="MISC" url="http://www.raffon.net/advisories/maxthon/searchbarid.html">http://www.raffon.net/advisories/maxthon/searchbarid.html</ref><ref patch="1" source="MISC" url="http://forum.maxthon.com/forum/index.php?showtopic=18207">http://forum.maxthon.com/forum/index.php?showtopic=18207</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/12898">12898</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14712">14712</ref><ref adv="1" source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=111175236620942&amp;w=2">20050325 Maxthon browser search bar information disclosure</ref></refs><vuln_soft><prod name="Maxthon" vendor="Maxthon"><vers num="1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0906" published="2005-05-02" seq="2005-0906" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in a player logging function in the Tincat network library 2.x before 2.0.28, as used in games such as Sacred and The Settlers: Heritage of Kings, allows remote attackers to execute arbitrary code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/394404">20050328 Buffer-overflow in Tincat 2 minor than 2.0.28 (Sacred, Settlers 5 and others)</ref><ref source="Luigi Auriemma" url="http://aluigi.altervista.org/adv/tincat2bof-adv.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/12912">12912</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14762">14762</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14767">14767</ref></refs><vuln_soft><prod name="Sacred" vendor="Sacred"><vers num="1.8.2.6"/></prod><prod name="Tincat" vendor="Instance Four"><vers num="Release 2"/></prod><prod name="The Settlers: Heritage of Kings" vendor="UBI Soft"><vers num="1.0 2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0907" published="2005-05-02" seq="2005-0907" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in Valdersoft Shopping Cart 3.0 allow remote attackers to execute arbitrary SQL commands via (1) the id parameter to category.php, (2) the id parameter to item.php, (3) the lang parameter to index.php, (4) the searchQuery parameter to search_result.php, (5) or the searchTopCategoryID parameter to search_result.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="MISC" url="http://securitytracker.com/id?1013565">http://securitytracker.com/id?1013565</ref><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/394406/2005-03-26/2005-04-01/2">20050327 Multiple sql injection, and xss vulnerabilities in Vladersoft Shopping Cart v.3.0</ref></refs><vuln_soft><prod name="Shopping Cart" vendor="Valdersoft"><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0908" published="2005-03-28" seq="2005-0908" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Valdersoft Shopping Cart 3.0 allow remote attackers to inject arbitrary web script or HTML via (1) the lang parameter to index.php or (2) the searchTopCategoryID parameter to search_result.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="MISC" url="http://securitytracker.com/id?1013565">http://securitytracker.com/id?1013565</ref><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/394406/2005-03-26/2005-04-01/2">20050327 Multiple sql injection, and xss vulnerabilities in Vladersoft Shopping Cart v.3.0</ref></refs><vuln_soft><prod name="Valdersoft Shopping Cart" vendor="Valdersoft"><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-28" name="CVE-2005-0909" published="2005-05-02" seq="2005-0909" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in shoutact.php for TKai&apos;s Shoutbox allows remote attackers to execute arbitrary PHP code via the query parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=111202260908735&amp;w=2">20050328 THai&apos;s Shoutbox correction name</ref><ref source="BID" url="http://www.securityfocus.com/bid/12914">12914</ref></refs><vuln_soft><prod name="Tkais Shoutbox" vendor="Tkais Shoutbox"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0910" published="2005-05-02" seq="2005-0910" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in exoops allow remote attackers to inject arbitrary web script or HTML via (1) the sortdays parameter to viewforum.php or (2) the viewcat parameter to index.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MISC" url="http://securitytracker.com/id?1013566">http://securitytracker.com/id?1013566</ref></refs><vuln_soft><prod name="e-Xoops" vendor="e-Xoops"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0911" published="2005-03-28" seq="2005-0911" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in exoops may allow remote attackers to execute arbitrary SQL commands via (1) the viewcat parameter to index.php or (2) the artid parameter in the viewarticle action for index.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://securitytracker.com/id?1013566">http://securitytracker.com/id?1013566</ref></refs><vuln_soft><prod name="e-Xoops" vendor="e-Xoops"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0912" published="2005-03-24" seq="2005-0912" severity="High" type="CVE"><desc><descript source="cve">Unknown vulnerabilities in deplate before 0.7.2 have unknown impact, possibly involving elements.rb.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="MISC" url="http://securitytracker.com/id?1013555">http://securitytracker.com/id?1013555</ref><ref adv="1" patch="1" source="CONFIRM" url="http://sourceforge.net/project/shownotes.php?release_id=315034">http://sourceforge.net/project/shownotes.php?release_id=315034</ref></refs><vuln_soft><prod name="deplate" vendor="deplate"><vers num="0.7.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0913" published="2005-05-02" seq="2005-0913" severity="High" type="CVE"><desc><descript source="cve">Unknown vulnerability in the regex_replace modifier (modifier.regex_replace.php) in Smarty before 2.6.8 allows attackers to execute arbitrary PHP code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><range><network/></range><refs><ref patch="1" source="CONFIRM" url="http://news.php.net/php.smarty.dev/2673">http://news.php.net/php.smarty.dev/2673</ref><ref patch="1" source="MISC" url="http://securitytracker.com/id?1013556">http://securitytracker.com/id?1013556</ref><ref adv="1" patch="1" source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200503-35.xml">GLSA-200503-35</ref><ref source="BID" url="http://www.securityfocus.com/bid/12941">12941</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14729/">14729</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19880">smarty-regexreplace-security-bpass(19880)</ref></refs><vuln_soft><prod name="Smarty" vendor="Smarty"><vers num="2.6.7"/><vers num="2.6.6"/><vers num="2.6.5"/><vers num="2.6.4"/><vers num="2.6.3"/><vers num="2.6.2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0914" published="2005-03-26" seq="2005-0914" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in CPG Dragonfly 9.0.2.0 allow remote attackers to inject arbitrary web script or HTML via (1) the profile parameter to index.php or (2) the cat parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://security.talte.net/content/view/252/46/">http://security.talte.net/content/view/252/46/</ref><ref adv="1" source="MISC" url="http://securitytracker.com/id?1013573">http://securitytracker.com/id?1013573</ref></refs><vuln_soft><prod name="CPG Dragonfly CMS" vendor="CPG-Nuke"><vers num="9.0.2 .0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0915" published="2005-05-02" seq="2005-0915" severity="High" type="CVE"><desc><descript source="cve">Webmasters-Debutants WD Guestbook 2.8 allows remote attackers to bypass authentication and perform certain administrator actions via a direct HTTP POST request to (1) ajout_admin2.php or (2) suppr.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="MISC" url="http://securitytracker.com/id?1013570">http://securitytracker.com/id?1013570</ref></refs><vuln_soft><prod name="WD Guestbook" vendor="Webmasters-Debutants"><vers num="2.8"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0916" published="2005-05-02" seq="2005-0916" severity="Low" type="CVE"><desc><descript source="cve">AIO in the Linux kernel 2.6.11 on the PPC64 or IA64 architectures with CONFIG_HUGETLB_PAGE enabled allows local users to cause a denial of service (system panic) via a process that executes the io_queue_init function but exits without running io_queue_release, which causes exit_aio and is_hugepage_only_range to fail.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/><env/></vuln_types><range><local/></range><refs><ref source="MISC" url="http://groups-beta.google.com/group/linux.kernel/browse_thread/thread/13b43bd5783842f6/7ce3c5a514a497ab?q=io_queue_init&amp;rnum=3#7ce3c5a514a497ab">http://groups-beta.google.com/group/linux.kernel/browse_thread/thread/13b43bd5783842f6/7ce3c5a514a497ab?q=io_queue_init&amp;rnum=3#7ce3c5a514a497ab</ref><ref source="CONFIRM" url="http://linux.bkbits.net:8080/linux-2.6/cset%404248c8c0es30_4YVdwa6vteKi7h_nw">http://linux.bkbits.net:8080/linux-2.6/cset%404248c8c0es30_4YVdwa6vteKi7h_nw</ref><ref source="SUSE-SA" url="http://www.novell.com/linux/security/advisories/2005_50_kernel.html">2005:050</ref><ref source="BID" url="http://www.securityfocus.com/bid/12987">12987</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.6.11"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-28" name="CVE-2005-0917" published="2005-05-02" seq="2005-0917" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in index_header.php for EncapsBB 0.3.2_fixed, and possibly other versions, allows remote attackers to execute arbitrary PHP code via the root parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MISC" url="http://securitytracker.com/id?1013569">http://securitytracker.com/id?1013569</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14761">14761</ref><ref source="OSVDB" url="http://www.osvdb.org/15078">15078</ref></refs><vuln_soft><prod name="EncapsBB" vendor="PowerDev"><vers num="0.3.2_fixed"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0918" published="2005-05-05" seq="2005-0918" severity="Medium" type="CVE"><desc><descript source="cve">The NPSVG3.dll ActiveX control for Adobe SVG Viewer 3.02 and earlier, when running on Internet Explorer, allows remote attackers to determine the existence of arbitrary files by setting the src property to the target filename and using Javascript to determine if the web page immediately stops loading, which indicates whether the file exists or not.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/><input/></vuln_types><range><network/></range><refs><ref patch="1" source="MISC" url="http://www.hyperdose.com/advisories/H2005-07.txt">http://www.hyperdose.com/advisories/H2005-07.txt</ref><ref patch="1" source="CONFIRM" url="http://www.adobe.com/support/techdocs/323585.html">http://www.adobe.com/support/techdocs/323585.html</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/15255">15255</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013890">1013890</ref></refs><vuln_soft><prod name="SVG Viewer" vendor="Adobe"><vers num="3.02"/><vers num="3.01"/><vers num="3.0"/><vers num="2.0"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0919" published="2005-03-29" seq="2005-0919" severity="Medium" type="CVE"><desc><descript source="cve">Adventia Chat 3.1 and Server Pro 3.0 allows remote attackers to inject arbitrary web script or HTML into the chat space, which leaves other users vulnerable to cross-site scripting (XSS) attacks.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=111211930330410&amp;w=2">20050329 Adventia Chat</ref><ref adv="1" source="MISC" url="http://exploitlabs.com/files/advisories/EXPL-A-2005-003-adventiachat.txt">http://exploitlabs.com/files/advisories/EXPL-A-2005-003-adventiachat.txt</ref><ref adv="1" source="MISC" url="http://securitytracker.com/id?1013588">http://securitytracker.com/id?1013588</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/12927">12927</ref><ref source="BID" url="http://www.securityfocus.com/bid/12940">12940</ref><ref source="OSVDB" url="http://www.osvdb.org/15156">15156</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/21317">adventia-chat-field-xss(21317)</ref></refs><vuln_soft><prod name="Adventia Server Pro" vendor="Adventia"><vers num="3.0"/></prod><prod name="Adventia Chat" vendor="Adventia"><vers num="3.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0920" published="2005-05-02" seq="2005-0920" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in Bugtracker.NET 2.0.1 allow remote attackers to execute arbitrary SQL commands via unknown vectors.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="CONFIRM" url="http://sourceforge.net/project/shownotes.php?release_id=315830">http://sourceforge.net/project/shownotes.php?release_id=315830</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/12925">12925</ref></refs><vuln_soft><prod name="Bugtracker.NET" vendor="Bugtracker.NET"><vers num="2.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0921" published="2005-05-02" seq="2005-0921" severity="Medium" type="CVE"><desc><descript source="cve">Microsoft Outlook 2002 Connector for IBM Lotus Domino 2.0 allows local users to save passwords and login credentials locally, even when password caching is disabled by a group policy.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="MSKB" url="http://support.microsoft.com/kb/896093">896093</ref><ref source="BID" url="http://www.securityfocus.com/bid/12913">12913</ref></refs><vuln_soft><prod name="Outlook" vendor="Microsoft"><vers edition="IBM Lotus Domino" num="2002 Connector"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-28" name="CVE-2005-0922" published="2005-05-02" seq="2005-0922" severity="Medium" type="CVE"><desc><descript source="cve">Unknown vulnerability in the Auto-Protect module in Symantec Norton AntiVirus 2004 and 2005, as also used in Internet Security 2004/2005 and System Works 2004/2005, allows attackers to cause a denial of service (system hang or crash) by triggering a scan of a certain file type.</descript></desc><loss_types><avail/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref adv="1" source="CONFIRM" url="http://securityresponse.symantec.com/avcenter/security/Content/2005.03.28.html">http://securityresponse.symantec.com/avcenter/security/Content/2005.03.28.html</ref><ref source="MISC" url="http://securitytracker.com/id?1013585">http://securitytracker.com/id?1013585</ref><ref source="MISC" url="http://securitytracker.com/id?1013586">http://securitytracker.com/id?1013586</ref><ref source="MISC" url="http://securitytracker.com/id?1013587">http://securitytracker.com/id?1013587</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/14741">14741</ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/146020">VU#146020</ref><ref source="BID" url="http://www.securityfocus.com/bid/12923">12923</ref></refs><vuln_soft><prod name="Norton Internet Security" vendor="Symantec"><vers num="2005"/><vers edition="Professional" num="2004"/></prod><prod name="Norton System Works" vendor="Symantec"><vers num="2004 Professional"/><vers num="2005 Premier"/></prod><prod name="Norton AntiVirus" vendor="Symantec"><vers num="2005"/><vers edition="MS Exchange" num="2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-28" name="CVE-2005-0923" published="2005-05-02" seq="2005-0923" severity="Low" type="CVE"><desc><descript source="cve">The SmartScan feature in the Auto-Protect module for Symantec Norton AntiVirus 2004 and 2005, as also used in Internet Security 2004/2005 and System Works 2004/2005, allows attackers to cause a denial of service (CPU consumption and system crash) by renaming a file on a network share.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><local/></range><refs><ref adv="1" source="CONFIRM" url="http://securityresponse.symantec.com/avcenter/security/Content/2005.03.28.html">http://securityresponse.symantec.com/avcenter/security/Content/2005.03.28.html</ref><ref source="MISC" url="http://securitytracker.com/id?1013585">http://securitytracker.com/id?1013585</ref><ref source="MISC" url="http://securitytracker.com/id?1013586">http://securitytracker.com/id?1013586</ref><ref source="MISC" url="http://securitytracker.com/id?1013587">http://securitytracker.com/id?1013587</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14741">14741</ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/713620">VU#713620</ref><ref source="BID" url="http://www.securityfocus.com/bid/12924">12924</ref></refs><vuln_soft><prod name="Norton Internet Security" vendor="Symantec"><vers num="2005"/><vers edition="Professional" num="2004"/></prod><prod name="Norton System Works" vendor="Symantec"><vers num="2004 Professional"/><vers num="2005 Premier"/></prod><prod name="Norton AntiVirus" vendor="Symantec"><vers edition="MS Exchange" num="2.1"/><vers num="2005"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0924" published="2005-03-29" seq="2005-0924" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Adventia E-Data 2.0 allows remote attackers to inject arbitrary web script or HTML via a query keyword.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=111211945505635&amp;w=2">20050329 E-Data</ref><ref adv="1" source="MISC" url="http://exploitlabs.com/files/advisories/EXPL-A-2005-004-edata.txt">http://exploitlabs.com/files/advisories/EXPL-A-2005-004-edata.txt</ref><ref adv="1" source="MISC" url="http://securitytracker.com/id?1013589">http://securitytracker.com/id?1013589</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/14739">14739</ref><ref source="BID" url="http://www.securityfocus.com/bid/12927">12927</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19889">edata-new-user-xss(19889)</ref></refs><vuln_soft><prod name="E-Data" vendor="Adventia"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-08-22" name="CVE-2005-0925" published="2005-05-02" seq="2005-0925" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in login.asp for Ublog Reload 1.0 through 1.0.4 allows remote attackers to inject arbitrary web script or HTML via the msg parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/12931">12931</ref><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111214393101387&amp;w=2">20050329 [PersianHacker.NET 200503-11]Ublog reload 1.0.4 and prior</ref><ref source="MISC" url="http://www.persianhacker.net/news/news-2945.html">http://www.persianhacker.net/news/news-2945.html</ref><ref adv="1" patch="1" source="SECTRACK" url="http://securitytracker.com/id?1013603">1013603</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/14725">14725</ref><ref source="OSVDB" url="http://www.osvdb.org/15121">15121</ref></refs><vuln_soft><prod name="Ublog Reload" vendor="Uapplication"><vers num="1.0.4"/><vers num="1.0.3"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0926" published="2005-05-02" seq="2005-0926" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in Sylpheed before 1.0.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via attachments with MIME-encoded file names.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref source="CONFIRM" url="http://sylpheed.good-day.net/changelog.html.en">http://sylpheed.good-day.net/changelog.html.en</ref><ref source="XForce" url="http://xforce.iss.net/xforce/xfdb/19901">Sylpheed MIME attachment buffer overflow</ref></refs><vuln_soft><prod name="Sylpheed" vendor="Sylpheed"><vers num="1.0.3"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0.0"/><vers num="0.9.9"/><vers num="0.9.8"/><vers num="0.9.7"/><vers num="0.9.6"/><vers num="0.9.5"/><vers num="0.9.4"/><vers num="0.9.12"/><vers num="0.9.11"/><vers num="0.9.10"/><vers num="0.8.11"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0927" published="2005-05-02" seq="2005-0927" severity="High" type="CVE"><desc><descript source="cve">Unknown vulnerability in subs.pl for WebAPP 0.9.9 through 0.9.9.2 has unknown impact and attack vectors, probably involving shell metacharacters or .. sequences.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref patch="1" source="CONFIRM" url="http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&amp;id=195">http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&amp;id=195</ref><ref patch="1" source="CONFIRM" url="http://sourceforge.net/project/shownotes.php?release_id=316038">http://sourceforge.net/project/shownotes.php?release_id=316038</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/14716">14716</ref></refs><vuln_soft><prod name="WebAPP" vendor="Web-APP.org"><vers num="0.9.9"/><vers num="0.9.9.1"/><vers num="0.9.9.2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-27" name="CVE-2005-0928" published="2005-05-02" seq="2005-0928" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in PhotoPost PHP Pro 5.x allow remote attackers to inject arbitrary web script or HTML via the (1) cat, (2) password, (3) ppuser, (4) sort, or (5) si parameters to showgallery.php, the (6) ppuser, (7) sort, or (8) si parameters to showmembers.php, or (9) the photo parameter to slideshow.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MISC" url="http://securitytracker.com/id?1013581">http://securitytracker.com/id?1013581</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/14742">14742</ref><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111205342909640&amp;w=2">20050328 Multiple Sql injection, and multiple XSS vulnerabilities in Photopost PHP Pro Photo Gallery Software.</ref><ref source="OSVDB" url="http://www.osvdb.org/15096">15096</ref><ref source="OSVDB" url="http://www.osvdb.org/15097">15097</ref><ref source="OSVDB" url="http://www.osvdb.org/15098">15098</ref></refs><vuln_soft><prod name="PhotoPost PHP Pro" vendor="PhotoPost"><vers num="5.02"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-27" name="CVE-2005-0929" published="2005-05-02" seq="2005-0929" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in PhotoPost PHP Pro 5.x may allow remote attackers to execute arbitrary SQL commands via (1) the sl parameter to showmembers.php or (2) the photo parameter to showphoto.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MISC" url="http://securitytracker.com/id?1013581">http://securitytracker.com/id?1013581</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14742">14742</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111205342909640&amp;w=2">20050328 Multiple Sql injection, and multiple XSS vulnerabilities in Photopost PHP Pro Photo Gallery Software.</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111213719017716&amp;w=2">20050328 Re: Multiple Sql injection, and multiple XSS vulnerabilities in Photopost PHP Pro Photo Gallery Software.</ref><ref source="OSVDB" url="http://www.osvdb.org/15099">15099</ref><ref source="OSVDB" url="http://www.osvdb.org/15100">15100</ref></refs><vuln_soft><prod name="PhotoPost PHP Pro" vendor="PhotoPost"><vers num="5.0 RC3"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0930" published="2005-05-02" seq="2005-0930" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in message.php in Chatness 2.5.1 and earlier allows remote attackers to inject arbitrary web script or HTML via (1) the user field or (2) the message parameter to message.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/394526">20050329 [PersianHacker.NET 200503-12]Chatness 2.5.1 and prior XSS Vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/12929">12929</ref><ref source="MISC" url="http://www.persianhacker.net/news/news-2946.html">http://www.persianhacker.net/news/news-2946.html</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013604">1013604</ref></refs><vuln_soft><prod name="Chatness" vendor="Chatness"><vers num="2.5.1"/><vers num="2.5" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-28" name="CVE-2005-0931" published="2005-03-29" seq="2005-0931" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in The Includer 1.0 and 1.1 allows remote attackers to execute arbitrary PHP code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/12926">12926</ref></refs><vuln_soft><prod name="The Includer" vendor="Jimmy"><vers num="1.1"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-03-29" name="CVE-2005-0932" published="2005-05-02" seq="2005-0932" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in phpCOIN 1.2.1b and earlier allow remote attackers to execute arbitrary SQL commands (1) via the search engine, (2) the username or email fields in the &quot;forgotten password&quot; feature, or (3) the domain name in a package order.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://www.gulftech.org/?node=research&amp;article_id=00065-03292005">http://www.gulftech.org/?node=research&amp;article_id=00065-03292005</ref><ref source="BID" url="http://www.securityfocus.com/bid/12917">12917</ref><ref source="MISC" url="http://www.gulftech.org/?node=research&amp;article_id=00065-03292005">http://www.gulftech.org/?node=research&amp;article_id=00065-03292005</ref></refs><vuln_soft><prod name="phpCOIN" vendor="COINSoft Technologies"><vers num="1.2.1b"/><vers num="1.2.1"/><vers num="1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-03-29" name="CVE-2005-0933" published="2005-05-02" seq="2005-0933" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in auxpage.php for phpCOIN 1.2.1b and earlier allows remote attackers to read arbitrary files via the page parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MISC" url="http://www.gulftech.org/?node=research&amp;article_id=00065-03292005">http://www.gulftech.org/?node=research&amp;article_id=00065-03292005</ref><ref source="BID" url="http://www.securityfocus.com/bid/12917">12917</ref><ref source="MISC" url="http://www.gulftech.org/?node=research&amp;article_id=00065-03292005">http://www.gulftech.org/?node=research&amp;article_id=00065-03292005</ref></refs><vuln_soft><prod name="phpCOIN" vendor="COINSoft Technologies"><vers num="1.2.1b"/><vers num="1.2.1"/><vers num="1.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0934" published="2005-05-02" seq="2005-0934" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in WackoWiki R4 allow remote attackers to inject arbitrary web script or HTML via unknown vectors.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="CONFIRM" url="http://wackowiki.com/WackoDownload/InEnglish#h4828-4">http://wackowiki.com/WackoDownload/InEnglish#h4828-4</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14720">14720</ref></refs><vuln_soft><prod name="WackoWiki" vendor="WackoWiki"><vers num="R4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0935" published="2005-05-02" seq="2005-0935" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in ESMI PayPal Storefront allow remote attackers to execute arbitrary SQL commands via the (1) idpages parameter to pages.php or the (2) id2 parameter to products1.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MISC" url="http://www.hackerscenter.com/Archive/view.asp?id=1774">http://www.hackerscenter.com/Archive/view.asp?id=1774</ref><ref source="MISC" url="http://securitytracker.com/id?1013563">http://securitytracker.com/id?1013563</ref><ref source="BID" url="http://www.securityfocus.com/bid/12903">12903</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/14711">14711</ref><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111221890614271&amp;w=2">20050330 Multiple sql injection, and xss vulnerabilities in Pay pal Storefront</ref><ref source="OSVDB" url="http://www.osvdb.org/15057">15057</ref><ref source="OSVDB" url="http://www.osvdb.org/15058">15058</ref></refs><vuln_soft><prod name="PayPal Storefront" vendor="ESMI"><vers num="1.7"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-22" name="CVE-2005-0936" published="2005-05-02" seq="2005-0936" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting vulnerability in products1h.php in ESMI PayPal Storefront allows remote attackers to inject arbitrary web script or HTML via the id parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MISC" url="http://www.hackerscenter.com/Archive/view.asp?id=1774">http://www.hackerscenter.com/Archive/view.asp?id=1774</ref><ref source="MISC" url="http://securitytracker.com/id?1013563">http://securitytracker.com/id?1013563</ref><ref source="BID" url="http://www.securityfocus.com/bid/12904">12904</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14711">14711</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111221890614271&amp;w=2">20050330 Multiple sql injection, and xss vulnerabilities in Pay pal Storefront</ref><ref source="OSVDB" url="http://www.osvdb.org/15059">15059</ref></refs><vuln_soft><prod name="PayPal Storefront" vendor="ESMI"><vers num="1.7"/></prod></vuln_soft></entry><entry CVSS_base_score="1.2" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="2.9" CVSS_score="1.2" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0937" published="2005-02-22" seq="2005-0937" severity="Low" type="CVE"><desc><descript source="cve">Some futex functions in futex.c for Linux kernel 2.6.x perform get_user calls while holding the mmap_sem semaphore, which could allow local users to cause a deadlock condition in do_page_fault by triggering get_user faults while another thread is executing mmap or other functions.</descript></desc><loss_types><avail/></loss_types><vuln_types><race/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="MISC" url="http://lkml.org/lkml/2005/2/22/123">http://lkml.org/lkml/2005/2/22/123</ref><ref adv="1" source="CONFIRM" url="http://linux.bkbits.net:8080/linux-2.6/cset@421cfc11zFsK9gxvSJ2t__FCmuUd3Q">http://linux.bkbits.net:8080/linux-2.6/cset@421cfc11zFsK9gxvSJ2t__FCmuUd3Q</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/427980/100/0/threaded">FLSA:157459-3</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-420.html">RHSA-2005:420</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.6.11 .6"/><vers num="2.6.11 .5"/><vers num="2.6.11 -rc4"/><vers num="2.6.11 -rc3"/><vers num="2.6.11 -rc2"/><vers num="2.6.11"/><vers num="2.6.10 rc2"/><vers num="2.6.10"/><vers edition="2.6.20" num="2.6.9"/><vers num="2.6.8-rc3"/><vers num="2.6.8-rc2"/><vers num="2.6.8-rc1"/><vers num="2.6.8"/><vers num="2.6.7 rc1"/><vers num="2.6.7"/><vers num="2.6.6-rc1"/><vers num="2.6.6"/><vers num="2.6.5"/><vers num="2.6.4"/><vers num="2.6.3"/><vers num="2.6.2"/><vers num="2.6.1 -rc2"/><vers num="2.6.1 -rc1"/><vers num="2.6.1"/><vers num="2.6 .10"/><vers num="2.6 -test9-CVS"/><vers num="2.6 -test9"/><vers num="2.6 -test8"/><vers num="2.6 -test7"/><vers num="2.6 -test6"/><vers num="2.6 -test5"/><vers num="2.6 -test4"/><vers num="2.6 -test3"/><vers num="2.6 -test2"/><vers num="2.6 -test11"/><vers num="2.6 -test10"/><vers num="2.6 -test1"/><vers num="2.6"/><vers num="2.5.69"/><vers num="2.5.68"/><vers num="2.5.67"/><vers num="2.5.66"/><vers num="2.5.65"/><vers num="2.5.64"/><vers num="2.5.63"/><vers num="2.5.62"/><vers num="2.5.61"/><vers num="2.5.60"/><vers num="2.5.59"/><vers num="2.5.58"/><vers num="2.5.57"/><vers num="2.5.56"/><vers num="2.5.55"/><vers num="2.5.54"/><vers num="2.5.53"/><vers num="2.5.52"/><vers num="2.5.51"/><vers num="2.5.50"/><vers num="2.5.49"/><vers num="2.5.48"/><vers num="2.5.47"/><vers num="2.5.46"/><vers num="2.5.45"/><vers num="2.5.44"/><vers num="2.5.43"/><vers num="2.5.42"/><vers num="2.5.41"/><vers num="2.5.40"/><vers num="2.5.39"/><vers num="2.5.38"/><vers num="2.5.37"/><vers num="2.5.36"/><vers num="2.5.35"/><vers num="2.5.34"/><vers num="2.5.33"/><vers num="2.5.32"/><vers num="2.5.31"/><vers num="2.5.30"/><vers num="2.5.29"/><vers num="2.5.28"/><vers num="2.5.27"/><vers num="2.5.26"/><vers num="2.5.25"/><vers num="2.5.24"/><vers num="2.5.23"/><vers num="2.5.22"/><vers num="2.5.21"/><vers num="2.5.20"/><vers num="2.5.19"/><vers num="2.5.18"/><vers num="2.5.17"/><vers num="2.5.16"/><vers num="2.5.15"/><vers num="2.5.14"/><vers num="2.5.13"/><vers num="2.5.12"/><vers num="2.5.11"/><vers num="2.5.10"/><vers num="2.5.9"/><vers num="2.5.8"/><vers num="2.5.7"/><vers num="2.5.6"/><vers num="2.5.5"/><vers num="2.5.4"/><vers num="2.5.3"/><vers num="2.5.2"/><vers num="2.5.1"/><vers num="2.5 .0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0938" published="2005-05-02" seq="2005-0938" severity="Medium" type="CVE"><desc><descript source="cve">Ublog Reload 1.0 through 1.0.4 stores ublogreload.mdb under the web root, which allows remote attackers to read usernames and hashed passwords via a direct request to ublogreload.mdb.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111214393101387&amp;w=2">20050329 [PersianHacker.NET 200503-11]Ublog reload 1.0.4 and prior</ref><ref source="MISC" url="http://securitytracker.com/id?1013603">http://securitytracker.com/id?1013603</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14725">14725</ref></refs><vuln_soft><prod name="Ublog Reload" vendor="Uapplication"><vers num="1.0"/><vers num="1.0.1"/><vers num="1.0.2"/><vers num="1.0.3"/><vers num="1.0.4"/></prod></vuln_soft></entry><entry modified="2005-10-25" name="CVE-2005-0940" published="2005-05-02" reject="1" seq="2005-0940" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2005-0490.  Reason: This candidate was inadvertently referenced in a vendor advisory due to a typo.  Notes: All CVE users should reference CVE-2005-0490 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript></desc><refs/></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0941" published="2005-05-02" seq="2005-0941" severity="Medium" type="CVE"><desc><descript source="cve">The StgCompObjStream::Load function in OpenOffice.org OpenOffice 1.1.4 and earlier allocates memory based on 16 bit length values, but process memory using 32 bit values, which allows remote attackers to cause a denial of service and possibly execute arbitrary code via a DOC document with certain length values, which leads to a heap-based buffer overflow.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/395516">20050412 OpenOffice DOC document Heap Overflow</ref><ref source="CONFIRM" url="http://www.openoffice.org/issues/show_bug.cgi?id=46388">http://www.openoffice.org/issues/show_bug.cgi?id=46388</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200504-13.xml">GLSA-200504-13</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-375.html">RHSA-2005:375</ref><ref source="BID" url="http://www.securityfocus.com/bid/13092">13092</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_21_sr.html">SUSE-SR:2005:021</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17027">17027</ref></refs><vuln_soft><prod name="OpenOffice" vendor="OpenOffice"><vers num="1.1.4"/><vers num="1.1.3"/><vers num="1.1.2"/><vers num="1.1.1"/><vers num="1.1.0"/><vers num="1.0.2"/><vers num="1.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0942" published="2005-05-02" seq="2005-0942" severity="Medium" type="CVE"><desc><descript source="cve">The XP Server process (xp_server) in Sybase Adaptive Server Enterprise (ASE) XP Server 12.x before 12.5.3 ESD#1 allows attackers to cause a denial of service (process crash) via malformed data sent to the XP Server TCP port.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref patch="1" source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2004-12/0315.html">20041222 Sybase ASE 12.5.2 vulnerabilities</ref><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/393851">20050321 Details of Sybase ASE bugs withheld</ref><ref adv="1" patch="1" source="CONFIRM" url="http://www.sybase.com/detail?id=1034520">http://www.sybase.com/detail?id=1034520</ref><ref adv="1" source="CONFIRM" url="http://www.sybase.com/detail?id=1034752">http://www.sybase.com/detail?id=1034752</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/12080">12080</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/13632">13632</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19354">sybase-adaptive-server(19354)</ref><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111272918117194&amp;w=2">20050405 Sybase ASE Multiple Security Issues (#NISR05042005)</ref><ref adv="1" patch="1" source="MISC" url="http://www.ngssoftware.com/advisories/sybase-ase.txt">http://www.ngssoftware.com/advisories/sybase-ase.txt</ref></refs><vuln_soft><prod name="Adaptive Server Enterprise" vendor="Sybase"><vers num="12.5.3"/><vers num="12.5.2"/><vers edition="Win" num="12.5"/><vers edition="Sun" num="12.5"/><vers edition="SGI" num="12.5"/><vers edition="Linux" num="12.5"/><vers edition="HP" num="12.5"/><vers edition="Digital Unix" num="12.5"/><vers edition="Win" num="12.0.1"/><vers edition="Sun" num="12.0.1"/><vers edition="HP" num="12.0.1"/><vers edition="Digital Unix" num="12.0.1"/><vers edition="Win" num="12.0"/><vers edition="Sun" num="12.0"/><vers edition="HP" num="12.0"/><vers edition="Digital Unix" num="12.0"/><vers edition="Win" num="11.9.2"/><vers edition="Sun" num="11.9.2"/><vers edition="HP" num="11.9.2"/><vers edition="Digital Unix" num="11.9.2"/><vers edition="Win" num="11.5.1"/><vers edition="Sun" num="11.5.1"/><vers edition="HP" num="11.5.1"/><vers edition="Digital Unix" num="11.5.1"/><vers edition="Win" num="11.5"/><vers edition="Sun" num="11.5"/><vers edition="HP" num="11.5"/><vers edition="Digital Unix" num="11.5"/><vers edition="Linux" num="11.03.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0943" published="2005-03-30" seq="2005-0943" severity="Medium" type="CVE"><desc><descript source="cve">Cisco VPN 3000 series Concentrator running firmware 4.1.7.A and earlier allows remote attackers to cause a denial of service (device reload or drop user connection) via a crafted HTTPS packet.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-sa-20050330-vpn3k.shtml">20050330 Cisco VPN 3000 Concentrator Vulnerable to Crafted SSL Attack</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/12948">12948</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14784">14784</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19903">cisco-vpn-3000-dos(19903)</ref></refs><vuln_soft><prod name="VPN 3015 Concentrator" vendor="Cisco"><vers num=""/></prod><prod name="VPN 3060 Concentrator" vendor="Cisco"><vers num=""/></prod><prod name="VPN 3000 Concentrator" vendor="Cisco"><vers num="4.1.5 .B"/><vers num="4.1 .x"/><vers num="4.0.5 .B"/><vers num="4.0.1"/><vers num="4.0 .x"/><vers num="4.0"/><vers num="3.6.7 D"/><vers num="3.6.7"/><vers num="3.6.1"/><vers num="3.6"/><vers num="3.5.5"/><vers num="3.5.4"/><vers num="3.5.3"/><vers num="3.5.2"/><vers num="3.5.1"/><vers num="3.5 (Rel)"/><vers num="3.1.4"/><vers num="3.1.2"/><vers num="3.1.1"/><vers num="3.1 (Rel)"/><vers num="3.1"/><vers num="3.0.4"/><vers num="3.0.3 (B)"/><vers num="3.0.3 (A)"/><vers num="3.0"/><vers num="2.5.2 (F)"/><vers num="2.5.2 (D)"/><vers num="2.5.2 (C)"/><vers num="2.5.2 (B)"/><vers num="2.5.2 (A)"/><vers num="2.0"/><vers num="4.1.7.A"/></prod><prod name="VPN 3020 Concentrator" vendor="Cisco"><vers num=""/></prod><prod name="VPN 3005 Concentrator" vendor="Cisco"><vers num="4.0.1"/><vers num="4.0"/><vers num="3.6.7 F"/><vers num="3.6.7 D"/><vers num="3.6.7 C"/><vers num="3.6.7 B"/><vers num="3.6.7 A"/><vers num="3.6.7"/><vers num="3.6.5"/><vers num="3.6.3"/></prod><prod name="VPN 3002 Hardware Client" vendor="Cisco"><vers num=""/></prod><prod name="VPN 3080 Concentrator" vendor="Cisco"><vers num=""/></prod><prod name="VPN 3030 Concentator" vendor="Cisco"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-08-21" name="CVE-2005-0944" published="2005-05-02" seq="2005-0944" severity="High" type="CVE"><desc><descript source="cve">Unknown vulnerability in Microsoft Jet DB engine (msjet40.dll) 4.00.8618.0, related to insufficient data validation, allows remote attackers to execute arbitrary code via a crafted mdb file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111231465920199&amp;w=2">20050331 [HV-HIGH] Microsoft Jet DB engine vulnerabilities</ref><ref adv="1" source="MISC" url="http://www.hexview.com/docs/20050331-1.txt">http://www.hexview.com/docs/20050331-1.txt</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/176380">VU#176380</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/442446/100/100/threaded">20060804 Will Microsoft patch remarkable old Msjet40.dll issue?</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/442610/100/100/threaded">20060808 Re: Will Microsoft patch remarkable old Msjet40.dll issue?</ref><ref source="" url="http://blogs.securiteam.com/?p=535"></ref></refs><vuln_soft><prod name="Jet DB Engine" vendor="Microsoft"><vers num="4.00.8618.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0945" published="2005-05-02" seq="2005-0945" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in ACS Blog 1.1.1 allows remote attackers to inject arbitrary web script or HTML via onmouseover or onload events in (1) img, (2) link, or (3) mail tags.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111214069029812&amp;w=2">20050328 Multiple XSS vulnerabilities in ACS Blog</ref><ref source="MISC" url="http://www.securitytracker.com/alerts/2005/Mar/1013584.html">http://www.securitytracker.com/alerts/2005/Mar/1013584.html</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/14744/">14744</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19864">acsblog-tags-xss(19864)</ref><ref adv="1" source="SECTRACK" url="http://securitytracker.com/id?1013584">1013584</ref></refs><vuln_soft><prod name="ACS Blog" vendor="ASP Press"><vers num="1.1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-03-29" name="CVE-2005-0946" published="2005-03-29" seq="2005-0946" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in phpCoin 1.2.1b and earlier allows remote attackers to execute arbitrary SQL commands via the (1) term/keywords field on the search page, (2) username or (3) e-mail field on the forgot password page, or (4) domain name on the ordering new package page.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111214190111520&amp;w=2">20050329 Multiple phpCoin Vulnerabilities</ref><ref adv="1" patch="1" source="MISC" url="http://www.gulftech.org/?node=research&amp;article_id=00065-03292005">http://www.gulftech.org/?node=research&amp;article_id=00065-03292005</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/12917">12917</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111214190111520&amp;w=2">20050329 Multiple phpCoin Vulnerabilities</ref><ref source="MISC" url="http://www.gulftech.org/?node=research&amp;article_id=00065-03292005">http://www.gulftech.org/?node=research&amp;article_id=00065-03292005</ref></refs><vuln_soft><prod name="phpCOIN" vendor="COINSoft Technologies"><vers num="1.2.1b"/><vers num="1.2.1"/><vers num="1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-03-29" name="CVE-2005-0947" published="2005-05-02" seq="2005-0947" severity="High" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in auxpage.php in phpCoin 1.2.1b and earlier allows remote attackers to read and execute arbitrary files via a .. (dot dot) in the page parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111214190111520&amp;w=2">20050329 Multiple phpCoin Vulnerabilities</ref><ref adv="1" source="MISC" url="http://www.gulftech.org/?node=research&amp;article_id=00065-03292005">http://www.gulftech.org/?node=research&amp;article_id=00065-03292005</ref><ref source="BID" url="http://www.securityfocus.com/bid/12917">12917</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19896">phpcoin-auxpage-file-include(19896)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111214190111520&amp;w=2">20050329 Multiple phpCoin Vulnerabilities</ref><ref source="MISC" url="http://www.gulftech.org/?node=research&amp;article_id=00065-03292005">http://www.gulftech.org/?node=research&amp;article_id=00065-03292005</ref></refs><vuln_soft><prod name="phpCOIN" vendor="COINSoft Technologies"><vers num="1.2.1b"/><vers num="1.2.1"/><vers num="1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-23" name="CVE-2005-0948" published="2005-05-02" seq="2005-0948" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in ad_click.asp for PortalApp allows remote attackers to execute arbitrary SQL commands via the banner_id parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111213291118273&amp;w=2">20050329 Multiple sql injection, and xss vulnerabilities in PortalApp</ref><ref source="MISC" url="http://securitytracker.com/id?1013591">http://securitytracker.com/id?1013591</ref><ref source="BID" url="http://www.securityfocus.com/bid/12936">12936</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14749">14749</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19892">portalapp-adclick-sql-injection(19892)</ref></refs><vuln_soft><prod name="PortalApp" vendor="Iatek"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-23" name="CVE-2005-0949" published="2005-05-02" seq="2005-0949" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in content.asp in Iatek PortalApp allow remote attackers to inject arbitrary web script or HTML via the (1) contenttype or (2) keywords parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111213291118273&amp;w=2">20050329 Multiple sql injection, and xss vulnerabilities in PortalApp</ref><ref source="BID" url="http://www.securityfocus.com/bid/12936">12936</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14749">14749</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19891">portalapp-contentasp-xss(19891)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013591">1013591</ref></refs><vuln_soft><prod name="PortalApp" vendor="Iatek"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0950" published="2005-03-29" seq="2005-0950" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in FastStone 4in1 Browser 1.2 allows remote attackers to read arbitrary files via a (1) ... (triple dot) or (2) ..\ (dot dot backslash) in the URL.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111213034206802&amp;w=2">20050329 directory traversal in FastStone 4in1 Browser 1.2</ref><ref adv="1" patch="1" source="MISC" url="http://www.autistici.org/fdonato/advisory/FastStone4in1Browser1.2-adv.txt">http://www.autistici.org/fdonato/advisory/FastStone4in1Browser1.2-adv.txt</ref><ref adv="1" patch="1" source="MISC" url="http://www.securitytracker.com/alerts/2005/Mar/1013596.html">http://www.securitytracker.com/alerts/2005/Mar/1013596.html</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/12937">12937</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14743">14743</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19900">faststone-dotdot-directory-traversal(19900)</ref><ref adv="1" patch="1" source="SECTRACK" url="http://securitytracker.com/id?1013596">1013596</ref></refs><vuln_soft><prod name="4in1 Browser" vendor="FastStone"><vers num="1.2"/></prod></vuln_soft></entry><entry modified="2005-10-20" name="CVE-2005-0951" published="2005-05-02" reject="1" seq="2005-0951" type="CVE"><desc><descript source="cve">** REJECT **   DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: none.  Reason: this candidate was created as a result of an analysis error for a researcher advisory for an issue that already existed.  It stated an incorrect parameter, which was not part of the vulnerability at all. Notes: CVE users should not reference this candidate at all.</descript></desc><refs/></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0952" published="2005-05-02" seq="2005-0952" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting vulnerability in pafiledb.php in PaFileDB 3.1 allows remote attackers to inject arbitrary web script or HTML via the id parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111221940107161&amp;w=2">20050330 PaFileDB Version 3.1 and below are exploitable via a XSS and a SQL injection vulnerability</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/448017/100/100/threaded">20061008 XSS IN paFileDB 3.1</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/29394">
pafiledb-action-xss(29394)</ref></refs><vuln_soft><prod name="paFileDB" vendor="PHP Arena"><vers num="3.1"/></prod></vuln_soft></entry><entry CVSS_base_score="3.7" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="6.4" CVSS_score="3.7" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0953" published="2005-05-02" seq="2005-0953" severity="Low" type="CVE"><desc><descript source="cve">Race condition in bzip2 1.0.2 and earlier allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by bzip2 after the decompression is complete.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><race/></vuln_types><range><local/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111229375217633&amp;w=2">20050330 bzip2 TOCTOU file-permissions vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/12954">12954</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19926">bzip2-toctou-symlink(19926)</ref><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-730">DSA-730</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1154.html">OVAL1154</ref><ref source="FEDORA" url="http://www.fedoralegacy.org/updates/FC2/2005-11-14-FLSA_2005_158801__Updated_bzip2_packages_fix_security_issues.html">FLSA:158801</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:026">MDKSA-2006:026</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-474.html">RHSA-2005:474</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20060301-01.U.asc">20060301-01-U</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19183">19183</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1154">oval:org.mitre.oval:def:1154</ref><ref source="OPENPKG" url="http://www.openpkg.com/security/advisories/OpenPKG-SA-2007.002.html">OpenPKG-SA-2007.002</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=307041"></ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2007/Nov/msg00002.html">APPLE-SA-2007-11-14</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:026">MDKSA-2006:026</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-103118-1">103118</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-319A.html">TA07-319A</ref><ref source="BID" url="http://www.securityfocus.com/bid/26444">26444</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/3525">ADV-2007-3525</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/3868">ADV-2007-3868</ref><ref source="SECUNIA" url="http://secunia.com/advisories/27274">27274</ref><ref source="SECUNIA" url="http://secunia.com/advisories/27643">27643</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-200191-1">200191</ref><ref source="NETBSD" url="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2008-004.txt.asc">NetBSD-SA2008-004</ref><ref source="SECUNIA" url="http://secunia.com/advisories/29940">29940</ref></refs><vuln_soft><prod name="bzip2" vendor="bzip"><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0"/><vers num="0.9.5 d"/><vers num="0.9.5 c"/><vers num="0.9.5 b"/><vers num="0.9.5 a"/><vers num="0.9 c"/><vers num="0.9 b"/><vers num="0.9 a"/><vers num="0.9"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-04-24" name="CVE-2005-0954" published="2005-05-02" seq="2005-0954" severity="Medium" type="CVE"><desc><descript source="cve">Windows Explorer and Internet Explorer in Windows 2000 SP1 allows remote attackers to cause a denial of service (CPU consumption) via a malformed Windows Metafile (WMF) file.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111231106513788&amp;w=2">20050331 WindowsXP malformed .wmf files DoS</ref><ref adv="1" source="MISC" url="http://www.securiteam.com/windowsntfocus/5CP081FFFY.html">http://www.securiteam.com/windowsntfocus/5CP081FFFY.html</ref><ref source="BID" url="http://www.securityfocus.com/bid/9892">9892</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/15507">winxp-explorer-wmf-dos(15507)</ref></refs><vuln_soft><prod name="Windows XP" vendor="Microsoft"><vers edition="Gold" num="Professional"/><vers edition="Gold" num="Professional"/><vers num="Media Center"/><vers edition="SP1" num="Home"/><vers num="Home"/></prod><prod name="Windows Explorer" vendor="Microsoft"><vers num=""/></prod><prod name="Internet Explorer" vendor="Microsoft"><vers num="6.0.2900"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0955" published="2005-05-02" seq="2005-0955" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in InterAKT MX Shop 1.1.1 allows remote attackers to execute arbitrary SQL commands via the id_ctg parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111230101127767&amp;w=2">20050331 MX Shop 1.1.1 and MX Kart 1.1.2 are vulnerable to multiple SQL injection vulnerabilities</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/14793">14793</ref><ref source="BID" url="http://www.securityfocus.com/bid/12957">12957</ref></refs><vuln_soft><prod name="MX Shop" vendor="InterAKT"><vers num="1.1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0956" published="2005-05-02" seq="2005-0956" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in index.php in InterAKT MX Kart 1.1.2 allow remote attackers to execute arbitrary SQL commands via the (1) idp, (2) id_ctg, or (3) id_man parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111230101127767&amp;w=2">20050331 MX Shop 1.1.1 and MX Kart 1.1.2 are vulnerable to multiple SQL injection vulnerabilities</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14793">14793</ref></refs><vuln_soft><prod name="MX Kart" vendor="InterAKT"><vers num="1.1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0957" published="2005-03-31" seq="2005-0957" severity="High" type="CVE"><desc><descript source="cve">Bay Technical Associates RPC-3 Telnet Host 3.05 allows remote attackers to bypass authentication by pressing the escape and enter keys at the username prompt.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111230568025271&amp;w=2">20050331 Bay Technical Associates telnet server logon bypass</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/12955">12955</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19921">rpc3-logon-bypass-authentication(19921)</ref></refs><vuln_soft><prod name="RPC3 Telnet" vendor="Bay Technical Associates"><vers num="F 3.05"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0958" published="2005-05-02" seq="2005-0958" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in the log_do function in log.c for YepYep mtftpd 0.0.3, when the statistics option is enabled, allows remote attackers to execute arbitrary code via the CWD command.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/><design/><env/></vuln_types><range><network/></range><refs><ref source="MISC" url="http://unl0ck.org/files/papers/mtftpd.txt">http://unl0ck.org/files/papers/mtftpd.txt</ref><ref source="MISC" url="http://www.securiteam.com/exploits/5KP0W0AF5K.html">http://www.securiteam.com/exploits/5KP0W0AF5K.html</ref><ref source="MISC" url="http://www.tripbit.org/advisories/TA-040305.txt">http://www.tripbit.org/advisories/TA-040305.txt</ref><ref source="BID" url="http://www.securityfocus.com/bid/12947">12947</ref></refs><vuln_soft><prod name="mtftpd" vendor="YepYep"><vers num="0.3"/><vers num="0.2"/><vers num="0.1a"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0959" published="2005-05-02" seq="2005-0959" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the mt_do_dir function in YepYep mtftpd 0.0.3 may allow attackers to execute arbitrary code via a long path.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/12947">12947</ref></refs><vuln_soft><prod name="mtftpd" vendor="YepYep"><vers num="0.3"/><vers num="0.2"/><vers num="0.1a"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0960" published="2005-05-02" seq="2005-0960" severity="Medium" type="CVE"><desc><descript source="cve">Multiple vulnerabilities in the SACK functionality in (1) tcp_input.c and (2) tcp_usrreq.c OpenBSD 3.5 and 3.6 allow remote attackers to cause a denial of service (memory exhaustion or system crash).</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref patch="1" source="OPENBSD" url="http://www.openbsd.org/errata.html#sack">20050330 [3.6] 013: RELIABILITY FIX: March 30, 2005</ref><ref patch="1" source="OPENBSD" url="http://www.openbsd.org/errata35.html#sack">20050330 [3.5] 030: RELIABILITY FIX: March 30, 2005</ref><ref patch="1" source="MISC" url="http://securitytracker.com/id?1013611">http://securitytracker.com/id?1013611</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/12951">12951</ref></refs><vuln_soft><prod name="OpenBSD" vendor="OpenBSD"><vers num="3.6"/><vers num="3.5"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0961" published="2005-05-02" seq="2005-0961" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Horde 3.0.4 before 3.0.4-RC2 allows remote attackers to inject arbitrary web script or HTML via the parent frame title.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="CONFIRM" url="http://lists.horde.org/archives/announce/2005/000176.html">http://lists.horde.org/archives/announce/2005/000176.html</ref><ref source="CONFIRM" url="http://cvs.horde.org/diff.php/horde/docs/CHANGES?r1=1.515.2.49&amp;r2=1.515.2.93&amp;ty=h">http://cvs.horde.org/diff.php/horde/docs/CHANGES?r1=1.515.2.49&amp;r2=1.515.2.93&amp;ty=h</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14730">14730</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_16_sr.html">SUSE-SR:2005:016</ref></refs><vuln_soft><prod name="Application Framework" vendor="Horde"><vers num="3.0.4 RC1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0962" published="2005-05-02" seq="2005-0962" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in index.php for Lighthouse Squirrelcart allows remote attackers to execute arbitrary SQL commands via the (1) crn parameter in a show action or (2) rn parameter in a show_detail action.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/12944">12944</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/14770">14770</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19904">squirrelcart-index-sql-injection(19904)</ref></refs><vuln_soft><prod name="Squirrelcart" vendor="Lighthouse Development"><vers num="1.5.5"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0963" published="2005-05-02" seq="2005-0963" severity="Low" type="CVE"><desc><descript source="cve">An error in the Toshiba ACPI BIOS 1.6 causes the BIOS to only examine the first slot in the Master Boot Record (MBR) table for an active partition, which prevents the system from booting even though the MBR is not malformed.  NOTE: it has been debated as to whether or not this issue poses a security vulnerability, since administrative privileges would be required, and other DoS attacks are possible with such privileges.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111214319914810&amp;w=2">20050329 Portcullis Security Advisory 05-011 ACPI 1.6 BIOS</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111229708208629&amp;w=2">20050331 Re: Portcullis Security Advisory 05-011 ACPI 1.6 BIOS</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111229803502643&amp;w=2">20050331 RE: Portcullis Security Advisory 05-011 ACPI 1.6 BIOS</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19895">toshiba-acpi-bios-dos(19895)</ref></refs><vuln_soft><prod name="ACPI BIOS" vendor="Toshiba"><vers num="1.6"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0964" published="2005-05-02" seq="2005-0964" severity="Medium" type="CVE"><desc><descript source="cve">Unknown vulnerability in Kerio Personal Firewall 4.1.2 and earlier allows local users to bypass firewall rules via a malicious process that impersonates a legitimate process that has fewer restrictions.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><access/><design/></vuln_types><range><local/></range><refs><ref adv="1" source="CONFIRM" url="http://www.kerio.com/security_advisory.html#0503">http://www.kerio.com/security_advisory.html#0503</ref><ref source="MISC" url="http://securitytracker.com/id?1013607">http://securitytracker.com/id?1013607</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/12946">12946</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/14717">14717</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19893">kerio-firewall-rule-security-bypass(19893)</ref></refs><vuln_soft><prod name="Personal Firewall" vendor="Kerio"><vers num="4.1.2"/><vers num="4.1.1"/><vers num="4.1"/><vers num="4.0.16"/><vers num="4.0.10"/><vers num="4.0.9"/><vers num="4.0.8"/><vers num="4.0.7"/><vers num="4.0.6"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0965" published="2005-05-02" seq="2005-0965" severity="Medium" type="CVE"><desc><descript source="cve">The gaim_markup_strip_html function in Gaim 1.2.0, and possibly earlier versions, allows remote attackers to cause a denial of service (application crash) via a string that contains malformed HTML, which causes an out-of-bounds read.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111238715307356&amp;w=2">20050401 multiple remote denial of service vulnerabilities in Gaim</ref><ref adv="1" source="CONFIRM" url="http://gaim.sourceforge.net/security/index.php?id=13">http://gaim.sourceforge.net/security/index.php?id=13</ref><ref adv="1" source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:071">MDKSA-2005:071</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14815">14815</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/426078/100/0/threaded">FLSA:158543</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-365.html">RHSA-2005:365</ref><ref source="BID" url="http://www.securityfocus.com/bid/12999">12999</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_36_sudo.html">SUSE-SA:2005:036</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:071">MDKSA-2005:071</ref></refs><vuln_soft><prod name="Gaim" vendor="Rob Flynn"><vers num="1.2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0966" published="2005-05-02" seq="2005-0966" severity="Medium" type="CVE"><desc><descript source="cve">The IRC protocol plugin in Gaim 1.2.0, and possibly earlier versions, allows (1) remote attackers to inject arbitrary Gaim markup via irc_msg_kick, irc_msg_mode, irc_msg_part, irc_msg_quit, (2) remote attackers to inject arbitrary Pango markup and pop up empty dialog boxes via irc_msg_invite, or (3) malicious IRC servers to cause a denial of service (application crash) by injecting certain Pango markup into irc_msg_badmode, irc_msg_banned, irc_msg_unknown, irc_msg_nochan functions.</descript></desc><loss_types><avail/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111238715307356&amp;w=2">20050401 multiple remote denial of service vulnerabilities in Gaim</ref><ref patch="1" source="CONFIRM" url="http://sourceforge.net/project/shownotes.php?group_id=235&amp;release_id=317750">http://sourceforge.net/project/shownotes.php?group_id=235&amp;release_id=317750</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19937">gaim-irc-plugin-bo(19937)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19939">gaim-ircmsginvite-dos(19939)</ref><ref adv="1" source="CONFIRM" url="http://gaim.sourceforge.net/security/index.php?id=14">http://gaim.sourceforge.net/security/index.php?id=14</ref><ref adv="1" source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:071">MDKSA-2005:071</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14815">14815</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/426078/100/0/threaded">FLSA:158543</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-365.html">RHSA-2005:365</ref><ref source="BID" url="http://www.securityfocus.com/bid/13003">13003</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_36_sudo.html">SUSE-SA:2005:036</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:071">MDKSA-2005:071</ref></refs><vuln_soft><prod name="Gaim" vendor="Rob Flynn"><vers num="1.2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0967" published="2005-05-02" seq="2005-0967" severity="Medium" type="CVE"><desc><descript source="cve">Gaim 1.2.0 allows remote attackers to cause a denial of service (application crash) via a malformed file transfer request to a Jabber user, which leads to an out-of-bounds read.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="CONFIRM" url="http://gaim.sourceforge.net/security/?id=15">http://gaim.sourceforge.net/security/?id=15</ref><ref source="CONFIRM" url="http://sourceforge.net/tracker/?func=detail&amp;aid=1172115&amp;group_id=235&amp;atid=100235">http://sourceforge.net/tracker/?func=detail&amp;aid=1172115&amp;group_id=235&amp;atid=100235</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1013645">1013645</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14815">14815</ref><ref adv="1" source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:071">MDKSA-2005:071</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/426078/100/0/threaded">FLSA:158543</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-365.html">RHSA-2005:365</ref><ref source="BID" url="http://www.securityfocus.com/bid/13004">13004</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_36_sudo.html">SUSE-SA:2005:036</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:071">MDKSA-2005:071</ref></refs><vuln_soft><prod name="Gaim" vendor="Rob Flynn"><vers num="1.2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0968" published="2005-05-02" seq="2005-0968" severity="Medium" type="CVE"><desc><descript source="cve">Computer Associates (CA) eTrust Intrusion Detection 3.0 allows remote attackers to cause a denial of service via large size values that are not properly validated before calling the CPImportKey function in the Crypto API.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=223&amp;type=vulnerabilities">20050405 Computer Associates eTrust Intrusion Detection System CPImportKey DoS Vulnerability</ref></refs><vuln_soft><prod name="eTrust Intrusion Detection" vendor="Computer Associates"><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0969" published="2005-05-12" seq="2005-0969" severity="Medium" type="CVE"><desc><descript source="cve">Heap-based buffer overflow in the syscall emulation functionality in Mac OS X before 10.3.9 allows local users to cause a denial of service (kernel panic) and possibly execute arbitrary code via crafted parameters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/Apr/msg00000.html">APPLE-SA-2005-04-15</ref></refs><vuln_soft><prod name="Mac OS X" vendor="Apple"><vers num="10.3.8"/><vers num="10.3.7"/><vers num="10.3.6"/><vers num="10.3.5"/><vers num="10.3.4"/><vers num="10.3.3"/><vers num="10.3.2"/><vers num="10.3.1"/><vers num="10.3"/><vers num="10.2.8"/><vers num="10.2.7"/><vers num="10.2.6"/><vers num="10.2.5"/><vers num="10.2.4"/><vers num="10.2.3"/><vers num="10.2.2"/><vers num="10.2.1"/><vers num="10.2"/><vers num="10.1.5"/><vers num="10.1.4"/><vers num="10.1.3"/><vers num="10.1.2"/><vers num="10.1.1"/><vers num="10.1"/><vers num="10.0.4"/><vers num="10.0.3"/><vers num="10.0.2"/><vers num="10.0.1"/><vers num="10.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="10.0" CVSS_score="7.6" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0970" published="2005-05-02" seq="2005-0970" severity="High" type="CVE"><desc><descript source="cve">Mac OS X 10.3.9 and earlier allows users to install, create, and execute setuid/setgid scripts, contrary to the the intended design, which may allow attackers to conduct unauthorized activities with escalated privileges via vulnerable scripts.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><network/><user_init/></range><refs><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/Apr/msg00000.html">APPLE-SA-2005-04-15</ref></refs><vuln_soft><prod name="Mac OS X" vendor="Apple"><vers num="10.3.9"/><vers num="10.3.8"/><vers num="10.3.7"/><vers num="10.3.6"/><vers num="10.3.5"/><vers num="10.3.4"/><vers num="10.3.3"/><vers num="10.3.2"/><vers num="10.3.1"/><vers num="10.3"/><vers num="10.2.8"/><vers num="10.2.7"/><vers num="10.2.6"/><vers num="10.2.5"/><vers num="10.2.4"/><vers num="10.2.3"/><vers num="10.2.2"/><vers num="10.2.1"/><vers num="10.2"/><vers num="10.1.5"/><vers num="10.1.4"/><vers num="10.1.3"/><vers num="10.1.2"/><vers num="10.1.1"/><vers num="10.1"/><vers num="10.0.4"/><vers num="10.0.3"/><vers num="10.0.2"/><vers num="10.0.1"/><vers num="10.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0971" published="2005-05-12" seq="2005-0971" severity="Medium" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in the semop system call in Mac OS X 10.3.9 and earlier allows local users to gain privileges via crafted arguments.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/Apr/msg00000.html">APPLE-SA-2005-04-15</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/212190">VU#212190</ref></refs><vuln_soft><prod name="Mac OS X" vendor="Apple"><vers num="10.3.9"/><vers num="10.3.8"/><vers num="10.3.7"/><vers num="10.3.6"/><vers num="10.3.5"/><vers num="10.3.4"/><vers num="10.3.3"/><vers num="10.3.2"/><vers num="10.3.1"/><vers num="10.3"/><vers num="10.2.8"/><vers num="10.2.7"/><vers num="10.2.6"/><vers num="10.2.5"/><vers num="10.2.4"/><vers num="10.2.3"/><vers num="10.2.2"/><vers num="10.2.1"/><vers num="10.2"/><vers num="10.1.5"/><vers num="10.1.4"/><vers num="10.1.3"/><vers num="10.1.2"/><vers num="10.1.1"/><vers num="10.1"/><vers num="10.0.4"/><vers num="10.0.3"/><vers num="10.0.2"/><vers num="10.0.1"/><vers num="10.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0972" published="2005-05-12" seq="2005-0972" severity="High" type="CVE"><desc><descript source="cve">Integer overflow in the searchfs system call in Mac OS X 10.3.9 and earlier allows local users to execute arbitrary code via crafted parameters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><local/></range><refs><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/Apr/msg00000.html">APPLE-SA-2005-04-15</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/185702">VU#185702</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.3.8"/><vers num="10.3.7"/><vers num="10.3.6"/><vers num="10.3.5"/><vers num="10.3.4"/><vers num="10.3.3"/><vers num="10.3.2"/><vers num="10.3.1"/><vers num="10.3"/><vers num="10.2.8"/><vers num="10.2.7"/><vers num="10.2.6"/><vers num="10.2.5"/><vers num="10.2.4"/><vers num="10.2.3"/><vers num="10.2.2"/><vers num="10.2.1"/><vers num="10.2"/><vers num="10.1.5"/><vers num="10.1.4"/><vers num="10.1.3"/><vers num="10.1.2"/><vers num="10.1.1"/><vers num="10.1"/><vers num="10.0"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.3.8"/><vers num="10.3.7"/><vers num="10.3.6"/><vers num="10.3.5"/><vers num="10.3.4"/><vers num="10.3.3"/><vers num="10.3.2"/><vers num="10.3.1"/><vers num="10.3"/><vers num="10.2.8"/><vers num="10.2.7"/><vers num="10.2.6"/><vers num="10.2.5"/><vers num="10.2.4"/><vers num="10.2.3"/><vers num="10.2.2"/><vers num="10.2.1"/><vers num="10.2"/><vers num="10.1.5"/><vers num="10.1.4"/><vers num="10.1.3"/><vers num="10.1.2"/><vers num="10.1.1"/><vers num="10.1"/><vers num="10.0.4"/><vers num="10.0.3"/><vers num="10.0.2"/><vers num="10.0.1"/><vers num="10.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0973" published="2005-05-12" seq="2005-0973" severity="Low" type="CVE"><desc><descript source="cve">Unknown vulnerability in the setsockopt system call in Mac OS X 10.3.9 and earlier allows local users to cause a denial of service (memory exhaustion) via crafted arguments.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/Apr/msg00000.html">APPLE-SA-2005-04-15</ref></refs><vuln_soft><prod name="Mac OS X" vendor="Apple"><vers num="10.3.9"/><vers num="10.3.8"/><vers num="10.3.7"/><vers num="10.3.6"/><vers num="10.3.5"/><vers num="10.3.4"/><vers num="10.3.3"/><vers num="10.3.2"/><vers num="10.3.1"/><vers num="10.3"/><vers num="10.2.8"/><vers num="10.2.7"/><vers num="10.2.6"/><vers num="10.2.5"/><vers num="10.2.4"/><vers num="10.2.3"/><vers num="10.2.2"/><vers num="10.2.1"/><vers num="10.2"/><vers num="10.1.5"/><vers num="10.1.4"/><vers num="10.1.3"/><vers num="10.1.2"/><vers num="10.1.1"/><vers num="10.1"/><vers num="10.0.4"/><vers num="10.0.3"/><vers num="10.0.2"/><vers num="10.0.1"/><vers num="10.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0974" published="2005-05-12" seq="2005-0974" severity="High" type="CVE"><desc><descript source="cve">Unknown vulnerability in the nfs_mount call in Mac OS X 10.3.9 and earlier allows local users to gain privileges via crafted arguments.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/Apr/msg00000.html">APPLE-SA-2005-04-15</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/713614">VU#713614</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/May/msg00004.html">APPLE-SA-2005-05-19</ref></refs><vuln_soft><prod name="Mac OS X" vendor="Apple"><vers num="10.3.9"/><vers num="10.3.8"/><vers num="10.3.7"/><vers num="10.3.6"/><vers num="10.3.5"/><vers num="10.3.4"/><vers num="10.3.3"/><vers num="10.3.2"/><vers num="10.3.1"/><vers num="10.3"/><vers num="10.2.8"/><vers num="10.2.7"/><vers num="10.2.6"/><vers num="10.2.5"/><vers num="10.2.4"/><vers num="10.2.3"/><vers num="10.2.2"/><vers num="10.2.1"/><vers num="10.2"/><vers num="10.1.5"/><vers num="10.1.4"/><vers num="10.1.3"/><vers num="10.1.2"/><vers num="10.1.1"/><vers num="10.1"/><vers num="10.0.4"/><vers num="10.0.3"/><vers num="10.0.2"/><vers num="10.0.1"/><vers num="10.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0975" published="2005-05-02" seq="2005-0975" severity="Low" type="CVE"><desc><descript source="cve">Integer signedness error in the parse_machfile function in the mach-o loader (mach_loader.c) for the Darwin Kernel as used in Mac OS X 10.3.7, and other versions before 10.3.9, allows local users to cause a denial of service (CPU consumption) via a crafted mach-o header.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110616533903671&amp;w=2">20050119 Darwin Kernel Vulnerability</ref><ref adv="1" source="MISC" url="http://felinemenace.org/advisories/macosx.txt">http://felinemenace.org/advisories/macosx.txt</ref><ref adv="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/Apr/msg00000.html">APPLE-SA-2005-04-15</ref><ref adv="1" source="CIAC" url="http://www.ciac.org/ciac/bulletins/p-185.shtml">P-185</ref><ref adv="1" source="MISC" url="http://www.frsirt.com/english/advisories/2005/0041">http://www.frsirt.com/english/advisories/2005/0041</ref><ref source="BID" url="http://www.securityfocus.com/bid/12314">12314</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1012941">1012941</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1013735">1013735</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/13902">13902</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18979">macos-machloader-dos(18979)</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.3"/><vers num="10.3.1"/><vers num="10.3.2"/><vers num="10.3.3"/><vers num="10.3.4"/><vers num="10.3.5"/><vers num="10.3.6"/><vers num="10.3.7"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.3"/><vers num="10.3.1"/><vers num="10.3.2"/><vers num="10.3.3"/><vers num="10.3.4"/><vers num="10.3.5"/><vers num="10.3.6"/></prod><prod name="Darwin Kernel" vendor="OpenDarwin"><vers num="7.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0976" published="2005-05-02" seq="2005-0976" severity="Medium" type="CVE"><desc><descript source="cve">AppleWebKit (WebCore and WebKit), as used in multiple products such as Safari 1.2 and OmniGroup OmniWeb 5.1, allows remote attackers to read arbitrary files via the XMLHttpRequest Javascript component, as demonstrated using automatically mounted disk images and file:// URLs.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MISC" url="http://remahl.se/david/vuln/001/">http://remahl.se/david/vuln/001/</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/Apr/msg00000.html">APPLE-SA-2005-04-15</ref></refs><vuln_soft><prod name="Shiira" vendor="HMDT"><vers num="0.93"/></prod><prod name="Safari" vendor="Apple"><vers num="1.2"/></prod><prod name="OmniWeb" vendor="OmniGroup"><vers num="5.1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0977" published="2005-05-02" seq="2005-0977" severity="Low" type="CVE"><desc><descript source="cve">The shmem_nopage function in shmem.c for the tmpfs driver in Linux kernel 2.6 does not properly verify the address argument, which allows local users to cause a denial of service (kernel crash) via an invalid address.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111238412403118&amp;w=2">20050401 [USN-103-1] Linux kernel vulnerabilities</ref><ref source="CONFIRM" url="http://linux.bkbits.net:8080/linux-2.6/cset@420551fbRlv9-QG6Gw9Lw_bKVfPSsg">http://linux.bkbits.net:8080/linux-2.6/cset@420551fbRlv9-QG6Gw9Lw_bKVfPSsg</ref><ref source="CONFIRM" url="http://lkml.org/lkml/2005/2/5/111">http://lkml.org/lkml/2005/2/5/111</ref><ref source="BID" url="http://www.securityfocus.com/bid/12970">12970</ref><ref adv="1" source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-103-1">USN-103-1</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-366.html">RHSA-2005:366</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/427980/100/0/threaded">FLSA:157459-3</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.6.8.1.5"/><vers edition="386" num="2.6.8.1.5"/><vers edition="686" num="2.6.8.1.5"/><vers edition="686_smp" num="2.6.8.1.5"/><vers edition="AMD64" num="2.6.8.1.5"/><vers edition="AMD64_K8" num="2.6.8.1.5"/><vers edition="AMD64_K8_smp" num="2.6.8.1.5"/><vers edition="AMD64_Xeon" num="2.6.8.1.5"/><vers edition="K7" num="2.6.8.1.5"/><vers edition="K7_smp" num="2.6.8.1.5"/><vers edition="Power3" num="2.6.8.1.5"/><vers edition="Power3_smp" num="2.6.8.1.5"/><vers edition="Power4" num="2.6.8.1.5"/><vers edition="Power4_smp" num="2.6.8.1.5"/><vers edition="PowerPC" num="2.6.8.1.5"/><vers edition="PowerPC_smp" num="2.6.8.1.5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0978" published="2005-05-02" seq="2005-0978" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in the Object Push service in IVT BlueSoleil 1.4 allows remote attackers to upload arbitrary files via a .. (dot dot) in a PUSH command.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111238511206503&amp;w=2">20050401 DMA[2005-0401a] - &apos;IVT BlueSoleil Directory Transversal&apos;</ref><ref source="MISC" url="http://www.digitalmunition.com/DMA%5B2005-0401a%5D.txt">http://www.digitalmunition.com/DMA%5B2005-0401a%5D.txt</ref><ref source="BID" url="http://www.securityfocus.com/bid/12961">12961</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14790/">14790</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19930">bluesoleil-object-push-directory-traversal(19930)</ref></refs><vuln_soft><prod name="BlueSoleil" vendor="IVT"><vers num="1.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0979" published="2005-05-02" seq="2005-0979" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in RUMBA 7.3 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via crafted values in a profile file, as demonstrated using a long SysName field.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111238364916500&amp;w=2">20050401 Buffer Overflow within the RUMBA product</ref><ref source="BID" url="http://www.securityfocus.com/bid/12965">12965</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19934">rumba-profile-values-bo(19934)</ref></refs><vuln_soft><prod name="RUMBA" vendor="NetManage"><vers num="7.4"/><vers num="7.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-28" name="CVE-2005-0980" published="2005-05-02" seq="2005-0980" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in index.php in AlstraSoft EPay Pro 2.0 allows remote attackers to execute arbitrary PHP code by modifying the view parameter to reference a URL on a remote web server that contains the code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111247198021626&amp;w=2">20050402 AlstraSoft EPay Pro v2.0 has file include and multiple xss</ref><ref source="BID" url="http://www.securityfocus.com/bid/12973">12973</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/14802">14802</ref></refs><vuln_soft><prod name="EPay" vendor="AlstraSoft"><vers edition="Enterprise" num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0981" published="2005-05-02" seq="2005-0981" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in AlstraSoft EPay Pro 2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) payment or (2) send parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111247198021626&amp;w=2">20050402 AlstraSoft EPay Pro v2.0 has file include and multiple xss</ref><ref source="BID" url="http://www.securityfocus.com/bid/12974">12974</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/14802">14802</ref></refs><vuln_soft><prod name="EPay" vendor="AlstraSoft"><vers edition="Enterprise" num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0982" published="2005-05-02" seq="2005-0982" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Yet Another Forum.net 0.9.9 allow remote attackers to inject arbitrary web script or HTML via the (1) name, (2) location, or (3) Subject field.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111247338301262&amp;w=2">20050402 Yet Another Forum.net XSS vulnerabilities</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013632">1013632</ref></refs><vuln_soft><prod name="Yet Another Forum.net" vendor="Yet Another Forum.net"><vers num="0.9.9"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-22" name="CVE-2005-0983" published="2005-05-02" seq="2005-0983" severity="Medium" type="CVE"><desc><descript source="cve">Quake 3 engine, as used in multiple games, allows remote attackers to cause a denial of service (client disconnect) via a long message, which is not properly truncated and causes the engine to process the remaining data as if it were network data.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref source="Luigi Auriemma" url="http://aluigi.altervista.org/adv/q3msgboom-adv.txt"></ref><ref source="ET Pro" url="http://bani.anime.net/banimod/forums/viewtopic.php?p=27322">BUGFIX: Oversize server commands</ref><ref source="BID" url="http://www.securityfocus.com/bid/12976">12976</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14811">14811</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111246796918067&amp;w=2">20050402 In-game players kicking in the Quake 3 engine</ref></refs><vuln_soft><prod name="Call of Duty" vendor="Activision"><vers num="1.5b"/><vers num="1.4"/></prod><prod name="Quake 3 Arena" vendor="id Software"><vers num="1.31"/><vers num="1.16"/><vers num="1.1.7"/></prod><prod name="Wolfenstein: Enemy Territory" vendor="id Software"><vers num="2.56"/><vers num="1.0.2"/></prod><prod name="Call of Duty United Offensive" vendor="Activision"><vers num="1.41"/><vers num="1.51b"/></prod><prod name="Soldier Of Fortune 2" vendor="Raven Software"><vers num="1.0.3"/><vers num="1.0.2"/></prod><prod name="Star Wars Jedi Knight II Jedi Outcast" vendor="LucasArts"><vers num="1.0.4"/></prod><prod name="Star Wars Jedi Knight Jedi Academy" vendor="LucasArts"><vers num="1.0.11"/></prod><prod name="Quake 3 Arena Server" vendor="id Software"><vers num="1.29g"/><vers num="1.29f"/></prod><prod name="Return to Castle Wolfenstein" vendor="Activision"><vers num="1.1"/><vers num="1.0"/></prod><prod name="Quake 3 engine" vendor="id software"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0984" published="2005-05-02" seq="2005-0984" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in the G_Printf function in Star Wars Jedi Knight: Jedi Academy 1.011 and earlier allows remote attackers to execute arbitrary code via a long message using commands such as (1) say and (2) tell.</descript></desc><loss_types><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Luigi Auriemma" url="http://aluigi.altervista.org/adv/jamsgbof-adv.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/12977">12977</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/14809">14809</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111246855213653&amp;w=2">20050402 In-game server buffer-overflow in Jedi Academy 1.011</ref></refs><vuln_soft><prod name="Star Wars Jedi Knight Jedi Academy" vendor="LucasArts"><vers num="1.0.11"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-08-08" name="CVE-2005-0985" published="2005-12-31" seq="2005-0985" severity="Low" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the Mac OS X kernel before 10.3.8 allows local users to cause a denial of service (temporary hang) via unspecified attack vectors related to the fan control unit (FCU) driver.</descript></desc><loss_types><avail/></loss_types><vuln_types><other/></vuln_types><range><local/></range><refs><ref source="" url="http://docs.info.apple.com/article.html?artnum=301324"></ref></refs><vuln_soft><prod name="Mac OS X" vendor="Apple"><vers num="10.3.7" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0986" published="2005-05-02" seq="2005-0986" severity="Medium" type="CVE"><desc><descript source="cve">NLSCCSTR.DLL in the web service in IBM Lotus Domino Server 6.5.1, 6.0.3, and possibly other versions allows remote attackers to cause a denial of service (deep recursion and nHTTP.exe process crash) via a long GET request containing UNICODE decimal value 430 characters, which causes the stack to be exhausted.  NOTE: IBM has reported that it is unable to replicate this issue.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=224&amp;type=vulnerabilities">20050406 IBM Lotus Domino Server Web Service DoS Vulnerability</ref><ref adv="1" source="MISC" url="http://www-1.ibm.com/support/docview.wss?uid=swg21202446">http://www-1.ibm.com/support/docview.wss?uid=swg21202446</ref><ref source="MISC" url="http://news.zdnet.co.uk/software/applications/0,39020384,39194293,00.htm">http://news.zdnet.co.uk/software/applications/0,39020384,39194293,00.htm</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/14858">14858</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/0322">ADV-2005-0322</ref></refs><vuln_soft><prod name="Lotus Domino Server" vendor="IBM"><vers num="6.0.3"/><vers num="6.5.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0987" published="2005-05-02" seq="2005-0987" severity="Medium" type="CVE"><desc><descript source="cve">Unknown vulnerability in IRC Services NickServ LISTLINKS before 5.0.50 allows remote attackers to obtain the links of a nick.</descript></desc><loss_types><conf/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1013622">1013622</ref><ref source="CONFIRM" url="http://www.ircservices.esper.net/Changes.txt">http://www.ircservices.esper.net/Changes.txt</ref></refs><vuln_soft><prod name="NickServ LISTLINKS" vendor="IRC Services"><vers num="5.0.49"/><vers num="5.0.48"/><vers num="5.0.47"/><vers num="5.0.46"/><vers num="5.0.45"/><vers num="5.0.44"/><vers num="5.0.43"/><vers num="5.0.42"/><vers num="5.0.41"/><vers num="5.0.40"/><vers num="5.0.39"/><vers num="5.0.38"/><vers num="5.0.37"/><vers num="5.0.36"/><vers num="5.0.35"/><vers num="5.0.34"/><vers num="5.0.33"/><vers num="5.0.32"/><vers num="5.0.31"/><vers num="5.0.30"/><vers num="5.0.29"/><vers num="5.0.28"/><vers num="5.0.27"/><vers num="5.0.26"/><vers num="5.0.25"/><vers num="5.0.24"/><vers num="5.0.23"/><vers num="5.0.22"/><vers num="5.0.21"/><vers num="5.0.20"/><vers num="5.0.19"/><vers num="5.0.18"/><vers num="5.0.17"/><vers num="5.0.16"/><vers num="5.0.15"/><vers num="5.0.14"/><vers num="5.0.13"/><vers num="5.0.12"/><vers num="5.0.11"/><vers num="5.0.10"/><vers num="5.0.9"/><vers num="5.0.8"/><vers num="5.0.7"/><vers num="5.0.6"/><vers num="5.0.5"/><vers num="5.0.4"/><vers num="5.0.3"/><vers num="5.0.2"/><vers num="5.0.1"/><vers num="5.0.0"/></prod></vuln_soft></entry><entry CVSS_base_score="3.7" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="6.4" CVSS_score="3.7" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-05-11" name="CVE-2005-0988" published="2005-05-02" seq="2005-0988" severity="Low" type="CVE"><desc><descript source="cve">Race condition in gzip 1.2.4, 1.3.3, and earlier, when decompressing a gzipped file, allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by gzip after the decompression is complete.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><race/></vuln_types><range><local/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/394965">20050404 gzip TOCTOU file-permissions vulnerability</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/12996">12996</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-752">DSA-752</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1169.html">OVAL1169</ref><ref source="SCO" url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.58/SCOSA-2005.58.txt">SCOSA-2005.58</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18100">18100</ref><ref source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2005-357.html">RHSA-2005:357</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101816-1">101816</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2006//Aug/msg00000.html">APPLE-SA-2006-08-01</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21253">21253</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/3101">ADV-2006-3101</ref><ref source="OSVDB" url="http://www.osvdb.org/15487">15487</ref><ref source="BID" url="http://www.securityfocus.com/bid/19289">19289</ref><ref source="SLACKWARE" url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2006&amp;m=slackware-security.555852">SSA:2006-262</ref><ref source="SECUNIA" url="http://secunia.com/advisories/22033">22033</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1169">oval:org.mitre.oval:def:1169</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:765">oval:org.mitre.oval:def:765</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-214A.html">TA06-214A</ref></refs><vuln_soft><prod name="TurboLinux Desktop" vendor="TurboLinux"><vers num="10.0"/></prod><prod name="Enterprise Linux" vendor="Red Hat"><vers edition="Workstation" num="4.0"/><vers edition="Workstation Server" num="3.0"/><vers edition="Workstation" num="2.1"/><vers edition="Workstation" num="2.1"/><vers edition="Enterprise Server" num="4.0"/><vers edition="Enterprise Server" num="3.0"/><vers edition="Enterprise Server" num="2.1"/><vers edition="Enterprise Server" num="2.1"/><vers edition="Advanced Server" num="4.0"/><vers edition="Advanced Server" num="3.0"/><vers edition="Advanced Server" num="2.1"/><vers edition="Advanced Server" num="2.1"/></prod><prod name="Ubuntu Linux" vendor="Ubuntu"><vers edition="powerpc" num="5.04"/><vers edition="i386" num="5.04"/><vers edition="amd64" num="5.04"/><vers edition="ppc" num="4.1"/><vers edition="ia64" num="4.1"/><vers edition="ia64" num="4.1"/></prod><prod name="FreeBSD" vendor="FreeBSD"><vers num="5.4 Releng"/><vers num="5.4 Release"/><vers num="5.4 pre"/><vers num="5.3 Stable"/><vers num="5.3 Releng"/><vers num="5.3 Release"/><vers num="5.3"/><vers num="5.2.1 Release"/><vers num="5.2 Releng"/><vers num="5.2 Release"/><vers num="5.2"/><vers num="5.1 Releng"/><vers num="5.1 Release Alpha"/><vers num="5.1 p5 Release"/><vers num="5.1 Release"/><vers num="5.1"/><vers num="5.0 Releng"/><vers num="5.0 p14 Release"/><vers num="5.0 alpha"/><vers num="5.0"/><vers num="4.11 Stable"/><vers num="4.11 Releng"/><vers num="4.11 p3 Release"/><vers num="4.10 Releng"/><vers num="4.10 p8 Release"/><vers num="4.10 Release"/><vers num="4.10"/><vers num="4.9 Releng"/><vers num="4.9 pre"/><vers num="4.9"/><vers num="4.8 Releng"/><vers num="4.8 p6 Release"/><vers num="4.8 pre"/><vers num="4.8"/><vers num="4.7 Stable"/><vers num="4.7 Releng"/><vers num="4.7 p17 Release"/><vers num="4.7 Release"/><vers num="4.7"/><vers num="4.6.2"/><vers num="4.6 Stable"/><vers num="4.6 Releng"/><vers num="4.6 p20 Release"/><vers num="4.6 Release"/><vers num="4.6"/><vers num="4.5 Stable pre 2002-03-07"/><vers num="4.5 Stable"/><vers num="4.5 Releng"/><vers num="4.5 p32 Release"/><vers num="4.5 Release"/><vers num="4.5"/><vers num="4.4 Stable"/><vers num="4.4 Releng"/><vers num="4.4 p42 Release"/><vers num="4.4"/><vers num="4.3 Stable"/><vers num="4.3 Releng"/><vers num="4.3 p38 Release"/><vers num="4.3 Release"/><vers num="4.3"/><vers num="4.2 Stable pre 2000-12-23"/><vers num="4.2 Stable pre 2001-05-02"/><vers num="4.2 Stable"/><vers num="4.2 Release"/><vers num="4.2"/><vers num="4.1.1 Stable"/><vers num="4.1.1 Release"/><vers num="4.1.1"/><vers num="4.1"/><vers num="4.0 Releng"/><vers num="4.0 alpha"/><vers num="4.0"/></prod><prod name="Secure Enterprise Linux" vendor="Trustix"><vers num="2.0"/></prod><prod name="gzip" vendor="GNU"><vers num="1.3.3"/><vers num="1.2.4a"/><vers num="1.2.4"/></prod><prod name="Advanced Workstation Itanium Processor" vendor="Red Hat"><vers edition="IA64" num="2.1"/><vers num="2.1"/></prod><prod name="Turbolinux Appliance Server" vendor="Turbolinux"><vers num="1.0 Workgroup"/><vers num="1.0 Hosting"/></prod><prod name="Turbolinux Server" vendor="Turbolinux"><vers num="10.0"/><vers num="8.0"/><vers num="7.0"/></prod><prod name="Desktop" vendor="Red Hat"><vers num="4.0"/><vers num="3.0"/></prod><prod name="Secure Linux" vendor="Trustix"><vers num="2.2"/><vers num="2.1"/></prod><prod name="TurboLinux Workstation" vendor="TurboLinux"><vers num="8.0"/><vers num="7.0"/></prod><prod name="Turbolinux Home" vendor="Turbolinux"><vers num=""/></prod><prod name="Linux" vendor="Gentoo"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0989" published="2005-05-02" seq="2005-0989" severity="Medium" type="CVE"><desc><descript source="cve">The find_replen function in jsstr.c in the the Javascript engine for Mozilla Suite 1.7.6, Firefox 1.0.1 and 1.0.2, and Netscape 7.2 allows remote attackers to read portions of heap memory in a Javascript string via the lambda replace method.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="CONFIRM" url="https://bugzilla.mozilla.org/show_bug.cgi?id=288688">https://bugzilla.mozilla.org/show_bug.cgi?id=288688</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14820">14820</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14821">14821</ref><ref adv="1" source="CONFIRM" url="http://www.mozilla.org/security/announce/mfsa2005-33.html">http://www.mozilla.org/security/announce/mfsa2005-33.html</ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200504-18.xml">GLSA-200504-18</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-383.html">RHSA-2005:383</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-386.html">RHSA-2005:386</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013635">1013635</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013643">1013643</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval100025.html">OVAL100025</ref><ref source="SCO" url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.49/SCOSA-2005.49.txt">SCOSA-2005.49</ref><ref source="BID" url="http://www.securityfocus.com/bid/15495">15495</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-384.html">RHSA-2005:384</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-601.html">RHSA-2005:601</ref><ref source="BID" url="http://www.securityfocus.com/bid/12988">12988</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_04_25.html">SUSE-SA:2006:022</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19823">19823</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100025">oval:org.mitre.oval:def:100025</ref></refs><vuln_soft><prod name="Mozilla" vendor="Mozilla"><vers num="1.7.6"/></prod><prod name="Netscape" vendor="Netscape"><vers num="7.2"/></prod><prod name="Firefox" vendor="Mozilla"><vers num="1.0.1"/><vers num="1.0.2"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0990" published="2005-05-02" seq="2005-0990" severity="Low" type="CVE"><desc><descript source="cve">unshar (unshar.c) in sharutils 4.2.1 allows local users to overwrite arbitrary files via a symlink attack on the unsh.X temporary file.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111263775029861&amp;w=2">20050404 [USN-104-1] unshar vulnerability</ref><ref adv="1" source="Debian" url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=302412">302412: exploitable temporary file race in unshar</ref><ref adv="1" source="ubuntu" url="https://bugzilla.ubuntu.com/show_bug.cgi?id=8459">8459</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-377.html">RHSA-2005:377</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19957">sharutils-temp-file-symlink(19957)</ref><ref adv="1" source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-104-1">USN-104-1</ref></refs><vuln_soft><prod name="sharutils" vendor="GNU"><vers num="4.2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0991" published="2005-05-02" seq="2005-0991" severity="Low" type="CVE"><desc><descript source="cve">RC.BOOT in IBM AIX 5.1, 5.2, and 5.3 does not &quot;use a secure location for temporary files,&quot; which allows local users to have an unknown impact, probably by overwriting files.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY59205&amp;apar=only">IY59205</ref><ref source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY59206&amp;apar=only">IY59206</ref><ref source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY59207&amp;apar=only">IY59207</ref><ref source="BID" url="http://www.securityfocus.com/bid/12992">12992</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="5.3 L"/><vers num="5.3"/><vers num="5.2 L"/><vers num="5.2"/><vers num="5.1L"/><vers num="5.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0992" published="2005-05-02" seq="2005-0992" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in phpMyAdmin before 2.6.2-rc1 allows remote attackers to inject arbitrary web script or HTML via the convcharset parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://www.arrelnet.com/advisories/adv20050403.html">http://www.arrelnet.com/advisories/adv20050403.html</ref><ref adv="1" source="CONFIRM" url="http://www.phpmyadmin.net/home_page/security.php?issue=PMASA-2005-3">http://www.phpmyadmin.net/home_page/security.php?issue=PMASA-2005-3</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/12982">12982</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/14799">14799</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19940">phpmyadmin-convcharset-xss(19940)</ref><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111264361622660&amp;w=2">20050404 phpMyAdmin Cross-site Scripting Vulnerability</ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200504-08.xml">GLSA-200504-08</ref></refs><vuln_soft><prod name="phpMyAdmin" vendor="phpMyAdmin"><vers num="2.6.1 pl3"/><vers num="2.6.1 pl1"/><vers num="2.6.1 rc1"/><vers num="2.6.1"/><vers num="2.6.0 pl3"/><vers num="2.6.0 pl2"/><vers num="2.6.0 pl1"/><vers num="2.5.7 pl1"/><vers num="2.5.7"/><vers num="2.5.6 rc1"/><vers num="2.5.5 pl1"/><vers num="2.5.5 rc2"/><vers num="2.5.5 rc1"/><vers num="2.5.5"/><vers num="2.5.4"/><vers num="2.5.3"/><vers num="2.5.2"/><vers num="2.5.1"/><vers num="2.5.0"/><vers num="2.4.0"/><vers num="2.3.2"/><vers num="2.3.1"/><vers num="2.2.6"/><vers num="2.2.5"/><vers num="2.2.4"/><vers num="2.2.3"/><vers num="2.2.2"/><vers num="2.2 rc3"/><vers num="2.2 rc2"/><vers num="2.2 rc1"/><vers num="2.2 pre2"/><vers num="2.2 pre1"/><vers num="2.2"/><vers num="2.1.2"/><vers num="2.1.1"/><vers num="2.1"/><vers num="2.0.5"/><vers num="2.0.4"/><vers num="2.0.3"/><vers num="2.0.2"/><vers num="2.0.1"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0993" published="2005-05-02" seq="2005-0993" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in nwprint in SCO OpenServer 5.0.7 allows local users to execute arbitrary code via a long command line argument.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111263251718491&amp;w=2">20050404 possible privilege escalation on Sco OpenServer 5.0.7</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/12986">12986</ref></refs><vuln_soft><prod name="OpenServer" vendor="SCO"><vers num="5.0.7"/><vers num="5.0.6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-25" name="CVE-2005-0994" published="2005-05-02" seq="2005-0994" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in ProductCart 2.7 allow remote attackers to execute arbitrary SQL commands via (1) the Category or resultCnt parameters to advSearch_h.asp, and possibly (2) the offset parameter to tarinasworld_butterflyjournal.asp.  NOTE: it is possible that item (2) is the result of a typo or editing error from the original research report.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/12990">12990</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/14833">14833</ref><ref source="OSVDB" url="http://www.osvdb.org/15263">15263</ref><ref source="OSVDB" url="http://www.osvdb.org/15265">15265</ref></refs><vuln_soft><prod name="ProductCart" vendor="Early Impact"><vers num="2.7"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-25" name="CVE-2005-0995" published="2005-05-02" seq="2005-0995" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in ProductCart 2.7 allow remote attackers to inject arbitrary web script or HTML via (1) the keyword parameter to advSearch_h.asp, (2) the redirectUrl parameter to NewCust.asp, (3) the country parameter to storelocator_submit.asp, or (4) the error parameter to techErr.asp. NOTE: it has been reported that storelocator_submit.asp does not exist in ProductCart.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/12990">12990</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/14833">14833</ref><ref source="OSVDB" url="http://www.osvdb.org/15264">15264</ref><ref source="OSVDB" url="http://www.osvdb.org/15266">15266</ref><ref source="OSVDB" url="http://www.osvdb.org/15268">15268</ref></refs><vuln_soft><prod name="ProductCart" vendor="Early Impact"><vers num="2.7"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0996" published="2005-05-02" seq="2005-0996" severity="Medium" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in the Downloads module for PHP-Nuke 7.6 allow remote attackers to inject arbitrary web script or HTML via (1) the email or url parameters in the Add function, (2) the min parameter in the viewsdownload function, or (3) the min parameter in the search function.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111289685724764&amp;w=2">20050403 [SECURITYREASON.COM] phpnuke 7.6 Multiple vulnerabilities in Downloads Module cXIb8O3.13</ref></refs><vuln_soft><prod name="PHP-Nuke" vendor="Francisco Burzi"><vers num="7.6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0997" published="2005-05-02" seq="2005-0997" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in the Web_Links module for PHP-Nuke 7.6 allow remote attackers to execute arbitrary SQL commands via (1) the email or url parameters in the Add function, (2) the url parameter in the modifylinkrequestS function, (3) the orderby or min parameters in the viewlink function, (4) the orderby, min, or show parameters in the search function, or (5) the ratenum parameter in the MostPopular function.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111289685724764&amp;w=2">20050403 [SECURITYREASON.COM] phpnuke 7.6 Multiple vulnerabilities in Web_Links Module cXIb8O3.14</ref></refs><vuln_soft><prod name="PHP-Nuke" vendor="Francisco Burzi"><vers num="7.6"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0998" published="2005-05-02" seq="2005-0998" severity="Medium" type="CVE"><desc><descript source="cve">The Web_Links module for PHP-Nuke 7.6 allows remote attackers to obtain sensitive information via an invalid show parameter, which triggers a division by zero PHP error that leaks the full pathname of the server.</descript></desc><loss_types><conf/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111289685724764&amp;w=2">20050403 [SECURITYREASON.COM] phpnuke 7.6 Multiple vulnerabilities in Web_Links Module cXIb8O3.14</ref></refs><vuln_soft><prod name="PHP-Nuke" vendor="Francisco Burzi"><vers num="7.6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0999" published="2005-05-02" seq="2005-0999" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in the Top module for PHP-Nuke 6.x through 7.6 allows remote attackers to execute arbitrary SQL commands via the querylang parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111281649616901&amp;w=2">20050406 [waraxe-2005-SA#041] - Critical Sql Injection in PhpNuke 6.x-7.6</ref><ref adv="1" source="MISC" url="http://www.waraxe.us/advisory-41.html">http://www.waraxe.us/advisory-41.html</ref></refs><vuln_soft><prod name="PHP-Nuke" vendor="Francisco Burzi"><vers num="6.0"/><vers num="6.5 RC3"/><vers num="6.5 RC2"/><vers num="6.5 RC1"/><vers num="6.5 FINAL"/><vers num="6.5 Beta1"/><vers num="6.5"/><vers num="6.6"/><vers num="6.7"/><vers num="6.9"/><vers num="7.0 FINAL"/><vers num="7.0"/><vers num="7.1"/><vers num="7.2"/><vers num="7.3"/><vers num="7.4"/><vers num="7.5"/><vers num="7.6"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1000" published="2005-05-02" seq="2005-1000" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in PHP-Nuke 7.6 allow remote attackers to inject arbitrary web script or HTML via (1) the bid parameter to the EmailStats op in banners.pgp, (2) the ratenum parameter in the TopRated and MostPopular actions in the Web_Links module, (3) the ttitle parameter in the viewlinkdetails, viewlinkeditorial, viewlinkcomments, and ratelink actions in the Web_Links module, or (4) the username parameter in the Your_Account module.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2005-04/0037.html">20050404 [SECURITYREASON.COM] PhpNuke 7.6=&gt;x Multiple vulnerabilities cXIb8O3.12</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19952">phpnuke-modulesphp-xss(19952)</ref><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111263454308478&amp;w=2">20050403 Full path disclosure and XSS in PHPNuke</ref></refs><vuln_soft><prod name="PHP-Nuke" vendor="Francisco Burzi"><vers num="7.6"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1001" published="2005-05-02" seq="2005-1001" severity="Medium" type="CVE"><desc><descript source="cve">PHP-Nuke 7.6 allows remote attackers to obtain sensitive information via direct requests to (1) the Surveys module with the file parameter set to comments or (2) 3D-Fantasy/theme.php, which leaks the full pathname of the web server in a PHP error message.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/RL">:REFERENCEURL:http://archives.neohapsis.com/archives/bugtraq/2005-04/0037.html</ref><ref adv="1" patch="1" source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2005-04/0037.html">20050404 [SECURITYREASON.COM] PhpNuke 7.6=&gt;x Multiple vulnerabilities cXIb8O3.12</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19953">phpnuke-modulesphp-path-disclosure(19953)</ref></refs><vuln_soft><prod name="PHP-Nuke" vendor="Francisco Burzi"><vers num="7.6"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1002" published="2005-05-02" seq="2005-1002" severity="Medium" type="CVE"><desc><descript source="cve">logwebftbs2000.exe in Logics Software File Transfer (LOG-FT) allows remote attackers to read arbitrary files via modified (1) VAR_FT_LANG and (2) VAR_FT_TMPL parameters.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/12998">12998</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14851">14851</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111271950916436&amp;w=2">20050405 Logics Software BS2000 Host to Web Client ALL PLATFORMS</ref></refs><vuln_soft><prod name="LOG-FT" vendor="Logics Software"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1003" published="2005-05-02" seq="2005-1003" severity="High" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in index.php for ProfitCode PayProCart 3.0 allows remote attackers to include arbitrary PHP files via .. (dot dot) sequences in the modID parameter.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111264602406090&amp;w=2">20050404 Authenticaion bypass, Directory transversal and XSS</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013640">1013640</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14832">14832</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19954">payprocart-dotdot-directory-traversal(19954)</ref></refs><vuln_soft><prod name="PayProCart" vendor="ProfitCode"><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1004" published="2005-05-02" seq="2005-1004" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in usrdetails.php in ProfitCode PayProCart 3.0 allows remote attackers to inject arbitrary web script or HTML via the sgnuptype parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111264602406090&amp;w=2">20050404 Authenticaion bypass, Directory transversal and XSS</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013640">1013640</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14832">14832</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19955">Payprocart-usrdetails-xss(19955)</ref></refs><vuln_soft><prod name="PayProCart" vendor="ProfitCode"><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1005" published="2005-05-02" seq="2005-1005" severity="High" type="CVE"><desc><descript source="cve">ProfitCode PayProCart 3.0 allows remote attackers to bypass authentication and gain administrative privileges to the admin control panel, as demonstrated via a direct request to adminshop/index.php with hex-encoded .. sequences in the ftoedit parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111264602406090&amp;w=2">20050404 Authenticaion bypass, Directory transversal and XSS</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013640">1013640</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14832">14832</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19956">payprocart-index-bypass-authentication(19956)</ref></refs><vuln_soft><prod name="PayProCart" vendor="ProfitCode"><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1006" published="2005-05-02" seq="2005-1006" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in SonicWALL SOHO 5.1.7.0 allow remote attackers to inject arbitrary web script or HTML via (1) the URL or (2) the user login name, which is not filtered when the administrator views the log file.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2005-04/0041.html">20050404 SonicWALL SOHO/10 - XSS vulnerability</ref><ref source="MISC" url="http://www.oliverkarow.de/research/SonicWall.txt">http://www.oliverkarow.de/research/SonicWall.txt</ref><ref source="BID" url="http://www.securityfocus.com/bid/12984">12984</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013638">1013638</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14823">14823</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19958">sonicwall-http-get-requests-xss(19958)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19960">sonicwall-username-code-execution(19960)</ref><ref source="OSVDB" url="http://www.osvdb.org/15261">15261</ref><ref source="OSVDB" url="http://www.osvdb.org/15262">15262</ref></refs><vuln_soft><prod name="SOHO" vendor="SonicWall"><vers num="5.1.7.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1007" published="2005-05-02" seq="2005-1007" severity="Medium" type="CVE"><desc><descript source="cve">Unknown vulnerability in the LIST functionality in CommuniGate Pro before 4.3c3 allows remote attackers to cause a denial of service (server crash) via certain multipart messages.</descript></desc><loss_types><avail/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref source="CONFIRM" url="http://www.stalker.com/CommuniGatePro/History.html">http://www.stalker.com/CommuniGatePro/History.html</ref><ref source="OSVDB" url="http://www.osvdb.org/15257">15257</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/14604">14604</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19961">communigatepro-list-dos(19961)</ref></refs><vuln_soft><prod name="Communigate Pro" vendor="Stalker"><vers num="4.3c2"/><vers num="4.3c1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1008" published="2005-05-02" seq="2005-1008" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in posts.asp for ASP-DEv XM Forum RC3 allows remote attackers to inject arbitrary web script or HTML via a &quot;javascript:&quot; URL in an IMG tag.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/12958">12958</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013614">1013614</ref></refs><vuln_soft><prod name="XM Forum" vendor="ASP-Dev"><vers num="RC3"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1009" published="2005-05-02" seq="2005-1009" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in BakBone NetVault 6.x and 7.x allow (1) remote attackers to execute arbitrary code via a modified computer name and length that leads to a heap-based buffer overflow, or (2) local users to execute arbitrary code via a long Name entry in the configure.cfg file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/394801">20050401 [Hat-Squad Advisory] Bakbone NetVault Heap overflow Vulnerabilities</ref><ref adv="1" source="MISC" url="http://www.hat-squad.com/en/000164.html">http://www.hat-squad.com/en/000164.html</ref><ref adv="1" source="MISC" url="http://www.class101.org/netv-remhbof.pdf">http://www.class101.org/netv-remhbof.pdf</ref><ref adv="1" source="MISC" url="http://www.hat-squad.com/en/000165.html">http://www.hat-squad.com/en/000165.html</ref><ref adv="1" source="MISC" url="http://www.class101.org/netv-locsbof.pdf">http://www.class101.org/netv-locsbof.pdf</ref><ref source="BID" url="http://www.securityfocus.com/bid/12967">12967</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013625">1013625</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/14814">14814</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19932">netvault-configurecfg-bo(19932)</ref></refs><vuln_soft><prod name="NetVault" vendor="BakBone"><vers num="7.1"/><vers num="7.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1010" published="2005-05-02" seq="2005-1010" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Comersus Cart 6 allows remote attackers to inject arbitrary web script or HTML via the account username.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/13000">13000</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013634">1013634</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14825">14825</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19962">comersus-username-xss(19962)</ref></refs><vuln_soft><prod name="Comersus Cart" vendor="Comersus Open Technologies"><vers num="6.0.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1011" published="2005-05-02" seq="2005-1011" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in content.asp in SiteEnable allows remote attackers to execute arbitrary SQL commands via the sortby parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MISC" url="http://www.zone-h.com/en/advisories/read/id=7367/">http://www.zone-h.com/en/advisories/read/id=7367/</ref><ref source="BID" url="http://www.securityfocus.com/bid/12985">12985</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013631">1013631</ref></refs><vuln_soft><prod name="SiteEnable" vendor="Iatek"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1012" published="2005-05-02" seq="2005-1012" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Iatek SiteEnable allows remote attackers to inject arbitrary web script or HTML via (1) the contenttype parameter to content.asp, (2) the title, or (3) the description.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://www.zone-h.com/en/advisories/read/id=7367/">http://www.zone-h.com/en/advisories/read/id=7367/</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013631">1013631</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19891">portalapp-contentasp-xss(19891)</ref></refs><vuln_soft><prod name="SiteEnable" vendor="Iatek"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2007-07-24" name="CVE-2005-1013" published="2005-05-02" seq="2005-1013" severity="Medium" type="CVE"><desc><descript source="cve">The SMTP service in MailEnable Enterprise 1.04 and earlier and Professional 1.54 and earlier allows remote attackers to cause a denial of service (server crash) via an EHLO command with a Unicode string.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111273637518494&amp;w=2">20050405 MailEnable Smtpd remote Dos [x0n3-h4ck]</ref><ref adv="1" patch="1" source="MISC" url="http://www.securiteam.com/windowsntfocus/5HP031PFFG.html">http://www.securiteam.com/windowsntfocus/5HP031PFFG.html</ref><ref patch="1" source="CONFIRM" url="http://www.mailenable.com/hotfix/">http://www.mailenable.com/hotfix/</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/12994">12994</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1013637">1013637</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14812">14812</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19948">mailenable-smtp-dos(19948)</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19973">mailenable-ehlo-dos(19973)</ref><ref source="OSVDB" url="http://www.osvdb.org/15232">15232</ref></refs><vuln_soft><prod name="MailEnable Professional" vendor="MailEnable"><vers num="1.54"/><vers num="1.53"/><vers num="1.52"/><vers num="1.51"/><vers num="1.5"/></prod><prod name="MailEnable Enterprise" vendor="MailEnable"><vers num="1.04"/><vers num="1.03"/><vers num="1.02"/><vers num="1.01"/><vers num="1.00"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-07-24" name="CVE-2005-1014" published="2005-05-02" seq="2005-1014" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the IMAP service for MailEnable Enterprise 1.04 and earlier and Professional 1.54 allows remote attackers to execute arbitrary code via a long AUTHENTICATE command.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-April/033123.html">20050405 MailEnable Imapd remote BoF + Exploit [x0n3-h4ck]</ref><ref patch="1" source="CONFIRM" url="http://www.mailenable.com/hotfix/">http://www.mailenable.com/hotfix/</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/12995">12995</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1013637">1013637</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14812">14812</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19947">mailenable-imap-dos(19947)</ref></refs><vuln_soft><prod name="MailEnable Professional" vendor="MailEnable"><vers num="1.54"/><vers num="1.53"/><vers num="1.52"/><vers num="1.51"/><vers num="1.5"/></prod><prod name="MailEnable Enterprise" vendor="MailEnable"><vers num="1.04"/><vers num="1.03"/><vers num="1.02"/><vers num="1.01"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-07-24" name="CVE-2005-1015" published="2005-05-02" seq="2005-1015" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in MailEnable Imapd (MEIMAP.exe) allows remote attackers to execute arbitrary code via a long LOGIN command.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-April/033144.html">20050406 Re: MailEnable Imapd remote BoF + Exploit [x0n3-h4ck]</ref></refs><vuln_soft><prod name="Imapd" vendor="MailEnable"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1016" published="2005-05-02" seq="2005-1016" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in links_add_form.asp for MaxWebPortal 1.33 and earlier allows remote attackers to inject arbitrary web script or HTML via a Javascript URL in a banner URL.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MISC" url="http://www.hackerscenter.com/archive/view.asp?id=1807">http://www.hackerscenter.com/archive/view.asp?id=1807</ref><ref source="BID" url="http://www.securityfocus.com/bid/12968">12968</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013617">1013617</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14752">14752</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19929">maxwebportal-linksaddform-xss(19929)</ref></refs><vuln_soft><prod name="MaxWebPortal" vendor="MaxWebPortal"><vers num="1.33" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1017" published="2005-05-02" seq="2005-1017" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in the Update_Events function in events_functions.asp in MaxWebPortal 1.33 and earlier allows remote attackers to execute abritrary SQL commands via the EVENT_ID parameter, as demonstrated using events.asp.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MISC" url="http://www.hackerscenter.com/archive/view.asp?id=1807">http://www.hackerscenter.com/archive/view.asp?id=1807</ref><ref source="BID" url="http://www.securityfocus.com/bid/12968">12968</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1013617">1013617</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14752">14752</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19928">maxwebportal-eventsfunctions-sql-injection(19928)</ref></refs><vuln_soft><prod name="MaxWebPortal" vendor="MaxWebPortal"><vers num="1.33" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1018" published="2005-05-02" seq="2005-1018" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the UniversalAgent for Computer Associates (CA) BrightStor ARCserve Backup allows remote authenticated users to cause a denial of service or execute arbitrary code via an agent request to TCP port 6050 with a large argument before the option field.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=232&amp;type=vulnerabilities">20050411 Computer Associates BrightStor ARCserve Backup UniversalAgent Buffer Overflow</ref><ref patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111351851802682&amp;w=2">20050414 Computer Associates BrightStor ARCserve Backup and BrightStor Enterprise Backup UniversalAgent buffer overflow vulnerability</ref></refs><vuln_soft><prod name="BrightStor ARCserve Backup" vendor="Computer Associates"><vers edition="Windows" num="11.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1019" published="2005-05-02" seq="2005-1019" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the getConfig function in Aeon 0.2a and earlier allows local users to gain privileges via a long HOME environment variable.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111262942708249&amp;w=2">20050404 Local buffer overflow  on Aeon&lt;=0.2a</ref><ref source="MISC" url="http://security-tmp.h14.ru/exploits/23laeon.c.txt">http://security-tmp.h14.ru/exploits/23laeon.c.txt</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19951">aeon-getconfig-bo(19951)</ref></refs><vuln_soft><prod name="Aeon" vendor="Aeon"><vers num="0.2a"/><vers num="0.2"/><vers num="0.1.9"/><vers num="0.1.8"/></prod></vuln_soft></entry><entry CVSS_base_score="7.1" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.9" CVSS_score="7.1" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2008-08-20" name="CVE-2005-1020" published="2005-05-02" seq="2005-1020" severity="High" type="CVE"><desc><descript source="cve">Secure Shell (SSH) 2 in Cisco IOS 12.0 through 12.3 allows remote attackers to cause a denial of service (device reload) (1) via a username that contains a domain name when using a TACACS+ server to authenticate, (2) when a new SSH session is in the login phase and a currently logged in user issues a send command, or (3) when IOS is logging messages and an SSH session is terminated while the server is sending data.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-sa-20050406-ssh.shtml">20050406 Vulnerabilities in Cisco IOS Secure Shell Server</ref><ref source="BID" url="http://www.securityfocus.com/bid/13043">13043</ref><ref adv="1" source="SECTRACK" url="http://www.securitytracker.com/alerts/2005/Apr/1013655.html">1013655</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14854">14854</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19987">cisco-ios-sshv2-tacacs-authentication-dos(19987)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19989">cisco-ios-authentication-send-dos(19989)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19990">cisco-ios-ssh-message-log-dos(19990)</ref></refs><vuln_soft><prod name="IOS" vendor="Cisco"><vers num="12.3YL"/><vers num="12.3YJ"/><vers num="12.3YH"/><vers num="12.3YG"/><vers num="12.3YF"/><vers num="12.3YE"/><vers num="12.3YD"/><vers num="12.3YC"/><vers num="12.3YA"/><vers num="12.3XZ"/><vers num="12.3XY"/><vers num="12.3XX"/><vers num="12.3XW"/><vers num="12.3XV"/><vers num="12.3XU"/><vers num="12.3XT"/><vers num="12.3XS"/><vers num="12.3XR"/><vers num="12.3XQ"/><vers num="12.3XN"/><vers num="12.3XM"/><vers num="12.3XL"/><vers num="12.3XK"/><vers num="12.3XJ"/><vers num="12.3XI"/><vers num="12.3XH"/><vers num="12.3XG"/><vers num="12.3XF"/><vers num="12.3XE"/><vers num="12.3XD"/><vers num="12.3XC"/><vers num="12.3XB"/><vers num="12.3XA"/><vers num="12.3T"/><vers num="12.3JA"/><vers num="12.3J"/><vers num="12.3BW"/><vers num="12.3BC"/><vers num="12.3B"/><vers num="12.3 XQ"/><vers num="12.3 XK"/><vers num="12.3 XH"/><vers num="12.3 XG"/><vers num="12.3 XF"/><vers num="12.3 XE"/><vers num="12.3 XD"/><vers num="12.3 XC"/><vers num="12.3 T"/><vers num="12.3 B"/><vers num="12.3 (6)"/><vers num="12.3 (5b)"/><vers num="12.3 (5a)b"/><vers num="12.3 (5a)"/><vers num="12.3 (5)"/><vers num="12.3 (4)XD1"/><vers num="12.3 (4)XD"/><vers num="12.3 (4)T3"/><vers num="12.3 (4)T2"/><vers num="12.3 (4)T1"/><vers num="12.3 (4)T"/><vers num="12.3 (2)XC2"/><vers num="12.3 (2)XC1"/><vers num="12.3 (2)T3"/><vers num="12.3"/><vers num="12.2ZP"/><vers num="12.2ZO"/><vers num="12.2ZN"/><vers num="12.2ZM"/><vers num="12.2ZL"/><vers num="12.2ZK"/><vers num="12.2ZJ"/><vers num="12.2ZI"/><vers num="12.2ZH"/><vers num="12.2ZG"/><vers num="12.2ZF"/><vers num="12.2ZE"/><vers num="12.2ZD"/><vers num="12.2ZC"/><vers num="12.2ZB"/><vers num="12.2ZA"/><vers num="12.2YZ"/><vers num="12.2YY"/><vers num="12.2YX"/><vers num="12.2YW"/><vers num="12.2YV"/><vers num="12.2YU"/><vers num="12.2YT"/><vers num="12.2YS"/><vers num="12.2YR"/><vers num="12.2YQ"/><vers num="12.2YP"/><vers num="12.2YO"/><vers num="12.2YN"/><vers num="12.2YM"/><vers num="12.2YL"/><vers num="12.2YK"/><vers num="12.2YJ"/><vers num="12.2YH"/><vers num="12.2YG"/><vers num="12.2YF"/><vers num="12.2YE"/><vers num="12.2YC"/><vers num="12.2YB"/><vers num="12.2YA"/><vers num="12.2XZ"/><vers num="12.2XW"/><vers num="12.2XU"/><vers num="12.2XT"/><vers num="12.2XS"/><vers num="12.2XQ"/><vers num="12.2XN"/><vers num="12.2XM"/><vers num="12.2XL"/><vers num="12.2XK"/><vers num="12.2XJ"/><vers num="12.2XI"/><vers num="12.2XH"/><vers num="12.2XG"/><vers num="12.2XF"/><vers num="12.2XE"/><vers num="12.2XD"/><vers num="12.2XC"/><vers num="12.2XB"/><vers num="12.2XA"/><vers num="12.2X"/><vers num="12.2T"/><vers num="12.2SZ"/><vers num="12.2SY"/><vers num="12.2SXD"/><vers num="12.2SXB"/><vers num="12.2SXA"/><vers num="12.2SX"/><vers num="12.2SW"/><vers num="12.2SV"/><vers num="12.2SU"/><vers num="12.2SE"/><vers num="12.2S"/><vers num="12.2MX"/><vers num="12.2MC"/><vers num="12.2MB"/><vers num="12.2JK"/><vers num="12.2EWA"/><vers num="12.2EW"/><vers num="12.2DX"/><vers num="12.2DD"/><vers num="12.2DA"/><vers num="12.2CZ"/><vers num="12.2CX"/><vers num="12.2BZ"/><vers num="12.2BY"/><vers num="12.2BX"/><vers num="12.2BW"/><vers num="12.2BC"/><vers num="12.2B"/><vers num="12.2 ZQ"/><vers num="12.2 ZJ"/><vers num="12.2 ZH"/><vers num="12.2 ZG"/><vers num="12.2 ZF"/><vers num="12.2 ZE"/><vers num="12.2 ZD"/><vers num="12.2 ZC"/><vers num="12.2 ZB"/><vers num="12.2 ZA"/><vers num="12.2 YZ"/><vers num="12.2 YY"/><vers num="12.2 YX"/><vers num="12.2 YW"/><vers num="12.2 YV"/><vers num="12.2 YU"/><vers num="12.2 YT"/><vers num="12.2 YS"/><vers num="12.2 YR"/><vers num="12.2 YQ"/><vers num="12.2 YP"/><vers num="12.2 YO"/><vers num="12.2 YN"/><vers num="12.2 YM"/><vers num="12.2 YL"/><vers num="12.2 YK"/><vers num="12.2 YJ"/><vers num="12.2 YH"/><vers num="12.2 YG"/><vers num="12.2 YF"/><vers num="12.2 YD"/><vers num="12.2 YC"/><vers num="12.2 YB"/><vers num="12.2 YA"/><vers num="12.2 XW"/><vers num="12.2 XT"/><vers num="12.2 XS"/><vers num="12.2 XR"/><vers num="12.2 XQ"/><vers num="12.2 XN"/><vers num="12.2 XM"/><vers num="12.2 XL"/><vers num="12.2 XK"/><vers num="12.2 XJ"/><vers num="12.2 XI"/><vers num="12.2 XH"/><vers num="12.2 XG"/><vers num="12.2 XF"/><vers num="12.2 XE"/><vers num="12.2 XD"/><vers num="12.2 XC"/><vers num="12.2 XB"/><vers num="12.2 XA"/><vers num="12.2 T"/><vers num="12.2 SZ"/><vers num="12.2 SY"/><vers num="12.2 SXB"/><vers num="12.2 SXA"/><vers num="12.2 SX"/><vers num="12.2 SW"/><vers num="12.2 S"/><vers num="12.2 MX"/><vers num="12.2 MC"/><vers num="12.2 MB"/><vers num="12.2 JA"/><vers num="12.2 DX"/><vers num="12.2 DD"/><vers num="12.2 DA"/><vers num="12.2 CY"/><vers num="12.2 CX"/><vers num="12.2 BZ"/><vers num="12.2 BX"/><vers num="12.2 BW"/><vers num="12.2 BC"/><vers num="12.2 B"/><vers num="12.2 12.2XU"/><vers num="12.2 (8)JA"/><vers num="12.2 (4)JA1"/><vers num="12.2 (4)JA"/><vers num="12.2 (23)"/><vers num="12.2 (21a)"/><vers num="12.2 (21)"/><vers num="12.2 (20)S1"/><vers num="12.2 (20)S"/><vers num="12.2 (20)EW"/><vers num="12.2 (2)XU2"/><vers num="12.2 (2)XU"/><vers num="12.2 (2)XT3"/><vers num="12.2 (2)XT"/><vers num="12.2 (2)XN"/><vers num="12.2 (2)XK2"/><vers num="12.2 (2)XK"/><vers num="12.2 (2)XJ1"/><vers num="12.2 (2)XJ"/><vers num="12.2 (2)XI2"/><vers num="12.2 (2)XI1"/><vers num="12.2 (2)XI"/><vers num="12.2 (2)XH3"/><vers num="12.2 (2)XH2"/><vers num="12.2 (2)XH"/><vers num="12.2 (2)XG"/><vers num="12.2 (2)XF"/><vers num="12.2 (2)XB4"/><vers num="12.2 (2)XB3"/><vers num="12.2 (2)XB"/><vers num="12.2 (2)XA5"/><vers num="12.2 (2)XA1"/><vers num="12.2 (2)XA"/><vers num="12.2 (2)T4"/><vers num="12.2 (18)SW"/><vers num="12.2 (18)SV"/><vers num="12.2 (18)SE"/><vers num="12.2 (18)S"/><vers num="12.2 (18)EWA"/><vers num="12.2 (18)EW"/><vers num="12.2 (17a)SXA"/><vers num="12.2 (16.1)B"/><vers num="12.2 (16)B"/><vers num="12.2 (15.1)S"/><vers num="12.2 (15)ZN"/><vers num="12.2 (14.5)T"/><vers num="12.2 (14.5)"/><vers num="12.2 (14)ZA2"/><vers num="12.2 (14)ZA"/><vers num="12.2 (14)SZ"/><vers num="12.2 (14)SY1"/><vers num="12.2 (14)SY"/><vers num="12.2 (12h)"/><vers num="12.2 (12g)"/><vers num="12.2 (11)T"/><vers num="12.2 (11)JA1"/><vers num="12.2 (11)JA"/><vers num="12.2 (1)XS1"/><vers num="12.2 (1)XS"/><vers num="12.2 (1)XQ"/><vers num="12.2 (1)XH"/><vers num="12.2 (1)XE3"/><vers num="12.2 (1)XE2"/><vers num="12.2 (1)XE"/><vers num="12.2 (1)XD4"/><vers num="12.2 (1)XD3"/><vers num="12.2 (1)XD1"/><vers num="12.2 (1)XD"/><vers num="12.2 (1)XA"/><vers num="12.2"/><vers num="12.1YJ"/><vers num="12.1YI"/><vers num="12.1YH"/><vers num="12.1YF"/><vers num="12.1YD"/><vers num="12.1YB"/><vers num="12.1YA"/><vers num="12.1XV"/><vers num="12.1XU"/><vers num="12.1XT"/><vers num="12.1XR"/><vers num="12.1XQ"/><vers num="12.1XP"/><vers num="12.1XM"/><vers num="12.1XL"/><vers num="12.1XJ"/><vers num="12.1XI"/><vers num="12.1XH"/><vers num="12.1XG"/><vers num="12.1XF"/><vers num="12.1XE"/><vers num="12.1XD"/><vers num="12.1XC"/><vers num="12.1XB"/><vers num="12.1XA"/><vers num="12.1T"/><vers num="12.1EY"/><vers num="12.1EX"/><vers num="12.1EW"/><vers num="12.1EV"/><vers num="12.1EO"/><vers num="12.1EC"/><vers num="12.1EA"/><vers num="12.1E"/><vers num="12.1DC"/><vers num="12.1DB"/><vers num="12.1DA"/><vers num="12.1AZ"/><vers num="12.1AY"/><vers num="12.1AX"/><vers num="12.1AA"/><vers num="12.1(20)EO"/><vers num="12.1(19)E1"/><vers num="12.1(13)E9"/><vers num="12.1 YJ"/><vers num="12.1 YI"/><vers num="12.1 YH"/><vers num="12.1 YF"/><vers num="12.1 YE"/><vers num="12.1 YD"/><vers num="12.1 YC"/><vers num="12.1 YB"/><vers num="12.1 YA"/><vers num="12.1 XZ"/><vers num="12.1 XY"/><vers num="12.1 XX"/><vers num="12.1 XW"/><vers num="12.1 XV"/><vers num="12.1 XU"/><vers num="12.1 XT"/><vers num="12.1 XS"/><vers num="12.1 XR"/><vers num="12.1 XQ"/><vers num="12.1 XP"/><vers num="12.1 XM"/><vers num="12.1 XL"/><vers num="12.1 XK"/><vers num="12.1 XJ"/><vers num="12.1 XI"/><vers num="12.1 XH"/><vers num="12.1 XG"/><vers num="12.1 XF"/><vers num="12.1 XE"/><vers num="12.1 XD"/><vers num="12.1 XC"/><vers num="12.1 XB"/><vers num="12.1 XA"/><vers num="12.1 T"/><vers num="12.1 M"/><vers num="12.1 EY"/><vers num="12.1 EX"/><vers num="12.1 EW"/><vers num="12.1 EV"/><vers num="12.1 EU"/><vers num="12.1 EO"/><vers num="12.1 EC"/><vers num="12.1 EB"/><vers num="12.1 EA"/><vers num="12.1 E"/><vers num="12.1 DC"/><vers num="12.1 DB"/><vers num="12.1 DA"/><vers num="12.1 CX"/><vers num="12.1 AY"/><vers num="12.1 AX"/><vers num="12.1 AA"/><vers num="12.1 (20)EW1"/><vers num="12.1 (20)EW"/><vers num="12.1 (20)EC1"/><vers num="12.1 (20)EC"/><vers num="12.1 (20)EA1"/><vers num="12.1 (20)E2"/><vers num="12.1 (20)E1"/><vers num="12.1 (20)E"/><vers num="12.1 (11b)E14"/><vers num="12.1 (11b)E12"/><vers num="12.1 (11b)E"/><vers num="12.1 (11)E"/><vers num="12.1"/><vers num="12.0XV"/><vers num="12.0XU"/><vers num="12.0XT"/><vers num="12.0XS"/><vers num="12.0XR"/><vers num="12.0XQ"/><vers num="12.0XP"/><vers num="12.0XN"/><vers num="12.0XM"/><vers num="12.0XL"/><vers num="12.0XK"/><vers num="12.0XJ"/><vers num="12.0XI"/><vers num="12.0XH"/><vers num="12.0XG"/><vers num="12.0XF"/><vers num="12.0XE"/><vers num="12.0XD"/><vers num="12.0XC"/><vers num="12.0XB"/><vers num="12.0XA"/><vers num="12.0WX"/><vers num="12.0WT"/><vers num="12.0WC"/><vers num="12.0W5"/><vers num="12.0T"/><vers num="12.0SZ"/><vers num="12.0SY"/><vers num="12.0SX"/><vers num="12.0ST"/><vers num="12.0SP"/><vers num="12.0SC"/><vers num="12.0S"/><vers num="12.0DC"/><vers num="12.0DB"/><vers num="12.0DA"/><vers num="12.0 XW"/><vers num="12.0 XV"/><vers num="12.0 XU"/><vers num="12.0 XS"/><vers num="12.0 XR"/><vers num="12.0 XQ"/><vers num="12.0 XP"/><vers num="12.0 XN"/><vers num="12.0 XM"/><vers num="12.0 XL"/><vers num="12.0 XK"/><vers num="12.0 XJ"/><vers num="12.0 XI"/><vers num="12.0 XH"/><vers num="12.0 XG"/><vers num="12.0 XF"/><vers num="12.0 XE"/><vers num="12.0 XD"/><vers num="12.0 XC"/><vers num="12.0 XB"/><vers num="12.0 XA"/><vers num="12.0 WT"/><vers num="12.0 WC"/><vers num="12.0 W5"/><vers num="12.0 T"/><vers num="12.0 SZ"/><vers num="12.0 SY"/><vers num="12.0 SX"/><vers num="12.0 SV"/><vers num="12.0 ST"/><vers num="12.0 SP"/><vers num="12.0 SL"/><vers num="12.0 SC"/><vers num="12.0 S"/><vers num="12.0 DC"/><vers num="12.0 DB"/><vers num="12.0 DA"/><vers num="12.0 (27)SV1"/><vers num="12.0 (27)SV"/><vers num="12.0 (27)S"/><vers num="12.0 (26)S1"/><vers num="12.0 (24.2)S"/><vers num="12.0 (24)S5"/><vers num="12.0 (24)S4"/><vers num="12.0 (24)S1"/><vers num="12.0 (23)S5"/><vers num="12.0 (23)S4"/><vers num="12.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.1" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.9" CVSS_score="7.1" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2008-07-22" name="CVE-2005-1021" published="2005-05-02" seq="2005-1021" severity="High" type="CVE"><desc><descript source="cve">Memory leak in Secure Shell (SSH) in Cisco IOS 12.0 through 12.3, when authenticating against a TACACS+ server, allows remote attackers to cause a denial of service (memory consumption) via an incorrect username or password.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-sa-20050406-ssh.shtml">20050406 Vulnerabilities in Cisco IOS Secure Shell Server</ref><ref source="BID" url="http://www.securityfocus.com/bid/13042">13042</ref><ref patch="1" source="SECTRACK" url="http://www.securitytracker.com/alerts/2005/Apr/1013655.html">1013655</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14854">14854</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19991">cisco-ios-memory-leak-dos(19991)</ref><ref source="OSVDB" url="http://www.osvdb.org/15303">15303</ref></refs><vuln_soft><prod name="IOS" vendor="Cisco"><vers num="12.3 YK"/><vers num="12.3 YJ"/><vers num="12.3 YH"/><vers num="12.3 YG"/><vers num="12.3 YF"/><vers num="12.3 YD"/><vers num="12.3 YA"/><vers num="12.3 XY"/><vers num="12.3 XX"/><vers num="12.3 XW"/><vers num="12.3 XU"/><vers num="12.3 XS"/><vers num="12.3 XR"/><vers num="12.3 XQ"/><vers num="12.3 XM"/><vers num="12.3 XL"/><vers num="12.3 XK"/><vers num="12.3 XJ"/><vers num="12.3 XI"/><vers num="12.3 XH"/><vers num="12.3 XG"/><vers num="12.3 XF"/><vers num="12.3 XE"/><vers num="12.3 XD"/><vers num="12.3 T"/><vers num="12.2 ZA"/><vers num="12.2 YZ"/><vers num="12.2 YX"/><vers num="12.2 YO"/><vers num="12.2 YK"/><vers num="12.2 YE"/><vers num="12.2 XS"/><vers num="12.2 XN"/><vers num="12.2 XF"/><vers num="12.2 XC"/><vers num="12.2 XA"/><vers num="12.2 T"/><vers num="12.2 SZ"/><vers num="12.2 SY"/><vers num="12.2 SXD"/><vers num="12.2 SXB"/><vers num="12.2 SXA"/><vers num="12.2 SX"/><vers num="12.2 SV"/><vers num="12.2 SU"/><vers num="12.2 SEB"/><vers num="12.2 SEA"/><vers num="12.2 SE"/><vers num="12.2 S"/><vers num="12.2 EX"/><vers num="12.2 EWA"/><vers num="12.2 EW"/><vers num="12.2 EU"/><vers num="12.2 DX"/><vers num="12.2 DD"/><vers num="12.2 B"/><vers num="12.2"/><vers num="12.1 YI"/><vers num="12.1 YH"/><vers num="12.1 YF"/><vers num="12.1 YE"/><vers num="12.1 YD"/><vers num="12.1 YC"/><vers num="12.1 YB"/><vers num="12.1 YA"/><vers num="12.1 XV"/><vers num="12.1 XU"/><vers num="12.1 XT"/><vers num="12.1 XR"/><vers num="12.1 XQ"/><vers num="12.1 XP"/><vers num="12.1 XM"/><vers num="12.1 XL"/><vers num="12.1 XI"/><vers num="12.1 XH"/><vers num="12.1 XG"/><vers num="12.1 XF"/><vers num="12.1 XE"/><vers num="12.1 XD"/><vers num="12.1 T"/><vers num="12.1 EX"/><vers num="12.1 EW"/><vers num="12.1 EU"/><vers num="12.1 EC"/><vers num="12.1 EB"/><vers num="12.1 EA"/><vers num="12.1 E"/><vers num="12.1 DC"/><vers num="12.1 DB"/><vers num="12.1 AZ"/><vers num="12.1 AX"/><vers num="12.0 SX"/><vers num="12.0 S"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1022" published="2005-05-02" seq="2005-1022" severity="Medium" type="CVE"><desc><descript source="cve">ColdFusion 6.1 Updater 1 places Java .class files under the web root in the /WEB-INF/cfclasses directory, which allows remote attackers to obtain sensitive information.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CONFIRM" url="http://www.macromedia.com/devnet/security/security_zone/mpsb05-02.html">http://www.macromedia.com/devnet/security/security_zone/mpsb05-02.html</ref><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111290407411801&amp;w=2">20050607 Macromedia Security Bulletin - ColdFusion MX 6.1</ref></refs><vuln_soft><prod name="ColdFusion" vendor="Macromedia"><vers num="6.1 Updater 1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-25" name="CVE-2005-1023" published="2005-05-02" seq="2005-1023" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in PHP-Nuke 6.x to 7.6 allow remote attackers to inject arbitrary web script or HTML via the (1) min parameter to the Search module, (2) the categories parameter to the FAQ module, or (3) the ltr parameter to the Encyclopedia module.  NOTE: the bid parameter issue in banners.php is already an item in CVE-2005-1000.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111263454308478&amp;w=2">20050403 Full path disclosure and XSS in PHPNuke</ref><ref source="MISC" url="http://www.securityreason.com/adv/PHPNuke%206.x-7.6-p1.txt">http://www.securityreason.com/adv/PHPNuke%206.x-7.6-p1.txt</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19952">phpnuke-modulesphp-xss(19952)</ref></refs><vuln_soft><prod name="PHP-Nuke" vendor="Francisco Burzi"><vers num="6.0"/><vers num="6.5 RC3"/><vers num="6.5 RC2"/><vers num="6.5 RC1"/><vers num="6.5 FINAL"/><vers num="6.5 Beta1"/><vers num="6.5"/><vers num="6.6"/><vers num="6.7"/><vers num="6.9"/><vers num="7.0 FINAL"/><vers num="7.0"/><vers num="7.1"/><vers num="7.2"/><vers num="7.3"/><vers num="7.4"/><vers num="7.5"/><vers num="7.6"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1024" published="2005-05-02" seq="2005-1024" severity="Medium" type="CVE"><desc><descript source="cve">modules.php in PHP-Nuke 6.x to 7.6 allows remote attackers to obtain sensitive information via a direct request to (1) my_headlines, (2) userinfo, or (3) search, which reveals the path in a PHP error message.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111263454308478&amp;w=2">20050403 Full path disclosure and XSS in PHPNuke</ref><ref adv="1" patch="1" source="MISC" url="http://www.securityreason.com/adv/PHPNuke%206.x-7.6-p1.txt">http://www.securityreason.com/adv/PHPNuke%206.x-7.6-p1.txt</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19953">phpnuke-modulesphp-path-disclosure(19953)</ref></refs><vuln_soft><prod name="PHP-Nuke" vendor="Francisco Burzi"><vers num="6.0"/><vers num="6.5 RC3"/><vers num="6.5 RC2"/><vers num="6.5 RC1"/><vers num="6.5 FINAL"/><vers num="6.5 Beta1"/><vers num="6.5"/><vers num="6.6"/><vers num="6.7"/><vers num="6.9"/><vers num="7.0 FINAL"/><vers num="7.0"/><vers num="7.1"/><vers num="7.2"/><vers num="7.3"/><vers num="7.4"/><vers num="7.5"/><vers num="7.6"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1025" published="2005-05-02" seq="2005-1025" severity="Medium" type="CVE"><desc><descript source="cve">The FTP server in AS/400 4.3, when running in IFS mode, allows remote attackers to obtain sensitive information via a symlink attack using RCMD and the ADDLNK utility, as demonstrated using the QSYS.LIB library.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111264136829017&amp;w=2">20050404 Disclosure of AS/400 user accounts via the FTP server</ref><ref source="MISC" url="http://www.venera.com/downloads/AS400_user_accounts_ftp_disclosure.pdf">http://www.venera.com/downloads/AS400_user_accounts_ftp_disclosure.pdf</ref><ref source="OSVDB" url="http://www.osvdb.org/15300">15300</ref></refs><vuln_soft><prod name="iSeries" vendor="IBM"><vers num="AS_400 4.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1026" published="2005-05-02" seq="2005-1026" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in SnailSource phpBB 2.0.x mods allow remote attackers to execute arbitrary SQL commands via the (1) file_id parameter to dlman.php in DLMan Pro or (2) id parameter to links.php in Linkz Pro (aka LinksLinks Pro).</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111272430128195&amp;w=2">20050404 SQL INJECTION in DLMan Pro.  PHPBB Mod.</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111271895819594&amp;w=2">20050404 SQL INJECTION in LinksLinks Pro.  PHPBB Mod.</ref><ref source="BID" url="http://www.securityfocus.com/bid/13028">13028</ref><ref source="BID" url="http://www.securityfocus.com/bid/13030">13030</ref><ref source="CONFIRM" url="http://www.snailsource.com/forum/dlman.php?func=file_info&amp;file_id=77">http://www.snailsource.com/forum/dlman.php?func=file_info&amp;file_id=77</ref></refs><vuln_soft><prod name="Linkz Pro" vendor="Linkz Pro"><vers num="1.0.3 beta2"/></prod><prod name="DLMan Pro" vendor="DLMan Pro"><vers num="0.9.8"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1027" published="2005-05-02" seq="2005-1027" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in PHP-Nuke 6.x through 7.6 allow remote attackers to inject arbitrary web script or HTML via the (1) username parameter in the Your_Account module, (2) avatarcategory parameter in the Your_Account module, or (3) lid parameter in the Downloads module.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111272010303144&amp;w=2">20050404 [SECURITYREASON.COM] Full path disclosure and XSS in PHPNuke part 3</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/321324">20030511 PHPNuke &quot;Your Account&quot; XSS Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/7570">7570</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/11994">phpnuke-modules-xss(11994)</ref></refs><vuln_soft><prod name="PHP-Nuke" vendor="Francisco Burzi"><vers num="6.0"/><vers num="6.5 RC3"/><vers num="6.5 RC2"/><vers num="6.5 RC1"/><vers num="6.5 FINAL"/><vers num="6.5 Beta1"/><vers num="6.5"/><vers num="6.6"/><vers num="6.7"/><vers num="6.9"/><vers num="7.0 FINAL"/><vers num="7.0"/><vers num="7.1"/><vers num="7.2"/><vers num="7.3"/><vers num="7.4"/><vers num="7.5"/><vers num="7.6"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1028" published="2005-05-02" seq="2005-1028" severity="Medium" type="CVE"><desc><descript source="cve">PHP-Nuke 6.x through 7.6 allows remote attackers to obtain sensitive information via a direct request to (1) index.php with the forum_admin parameter set, (2) the Surveys module, or (3) the Your_Account module, which reveals the path in a PHP error message.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111272010303144&amp;w=2">20050404 [SECURITYREASON.COM] Full path disclosure and XSS in PHPNuke part 3</ref></refs><vuln_soft><prod name="PHP-Nuke" vendor="Francisco Burzi"><vers num="6.0"/><vers num="6.5 RC3"/><vers num="6.5 RC2"/><vers num="6.5 RC1"/><vers num="6.5 FINAL"/><vers num="6.5 Beta1"/><vers num="6.5"/><vers num="6.6"/><vers num="6.7"/><vers num="6.9"/><vers num="7.0 FINAL"/><vers num="7.0"/><vers num="7.1"/><vers num="7.2"/><vers num="7.3"/><vers num="7.4"/><vers num="7.5"/><vers num="7.6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1029" published="2005-04-06" seq="2005-1029" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in Active Auction House allow remote attackers to execute arbitrary SQL commands via the (1) catid, (2) SortDir, or (3) Sortby parameter to default.asp, (4) itemID parameter to ItemInfo.asp, or (5) Email field to sendpassword.asp.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111280834000432&amp;w=2">20050406 Active Auction House has multiple Sql injection, error and XSS</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/13032">13032</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/13034">13034</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/13035">13035</ref><ref adv="1" source="SECTRACK" url="http://www.securitytracker.com/alerts/2005/Apr/1013649.html">1013649</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/14839">14839</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19977">aah-multiple-scripts-sql-injection(19977)</ref><ref source="OSVDB" url="http://www.osvdb.org/15281">15281</ref><ref source="OSVDB" url="http://www.osvdb.org/15282">15282</ref><ref source="OSVDB" url="http://www.osvdb.org/15283">15283</ref></refs><vuln_soft><prod name="Active Auction House" vendor="Active Web Softwares"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1030" published="2005-05-02" seq="2005-1030" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Active Auction House allow remote attackers to inject arbitrary web script or HTML via the (1) ReturnURL, (2) password, (3) username parameter, (4) ReturnURL parameter to account.asp, (5) Table, (6) Title parameter to sendpassword.asp, or (7) itemid to watchthisitem.asp.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111280834000432&amp;w=2">20050406 Active Auction House has multiple Sql injection, error and XSS</ref><ref source="BID" url="http://www.securityfocus.com/bid/13036">13036</ref><ref source="BID" url="http://www.securityfocus.com/bid/13038">13038</ref><ref source="BID" url="http://www.securityfocus.com/bid/13039">13039</ref><ref source="SECTRACK" url="http://www.securitytracker.com/alerts/2005/Apr/1013649.html">1013649</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/14839">14839</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19975">aah-multiple-scripts-xss(19975)</ref><ref source="OSVDB" url="http://www.osvdb.org/15284">15284</ref><ref source="OSVDB" url="http://www.osvdb.org/15285">15285</ref><ref source="OSVDB" url="http://www.osvdb.org/15286">15286</ref><ref source="OSVDB" url="http://www.osvdb.org/15287">15287</ref></refs><vuln_soft><prod name="Active Auction House" vendor="Active Web Softwares"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1031" published="2005-05-02" seq="2005-1031" severity="Medium" type="CVE"><desc><descript source="cve">RUNCMS 1.1A, and possibly other products based on e-Xoops (exoops), when &quot;Allow custom avatar upload&quot; is enabled, does not properly verify uploaded files, which allows remote attackers to upload arbitrary files.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111280711228450&amp;w=2">20050406 runcms/e-xoops 1.1A and below file upload vulnerability</ref><ref source="CONFIRM" url="http://www.runcms.org/public/modules/news/">http://www.runcms.org/public/modules/news/</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/13027">13027</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14869">14869</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/20001">exoops-runcms-upload-files(20001)</ref></refs><vuln_soft><prod name="E-Xoops" vendor="E-Xoops"><vers num="1.05r3"/></prod><prod name="RunCMS" vendor="RunCMS"><vers num="1.1a"/><vers num="1.1"/></prod></vuln_soft></entry><entry modified="2006-03-08" name="CVE-2005-1032" published="2005-04-06" reject="1" seq="2005-1032" type="CVE"><desc><descript source="cve">** REJECT **  cart.php in LiteCommerce might allow remote attackers to obtain sensitive information via invalid (1) category_id or (2) product_id parameters.  NOTE: this issue was originally claimed to be due to SQL injection, but the original researcher is known to be frequently inaccurate with respect to bug type and severity.  The vendor has disputed this issue, saying &quot;These reports are credited to malicious person we refused to hire. We have not taken legal action against him only because he is located in India.  The vulnerabilites reported can not be reproduced, hence information you provide is contrary to fact.&quot; Further investigation by CVE personnel shows that an invalid SQL syntax error could be generated, but it only reveals portions of underlying database structure, which is already available in documentation from the vendor, and it does not appear to lead to path disclosure.  Therefore, this issue is not a vulnerability or an exposure, and it probably should be REJECTED.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111281524405632&amp;w=2">20050406 LiteCommerce Sql injection and reveling errors vulnerability</ref><ref source="" url="http://digitalparadox.org/advisories/lico.txt"></ref><ref source="" url="http://www.litecommerce.com/news.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/13044">13044</ref><ref source="OSVDB" url="http://www.osvdb.org/15314">15314</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14857">14857</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19998">litecommerce-cart-sql-injection(19998)</ref></refs></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1033" published="2005-05-02" seq="2005-1033" severity="Medium" type="CVE"><desc><descript source="cve">CubeCart 2.0.6 allows remote attackers to obtain sensitive information via an invalid (1) language parameter to index.php, (2) PHPSESSID parameter to index.php, (3) product parameter to tellafriend.php, (4) add parameter to view_cart.php, or (5) product parameter to view_product.php, which reveals the path in a PHP error message.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111281457918479&amp;w=2">20050406 [NOBYTES.COM: #6] CubeCart 2.0.6 - Information Disclosure</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013660">1013660</ref><ref source="OSVDB" url="http://www.osvdb.org/14064">14064</ref></refs><vuln_soft><prod name="CubeCart" vendor="Devellion"><vers num="2.0.6"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1034" published="2005-05-02" seq="2005-1034" severity="Medium" type="CVE"><desc><descript source="cve">SurgeFTP 2.2m1 allows remote attackers to cause a denial of service (application hang) via the LEAK command.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111289226204780&amp;w=2">20050407 [SIG^2 G-TEC] SurgeFTP LEAK Command Denial-Of-Service Vulnerability</ref><ref adv="1" source="MISC" url="http://www.security.org.sg/vuln/surgeftp22m1.html">http://www.security.org.sg/vuln/surgeftp22m1.html</ref><ref source="BID" url="http://www.securityfocus.com/bid/13054">13054</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013664">1013664</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14888">14888</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/20011">surgeftp-leak-ftp-dos(20011)</ref></refs><vuln_soft><prod name="SurgeFTP" vendor="NetWin"><vers num="2.2m1"/><vers num="2.2k3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1035" published="2005-04-05" seq="2005-1035" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in Pavuk before 0.9.32 have unknown attack vectors and impact.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CONFIRM" url="http://sourceforge.net/project/shownotes.php?release_id=313436">http://sourceforge.net/project/shownotes.php?release_id=313436</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14571">14571</ref></refs><vuln_soft><prod name="Pavuk" vendor="Pavuk"><vers num="0.9.31"/><vers num="0.9 pl30b"/><vers num="0.9 pl28"/><vers num="0.9pl28i"/><vers num="0.928r2"/><vers num="0.928r1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1036" published="2005-05-02" seq="2005-1036" severity="High" type="CVE"><desc><descript source="cve">FreeBSD 5.x to 5.4 on AMD64 does not properly initialize the IO permission bitmap used to allow user access to certain hardware, which allows local users to bypass intended access restrictions to cause a denial of service, obtain sensitive information, and possibly gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/><design/></vuln_types><range><local/></range><refs><ref source="FREEBSD" url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-05:03.amd64.asc">FreeBSD-SA-05:03</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="5.0"/><vers num="5.1"/><vers num="5.2"/><vers num="5.2.1"/><vers num="5.3"/><vers num="5.4"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1037" published="2005-05-02" seq="2005-1037" severity="High" type="CVE"><desc><descript source="cve">Unknown vulnerability in AIX 5.3.0, when configured as an NIS client, allows remote attackers to gain root privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY68825&amp;apar=only">IY68825</ref><ref adv="1" patch="1" source="MISC" url="http://www.niscc.gov.uk/niscc/docs/br-20050405-00278.html?lang=en">http://www.niscc.gov.uk/niscc/docs/br-20050405-00278.html?lang=en</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/14856">14856</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="5.3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1038" published="2005-05-02" seq="2005-1038" severity="Low" type="CVE"><desc><descript source="cve">crontab in Vixie cron 4.1, when running with the -e option, allows local users to read the cron files of other users by changing the file being edited to a symlink.  NOTE: there is insufficient information to know whether this is a duplicate of CVE-2001-0235.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/395093">20050406 crontab from vixie-cron allows read other users crontabs</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/13024">13024</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-361.html">RHSA-2005:361</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0117.html">RHSA-2006:0117</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20060401-01-U">20060401-01-U</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19532">19532</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-118.htm"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/20666">
20666</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_007_suse.html">
SUSE-SR:2007:007</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24995">
24995</ref></refs><vuln_soft><prod name="Vixie Cron" vendor="Paul Vixie"><vers num="4.1"/></prod><prod name="Enterprise Linux" vendor="Red Hat"><vers edition="Workstation" num="4.0"/><vers edition="Enterprise Server" num="4.0"/><vers edition="Advanced Server" num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="3.7" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="6.4" CVSS_score="3.7" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1039" published="2005-05-02" seq="2005-1039" severity="Low" type="CVE"><desc><descript source="cve">Race condition in Core Utilities (coreutils) 5.2.1, when (1) mkdir, (2) mknod, or (3) mkfifo is running with the -m switch, allows local users to modify permissions of other files.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><race/></vuln_types><range><local/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/13053">13053</ref></refs><vuln_soft><prod name="Coreutils" vendor="GNU"><vers num="5.2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1040" published="2005-05-02" seq="2005-1040" severity="High" type="CVE"><desc><descript source="cve">Multiple unknown vulnerabilities in netapplet in Novell Linux Desktop 9 allow local users to gain root privileges, related to &quot;User input [being] passed to network scripts without verification.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" source="SUSE" url="http://lists.suse.com/archive/suse-security-announce/2005-Apr/0002.html">SUSE-SR:2005:010</ref></refs><vuln_soft><prod name="Linux Desktop" vendor="Novell"><vers num="9"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1041" published="2005-05-02" seq="2005-1041" severity="Low" type="CVE"><desc><descript source="cve">The fib_seq_start function in fib_hash.c in Linux kernel allows local users to cause a denial of service (system crash) via /proc/net/route.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref patch="1" source="MLIST" url="http://marc.theaimsgroup.com/?l=bk-commits-head&amp;m=111186506706769&amp;w=2">[bk-commits-head] 20050319 [PATCH] Fix crash while reading /proc/net/route</ref><ref source="BID" url="http://www.securityfocus.com/bid/13267">13267</ref><ref source="SUSE" url="http://www.securityfocus.com/archive/1/archive/1/419522/100/0/threaded">SUSE-SA:2005:068</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17918">17918</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-366.html">RHSA-2005:366</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/427980/100/0/threaded">FLSA:157459-3</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1042" published="2005-05-02" seq="2005-1042" severity="High" type="CVE"><desc><descript source="cve">Integer overflow in the exif_process_IFD_TAG function in exif.c in PHP before 4.3.11 may allow remote attackers to execute arbitrary code via an IFD tag that leads to a negative byte count.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref patch="1" source="CONFIRM" url="http://cvs.php.net/diff.php/php-src/ext/exif/exif.c?r1=1.118.2.33&amp;r2=1.118.2.34&amp;ty=u">http://cvs.php.net/diff.php/php-src/ext/exif/exif.c?r1=1.118.2.33&amp;r2=1.118.2.34&amp;ty=u</ref><ref source="CONFIRM" url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=154021">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=154021</ref><ref patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200504-15.xml">GLSA-200504-15</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:072">MDKSA-2005:072</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-405.html">RHSA-2005:405</ref><ref patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111352585618473&amp;w=2">20050414 [USN-112-1] PHP4 vulnerabilities</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-406.html">RHSA-2005:406</ref><ref adv="1" source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-112-1">USN-112-1</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/Jun/msg00000.html">APPLE-SA-2005-06-08</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:072">MDKSA-2005:072</ref></refs><vuln_soft><prod name="PHP" vendor="PHP"><vers num="4.3.9"/><vers num="4.3.8"/><vers num="4.3.7"/><vers num="4.3.6"/><vers num="4.3.5"/><vers num="4.3.4"/><vers num="4.3.3"/><vers num="4.3.2"/><vers num="4.3.10"/><vers num="4.3.1"/><vers num="4.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1043" published="2005-04-14" seq="2005-1043" severity="Medium" type="CVE"><desc><descript source="cve">exif.c in PHP before 4.3.11 allows remote attackers to cause a denial of service (memory consumption and crash) via an EXIF header with a large IFD nesting level, which causes significant stack recursion.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="CONFIRM" url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=154025">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=154025</ref><ref adv="1" source="CONFIRM" url="http://cvs.php.net/diff.php/php-src/ext/exif/exif.c?r1=1.118.2.29&amp;r2=1.118.2.30&amp;ty=u">http://cvs.php.net/diff.php/php-src/ext/exif/exif.c?r1=1.118.2.29&amp;r2=1.118.2.30&amp;ty=u</ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200504-15.xml">GLSA-200504-15</ref><ref adv="1" patch="1" source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:072">MDKSA-2005:072</ref><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111352585618473&amp;w=2">20050414 [USN-112-1] PHP4 vulnerabilities</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-406.html">RHSA-2005:406</ref><ref adv="1" patch="1" source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-112-1">USN-112-1</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/Jun/msg00000.html">APPLE-SA-2005-06-08</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:072">MDKSA-2005:072</ref></refs><vuln_soft><prod name="SuSE Linux" vendor="SuSE"><vers num="9.3"/><vers edition="x86_64" num="9.2"/><vers num="9.2"/><vers edition="x86_64" num="9.1"/><vers num="9.1"/><vers edition="x86_64" num="9.0"/><vers num="9.0"/><vers num="8.2"/><vers num="8.1"/><vers edition="i386" num="8.0"/><vers num="8.0"/><vers edition="sparc" num="7.3"/><vers edition="ppc" num="7.3"/><vers edition="i386" num="7.3"/><vers num="7.3"/><vers edition="i386" num="7.2"/><vers num="7.2"/><vers edition="x86" num="7.1"/><vers edition="spa" num="7.1"/><vers edition="sparc" num="7.1"/><vers num="7.1 alpha"/><vers num="7.1"/><vers edition="sparc" num="7.0"/><vers edition="ppc" num="7.0"/><vers edition="i386" num="7.0"/><vers num="7.0 alpha"/><vers num="7.0"/><vers edition="ppc" num="6.4"/><vers edition="i386" num="6.4"/><vers num="6.4 alpha"/><vers num="6.4"/><vers edition="ppc" num="6.3"/><vers num="6.3 alpha"/><vers num="6.3"/><vers num="6.2"/><vers num="6.1 alpha"/><vers num="6.1"/><vers num="6.0"/><vers num="5.3"/><vers num="5.2"/><vers num="5.1"/><vers num="5.0"/><vers num="4.4.1"/><vers num="4.4"/><vers num="4.3"/><vers num="4.2"/><vers num="4.0"/><vers num="3.0"/><vers num="2.0"/><vers num="1.0"/></prod><prod name="Mac OS X Server" vendor="Apple"><vers num="10.4.1"/><vers num="10.4"/><vers num="10.3.9"/></prod><prod name="Conectiva Linux" vendor="Conectiva"><vers num="10.0"/><vers num="9.0"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.4.1"/><vers num="10.4"/><vers num="10.3.9"/></prod><prod name="Peachtree Linux" vendor="Peachtree"><vers num="release 1"/></prod><prod name="ProPack" vendor="SGI"><vers num="3.0"/></prod><prod name="PHP" vendor="PHP"><vers num="4.3.10"/><vers num="4.3.9"/><vers num="4.3.8"/><vers num="4.3.7"/><vers num="4.3.6"/><vers num="4.3.5"/><vers num="4.3.4"/><vers num="4.3.3"/><vers num="4.3.2"/><vers num="4.3.1"/><vers num="4.3"/></prod></vuln_soft></entry><entry modified="2005-10-25" name="CVE-2005-1044" published="2005-05-02" reject="1" seq="2005-1044" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2005-0941.  Reason: This candidate is a duplicate of CVE-2005-0941.  Notes: All CVE users should reference CVE-2005-0941 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript></desc><refs/></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-05" name="CVE-2005-1045" published="2005-05-02" seq="2005-1045" severity="High" type="CVE"><desc><descript source="cve">OpenText FirstClass 8.0 client does not properly sanitize strings before passing them to the Windows ShellExecute API, which allows remote attackers to execute arbitrary commands via a UNC path in a bookmark.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111323587931293&amp;w=2">20050408 OpenText FirstClass 8.0 Client Arbitrary File Execution</ref><ref source="BID" url="http://www.securityfocus.com/bid/13079">13079</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/14898/">14898</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20032">firstclass-bookmark-command-execution(20032)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013665">1013665</ref><ref source="OSVDB" url="http://www.osvdb.org/15356">15356</ref></refs><vuln_soft><prod name="Centrinity FirstClass Desktop Client" vendor="Centrinity"><vers num="8.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1046" published="2005-05-02" seq="2005-1046" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the kimgio library for KDE 3.4.0 allows remote attackers to execute arbitrary code via a crafted PCX image file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_22_kdelibs3.html">SuSE-SA:2005:022</ref><ref adv="1" source="MISC" url="http://bugs.kde.org/show_bug.cgi?id=102328">http://bugs.kde.org/show_bug.cgi?id=102328</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14908">14908</ref><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-714">DSA-714</ref><ref adv="1" patch="1" source="MISC" url="http://www.frsirt.com/english/advisories/2005/0331">http://www.frsirt.com/english/advisories/2005/0331</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-393.html">RHSA-2005:393</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/427976/100/0/threaded">FLSA:178606</ref><ref source="" url="http://www.kde.org/info/security/advisory-20050421-1.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/13096">
13096</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-103170-1">103170</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/4241">ADV-2007-4241</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28114">28114</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-201320-1">201320</ref></refs><vuln_soft><prod name="KDE" vendor="KDE"><vers num="3.4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1047" published="2005-04-07" seq="2005-1047" severity="High" type="CVE"><desc><descript source="cve">Meilad File upload script (up.php) mod for phpBB 2.0.x does not properly limit the types of files that can be uploaded, which allows remote authenticated users to execute arbitrary commands by uploading PHP files, then directly requesting them from the uploads directory.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111299353030534&amp;w=2">20050408 phpBB Upload Script </ref><ref adv="1" source="SECTRACK" url="http://securitytracker.com/id?1013671">1013671</ref></refs><vuln_soft><prod name="phpBB" vendor="phpBB Group"><vers num="2.0.9"/><vers num="2.0.8a"/><vers num="2.0.8"/><vers num="2.0.7a"/><vers num="2.0.7"/><vers num="2.0.6d"/><vers num="2.0.6c"/><vers num="2.0.6"/><vers num="2.0.5"/><vers num="2.0.4"/><vers num="2.0.3"/><vers num="2.0.2"/><vers num="2.0.14"/><vers num="2.0.13"/><vers num="2.0.12"/><vers num="2.0.11"/><vers num="2.0.10"/><vers num="2.0.1"/><vers num="2.0.0"/><vers num="2.0 RC4"/><vers num="2.0 RC3"/><vers num="2.0 RC2"/><vers num="2.0 RC1"/><vers num="2.0 Beta1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-04-07" name="CVE-2005-1048" published="2005-05-02" seq="2005-1048" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in modules.php in PostNuke 0.760 RC3 allows remote attackers to execute arbitrary SQL statements via the sid parameter.  NOTE: the vendor reports that they could not reproduce the issues for 760 RC3, or for .750.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111298226029957&amp;w=2">20050408 Sql injection, xss and path disclosure vulnerabilities in PostNuke 0.760-RC3</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/14868/">14868</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20019">postnuke-sid-sql-injection(20019)</ref><ref source="MISC" url="http://news.postnuke.com/modules.php?op=modload&amp;name=News&amp;file=article&amp;sid=2679">http://news.postnuke.com/modules.php?op=modload&amp;name=News&amp;file=article&amp;sid=2679</ref><ref source="OSVDB" url="http://www.osvdb.org/15371">15371</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013670">1013670</ref></refs><vuln_soft><prod name="PostNuke" vendor="PostNuke Software Foundation"><vers num="0.760 RC3"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-04-07" name="CVE-2005-1049" published="2005-05-02" seq="2005-1049" severity="Low" type="CVE"><desc><descript source="cve">Multiple cross-site scripting vulnerabilities in PostNuke 0.760-RC3 allow remote attackers to inject arbitrary web script or HTML via the (1) module parameter to admin.php or (2) op parameter to user.php. NOTE: the vendor reports that certain issues could not be reproduced for 760 RC3, or for .750.  However, the op/user.php issue exists when the pnAntiCracker setting is disabled.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111298226029957&amp;w=2">20050408 Sql injection, xss and path disclosure vulnerabilities in PostNuke 0.760-RC3</ref><ref patch="1" source="MISC" url="http://cvs.postnuke.com/viewcvs.cgi/Historic_PostNuke_Library/postnuke-devel/html/user.php.diff?r1=1.18&amp;r2=1.19">http://cvs.postnuke.com/viewcvs.cgi/Historic_PostNuke_Library/postnuke-devel/html/user.php.diff?r1=1.18&amp;r2=1.19</ref><ref source="BID" url="http://www.securityfocus.com/bid/13075">13075</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/13076">13076</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14868/">14868</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20018">postnuke-adminphp-userphp-xss(20018)</ref><ref adv="1" patch="1" source="MISC" url="http://news.postnuke.com/modules.php?op=modload&amp;name=News&amp;file=article&amp;sid=2679">http://news.postnuke.com/modules.php?op=modload&amp;name=News&amp;file=article&amp;sid=2679</ref><ref source="OSVDB" url="http://www.osvdb.org/15370">15370</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013670">1013670</ref></refs><vuln_soft><prod name="PostNuke" vendor="PostNuke Software Foundation"><vers num="0.760 RC3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-04-07" name="CVE-2005-1050" published="2005-05-02" seq="2005-1050" severity="Medium" type="CVE"><desc><descript source="cve">The modload op in the Reviews module for PostNuke 0.760-RC3 allows remote attackers to obtain sensitive information via an invalid id parameter, which reveals the path in a PHP error message.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111298226029957&amp;w=2">20050408 Sql injection, xss and path disclosure vulnerabilities in PostNuke 0.760-RC3</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20020">postnuke-modules-full-path-disclosure(20020)</ref><ref source="" url="http://digitalparadox.org/advisories/postnuke.txt"></ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013670">1013670</ref></refs><vuln_soft><prod name="PostNuke" vendor="PostNuke Software Foundation"><vers num="0.760 RC3"/></prod></vuln_soft></entry><entry CVSS_base_score="6.5" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="6.4" CVSS_score="6.5" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-02-13" name="CVE-2005-1051" published="2005-05-02" seq="2005-1051" severity="Medium" type="CVE"><desc><descript source="cve">SQL injection vulnerability in profile.php in PunBB 1.2.4 allows remote authenticated users to execute arbitrary SQL commands via the id parameter in a change_email action.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111306207306155&amp;w=2">20050408 PunBB &lt;= 1.2.4 - change email to become admin exploit</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/13071">13071</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14882">14882</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111306207306155&amp;w=2">20050408 PunBB &lt;= 1.2.4 - change email to become admin exploit</ref></refs><vuln_soft><prod name="PunBB" vendor="PunBB"><vers num="1.2.4"/><vers num="1.2.3"/><vers num="1.2.2"/><vers num="1.2.1"/><vers num="1.1.5"/><vers num="1.1.4"/><vers num="1.1.3"/><vers num="1.1.2"/><vers num="1.1.1"/><vers num="1.1"/><vers num="1.0.1"/><vers num="1.0 RC2"/><vers num="1.0 RC1"/><vers num="1.0 Beta3"/><vers num="1.0 Beta2"/><vers num="1.0 Beta1"/><vers num="1.0 alpha"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1052" published="2005-05-02" seq="2005-1052" severity="Medium" type="CVE"><desc><descript source="cve">Microsoft Outlook 2003 and Outlook Web Access (OWA) 2003 do not properly display comma separated addresses in the From field in an e-mail message, which could allow remote attackers to spoof e-mail addresses.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=227&amp;type=vulnerabilities">20050408 Microsoft Multiple E-Mail Client Address Spoofing Vulnerability</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20026">owa-email-spoofing(20026)</ref></refs><vuln_soft><prod name="Outlook Web Access" vendor="Microsoft"><vers num="2003"/></prod><prod name="Outlook" vendor="Microsoft"><vers num="2003"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-21" name="CVE-2005-1053" published="2005-05-02" seq="2005-1053" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in orderwiz.php in ModernBill 4.3.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) c_code or (2) aid parameters.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111323741032183&amp;w=2">20050410 Multiple ModernBill 4.3.0 And Earlier Vulnerabilities</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1013672">1013672</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/14890">14890</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20035">modernbill-orderwiz-xss(20035)</ref><ref source="OSVDB" url="http://www.osvdb.org/15426">15426</ref></refs><vuln_soft><prod name="ModernBill" vendor="ModernGigabyte"><vers num="4.3.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-21" name="CVE-2005-1054" published="2005-05-02" seq="2005-1054" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in news.php in ModernBill 4.3.0 and earlier allows remote attackers to execute arbitrary PHP code by modifying the DIR parameter to reference a URL on a remote web server that contains the code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111323741032183&amp;w=2">20050410 Multiple ModernBill 4.3.0 And Earlier Vulnerabilities</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1013672">1013672</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/14890">14890</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20036">modernbill-news-file-include(20036)</ref><ref source="OSVDB" url="http://www.osvdb.org/15427">15427</ref></refs><vuln_soft><prod name="ModernBill" vendor="ModernGigabyte"><vers num="4.3.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1055" published="2005-04-10" seq="2005-1055" severity="High" type="CVE"><desc><descript source="cve">TowerBlog 0.6 and earlier stores the login data file under the web root, which allows remote attackers to obtain the MD5 checksums of the username and password via a direct request to the _dat/login file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111323802003019&amp;w=2">20050410 TowerBlog &lt;= 0.6 Admin Account View [x0n3-h4ck]</ref><ref adv="1" patch="1" source="SECTRACK" url="http://securitytracker.com/id?1013675">1013675</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/14884">14884</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/20039">towerblog-datlogin-information-disclosure(20039)</ref><ref source="OSVDB" url="http://www.osvdb.org/15425">15425</ref></refs><vuln_soft><prod name="TowerBlog" vendor="TowerBlog"><vers num="0.6 r1"/><vers num="0.6"/><vers num="0.4 r1"/><vers num="0.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1056" published="2005-05-02" seq="2005-1056" severity="Medium" type="CVE"><desc><descript source="cve">Unknown vulnerability in HP OpenView Network Node Manager (NMM) 6.2 through 6.4, and 7.01 through 7.50, allows remote attackers to cause a denial of service.</descript></desc><loss_types><avail/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref adv="1" source="HP" url="http://www.securityfocus.com/advisories/8372">HPSBMA01125</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/14865">14865</ref><ref source="BID" url="http://www.securityfocus.com/bid/13029">13029</ref><ref source="OSVDB" url="http://www.osvdb.org/15321">15321</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013651">1013651</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19993">openview-network-node-manager-dos(19993)</ref></refs><vuln_soft><prod name="OpenView Network Node Manager" vendor="HP"><vers num="6.2"/><vers num="6.31"/><vers num="6.4"/><vers num="7.01"/><vers num="7.50"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1057" published="2005-05-02" seq="2005-1057" severity="High" type="CVE"><desc><descript source="cve">Cisco IOS 12.2T, 12.3 and 12.3T, when using Easy VPN Server XAUTH version 6 authentication, allows remote attackers to bypass authentication via a &quot;malformed packet.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-sa-20050406-xauth.shtml">20050406 Vulnerabilities in the Internet Key Exchange Xauth Implementation</ref></refs><vuln_soft><prod name="IOS" vendor="Cisco"><vers num="12.2T"/><vers num="12.3"/><vers num="12.3T"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1058" published="2005-05-02" seq="2005-1058" severity="High" type="CVE"><desc><descript source="cve">Cisco IOS 12.2T, 12.3 and 12.3T, when processing an ISAKMP profile that specifies XAUTH authentication after Phase 1 negotiation, may not process certain attributes in the ISAKMP profile that specifies XAUTH, which allows remote attackers to bypass XAUTH and move to Phase 2 negotiations.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-sa-20050406-xauth.shtml">20050406 Vulnerabilities in the Internet Key Exchange Xauth Implementation</ref></refs><vuln_soft><prod name="IOS" vendor="Cisco"><vers num="12.2T"/><vers num="12.3"/><vers num="12.3T"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1059" published="2005-05-02" seq="2005-1059" severity="Low" type="CVE"><desc><descript source="cve">Linksys WET11 1.5.4 allows remote attackers to change the password without providing the original password via the data parameter to changepw.html.</descript></desc><loss_types><int/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="FULLDISC" url="http://www.derkeiler.com/Mailing-Lists/Full-Disclosure/2005-04/0148.html">20050407 Cisco Linksys WET11 Password Resetting Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/13051">13051</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/14871">14871</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20008">linksys-wet11-security-bypass(20008)</ref></refs><vuln_soft><prod name="WET11" vendor="Linksys"><vers num="1.5.4"/><vers num="1.4.3"/><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1060" published="2005-05-02" seq="2005-1060" severity="Medium" type="CVE"><desc><descript source="cve">Unknown vulnerability in the TCP/IP functionality (TCPIP.NLM) in Novell Netware 6.x allows remote attackers to cause a denial of service (ABEND by Page Fault Processor Exception) via certain packets.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/13067">13067</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14874">14874</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20024">novell-netware-tcpipnlm-dos(20024)</ref></refs><vuln_soft><prod name="Netware" vendor="Novell"><vers num="6.5 SP1.1b"/><vers num="6.5 SP1.1a"/><vers num="6.5 SP3"/><vers num="6.5 SP2"/><vers num="6.5 SP1"/><vers num="6.5"/><vers num="6.0 SP3"/><vers num="6.0 SP2"/><vers num="6.0 SP1"/><vers num="6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1061" published="2005-05-02" seq="2005-1061" severity="Medium" type="CVE"><desc><descript source="cve">The secure script in LogWatch before 2.6-2 allows attackers to prevent LogWatch from detecting malicious activity via certain strings in the secure file that are later used as part of a regular expression, which causes the parser to crash, aka &quot;logwatch log processing regular expression DoS.&quot;</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-364.html">RHSA-2005:364</ref><ref source="CONFIRM" url="https://bugzilla.redhat.com/bugzilla-old/show_bug.cgi?id=137502">https://bugzilla.redhat.com/bugzilla-old/show_bug.cgi?id=137502</ref></refs><vuln_soft><prod name="Enterprise Linux AS" vendor="Red Hat"><vers edition="Advanced Server" num="2.1"/></prod><prod name="Enterprise Linux WS" vendor="Red Hat"><vers edition="Workstation" num="2.1"/></prod><prod name="Enterprise Linux ES" vendor="Red Hat"><vers edition="Enterprise Server" num="2.1"/></prod><prod name="LogWatch" vendor="LogWatch"><vers num="2.6.2"/></prod><prod name="Linux Advanced Workstation" vendor="Red Hat"><vers edition="Itanium" num="2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-27" name="CVE-2005-1062" published="2005-05-02" seq="2005-1062" severity="High" type="CVE"><desc><descript source="cve">The administration protocol for Kerio WinRoute Firewall 6.x up to 6.0.10, Personal Firewall 4.x up to 4.1.2, and MailServer up to 6.0.8 allows remote attackers to quickly obtain passwords that are 5 characters or less via brute force methods.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="Universidade de Coruna" url="http://research.tic.udc.es/scg/advisories/20050429-1.txt"> http://research.tic.udc.es/scg/advisories/20050429-1.txt</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/397221">20050429 [CAN-2005-1062] Administration protocol abuse allows local/remote password cracking</ref><ref adv="1" source="CONFIRM" url="http://www.kerio.com/security_advisory.html">http://www.kerio.com/security_advisory.html</ref><ref source="" url="http://research.tic.udc.es/scg/advisories/20050429-1.txt"></ref></refs><vuln_soft><prod name="Kerio MailServer" vendor="Kerio"><vers num="6.0.8"/><vers num="6.0.7"/><vers num="6.0.6"/><vers num="6.0.5"/><vers num="6.0.4"/><vers num="6.0.3"/><vers num="6.0.2"/><vers num="6.0.1"/><vers num="6.0.0"/></prod><prod name="WinRoute Firewall" vendor="Kerio"><vers num="6.0.10"/><vers num="6.0.9"/><vers num="6.0.8"/><vers num="6.0.7"/><vers num="6.0.6"/><vers num="6.0.5"/><vers num="6.0.4"/><vers num="6.0.3"/><vers num="6.0.2"/><vers num="6.0.1"/><vers num="6.0.0"/></prod><prod name="Personal Firewall" vendor="Kerio"><vers num="4.1.2"/><vers num="4.1.1"/><vers num="4.1.0"/><vers num="4.0.16"/><vers num="4.0.15"/><vers num="4.0.14"/><vers num="4.0.13"/><vers num="4.0.12"/><vers num="4.0.11"/><vers num="4.0.10"/><vers num="4.0.9"/><vers num="4.0.8"/><vers num="4.0.7"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-27" name="CVE-2005-1063" published="2005-04-29" seq="2005-1063" severity="Medium" type="CVE"><desc><descript source="cve">The administration protocol for Kerio WinRoute Firewall 6.x up to 6.0.10, Personal Firewall 4.x up to 4.1.2, and MailServer up to 6.0.8 allows remote attackers to cause a denial of service (CPU consumption) via certain attacks that force the product to &quot;compute unexpected conditions&quot; and &quot;perform cryptographic operations.&quot;</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/397220">20050429 [CAN-2005-1063] Administration protocol abuse leads to Service and System Denial of Service</ref><ref adv="1" patch="1" source="CONFIRM" url="http://www.kerio.com/security_advisory.html">http://www.kerio.com/security_advisory.html</ref></refs><vuln_soft><prod name="Kerio Mailserver" vendor="Kerio"><vers num="6.0.5"/><vers num="6.0.4"/><vers num="6.0.3"/><vers num="6.0.2"/><vers num="6.0.1"/><vers num="6.0"/></prod><prod name="WinRoute Firewall" vendor="Kerio"><vers num="6.0.9"/><vers num="6.0.8"/><vers num="6.0.7"/><vers num="6.0.6"/><vers num="6.0.5"/><vers num="6.0.4"/><vers num="6.0.3"/><vers num="6.0.2"/><vers num="6.0.1"/><vers num="6.0"/></prod><prod name="Personal Firewall" vendor="Kerio"><vers num="4.1.2"/><vers num="4.1.1"/><vers num="4.1"/><vers num="4.0.16"/><vers num="4.0.10"/><vers num="4.0.9"/><vers num="4.0.8"/><vers num="4.0.7"/><vers num="4.0.6"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1064" published="2005-04-10" seq="2005-1064" severity="Medium" type="CVE"><desc><descript source="cve">The copy_symlink function in rsnapshot 1.2.0 and 1.1.x before 1.1.7 changes the ownership of files that a symlink points to rather than the symlink itself, which allows local users to obtain access to arbitrary files.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=111317179531000&amp;w=2">20050410 rsnapshot Security Advisory 001</ref><ref adv="1" patch="1" source="CONFIRM" url="http://www.rsnapshot.org/security/2005/001.html">http://www.rsnapshot.org/security/2005/001.html</ref><ref adv="1" patch="1" source="SECTRACK" url="http://securitytracker.com/id?1013674">1013674</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14878">14878</ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200504-12.xml">GLSA-200504-12</ref><ref source="OSVDB" url="http://www.osvdb.org/15420">15420</ref></refs><vuln_soft><prod name="filesystem snapshot utility" vendor="rsnapshot"><vers num="1.2"/><vers num="1.1.6"/><vers num="1.1.5"/><vers num="1.1.4"/><vers num="1.1.3"/><vers num="1.1.2"/><vers num="1.1.1"/><vers num="1.1"/><vers num="1.0.10"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1065" published="2005-05-02" seq="2005-1065" severity="Low" type="CVE"><desc><descript source="cve">tetex in Novell Linux Desktop 9 allows local users to determine the existence of arbitrary files via a symlink attack in the /var/cache/fonts directory.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="SUSE" url="http://lists.suse.com/archive/suse-security-announce/2005-Apr/0002.html">SUSE-SR:2005:010</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/13072">13072</ref></refs><vuln_soft><prod name="Linux Desktop" vendor="Novell"><vers num="9"/></prod></vuln_soft></entry><entry CVSS_base_score="1.2" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="2.9" CVSS_score="1.2" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1066" published="2005-05-02" seq="2005-1066" severity="Low" type="CVE"><desc><descript source="cve">Race condition in rpdump in Pine 4.62 and earlier allows local users to overwrite arbitrary files via a symlink attack.</descript></desc><loss_types><int/></loss_types><vuln_types><race/></vuln_types><range><local/></range><refs><ref adv="1" source="BUGTRAQ" url="http://msgs.securepoint.com/cgi-bin/get/bugtraq0504/126.html">20050411 rpdump TOCTOU file-permissions vulnerability</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/14899">14899</ref><ref source="OSVDB" url="http://www.osvdb.org/15456">15456</ref></refs><vuln_soft><prod name="Pine" vendor="University of Washington"><vers num="4.62"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1067" published="2005-04-08" seq="2005-1067" severity="High" type="CVE"><desc><descript source="cve">Vulnerability in Access_user Class before 1.75 allows local users to gain access as other users via the password &quot;new&quot;.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CONFIRM" url="http://freshmeat.net/projects/access_user/?branch_id=53852&amp;release_id=192770">http://freshmeat.net/projects/access_user/?branch_id=53852&amp;release_id=192770</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14897">14897</ref><ref source="OSVDB" url="http://www.osvdb.org/15348">15348</ref></refs><vuln_soft><prod name="Access_user Class" vendor="Access_user Class"><vers num="1.6"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1068" published="2005-05-02" seq="2005-1068" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in sCssBoard 1.11 and earlier allows remote attackers to execute arbitrary Javascript via [url] tags.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="CONFIRM" url="http://sourceforge.net/project/shownotes.php?release_id=318346">http://sourceforge.net/project/shownotes.php?release_id=318346</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/13041">13041</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1013659">1013659</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14694">14694</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/20021">scssboard-url-tag-xss(20021)</ref></refs><vuln_soft><prod name="sCssBoard" vendor="sCssBoard"><vers num="1.11"/><vers num="1.1"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1069" published="2005-05-02" seq="2005-1069" severity="High" type="CVE"><desc><descript source="cve">Unknown vulnerability in sCssBoard 1.11 and earlier has unknown impact, related to &quot;an exploit on the Profile page.&quot;</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref patch="1" source="CONFIRM" url="http://sourceforge.net/project/shownotes.php?release_id=318346">http://sourceforge.net/project/shownotes.php?release_id=318346</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1013659">1013659</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14694">14694</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/20022">scssboard-profile-unknown(20022)</ref></refs><vuln_soft><prod name="sCssBoard" vendor="sCssBoard"><vers num="1.11"/><vers num="1.1"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1070" published="2005-04-11" seq="2005-1070" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in index.php in Invision Power Board 1.3.1 Final and earlier allows remote attackers to execute arbitrary SQL commands via the st parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/395515">20050411 Invision board 1.3.1 and below are vulnerable to a sql injection vulnerability [PATCH INCLUDED]</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/13097">13097</ref><ref adv="1" source="SECTRACK" url="http://www.securitytracker.com/alerts/2005/Apr/1013676.html">1013676</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/20059">invision-memberlist-sql-injection(20059)</ref></refs><vuln_soft><prod name="Invision Board" vendor="Invision Power Services"><vers num="1.3.1 Final"/><vers num="1.3 Final"/><vers num="1.3"/><vers num="1.2"/><vers num="1.1.2"/><vers num="1.1.1"/><vers num="1.0.1"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-22" name="CVE-2005-1071" published="2005-04-12" seq="2005-1071" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in banner.inc.php in JPortal Web Portal 2.3.1 allows remote attackers to execute arbitrary SQL commands via the haslo parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/14919">14919</ref><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111331738223323&amp;w=2">20050412 Sql injection in jPortal version 2.3.1 (module banner)</ref><ref source="OSVDB" url="http://www.osvdb.org/15476">15476</ref></refs><vuln_soft><prod name="JPortal Web Portal" vendor="JPortal"><vers num="2.3.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1072" published="2005-04-08" seq="2005-1072" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in PunBB before 1.2.5 allows remote attackers to inject arbitrary web script or HTML.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CONFIRM" url="http://www.punbb.org/">http://www.punbb.org/</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14882">14882</ref></refs><vuln_soft><prod name="PunBB" vendor="PunBB"><vers num="1.2.4"/><vers num="1.2.3"/><vers num="1.2.2"/><vers num="1.2.1"/><vers num="1.1.5"/><vers num="1.1.4"/><vers num="1.1.3"/><vers num="1.1.2"/><vers num="1.1.1"/><vers num="1.1"/><vers num="1.0.1"/><vers num="1.0 RC2"/><vers num="1.0 RC1"/><vers num="1.0 Beta3"/><vers num="1.0 Beta2"/><vers num="1.0 Beta1"/><vers num="1.0 alpha"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1073" published="2005-05-02" seq="2005-1073" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in index.php for RadScripts RadBids Gold 2 allows remote attackers to read arbitrary files via the read parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/395527">20050409 Directory transversal, sql injection and xss vulnerabilities in RadBids Gold v2</ref><ref source="BID" url="http://www.securityfocus.com/bid/13080">13080</ref><ref source="OSVDB" url="http://www.osvdb.org/15428">15428</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/14906">14906</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20038">radbids-gold-php-xss(20038)</ref></refs><vuln_soft><prod name="RadBids Gold" vendor="RadScripts"><vers num="2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1074" published="2005-05-02" seq="2005-1074" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in index.php for RadScripts RadBids Gold 2 allows remote attackers to execute arbitrary SQL commands via the mode parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/395527">20050409 Directory transversal, sql injection and xss vulnerabilities in RadBids Gold v2</ref><ref source="BID" url="http://www.securityfocus.com/bid/13080">13080</ref><ref source="OSVDB" url="http://www.osvdb.org/15429">15429</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/14906">14906</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20040">radbids-gold-index-sql-injection(20040)</ref></refs><vuln_soft><prod name="RadBids Gold" vendor="RadScripts"><vers num="2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1075" published="2005-05-02" seq="2005-1075" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in RadScripts RadBids Gold 2 allow remote attackers to inject arbitrary web script or HTML via (1) the farea parameter to faq.php or the (2) cat, (3) order, or (4) area parameters to index.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/395527">20050409 Directory transversal, sql injection and xss vulnerabilities in RadBids Gold v2</ref><ref source="BID" url="http://www.securityfocus.com/bid/13080">13080</ref><ref source="OSVDB" url="http://www.osvdb.org/15430">15430</ref><ref source="OSVDB" url="http://www.osvdb.org/15431">15431</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/14906">14906</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20038">radbids-gold-php-xss(20038)</ref></refs><vuln_soft><prod name="RadBids Gold" vendor="RadScripts"><vers num="2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-05-01" name="CVE-2005-1076" published="2005-05-02" seq="2005-1076" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in the discussion board functionality for WebCT Campus Edition 4.1 allows remote attackers to inject arbitrary web script or HTML via the message field.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/395544">20050411 WebCT 4.1 vulnerable to XSS attacks</ref><ref source="BID" url="http://www.securityfocus.com/bid/13101">13101</ref></refs><vuln_soft><prod name="WebCT" vendor="WebCT"><vers num="Campus 4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1077" published="2005-04-12" seq="2005-1077" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in XAMPP 1.4.x allow remote attackers to inject arbitrary web script or HTML via (1) cds.php, (2) Guestbook-EN.pl, or (3) phonebook.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=111330048629182&amp;w=2">20050412 XAMPP</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/13126">13126</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/13127">13127</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/13128">13128</ref></refs><vuln_soft><prod name="Apache Distribution" vendor="XAMPP"><vers edition="Solaris" num="0.3"/><vers edition="Solaris" num="0.2"/><vers edition="Solaris" num="0.1"/><vers num="1.4.13"/><vers num="1.4.12"/><vers num="1.4.11"/><vers num="1.4.10a"/><vers num="1.4.10"/><vers num="1.4.9"/><vers num="1.4.8"/><vers num="1.4.7"/><vers num="1.4.6"/><vers num="1.4.5"/><vers num="1.4.4"/><vers num="1.4.3"/><vers num="1.4.2"/><vers num="1.4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1078" published="2005-04-12" seq="2005-1078" severity="High" type="CVE"><desc><descript source="cve">XAMPP 1.4.x has multiple default or null passwords, which allows attackers to gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=111330048629182&amp;w=2">20050412 XAMPP</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/13131">13131</ref></refs><vuln_soft><prod name="Apache Distribution" vendor="XAMPP"><vers edition="Solaris" num="0.3"/><vers edition="Solaris" num="0.2"/><vers edition="Solaris" num="0.1"/><vers num="1.4.13"/><vers num="1.4.12"/><vers num="1.4.11"/><vers num="1.4.10a"/><vers num="1.4.10"/><vers num="1.4.9"/><vers num="1.4.8"/><vers num="1.4.7"/><vers num="1.4.6"/><vers num="1.4.5"/><vers num="1.4.4"/><vers num="1.4.3"/><vers num="1.4.2"/><vers num="1.4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1079" published="2005-05-02" seq="2005-1079" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in index.php for zOOm Media Gallery 2.1.2 allows remote attackers to execute arbitrary SQL commands via the catid parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://www.securiteam.com/unixfocus/5LP0G0AFFY.html">http://www.securiteam.com/unixfocus/5LP0G0AFFY.html</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/14929">14929</ref><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111340031132596&amp;w=2">20050413 zOOM Media Gallery - Simple SQL Injection discovery</ref></refs><vuln_soft><prod name="zOOm Media Gallery" vendor="Mike de Boer"><vers num="2.1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1080" published="2005-05-02" seq="2005-1080" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in the Java Archive Tool (Jar) utility in J2SE SDK 1.4.2, 1.5 allows remote attackersto write arbitrary files via a .. (dot dot) in filenames in a .jar file.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://www.securiteam.com/securitynews/5IP0C0AFGW.html">http://www.securiteam.com/securitynews/5IP0C0AFGW.html</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/14902">14902</ref><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111331593310508&amp;w=2">20050412 7a69Adv#23 - Jar tool directory transversal vulnerability</ref></refs><vuln_soft><prod name="SDK" vendor="Sun"><vers num="1.5"/><vers num="1.4.2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1081" published="2005-05-02" seq="2005-1081" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in view.php in AzDGDatingPlatinum 1.1.0 allows remote attackers to inject arbitrary web script or HTML via the id parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/395530">20050409 AzDGDatingPlatinum multiple vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/13082">13082</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20052">azdgdating-platinum-viewphp-xss(20052)</ref></refs><vuln_soft><prod name="AzDGDating" vendor="Azerbaijan Development Group"><vers edition="Platinum" num="1.1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1082" published="2005-04-09" seq="2005-1082" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in AzDGDatingPlatinum 1.1.0 allows remote attackers to execute arbitrary SQL commands via (1) the id parameter to view.php or (2) the from parameter to members/index.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/395530">20050409 AzDGDatingPlatinum multiple vulnerabilities</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/13082">13082</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/20051">azdgdating-platinum-sql-injection(20051)</ref><ref source="OSVDB" url="http://www.osvdb.org/15525">15525</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/438607/100/100/threaded">20060628 AzDGDatingPlatinum&lt;&lt;--v1.1.0 &quot;view.php&quot; SQL Injection</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/27436">
azdgdatingplatinum-view-sql-injection(27436)</ref></refs><vuln_soft><prod name="AzDGDating" vendor="Azerbaijan Development Group"><vers edition="Platinum" num="1.1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1083" published="2005-05-02" seq="2005-1083" severity="Medium" type="CVE"><desc><descript source="cve">index.php in aeDating 3.2 allows remote attackers to include arbitrary files via the skin parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/14913">14913</ref></refs><vuln_soft><prod name="aeDating" vendor="AEwebworks"><vers num="3.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1084" published="2005-05-02" seq="2005-1084" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in sdating.php in aeDating 3.2 allows remote attackers to execute arbitrary SQL commands files via the event parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/14913">14913</ref></refs><vuln_soft><prod name="aeDating" vendor="AEwebworks"><vers num="3.2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1085" published="2005-05-02" seq="2005-1085" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in the control panel in aeDating 3.2 allows remote attackers to inject arbitrary web script or HTML.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/14913">14913</ref></refs><vuln_soft><prod name="aeDating" vendor="AEwebworks"><vers num="3.2"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1086" published="2005-05-02" seq="2005-1086" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in the cmdIS.DLL plugin for AN HTTPD Server 1.42n allows remote attackers to execute arbitrary code via an HTTP request with a long User-Agent header.</descript></desc><loss_types><avail/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://www.security.org.sg/vuln/anhttpd142n.html">http://www.security.org.sg/vuln/anhttpd142n.html</ref><ref source="BID" url="http://www.securityfocus.com/bid/13066">13066</ref><ref source="OSVDB" url="http://www.osvdb.org/15361">15361</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013666">1013666</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/14861">14861</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20029">an-httpd-cmdisdll-bo(20029)</ref></refs><vuln_soft><prod name="AN-HTTPD" vendor="AN"><vers num="1.42n"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1087" published="2005-04-07" seq="2005-1087" severity="Medium" type="CVE"><desc><descript source="cve">CRLF injection vulnerability in the cmdIS.DLL plugin for AN HTTPD Server 1.42n allows remote attackers to spoof or hide entries in the logfile, and possibly read files using an injected type command, via CRLF sequences in an HTTP request.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://www.security.org.sg/vuln/anhttpd142n.html">http://www.security.org.sg/vuln/anhttpd142n.html</ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/15362">15362</ref><ref adv="1" source="SECTRACK" url="http://securitytracker.com/id?1013666">1013666</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/14861">14861</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/20031">an-httpd-logfile-character-injection(20031)</ref></refs><vuln_soft><prod name="AN-HTTPD" vendor="AN"><vers num="1.42n"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1088" published="2005-05-02" seq="2005-1088" severity="High" type="CVE"><desc><descript source="cve">Unknown vulnerability in DameWare NT Utilities 4.8 and earlier, and Mini Remote Control 4.8 and earlier, allows local users to gain additional rights.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><other/></vuln_types><range><local/></range><refs><ref adv="1" source="CONFIRM" url="http://www.dameware.com/support/security/bulletin.asp?ID=SB5">http://www.dameware.com/support/security/bulletin.asp?ID=SB5</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/13023">13023</ref><ref source="OSVDB" url="http://www.osvdb.org/15275">15275</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1013653">1013653</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14829">14829</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19997">dameware-elevated-privileges(19997)</ref><ref source="OSVDB" url="http://www.osvdb.org/18732">18732</ref></refs><vuln_soft><prod name="NT Utilities" vendor="DameWare Development"><vers num="4.8"/><vers num="4.7"/><vers num="4.6"/><vers num="4.5"/><vers num="4.4"/><vers num="4.3"/><vers num="4.2"/><vers num="4.1"/><vers num="4.0"/><vers num="3.74.0.0"/><vers num="3.73.0.0"/><vers num="3.72.0.0"/><vers num="3.71.0.0"/><vers num="3.70"/><vers num="3.69"/><vers num="3.68.0.0"/><vers num="3.67"/><vers num="3.66.0.0"/><vers num="3.65.0.0"/><vers num="3.64.0.0"/><vers num="3.63.0.0"/><vers num="3.62.0.0"/><vers num="3.61.0.0"/><vers num="3.60.0.0"/><vers num="3.51"/><vers num="3.50"/><vers num="3.49"/><vers num="3.48.0.0"/><vers num="3.46.0.0"/><vers num="3.45.0.0"/><vers num="3.44.0.0"/><vers num="3.43.0.0"/><vers num="3.42.0.0"/><vers num="3.41.0.0"/><vers num="3.21.0.0"/><vers num="3.2.0.0"/><vers num="3.1.0.0"/><vers num="3.0.0.0"/></prod><prod name="Mini Remote Control" vendor="DameWare Development"><vers num="4.8"/><vers num="4.7"/><vers num="4.6"/><vers num="4.5"/><vers num="4.4"/><vers num="4.3"/><vers num="4.2"/><vers num="4.1"/><vers num="4.0"/><vers num="3.74"/><vers num="3.73"/><vers num="3.72"/><vers num="3.71"/><vers num="3.70"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1089" published="2005-04-11" seq="2005-1089" severity="Medium" type="CVE"><desc><descript source="cve">Unknown vulnerability in DC++ before 0.674 allows attackers to append data to arbitrary files.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CONFIRM" url="http://dcplusplus.sourceforge.net/index.php?t=8&amp;s=1">http://dcplusplus.sourceforge.net/index.php?t=8&amp;s=1</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14880">14880</ref><ref source="OSVDB" url="http://www.osvdb.org/15433">15433</ref></refs><vuln_soft><prod name="DC++" vendor="DC++"><vers num="0.673" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1090" published="2005-05-02" seq="2005-1090" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in the readFile and writeFile API for Maxthon 1.2.0 and 1.2.1 allows remote attackers to read or write arbitrary files.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://www.raffon.net/advisories/maxthon/multvulns.html">http://www.raffon.net/advisories/maxthon/multvulns.html</ref><ref source="BID" url="http://www.securityfocus.com/bid/13074">13074</ref><ref source="OSVDB" url="http://www.osvdb.org/15423">15423</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14918">14918</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20033">maxthon-directory-traversal(20033)</ref></refs><vuln_soft><prod name="Maxthon" vendor="Maxthon"><vers num="1.2.0"/><vers num="1.2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1091" published="2005-05-02" seq="2005-1091" severity="High" type="CVE"><desc><descript source="cve">Maxthon 1.2.0 and 1.2.1 allows remote attackers to bypass the security ID and use restricted plugin API functions via script that includes the max.src file into the source page.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="MISC" url="http://www.raffon.net/advisories/maxthon/multvulns.html">http://www.raffon.net/advisories/maxthon/multvulns.html</ref><ref source="BID" url="http://www.securityfocus.com/bid/13073">13073</ref><ref source="OSVDB" url="http://www.osvdb.org/15424">15424</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14918">14918</ref></refs><vuln_soft><prod name="Maxthon" vendor="Maxthon"><vers num="1.2.1"/><vers num="1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1092" published="2005-05-02" seq="2005-1092" severity="High" type="CVE"><desc><descript source="cve">Lightspeed DeluxeFTP 6.01 stores usernames and passwords in plaintext in sites.xml, which is world-readable, which allows local users to gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/><design/></vuln_types><range><local/></range><refs><ref adv="1" source="MISC" url="http://lostmon.blogspot.com/2005/04/deluxeftp-plain-text-passwords.html">http://lostmon.blogspot.com/2005/04/deluxeftp-plain-text-passwords.html</ref><ref source="BID" url="http://www.securityfocus.com/bid/13105">13105</ref><ref source="OSVDB" url="http://www.osvdb.org/15421">15421</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/14923">14923</ref></refs><vuln_soft><prod name="DeluxeFTP" vendor="Light Speed Technology"><vers num="6.0.1"/><vers num="7.0.1 beta"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1093" published="2005-05-02" seq="2005-1093" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the PopUp Plus 2.0.3.8 plugin for Miranda IM, with &quot;Use SmileyAdd Setting&quot; enabled, allows remote attackers to execute arbitrary code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://sec.org.il/coverages.php?c=89">http://sec.org.il/coverages.php?c=89</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/13048">13048</ref><ref source="OSVDB" url="http://www.osvdb.org/15482">15482</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013661">1013661</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20013">popupplus-message-bo(20013)</ref><ref adv="1" source="MISC" url="http://forums.miranda-im.org/showthread.php?t=1070">http://forums.miranda-im.org/showthread.php?t=1070</ref><ref patch="1" source="CONFIRM" url="http://forums.miranda-im.org/showthread.php?p=9624">http://forums.miranda-im.org/showthread.php?p=9624</ref><ref source="CONFIRM" url="http://www.miranda-im.org/">http://www.miranda-im.org/</ref></refs><vuln_soft><prod name="PopUp Plus Plugin for Miranda IM" vendor="PopUp Plus Plugin"><vers num="2.0.3.8"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1094" published="2005-04-08" seq="2005-1094" severity="Medium" type="CVE"><desc><descript source="cve">FTP Now 2.6.14 stores usernames and passwords in plaintext in sites.xml, which is world-readable, which allows local users to gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="SECTRACK" url="http://securitytracker.com/id?1013657">1013657</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/14889">14889</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/20025">ftpnow-sites-information-disclosure(20025)</ref><ref source="OSVDB" url="http://www.osvdb.org/15296">15296</ref></refs><vuln_soft><prod name="FTP Now" vendor="Network-Client.com"><vers num="2.6.14"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-08-28" name="CVE-2005-1095" published="2005-05-02" seq="2005-1095" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in main.asp for Ocean12 Membership Manager Pro 1.x allows remote attackers to inject arbitrary web script or HTML via the page parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MISC" url="http://www.hackerscenter.com/archive/view.asp?id=1865">http://www.hackerscenter.com/archive/view.asp?id=1865</ref><ref source="BID" url="http://www.securityfocus.com/bid/13046">13046</ref><ref source="OSVDB" url="http://www.osvdb.org/15306">15306</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013667">1013667</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/14864">14864</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20014">ocean12-membershipmgr-mainasp-xss(20014)</ref></refs><vuln_soft><prod name="Membership Manager Pro" vendor="Ocean12 Technologies"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-08-28" name="CVE-2005-1096" published="2005-04-06" seq="2005-1096" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in main.asp for Ocean12 Membership Manager Pro 1.x allows remote attackers to execute arbitrary SQL commands via the UserID parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://www.hackerscenter.com/archive/view.asp?id=1865">http://www.hackerscenter.com/archive/view.asp?id=1865</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/13049">13049</ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/15307">15307</ref><ref adv="1" source="SECTRACK" url="http://securitytracker.com/id?1013667">1013667</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/14864">14864</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/20015">ocean12-membershipmgr-mainasp-sql-injection(20015)</ref></refs><vuln_soft><prod name="Membership Manager Pro" vendor="Ocean12 Technologies"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1097" published="2005-05-02" seq="2005-1097" severity="Medium" type="CVE"><desc><descript source="cve">Rebrand P2P Share Spy 2.2 stores the user password in plaintext in the txtPassword value in the registry, which allows local users to gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="SECTRACK" url="http://securitytracker.com/id?1013673">1013673</ref></refs><vuln_soft><prod name="P2P Share Spy" vendor="Rebrand"><vers num="2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1098" published="2005-05-02" seq="2005-1098" severity="Low" type="CVE"><desc><descript source="cve">GetDataBack for NTFS 2.31 stores the username and license key in plaintext in the Name value in the License registry key, which may allow local users to obtain sensitive information.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="OSVDB" url="http://www.osvdb.org/15210">15210</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013644">1013644</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19967">getdataback-ntfs-information-disclosure(19967)</ref></refs><vuln_soft><prod name="GetDataBack for NTFS" vendor="Runtime Software"><vers num="2.31"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1099" published="2005-04-12" seq="2005-1099" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in the HandleChild function in server.c in Greylisting daemon (GLD) 1.3 and 1.4, when GLD is listening on a network interface, allow remote attackers to execute arbitrary code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111339935903880&amp;w=2">20050412 GLD (Greylisting daemon for Postfix) multiple vulnerabilities.</ref><ref adv="1" patch="1" source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200504-10.xml">GLSA-200504-10</ref><ref adv="1" patch="1" source="OSVDB" url="http://www.osvdb.org/15492">15492</ref><ref adv="1" source="SECTRACK" url="http://securitytracker.com/alerts/2005/Apr/1013678.html">1013678</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14941">14941</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/20066">gld-serverc-bo(20066)</ref><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111342432325670&amp;w=2">20050413 Gld 1.5 released (security fix)</ref><ref adv="1" source="CONFIRM" url="http://www.gasmi.net/down/gld-history">http://www.gasmi.net/down/gld-history</ref></refs><vuln_soft><prod name="GLD" vendor="Salim Gasmi"><vers num="1.4"/><vers num="1.3.1"/><vers num="1.3"/><vers num="1.2"/><vers num="1.1"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-05" name="CVE-2005-1100" published="2005-05-02" seq="2005-1100" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in the ErrorLog function in cnf.c in Greylisting daemon (GLD) 1.3 and 1.4 allows remote attackers to execute arbitrary code via format string specifiers in data that is passed directly to syslog.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111339935903880&amp;w=2">20050412 GLD (Greylisting daemon for Postfix) multiple vulnerabilities.</ref><ref patch="1" source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200504-10.xml">GLSA-200504-10</ref><ref source="OSVDB" url="http://www.osvdb.org/15493">15493</ref><ref source="SECTRACK" url="http://securitytracker.com/alerts/2005/Apr/1013678.html">1013678</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/14941">14941</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20067">gld-cnfc-format-string(20067)</ref></refs><vuln_soft><prod name="GLD" vendor="Salim Gasmi"><vers num="1.3"/><vers num="1.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1101" published="2005-05-02" seq="2005-1101" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in Lotus Domino Server 6.0.5 and 6.5.4 allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via large amounts of data in certain (1) time or (2) date fields.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111335285121320&amp;w=2">20050412 Remote Buffer Overflow in Lotus Domino</ref><ref adv="1" patch="1" source="MISC" url="http://www.ngssoftware.com/advisories/lotus-01.txt">http://www.ngssoftware.com/advisories/lotus-01.txt</ref><ref patch="1" source="CONFIRM" url="http://www-1.ibm.com/support/docview.wss?rs=463&amp;uid=swg21202431">http://www-1.ibm.com/support/docview.wss?rs=463&amp;uid=swg21202431</ref><ref source="OSVDB" url="http://www.osvdb.org/15364">15364</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/14879/">14879</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/20042">lotus-timedate-bo(20042)</ref></refs><vuln_soft><prod name="Lotus Domino Server" vendor="IBM"><vers num="6.0.5"/><vers num="6.5.4"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1102" published="2005-05-02" seq="2005-1102" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in template-functions-post.php in WordPress 1.5 and earlier allow remote attackers to execute arbitrary commands via the (1) content or (2) title of the post.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111336102101571&amp;w=2">20050412 WordPress XSS and HTML injection</ref><ref adv="1" patch="1" source="MISC" url="http://wordpress.org/support/topic.php?id=30721">http://wordpress.org/support/topic.php?id=30721</ref><ref adv="1" patch="1" source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200506-04.xml">GLSA-200506-04</ref><ref source="CONFIRM" url="http://bugs.gentoo.org/show_bug.cgi?id=88926">http://bugs.gentoo.org/show_bug.cgi?id=88926</ref></refs><vuln_soft><prod name="WordPress" vendor="WordPress"><vers num="1.5" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-08-24" name="CVE-2005-1103" published="2005-04-12" seq="2005-1103" severity="Medium" type="CVE"><desc><descript source="cve">Sygate Security Agent (SSA) in Sygate Secure Enterprise 3.5 through 4.1 does not prevent the security policy from being updated by unprivileged users, which allows local users to modify the policy by exporting the policy file, changing it, and importing it back into SSA.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><access/><input/></vuln_types><range><local/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111335219201828&amp;w=2">20050412 IRM 011: Sygate,Security Agent (Sygate Secure Enterprise) Fail Open</ref></refs><vuln_soft><prod name="Security Agent" vendor="Sygate Technologies"><vers num="4.1"/><vers num="4.0"/><vers num="3.5 build 2577"/><vers num="3.5 build 2576"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1104" published="2005-05-02" seq="2005-1104" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Centra 7 allow remote attackers to inject arbitrary web script or HTML via the (1) username, (2) first name, or (3) last name fields.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111335198125566&amp;w=2">20050412 Centra 7 XSS Exploit</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/14930">14930</ref></refs><vuln_soft><prod name="Centra" vendor="Centra"><vers num="7"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1105" published="2005-05-02" seq="2005-1105" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in the MimeBodyPart.getFileName method in JavaMail 1.3.2 allows remote attackers to write arbitrary files via a .. (dot dot) in the filename in the Content-Disposition header.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111335615600839&amp;w=2">20050412 JavaMail allows directory traversal in attachments</ref></refs><vuln_soft><prod name="JavaMail" vendor="Sun"><vers num="1.3.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1106" published="2005-05-02" seq="2005-1106" severity="Medium" type="CVE"><desc><descript source="cve">PictureViewer in QuickTime for Windows 6.5.2 allows remote attackers to cause a denial of service (application crash) via a GIF image with the maximum depth start value, possibly triggering an integer overflow.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111335498626164&amp;w=2">20050413 QuickTime for Windows malformed GIF DoS</ref></refs><vuln_soft><prod name="QuickTime PictureViewer" vendor="Apple"><vers num="6.5.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-09-27" name="CVE-2005-1107" published="2005-04-18" seq="2005-1107" severity="High" type="CVE"><desc><descript source="cve">McAfee Internet Security Suite 2005 uses insecure default ACLs for installed files, which allows local users to gain privileges or disable protection by modifying certain files.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=233&amp;type=vulnerabilities">20050418 McAfee Internet Security Suite 2005 Insecure File Permission Vulnerability</ref></refs><vuln_soft><prod name="McAfee Internet Security Suite" vendor="McAfee"><vers num="2005"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1108" published="2005-05-02" seq="2005-1108" severity="Medium" type="CVE"><desc><descript source="cve">The ij_untrusted_url function in JunkBuster 2.0.2-r2, with single-threaded mode enabled, allows remote attackers to overwrite the referrer field via a crafted HTTP request.</descript></desc><loss_types><int/></loss_types><vuln_types><design/><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200504-11.xml">GLSA-200504-11</ref><ref patch="1" source="MISC" url="http://bugs.gentoo.org/show_bug.cgi?id=88537">http://bugs.gentoo.org/show_bug.cgi?id=88537</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/13147">13147</ref><ref source="OSVDB" url="http://www.osvdb.org/15502">15502</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/14932/">14932</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/20093">junkbuster-ijuntrustedurl-gain-access(20093)</ref><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-713">DSA-713</ref></refs><vuln_soft><prod name="Internet JunkBuster" vendor="JunkBuster"><vers num="2.0.2 r2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1109" published="2005-05-02" seq="2005-1109" severity="High" type="CVE"><desc><descript source="cve">The filtering of URLs in JunkBuster before 2.0.2-r3 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via heap corruption.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200504-11.xml">GLSA-200504-11</ref><ref patch="1" source="MISC" url="http://bugs.gentoo.org/show_bug.cgi?id=88537">http://bugs.gentoo.org/show_bug.cgi?id=88537</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/13146">13146</ref><ref source="OSVDB" url="http://www.osvdb.org/15503">15503</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/14932/">14932</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/20094">junkbuster-heap-corruption(20094)</ref><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-713">DSA-713</ref></refs><vuln_soft><prod name="Internet JunkBuster" vendor="JunkBuster"><vers num="2.0.2 r2"/><vers num="2.0.2"/><vers num="2.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1110" published="2005-05-02" seq="2005-1110" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in the RespondeHTTPPendiente function in the HTTP server for SUMUS 0.2.2 allows remote attackers to execute arbitrary code via a large packet sent to TCP port 81.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111350491800089&amp;w=2">20050414 sumus[v0.2.2]: (httpd) remote buffer overflow exploit.</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013717">1013717</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20110">sumus-respondehttppendiente-bo(20110)</ref></refs><vuln_soft><prod name="Sumus" vendor="Sumus"><vers num="0.2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="3.7" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="6.4" CVSS_score="3.7" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1111" published="2005-05-02" seq="2005-1111" severity="Low" type="CVE"><desc><descript source="cve">Race condition in cpio 2.6 and earlier allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by cpio after the decompression is complete.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><race/></vuln_types><range><local/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111342664116120&amp;w=2">20050413 cpio TOCTOU file-permissions vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/13159">13159</ref><ref source="SCO" url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.32/SCOSA-2005.32.txt">SCOSA-2005.32</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval358.html">OVAL358</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-189-1">USN-189-1</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-846">DSA-846</ref><ref source="SCO" url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2006.2/SCOSA-2006.2.txt">SCOSA-2006.2</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18290">18290</ref><ref source="FREEBSD" url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-06:03.cpio.asc">FreeBSD-SA-06:03</ref><ref source="OSVDB" url="http://www.osvdb.org/15725">15725</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18395">18395</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-806.html">RHSA-2005:806</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17123">17123</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17532">17532</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-378.html">RHSA-2005:378</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16998">16998</ref><ref source="SUSE" url="http://lists.suse.com/archive/suse-security-announce/2006-May/0004.html">SUSE-SR:2006:010</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20117">20117</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:358">oval:org.mitre.oval:def:358</ref></refs><vuln_soft><prod name="cpio" vendor="GNU"><vers num="2.6"/><vers num="2.5.90"/><vers num="2.5"/><vers num="2.4.2"/><vers num="1.3"/><vers num="1.2"/><vers num="1.1"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1112" published="2005-05-02" seq="2005-1112" severity="Medium" type="CVE"><desc><descript source="cve">IBM WebSphere Application Server 6.0 and earlier, when sharing the document root of the web server, allows remote attackers to obtain the source code for Java Server Pages (.jsp) via an HTTP request with an invalid Host header, which causes the page to be processed by the web server instead of the JSP engine.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111342594129109&amp;w=2">20050413 IBM WebSphere Widespread configuration JSP disclosure</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/14962">14962</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20099">ibm-websphere-information-disclosure(20099)</ref><ref adv="1" source="SECTRACK" url="http://securitytracker.com/id?1013697">1013697</ref><ref source="OSVDB" url="http://www.osvdb.org/15501">15501</ref><ref source="BID" url="http://www.securityfocus.com/bid/13160">13160</ref></refs><vuln_soft><prod name="WebSphere Application Server" vendor="IBM"><vers num="6.0"/><vers num="5.1.1.3"/><vers num="5.1.1.2"/><vers num="5.1.1.1"/><vers num="5.1.1"/><vers num="5.1.0.5"/><vers num="5.1.0.4"/><vers num="5.1.0.2"/><vers num="5.1.0"/><vers num="5.0.2.9"/><vers num="5.0.2.8"/><vers num="5.0.2.7"/><vers num="5.0.2.6"/><vers num="5.0.2.5"/><vers num="5.0.2.4"/><vers num="5.0.2.3"/><vers num="5.0.2.1"/><vers num="5.0.2"/><vers num="5.0.1"/><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1113" published="2005-05-02" seq="2005-1113" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in PhpBB Plus 1.52 and earlier allow remote attackers to inject arbitrary web script or HTML via the bsid parameter to (1) groupcp.php, (2) index.php, (3) portal.php, (4) viewforum.php, or (5) viewtopic.php, (6) the c parameter to index.php, or (7) the article parameter to portal.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111343406309969&amp;w=2">20050413 Multiple Sql injection and XSS vulnerabilities in phpBB Plus and below and some of its modules</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20085">phpbb-multiple-modules-xss(20085)</ref></refs><vuln_soft><prod name="phpBB Plus" vendor="phpBB Group"><vers num="1.52" prev="1"/><vers num="1.51"/><vers num="1.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1114" published="2005-05-02" seq="2005-1114" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in album_search.php in Photo Album 2.0.53 for phpBB allow remote attackers to execute arbitrary SQL commands via the (1) mode or (2) search parameters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111343406309969&amp;w=2">20050413 Multiple Sql injection and XSS vulnerabilities in phpBB Plus and below and some of its modules</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20086">phpbb-multiple-modules-sql-injection(20086)</ref><ref source="MISC" url="http://www.digitalparadox.org/advisories/phpbbp.txt">http://www.digitalparadox.org/advisories/phpbbp.txt</ref><ref source="BID" url="http://www.securityfocus.com/bid/13155">13155</ref><ref source="OSVDB" url="http://www.osvdb.org/15931">15931</ref></refs><vuln_soft><prod name="Photo Album" vendor="Smartor"><vers num="2.0.53"/></prod><prod name="PhpBB" vendor="PhpBB Group"><vers num="2.0.0"/><vers num="2.0.1"/><vers num="2.0.2"/><vers num="2.0.3"/><vers num="2.0.4"/><vers num="2.0.5"/><vers num="2.0.6"/><vers num="2.0.6c"/><vers num="2.0.6d"/><vers num="2.0.7"/><vers num="2.0.7a"/><vers num="2.0.8"/><vers num="2.0.8a"/><vers num="2.0.9"/><vers num="2.0.10"/><vers num="2.0.11"/><vers num="2.0.12"/><vers num="2.0.13"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1115" published="2005-05-02" seq="2005-1115" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Photo Album 2.0.53 module for phpBB allow remote attackers to inject arbitrary web script or HTML via the bsid parameter to (1) album_cat.php or (2) album_comment.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111343406309969&amp;w=2">20050413 Multiple Sql injection and XSS vulnerabilities in phpBB Plus and below and some of its modules</ref><ref source="BID" url="http://www.securityfocus.com/bid/13157">13157</ref><ref source="BID" url="http://www.securityfocus.com/bid/13158">13158</ref></refs><vuln_soft><prod name="Photo Album" vendor="Smartor"><vers num="2.0.53"/></prod><prod name="PhpBB" vendor="PhpBB Group"><vers num="2.0.0"/><vers num="2.0.1"/><vers num="2.0.2"/><vers num="2.0.3"/><vers num="2.0.4"/><vers num="2.0.5"/><vers num="2.0.6"/><vers num="2.0.6c"/><vers num="2.0.6d"/><vers num="2.0.7"/><vers num="2.0.7a"/><vers num="2.0.8"/><vers num="2.0.8a"/><vers num="2.0.9"/><vers num="2.0.10"/><vers num="2.0.11"/><vers num="2.0.12"/><vers num="2.0.13"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1116" published="2005-05-02" seq="2005-1116" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in the Calendar module for phpBB allow remote attackers to inject arbitrary web script or HTML via the start parameter to calendar_scheduler.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111343406309969&amp;w=2">20050413 Multiple Sql injection and XSS vulnerabilities in phpBB Plus and below and some of its modules</ref></refs><vuln_soft><prod name="phpBB" vendor="phpBB Group"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-28" name="CVE-2005-1117" published="2005-05-02" seq="2005-1117" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in index.php in All4WWW-Homepagecreator 1.0a allows remote attackers to execute arbitrary PHP code by modifying the site parameter to reference a URL on a remote web server that contains the code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111350434925520&amp;w=2">20050414 All4WWW-Homepagecreator Remote Command Execution</ref><ref source="BID" url="http://www.securityfocus.com/bid/13169">13169</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/14972">14972</ref></refs><vuln_soft><prod name="All4WWW-Homepagecreator" vendor="All4WWW"><vers num="1.0a"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1118" published="2005-04-14" seq="2005-1118" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in IISWebAgentIF.dll in the RSA Authentication Agent for Web 5.2 allows remote attackers to inject arbitrary web script or HTML via the postdata parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="MISC" url="http://www.oliverkarow.de/research/rsaxss.txt">http://www.oliverkarow.de/research/rsaxss.txt</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/13168">13168</ref><ref adv="1" patch="1" source="SECTRACK" url="http://securitytracker.com/id?1013724">1013724</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14954">14954</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/20098">rsa-auth-postdata-xss(20098)</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/366372">VU#366372</ref></refs><vuln_soft><prod name="RSA Authentication Agent for Web" vendor="RSA"><vers num="5.2"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1119" published="2005-05-02" seq="2005-1119" severity="Low" type="CVE"><desc><descript source="cve">Sudo VISudo 1.6.8 and earlier allows local users to corrupt arbitrary files via a symlink attack on temporary files.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/13171">13171</ref></refs><vuln_soft><prod name="Sudo" vendor="Todd Miller"><vers num="1.6.8 p8"/><vers num="1.6.8 p1"/><vers num="1.6.8"/><vers num="1.6.7 p5"/><vers num="1.6.7"/><vers num="1.6.6"/><vers num="1.6.5 p2"/><vers num="1.6.5 p1"/><vers num="1.6.5"/><vers num="1.6.4 p2"/><vers num="1.6.4 p1"/><vers num="1.6.4"/><vers num="1.6.3 p7"/><vers num="1.6.3 p6"/><vers num="1.6.3 p5"/><vers num="1.6.3 p4"/><vers num="1.6.3 p3"/><vers num="1.6.3 p2"/><vers num="1.6.3 p1"/><vers num="1.6.3"/><vers num="1.6.2"/><vers num="1.6.1"/><vers num="1.6"/><vers num="1.5.9"/><vers num="1.5.8"/><vers num="1.5.7"/><vers num="1.5.6"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1120" published="2005-05-02" seq="2005-1120" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in IlohaMail 0.8.14 and earlier allow remote attackers to inject arbitrary web script or HTML via the e-mail (1) body, (2) filename, or (3) MIME type.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/13175">13175</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/14957">14957</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20095">ilohamail-mail-attached-file-xss(20095)</ref><ref source="OSVDB" url="http://www.osvdb.org/15506">15506</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013701">1013701</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1010">DSA-1010</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19266">19266</ref></refs><vuln_soft><prod name="IlohaMail" vendor="IlohaMail"><vers num="0.8.14 RC2"/><vers num="0.8.14 RC1"/><vers num="0.8.13"/><vers num="0.8.12"/><vers num="0.8.11"/><vers num="0.8.10"/><vers num="0.8.9"/><vers num="0.8.8"/><vers num="0.8.7"/><vers num="0.8.6"/><vers num="0.7.9"/><vers num="0.7.8"/><vers num="0.7.7"/><vers num="0.7.6"/><vers num="0.7.5"/><vers num="0.7.4.2"/><vers num="0.7.4"/><vers num="0.7.3"/><vers num="0.7.2"/><vers num="0.7.1"/><vers num="0.7.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1121" published="2005-05-02" seq="2005-1121" severity="Medium" type="CVE"><desc><descript source="cve">Format string vulnerability in the my_xlog function in lib.c for Oops! Proxy Server 1.5.23 and earlier, as called by the auth functions in the passwd_mysql and passwd_pgsql modules, may allow attackers to execute arbitrary code via a URL.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/13172">13172</ref><ref adv="1" patch="1" source="MISC" url="http://rst.void.ru/papers/advisory24.txt">http://rst.void.ru/papers/advisory24.txt</ref><ref adv="1" patch="1" source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200505-02.xml">GLSA-200505-02</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20191">oops-format-string(20191)</ref><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-726">DSA-726</ref></refs><vuln_soft><prod name="Linux" vendor="Gentoo"><vers num=""/></prod><prod name="Oops Proxy Server" vendor="Igor Khasilev"><vers num="1.5.53"/><vers num="1.5.19"/><vers num="1.4.22"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1122" published="2005-04-14" seq="2005-1122" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in cgi.c for Monkey daemon (monkeyd) before 0.9.1 allows remote attackers to cause a denial of service and possibly execute arbitrary code via an HTTP GET request containing double-encoded format string specifiers (aka &quot;double expansion error&quot;).</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200504-14.xml">GLSA-200504-14</ref><ref adv="1" source="MISC" url="http://bugs.gentoo.org/show_bug.cgi?id=87916">http://bugs.gentoo.org/show_bug.cgi?id=87916</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14953">14953</ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/15511">15511</ref></refs><vuln_soft><prod name="Monkey HTTP Daemon" vendor="Monkey"><vers num="0.9.0"/><vers num="0.8.2"/><vers num="0.8.1"/><vers num="0.8"/><vers num="0.7.2"/><vers num="0.7.1"/><vers num="0.7.0"/><vers num="0.6.3"/><vers num="0.6.2"/><vers num="0.6.1"/><vers num="0.6"/><vers num="0.5.1"/><vers num="0.5"/><vers num="0.4.2"/><vers num="0.4.1"/><vers num="0.4"/><vers num="0.1.4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-21" name="CVE-2005-1123" published="2005-05-02" seq="2005-1123" severity="Medium" type="CVE"><desc><descript source="cve">Monkey daemon (monkeyd) before 0.9.1 allows remote attackers to cause a denial of service (memory corruption) via a request for a zero byte file.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200504-14.xml">GLSA-200504-14</ref><ref source="MISC" url="http://bugs.gentoo.org/show_bug.cgi?id=87916">http://bugs.gentoo.org/show_bug.cgi?id=87916</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/14953">14953</ref><ref source="OSVDB" url="http://www.osvdb.org/15512">15512</ref></refs><vuln_soft><prod name="Monkey HTTP Daemon" vendor="Monkey"><vers num="0.9.0"/><vers num="0.8.5"/><vers num="0.8.4.2"/><vers num="0.8.4"/><vers num="0.8.4 rc2"/><vers num="0.8.4 rc1"/><vers num="0.8.3"/><vers num="0.8.2"/><vers num="0.8.1"/><vers num="0.8.0"/><vers num="0.7.2"/><vers num="0.7.1"/><vers num="0.7.0"/><vers num="0.6.3"/><vers num="0.6.2"/><vers num="0.6.1"/><vers num="0.6.0"/><vers num="0.5.2"/><vers num="0.5.1"/><vers num="0.5.0"/><vers num="0.4.2"/><vers num="0.4.1.1"/><vers num="0.4.1"/><vers num="0.4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1124" published="2005-05-02" seq="2005-1124" severity="Medium" type="CVE"><desc><descript source="cve">Unknown vulnerability in the libgss Generic Security Services Library in Solaris 7, 8, and 9 allows local users to gain privileges by loading their own GSS-API.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57734-1">57734</ref><ref source="OSVDB" url="http://www.osvdb.org/15516">15516</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/14971">14971</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers num="7.0"/><vers num="8.0"/><vers edition="SPARC" num="9.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1125" published="2005-05-02" seq="2005-1125" severity="Medium" type="CVE"><desc><descript source="cve">Race condition in libsafe 2.0.16 and earlier, when running in multi-threaded applications, allows attackers to bypass libsafe protection and exploit other vulnerabilities before the _libsafe_die function call is completed.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><race/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/395999">20050415 [Overflow.pl] Libsafe - Safety Check Bypass Vulnerability</ref><ref adv="1" source="MISC" url="http://www.overflow.pl/adv/libsafebypass.txt">http://www.overflow.pl/adv/libsafebypass.txt</ref><ref source="BID" url="http://www.securityfocus.com/bid/13190">13190</ref></refs><vuln_soft><prod name="Libsafe" vendor="Avaya"><vers num="2.0.16"/><vers num="2.0.15"/><vers num="2.0.14"/><vers num="2.0.13"/><vers num="2.0.12"/><vers num="2.0.11"/><vers num="2.0.10"/><vers num="2.0.9"/><vers num="2.0.8"/><vers num="2.0.7"/><vers num="2.0.6"/><vers num="2.0.5"/><vers num="2.0.4"/><vers num="2.0.3"/><vers num="2.0.2"/><vers num="2.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-09-17" name="CVE-2005-1126" published="2005-04-15" seq="2005-1126" severity="Low" type="CVE"><desc><descript source="cve">The SIOCGIFCONF ioctl (ifconf function) in FreeBSD 4.x through 4.11 and 5.x through 5.4 does not properly clear a buffer before using it, which allows local users to obtain portions of sensitive kernel memory.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="FREEBSD" url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-05:04.ifconf.asc">FreeBSD-SA-05:04</ref><ref adv="1" patch="1" source="OSVDB" url="http://www.osvdb.org/15514">15514</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14959">14959</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/20114">freebsd-ifconf-information-disclosure(20114)</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/Oct/msg00000.html">APPLE-SA-2005-10-31</ref><ref source="BID" url="http://www.securityfocus.com/bid/15252">15252</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/2256">ADV-2005-2256</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17368">17368</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="5.3 Stable"/><vers num="5.3 Releng"/><vers num="5.3 Release"/><vers num="5.3"/><vers num="5.2.1 Release"/><vers num="5.2 Releng"/><vers num="5.2 Release"/><vers num="5.2"/><vers num="5.1 Releng"/><vers num="5.1 Release Alpha"/><vers num="5.1 p5 Release"/><vers num="5.1 Release"/><vers num="5.1"/><vers num="5.0 Releng"/><vers num="5.0 p14 Release"/><vers num="5.0 alpha"/><vers num="5.0"/><vers num="4.11 Stable"/><vers num="4.10 Releng"/><vers num="4.10 Release"/><vers num="4.10"/><vers num="4.9 Releng"/><vers num="4.9 pre"/><vers num="4.9"/><vers num="4.8 Releng"/><vers num="4.8 p6 Release"/><vers num="4.8 pre"/><vers num="4.8"/><vers num="4.7 Stable"/><vers num="4.7 Releng"/><vers num="4.7 p17 Release"/><vers num="4.7 Release"/><vers num="4.7"/><vers num="4.6.2"/><vers num="4.6 Stable"/><vers num="4.6 Releng"/><vers num="4.6 p20 Release"/><vers num="4.6 Release"/><vers num="4.6"/><vers num="4.5 Stable pre 2002-03-07"/><vers num="4.5 Stable"/><vers num="4.5 Releng"/><vers num="4.5 p32 Release"/><vers num="4.5 Release"/><vers num="4.5"/><vers num="4.4 Stable"/><vers num="4.4 Releng"/><vers num="4.4 p42 Release"/><vers num="4.4"/><vers num="4.3 Stable"/><vers num="4.3 Releng"/><vers num="4.3 p38 Release"/><vers num="4.3 Release"/><vers num="4.3"/><vers num="4.2 Stable pre 2000-12-23"/><vers num="4.2 Stable pre 2001-05-02"/><vers num="4.2 Stable"/><vers num="4.2 Release"/><vers num="4.2"/><vers num="4.1.1 Stable"/><vers num="4.1.1 Release"/><vers num="4.1.1"/><vers num="4.1"/><vers num="4.0 Releng"/><vers num="4.0 alpha"/><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1127" published="2005-05-02" seq="2005-1127" severity="Medium" type="CVE"><desc><descript source="cve">Format string vulnerability in the log function in Net::Server 0.87 and earlier, as used in Postfix Greylisting Policy Server (Postgrey) 1.18 and earlier, and possibly other products, allows remote attackers to cause a denial of service (crash) via format string specifiers that are not properly handled before being sent to syslog, as demonstrated using sender addresses to Postgrey.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=111354538331167&amp;w=2">20050415 Use of function </ref><ref source="MLIST" url="http://lists.ee.ethz.ch/postgrey/msg00627.html">[postgrey] 20050414 Problem with crashing postgrey</ref><ref source="MLIST" url="http://lists.ee.ethz.ch/postgrey/msg00630.html">[postgrey] 20050414 Re: Problem with crashing postgrey</ref><ref patch="1" source="MLIST" url="http://lists.ee.ethz.ch/postgrey/msg00647.html">[postgrey] 20050414 ANNOUNCE: Postgrey 1.21 (SECURITY)</ref><ref source="OSVDB" url="http://www.osvdb.org/15517">15517</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/14958">14958</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20108">postgrey-logging-dos(20108)</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1121">DSA-1121</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1122">DSA-1122</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:131">MDKSA-2006:131</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21164">21164</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21152">21152</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21149">21149</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200608-18.xml">GLSA-200608-18</ref><ref source="BID" url="http://www.securityfocus.com/bid/13193">13193</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21452">21452</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:131">MDKSA-2006:131</ref></refs><vuln_soft><prod name="Postgrey" vendor="Postgrey"><vers num="1.18"/><vers num="1.17"/><vers num="1.16" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-22" name="CVE-2005-1128" published="2005-05-02" seq="2005-1128" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in VHCS 2.4 and earlier allow remote attackers to execute arbitrary SQL commands via certain inputs from HTTP POST queries.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="OSVDB" url="http://www.osvdb.org/15541">15541</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013703">1013703</ref></refs><vuln_soft><prod name="Virtual Hosting Control System" vendor="Virtual Hosting Control System"><vers num="2.4" prev="1"/><vers num="2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1129" published="2005-05-02" seq="2005-1129" severity="Low" type="CVE"><desc><descript source="cve">eGroupWare 1.0.6 and earlier, when an e-mail is composed with an attachment but not sent, will send that attachment in the next e-mail, which may cause sensitive information to be sent to the wrong recipient.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2005-04/0157.html">20050412 eGroupWare Leaks Files</ref><ref source="BID" url="http://www.securityfocus.com/bid/13137">13137</ref><ref source="OSVDB" url="http://www.osvdb.org/15499">15499</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14940">14940</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20088">egroupware-email-information-disclosure(20088)</ref></refs><vuln_soft><prod name="eGroupWare" vendor="eGroupWare"><vers num="1.0.6"/><vers num="1.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-05-04" name="CVE-2005-1130" published="2005-04-12" seq="2005-1130" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in Pinnacle Cart allows remote attackers to inject arbitrary web script or HTML via the pg parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://systemsecure.org/board/index.php?showtopic=8">http://systemsecure.org/board/index.php?showtopic=8</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/13138">13138</ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/15485">15485</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/14924">14924</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/20092">pinnaclecart-index-xss(20092)</ref></refs><vuln_soft><prod name="Pinnacle Cart" vendor="Desert Dog Software"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-03-27" name="CVE-2005-1131" published="2005-05-02" seq="2005-1131" severity="High" type="CVE"><desc><descript source="cve">Unknown vulnerability in Veritas i3 Focalpoint Server 7.1 and earlier has unknown attack vectors and unknown but &quot;critical&quot; impact.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref patch="1" source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2005-q2/0008.html">20040413 Patch available for critical Veritas i3 Server vulnerability</ref><ref patch="1" source="MISC" url="http://seer.support.veritas.com/docs/276119.htm">http://seer.support.veritas.com/docs/276119.htm</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/13142">13142</ref><ref source="OSVDB" url="http://www.osvdb.org/15498">15498</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1013694">1013694</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/14934">14934</ref></refs><vuln_soft><prod name="i3 FocalPoint Server" vendor="Symantec Veritas"><vers num="7.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1132" published="2005-05-02" seq="2005-1132" severity="Medium" type="CVE"><desc><descript source="cve">LG U8120 mobile phone allows remote attackers to cause a denial of service (device crash) via a malformed MIDI file.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref sig="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/395714">20050413 LG U8120 Mobile Phone Denial of Service</ref><ref sig="1" source="BID" url="http://www.securityfocus.com/bid/13154">13154</ref><ref sig="1" source="SECTRACK" url="http://securitytracker.com/id?1013777">1013777</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20091">lg-u8120-mobile-phone-dos(20091)</ref></refs><vuln_soft><prod name="LG mobile phone" vendor="LG Electronics"><vers num="U8120"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1133" published="2005-05-02" seq="2005-1133" severity="Medium" type="CVE"><desc><descript source="cve">The POP3 server in IBM iSeries AS/400 returns different error messages when the user exists or not, which allows remote attackers to determine valid user IDs on the server.</descript></desc><loss_types><conf/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/13156">13156</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111358863001693&amp;w=2">20050414 Enumeration of AS/400 users and their status via POP3</ref></refs><vuln_soft><prod name="iSeries" vendor="IBM"><vers num="AS_400"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1134" published="2005-04-13" seq="2005-1134" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in exit.php for Serendipity 0.8 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) url_id or (2) entry_id parameters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://seclists.org/lists/bugtraq/2005/Apr/0195.html">20050413 serendipity SQL Injection vulnerability</ref><ref adv="1" patch="1" source="CONFIRM" url="http://www.s9y.org/5.html">http://www.s9y.org/5.html</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/13161">13161</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/20119">serendipity-urlid-entryid-sql-injection(20119)</ref><ref adv="1" patch="1" source="CONFIRM" url="http://www.s9y.org/63.html#A9">http://www.s9y.org/63.html#A9</ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/15542">15542</ref><ref adv="1" source="SECTRACK" url="http://securitytracker.com/id?1013699">1013699</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/15145">15145</ref></refs><vuln_soft><prod name="Serendipity" vendor="S9Y"><vers num="0.8 Beta6"/><vers num="0.8 Beta5"/><vers num="0.7 rc1"/><vers num="0.7 Beta4"/><vers num="0.7 Beta2"/><vers num="0.7 beta3"/><vers num="0.7 beta1"/><vers num="0.7"/><vers num="0.6 rc2"/><vers num="0.6 rc1"/><vers num="0.6 pl3"/><vers num="0.6 pl2"/><vers num="0.6 pl1"/><vers num="0.6"/><vers num="0.5 pl1"/><vers num="0.5"/><vers num="0.4"/><vers num="0.3"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-08-24" name="CVE-2005-1135" published="2005-05-02" seq="2005-1135" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in search.php for Simple PHP Blog (sphpBlog) 0.4.0 allows remote attackers to inject arbitrary web script or HTML via the q parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MISC" url="http://echo.or.id/adv/adv12-y3dips-2005.txt">http://echo.or.id/adv/adv12-y3dips-2005.txt</ref><ref source="MISC" url="http://www.waraxe.us/ftopict-651.html">http://www.waraxe.us/ftopict-651.html</ref><ref source="BID" url="http://www.securityfocus.com/bid/13170">13170</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111359320312609&amp;w=2">20050415 [ECHO_ADV_12$2005] Vulnerabilities in sphpblog</ref></refs><vuln_soft><prod name="Simple PHP blog" vendor="Alexander Palmo"><vers num="0.4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1136" published="2005-04-14" seq="2005-1136" severity="Medium" type="CVE"><desc><descript source="cve">Simple PHP Blog (sphpBlog) 0.4.0 stores the (1) password.txt and (2) config.txt files under the web document root, which allows remote attackers to obtain sensitive information and crack passwords via a direct request to these files.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://echo.or.id/adv/adv12-y3dips-2005.txt">http://echo.or.id/adv/adv12-y3dips-2005.txt</ref><ref adv="1" source="MISC" url="http://www.waraxe.us/ftopict-651.html">http://www.waraxe.us/ftopict-651.html</ref><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111359320312609&amp;w=2">20050415 [ECHO_ADV_12$2005] Vulnerabilities in sphpblog</ref></refs><vuln_soft><prod name="sphpBlog" vendor="sphpBlog"><vers num="0.4 .0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-08-24" name="CVE-2005-1137" published="2005-05-02" seq="2005-1137" severity="Medium" type="CVE"><desc><descript source="cve">Simple PHP Blog (sphpBlog) 0.4.0 allows remote attackers to obtain sensitive information via a direct request to sb_functions.php, which leaks the full pathname in a PHP error message.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref source="MISC" url="http://echo.or.id/adv/adv12-y3dips-2005.txt">http://echo.or.id/adv/adv12-y3dips-2005.txt</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111359320312609&amp;w=2">20050415 [ECHO_ADV_12$2005] Vulnerabilities in sphpblog</ref></refs><vuln_soft><prod name="Simple PHP blog" vendor="Alexander Palmo"><vers num="0.4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-27" name="CVE-2005-1138" published="2005-04-18" seq="2005-1138" severity="Medium" type="CVE"><desc><descript source="cve">Unknown vulnerability in WebMail in Kerio MailServer before 6.0.9 allows remote attackers to cause a denial of service (CPU consumption) via certain e-mail messages.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CONFIRM" url="http://www.kerio.com/kms_history.html">http://www.kerio.com/kms_history.html</ref><ref adv="1" patch="1" source="SECTRACK" url="http://securitytracker.com/id?1013708">1013708</ref></refs><vuln_soft><prod name="Kerio MailServer" vendor="Kerio"><vers num="6.0.5"/><vers num="6.0.4"/><vers num="6.0.3"/><vers num="6.0.2"/><vers num="6.0.1"/><vers num="6.0"/><vers num="5.7.10"/><vers num="5.7.9"/><vers num="5.7.8"/><vers num="5.7.7"/><vers num="5.7.6"/><vers num="5.7.5"/><vers num="5.7.4"/><vers num="5.7.3"/><vers num="5.7.2"/><vers num="5.7.1"/><vers num="5.7.0"/><vers num="5.6.5"/><vers num="5.6.4"/><vers num="5.6.3"/><vers num="5.1.1"/><vers num="5.1"/><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1139" published="2005-04-14" seq="2005-1139" severity="High" type="CVE"><desc><descript source="cve">Opera 8 Beta 3, when using first-generation vetted digital certificates, displays the Organizational information of an SSL certificate, which is easily spoofed and can facilitate phishing attacks.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="MISC" url="http://www.geotrust.com/resources/advisory/sslorg/sslorg-advisory.htm">http://www.geotrust.com/resources/advisory/sslorg/sslorg-advisory.htm</ref><ref adv="1" source="MISC" url="http://www.geotrust.com/resources/advisory/sslorg/index.htm">http://www.geotrust.com/resources/advisory/sslorg/index.htm</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/13176">13176</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_31_opera.html">SUSE-SA:2005:031</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/40503">opera-ssl-spoofing(40503)</ref></refs><vuln_soft><prod name="Opera Web Browser" vendor="Opera Software"><vers num="8 Beta 3"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1140" published="2005-04-15" seq="2005-1140" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in myBloggie 2.1.1 allows remote attackers to inject arbitrary web script or HTML via the comments.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/395988">20050415 myBloggie 2.1.1</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/13192">13192</ref></refs><vuln_soft><prod name="myBloggie" vendor="myWebland"><vers num="2.1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1141" published="2005-04-15" seq="2005-1141" severity="High" type="CVE"><desc><descript source="cve">Integer overflow in the readpgm function in pnm.c for GOCR 0.40, when using the netpbm library, allows remote attackers to execute arbitrary code via a PNM file with large width and height values, which leads to a heap-based buffer overflow.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111358557823673&amp;w=2">20050415 [Overflow.pl] GOCR - Multiple vulnerabilities</ref><ref adv="1" source="MISC" url="http://www.overflow.pl/adv/gocr.txt">http://www.overflow.pl/adv/gocr.txt</ref></refs><vuln_soft><prod name="Optical Character Recognition Utility" vendor="GOCR"><vers num="0.40"/><vers num="0.39"/><vers num="0.37"/><vers num="0.3.4"/><vers num="0.3.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1142" published="2005-04-15" seq="2005-1142" severity="High" type="CVE"><desc><descript source="cve">Heap-based buffer overflow in the readpgm function in pnm.c for GOCR 0.40, when it is not using netpbm, allows remote attackers to execute arbitrary code via a P3 format PNM file with more data than implied by its width and height values.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111358557823673&amp;w=2">20050415 [Overflow.pl] GOCR - Multiple vulnerabilities</ref><ref adv="1" source="MISC" url="http://www.overflow.pl/adv/gocr.txt">http://www.overflow.pl/adv/gocr.txt</ref></refs><vuln_soft><prod name="Optical Character Recognition Utility" vendor="GOCR"><vers num="0.40"/><vers num="0.39"/><vers num="0.37"/><vers num="0.3.4"/><vers num="0.3.2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1143" published="2005-04-12" seq="2005-1143" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in EasyPHPCalendar before 6.2.8 allows remote attackers to inject arbitrary web script or HTML via the yr parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://www.snkenjoi.com/secadv/secadv4.txt">http://www.snkenjoi.com/secadv/secadv4.txt</ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/15544">15544</ref><ref adv="1" source="SECTRACK" url="http://securitytracker.com/id?1013704">1013704</ref><ref source="" url="http://docs.easyphpcalendar.com/Change%20Log/changeLog.htm">http://docs.easyphpcalendar.com/Change%20Log/changeLog.htm</ref></refs><vuln_soft><prod name="EasyPHPCalendar" vendor="EasyPHPCalendar"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1144" published="2005-04-12" seq="2005-1144" severity="Medium" type="CVE"><desc><descript source="cve">popup.php in EasyPHPCalendar before 6.2.8 allows remote attackers to obtain sensitive information via an invalid ev parameter, which reveals the full pathname of the web server in a PHP error message.</descript></desc><sols><sol source="nvd">Version 6.2.8 and above are fixed.</sol></sols><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://www.snkenjoi.com/secadv/secadv4.txt">http://www.snkenjoi.com/secadv/secadv4.txt</ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/15545">15545</ref><ref adv="1" source="SECTRACK" url="http://securitytracker.com/id?1013704">1013704</ref><ref source="" url="http://docs.easyphpcalendar.com/Change%20Log/changeLog.htm">http://docs.easyphpcalendar.com/Change%20Log/changeLog.htm</ref></refs><vuln_soft><prod name="EasyPHPCalendar" vendor="EasyPHPCalendar"><vers num="6.2.7" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-25" name="CVE-2005-1145" published="2005-04-12" seq="2005-1145" severity="Medium" type="CVE"><desc><descript source="cve">** DISPUTED **  NOTE: this issue has been disputed by the vendor.  Cross-site scripting (XSS) vulnerability in calendar.pl in CalendarScript 3.20 allows remote attackers to inject arbitrary web script or HTML via the template parameter, a different vulnerability than CVE-2005-1146.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://www.snkenjoi.com/secadv/secadv3.txt">http://www.snkenjoi.com/secadv/secadv3.txt</ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/15547">15547</ref><ref adv="1" source="SECTRACK" url="http://securitytracker.com/id?1013705">1013705</ref></refs><vuln_soft><prod name="CalendarScript" vendor="CalendarScript"><vers num="3.20"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-25" name="CVE-2005-1146" published="2005-04-12" seq="2005-1146" severity="Medium" type="CVE"><desc><descript source="cve">** DISPUTED **  NOTE: this issue has been disputed by the vendor.  Cross-site scripting (XSS) vulnerability in the login command in calendar.pl in CalendarScript 3.21 allows remote attackers to inject arbitrary web script or HTML via the username parameter, a different vulnerability than CVE-2005-1145.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://www.snkenjoi.com/secadv/secadv3.txt">http://www.snkenjoi.com/secadv/secadv3.txt</ref><ref adv="1" source="SECTRACK" url="http://securitytracker.com/id?1013705">1013705</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/20103">calendarscript-calendarpl-xss(20103)</ref></refs><vuln_soft><prod name="CalendarScript" vendor="CalendarScript"><vers num="3.20"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1147" published="2005-04-12" seq="2005-1147" severity="Medium" type="CVE"><desc><descript source="cve">calendar.pl in CalendarScript 3.20 allows remote attackers to obtain sensitive information via invalid (1) calendar or (2) template parameters, which leaks the full pathname and debug information.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://www.snkenjoi.com/secadv/secadv3.txt">http://www.snkenjoi.com/secadv/secadv3.txt</ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/15546">15546</ref><ref adv="1" source="SECTRACK" url="http://securitytracker.com/id?1013705">1013705</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/20102">calendarscript-path-disclosure(20102)</ref></refs><vuln_soft><prod name="CalendarScript" vendor="CalendarScript"><vers num="3.20"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1148" published="2005-05-02" seq="2005-1148" severity="Medium" type="CVE"><desc><descript source="cve">calendar.pl in CalendarScript 3.21 allows remote attackers to obtain sensitive information via invalid (1) year or (2) month parameters, which leaks the full pathname and debug information.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://www.snkenjoi.com/secadv/secadv3.txt">http://www.snkenjoi.com/secadv/secadv3.txt</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013705">1013705</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20102">calendarscript-path-disclosure(20102)</ref></refs><vuln_soft><prod name="CalendarScript" vendor="CalendarScript"><vers num="3.21"/><vers num="3.20"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1149" published="2005-04-13" seq="2005-1149" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in admin/login.asp in aspclick.it ACNews 1.0 allows remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/13148">13148</ref><ref adv="1" source="SECTRACK" url="http://securitytracker.com/id?1013681">1013681</ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/15494">15494</ref></refs><vuln_soft><prod name="ACNews" vendor="ACNews"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1150" published="2005-05-02" seq="2005-1150" severity="Medium" type="CVE"><desc><descript source="cve">Unknown vulnerability in Sun Java System Web Server 6.0 SP7 and earlier, when running on Windows systems, allows attackers to cause a denial of service (hang).</descript></desc><loss_types><avail/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57760-1">57760</ref><ref source="OSVDB" url="http://www.osvdb.org/15504">15504</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14961">14961</ref></refs><vuln_soft><prod name="Java System Web Server" vendor="Sun"><vers num="6.0 SP7"/><vers num="6.0 SP6"/><vers num="6.0 SP5"/><vers num="6.0 SP4"/><vers num="6.0 SP3"/><vers num="6.0 SP2"/><vers num="6.0 SP1"/><vers num="6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1151" published="2005-05-25" seq="2005-1151" severity="High" type="CVE"><desc><descript source="cve">qpopper 4.0.5 and earlier does not properly drop privileges before processing certain user-supplied files, which allows local users to overwrite or create arbitrary files as root.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-728">DSA-728</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200505-17.xml">GLSA-200505-17</ref><ref source="MISC" url="http://bugs.gentoo.org/show_bug.cgi?id=90622">http://bugs.gentoo.org/show_bug.cgi?id=90622</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15475">15475</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15478">15478</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15505">15505</ref></refs><vuln_soft><prod name="Debian Linux qpopper" vendor="Debian"><vers num="4.0.5"/><vers num="4.0.4" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1152" published="2005-05-25" seq="2005-1152" severity="Low" type="CVE"><desc><descript source="cve">popauth.c in qpopper 4.0.5 and earlier does not properly set the umask, which may cause qpopper to create files with group or world-writable permissions.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-728">DSA-728</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200505-17.xml">GLSA-200505-17</ref><ref source="Gentoo" url="http://bugs.gentoo.org/show_bug.cgi?id=90622">90622</ref><ref source="Gentoo" url="http://bugs.gentoo.org/attachment.cgi?id=58329&amp;action=view">58329</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15475">15475</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15478">15478</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15505">15505</ref></refs><vuln_soft><prod name="Debian Linux qpopper" vendor="Debian"><vers num="4.0.5"/><vers num="4.0.4" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1153" published="2005-05-02" seq="2005-1153" severity="High" type="CVE"><desc><descript source="cve">Firefox before 1.0.3 and Mozilla Suite before 1.7.7, when blocking a popup, allows remote attackers to execute arbitrary code via a javascript: URL that is executed when the user selects the &quot;Show javascript&quot; option.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="CONFIRM" url="http://www.mozilla.org/security/announce/mfsa2005-35.html">http://www.mozilla.org/security/announce/mfsa2005-35.html</ref><ref source="CONFIRM" url="https://bugzilla.mozilla.org/show_bug.cgi?id=289204">https://bugzilla.mozilla.org/show_bug.cgi?id=289204</ref><ref patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200504-18.xml">GLSA-200504-18</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-383.html">RHSA-2005:383</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-386.html">RHSA-2005:386</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14938">14938</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14992">14992</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval100023.html">OVAL100023</ref><ref source="SCO" url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.49/SCOSA-2005.49.txt">SCOSA-2005.49</ref><ref source="BID" url="http://www.securityfocus.com/bid/15495">15495</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-384.html">RHSA-2005:384</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100023">oval:org.mitre.oval:def:100023</ref></refs><vuln_soft><prod name="Mozilla" vendor="Mozilla"><vers num="1.7.6"/><vers num="1.7.5"/><vers num="1.7.3"/><vers num="1.7.2"/><vers num="1.7.1"/><vers num="1.7 rc3"/><vers num="1.7 rc2"/><vers num="1.7 rc1"/><vers num="1.7 beta"/><vers num="1.7 alpha"/><vers num="1.7"/><vers num="1.6 beta"/><vers num="1.6 alpha"/><vers num="1.6"/><vers num="1.5.1"/><vers num="1.5 rc2"/><vers num="1.5 rc1"/><vers num="1.5 alpha"/><vers num="1.5"/><vers num="1.4a"/><vers num="1.4.1"/><vers num="1.4"/><vers num="1.3"/></prod><prod name="Firefox" vendor="Mozilla"><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0"/><vers num="0.9.3"/><vers num="0.9.2"/><vers num="0.9.1"/><vers edition="rc" num="0.9"/><vers num="0.9"/><vers num="0.8"/><vers num="0.10.1"/><vers num="0.10"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1154" published="2005-05-02" seq="2005-1154" severity="High" type="CVE"><desc><descript source="cve">Firefox before 1.0.3 and Mozilla Suite before 1.7.7 allows remote attackers to execute arbitrary script in other domains via a setter function for a variable in the target domain, which is executed when the user visits that domain, aka &quot;Cross-site scripting through global scope pollution.&quot;</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="CONFIRM" url="http://www.mozilla.org/security/announce/mfsa2005-36.html">http://www.mozilla.org/security/announce/mfsa2005-36.html</ref><ref patch="1" source="CONFIRM" url="https://bugzilla.mozilla.org/show_bug.cgi?id=289675">https://bugzilla.mozilla.org/show_bug.cgi?id=289675</ref><ref patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200504-18.xml">GLSA-200504-18</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-383.html">RHSA-2005:383</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-386.html">RHSA-2005:386</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14938">14938</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14992">14992</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval100022.html">OVAL100022</ref><ref source="SCO" url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.49/SCOSA-2005.49.txt">SCOSA-2005.49</ref><ref source="BID" url="http://www.securityfocus.com/bid/15495">15495</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-384.html">RHSA-2005:384</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100022">oval:org.mitre.oval:def:100022</ref><ref source="BID" url="http://www.securityfocus.com/bid/13230">
13230</ref></refs><vuln_soft><prod name="Mozilla" vendor="Mozilla"><vers num="1.7.6"/><vers num="1.7.5"/><vers num="1.7.3"/><vers num="1.7.2"/><vers num="1.7.1"/><vers num="1.7 rc3"/><vers num="1.7 rc2"/><vers num="1.7 rc1"/><vers num="1.7 beta"/><vers num="1.7 alpha"/><vers num="1.7"/><vers num="1.6 beta"/><vers num="1.6 alpha"/><vers num="1.6"/><vers num="1.5.1"/><vers num="1.5 rc2"/><vers num="1.5 rc1"/><vers num="1.5 alpha"/><vers num="1.5"/><vers num="1.4a"/><vers num="1.4.1"/><vers num="1.4"/><vers num="1.3"/></prod><prod name="Firefox" vendor="Mozilla"><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0"/><vers num="0.9.3"/><vers num="0.9.2"/><vers num="0.9.1"/><vers edition="rc" num="0.9"/><vers num="0.9"/><vers num="0.8"/><vers num="0.10.1"/><vers num="0.10"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-04-07" name="CVE-2005-1155" published="2005-05-02" seq="2005-1155" severity="High" type="CVE"><desc><descript source="cve">The favicon functionality in Firefox before 1.0.3 and Mozilla Suite before 1.7.7 allows remote attackers to execute arbitrary code via a &lt;LINK rel=&quot;icon&quot;&gt; tag with a javascript: URL in the href attribute, aka &quot;Firelinking.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="MISC" url="http://www.mikx.de/firelinking/">http://www.mikx.de/firelinking/</ref><ref adv="1" source="CONFIRM" url="http://www.mozilla.org/security/announce/mfsa2005-37.html">http://www.mozilla.org/security/announce/mfsa2005-37.html</ref><ref patch="1" source="CONFIRM" url="https://bugzilla.mozilla.org/show_bug.cgi?id=290036">https://bugzilla.mozilla.org/show_bug.cgi?id=290036</ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200504-18.xml">GLSA-200504-18</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-383.html">RHSA-2005:383</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-386.html">RHSA-2005:386</ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/973309">VU#973309</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14938">14938</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14992">14992</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval100021.html">OVAL100021</ref><ref source="SCO" url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.49/SCOSA-2005.49.txt">SCOSA-2005.49</ref><ref source="BID" url="http://www.securityfocus.com/bid/15495">15495</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-384.html">RHSA-2005:384</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100021">oval:org.mitre.oval:def:100021</ref><ref source="BID" url="http://www.securityfocus.com/bid/13216">
13216</ref></refs><vuln_soft><prod name="Mozilla" vendor="Mozilla"><vers num="1.7.6"/><vers num="1.7.5"/><vers num="1.7.3"/><vers num="1.7.2"/><vers num="1.7.1"/><vers num="1.7 rc3"/><vers num="1.7 rc2"/><vers num="1.7 rc1"/><vers num="1.7 beta"/><vers num="1.7 alpha"/><vers num="1.7"/><vers num="1.6 beta"/><vers num="1.6 alpha"/><vers num="1.6"/><vers num="1.5.1"/><vers num="1.5 rc2"/><vers num="1.5 rc1"/><vers num="1.5 alpha"/><vers num="1.5"/><vers num="1.4a"/><vers num="1.4.1"/><vers num="1.4"/><vers num="1.3"/></prod><prod name="Firefox" vendor="Mozilla"><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0"/><vers num="0.9.3"/><vers num="0.9.2"/><vers num="0.9.1"/><vers edition="rc" num="0.9"/><vers num="0.9"/><vers num="0.8"/><vers num="0.10.1"/><vers num="0.10"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1156" published="2005-05-02" seq="2005-1156" severity="High" type="CVE"><desc><descript source="cve">Firefox before 1.0.3, Mozilla Suite before 1.7.7, and Netscape 7.2 allows remote attackers to execute arbitrary script and code via a new search plugin using sidebar.addSearchEngine, aka &quot;Firesearching 1.&quot;</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref source="MISC" url="http://www.mikx.de/firesearching/">http://www.mikx.de/firesearching/</ref><ref adv="1" source="CONFIRM" url="http://www.mozilla.org/security/announce/mfsa2005-38.html">http://www.mozilla.org/security/announce/mfsa2005-38.html</ref><ref patch="1" source="CONFIRM" url="https://bugzilla.mozilla.org/show_bug.cgi?id=290037">https://bugzilla.mozilla.org/show_bug.cgi?id=290037</ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200504-18.xml">GLSA-200504-18</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-383.html">RHSA-2005:383</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-386.html">RHSA-2005:386</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/13211">13211</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1013745">1013745</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14938">14938</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14992">14992</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14996">14996</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/20125">mozilla-plugin-xss(20125)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval100020.html">OVAL100020</ref><ref source="SCO" url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.49/SCOSA-2005.49.txt">SCOSA-2005.49</ref><ref source="BID" url="http://www.securityfocus.com/bid/15495">15495</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-384.html">RHSA-2005:384</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100020">oval:org.mitre.oval:def:100020</ref></refs><vuln_soft><prod name="Mozilla" vendor="Mozilla"><vers num="1.7.6"/><vers num="1.7.5"/><vers num="1.7.3"/><vers num="1.7.2"/><vers num="1.7.1"/><vers num="1.7 rc3"/><vers num="1.7 rc2"/><vers num="1.7 rc1"/><vers num="1.7 beta"/><vers num="1.7 alpha"/><vers num="1.7"/><vers num="1.6 beta"/><vers num="1.6 alpha"/><vers num="1.6"/><vers num="1.5.1"/><vers num="1.5 rc2"/><vers num="1.5 rc1"/><vers num="1.5 alpha"/><vers num="1.5"/><vers num="1.4a"/><vers num="1.4.1"/><vers num="1.4"/><vers num="1.3"/></prod><prod name="Netscape" vendor="Netscape"><vers num="7.2"/></prod><prod name="Firefox" vendor="Mozilla"><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0"/><vers num="0.9.3"/><vers num="0.9.2"/><vers num="0.9.1"/><vers edition="rc" num="0.9"/><vers num="0.9"/><vers num="0.8"/><vers num="0.10.1"/><vers num="0.10"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1157" published="2005-05-02" seq="2005-1157" severity="High" type="CVE"><desc><descript source="cve">Firefox before 1.0.3, Mozilla Suite before 1.7.7, and Netscape 7.2 allows remote attackers to replace existing search plugins with malicious ones using sidebar.addSearchEngine and the same filename as the target engine, which may not be displayed in the GUI, which could then be used to execute malicious script, aka &quot;Firesearching 2.&quot;</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref source="MISC" url="http://www.mikx.de/firesearching/">http://www.mikx.de/firesearching/</ref><ref adv="1" source="CONFIRM" url="http://www.mozilla.org/security/announce/mfsa2005-38.html">http://www.mozilla.org/security/announce/mfsa2005-38.html</ref><ref patch="1" source="CONFIRM" url="https://bugzilla.mozilla.org/show_bug.cgi?id=290037">https://bugzilla.mozilla.org/show_bug.cgi?id=290037</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-383.html">RHSA-2005:383</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-386.html">RHSA-2005:386</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/13211">13211</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14938">14938</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14992">14992</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14996">14996</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/20125">mozilla-plugin-xss(20125)</ref><ref source="SCO" url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.49/SCOSA-2005.49.txt">SCOSA-2005.49</ref><ref source="BID" url="http://www.securityfocus.com/bid/15495">15495</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-384.html">RHSA-2005:384</ref></refs><vuln_soft><prod name="Mozilla" vendor="Mozilla"><vers num="1.7.6"/><vers num="1.7.5"/><vers num="1.7.3"/><vers num="1.7.2"/><vers num="1.7.1"/><vers num="1.7 rc3"/><vers num="1.7 rc2"/><vers num="1.7 rc1"/><vers num="1.7 beta"/><vers num="1.7 alpha"/><vers num="1.7"/><vers num="1.6 beta"/><vers num="1.6 alpha"/><vers num="1.6"/><vers num="1.5.1"/><vers num="1.5 rc2"/><vers num="1.5 rc1"/><vers num="1.5 alpha"/><vers num="1.5"/><vers num="1.4a"/><vers num="1.4.1"/><vers num="1.4"/><vers num="1.3"/></prod><prod name="Netscape" vendor="Netscape"><vers num="7.2"/></prod><prod name="Firefox" vendor="Mozilla"><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0"/><vers num="0.9.3"/><vers num="0.9.2"/><vers num="0.9.1"/><vers edition="rc" num="0.9"/><vers num="0.9"/><vers num="0.8"/><vers num="0.10.1"/><vers num="0.10"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1158" published="2005-05-02" seq="2005-1158" severity="Medium" type="CVE"><desc><descript source="cve">Multiple &quot;missing security checks&quot; in Firefox before 1.0.3 allow remote attackers to inject arbitrary Javascript into privileged pages using the _search target of the Firefox sidebar.</descript></desc><loss_types><int/></loss_types><vuln_types><access/><input/></vuln_types><range><network/></range><refs><ref adv="1" source="CONFIRM" url="http://www.mozilla.org/security/announce/mfsa2005-39.html">http://www.mozilla.org/security/announce/mfsa2005-39.html</ref><ref patch="1" source="CONFIRM" url="https://bugzilla.mozilla.org/show_bug.cgi?id=290079">https://bugzilla.mozilla.org/show_bug.cgi?id=290079</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-383.html">RHSA-2005:383</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14938">14938</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval100019.html">OVAL100019</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100019">oval:org.mitre.oval:def:100019</ref><ref source="BID" url="http://www.securityfocus.com/bid/13231">
13231</ref></refs><vuln_soft><prod name="Firefox" vendor="Mozilla"><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0"/><vers num="0.9.3"/><vers num="0.9.2"/><vers num="0.9.1"/><vers edition="rc" num="0.9"/><vers num="0.9"/><vers num="0.8"/><vers num="0.10.1"/><vers num="0.10"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1159" published="2005-05-02" seq="2005-1159" severity="High" type="CVE"><desc><descript source="cve">The native implementations of InstallTrigger and other functions in Firefox before 1.0.3 and Mozilla Suite before 1.7.7 do not properly verify the types of objects being accessed, which causes the Javascript interpreter to continue execution at the wrong memory address, which may allow attackers to cause a denial of service (application crash) and possibly execute arbitrary code by passing objects of the wrong type.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><access/><input/></vuln_types><range><network/></range><refs><ref adv="1" source="CONFIRM" url="http://www.mozilla.org/security/announce/mfsa2005-40.html">http://www.mozilla.org/security/announce/mfsa2005-40.html</ref><ref patch="1" source="CONFIRM" url="https://bugzilla.mozilla.org/show_bug.cgi?id=290162">https://bugzilla.mozilla.org/show_bug.cgi?id=290162</ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200504-18.xml">GLSA-200504-18</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-383.html">RHSA-2005:383</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-386.html">RHSA-2005:386</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/13232">13232</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1013742">1013742</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1013743">1013743</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14938">14938</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14992">14992</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/20123">mozilla-installtrigger-command-execution(20123)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval100018.html">OVAL100018</ref><ref source="SCO" url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.49/SCOSA-2005.49.txt">SCOSA-2005.49</ref><ref source="BID" url="http://www.securityfocus.com/bid/15495">15495</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-384.html">RHSA-2005:384</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-601.html">RHSA-2005:601</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_04_25.html">SUSE-SA:2006:022</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19823">19823</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100018">oval:org.mitre.oval:def:100018</ref></refs><vuln_soft><prod name="Mozilla" vendor="Mozilla"><vers num="1.7.6"/><vers num="1.7.5"/><vers num="1.7.3"/><vers num="1.7.2"/><vers num="1.7.1"/><vers num="1.7 rc3"/><vers num="1.7 rc2"/><vers num="1.7 rc1"/><vers num="1.7 beta"/><vers num="1.7 alpha"/><vers num="1.7"/><vers num="1.6 beta"/><vers num="1.6 alpha"/><vers num="1.6"/><vers num="1.5.1"/><vers num="1.5 rc2"/><vers num="1.5 rc1"/><vers num="1.5 alpha"/><vers num="1.5"/><vers num="1.4a"/><vers num="1.4.1"/><vers num="1.4"/><vers num="1.3"/></prod><prod name="Firefox" vendor="Mozilla"><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0"/><vers num="0.9.3"/><vers num="0.9.2"/><vers num="0.9.1"/><vers edition="rc" num="0.9"/><vers num="0.9"/><vers num="0.8"/><vers num="0.10.1"/><vers num="0.10"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1160" published="2005-05-02" seq="2005-1160" severity="Medium" type="CVE"><desc><descript source="cve">The privileged &quot;chrome&quot; UI code in Firefox before 1.0.3 and Mozilla Suite before 1.7.7 allows remote attackers to gain privileges by overriding certain properties or methods of DOM nodes, as demonstrated using multiple attacks involving the eval function or the Script object.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><design/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="CONFIRM" url="http://www.mozilla.org/security/announce/mfsa2005-41.html">http://www.mozilla.org/security/announce/mfsa2005-41.html</ref><ref patch="1" source="CONFIRM" url="https://bugzilla.mozilla.org/show_bug.cgi?id=289074">https://bugzilla.mozilla.org/show_bug.cgi?id=289074</ref><ref patch="1" source="CONFIRM" url="https://bugzilla.mozilla.org/show_bug.cgi?id=289083">https://bugzilla.mozilla.org/show_bug.cgi?id=289083</ref><ref patch="1" source="CONFIRM" url="https://bugzilla.mozilla.org/show_bug.cgi?id=289961">https://bugzilla.mozilla.org/show_bug.cgi?id=289961</ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200504-18.xml">GLSA-200504-18</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-383.html">RHSA-2005:383</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-386.html">RHSA-2005:386</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14938">14938</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14992">14992</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval100017.html">OVAL100017</ref><ref source="SCO" url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.49/SCOSA-2005.49.txt">SCOSA-2005.49</ref><ref source="BID" url="http://www.securityfocus.com/bid/15495">15495</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-384.html">RHSA-2005:384</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-601.html">RHSA-2005:601</ref><ref source="BID" url="http://www.securityfocus.com/bid/13233">13233</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_04_25.html">SUSE-SA:2006:022</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19823">19823</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100017">oval:org.mitre.oval:def:100017</ref></refs><vuln_soft><prod name="Mozilla" vendor="Mozilla"><vers num="1.7.6"/><vers num="1.7.5"/><vers num="1.7.3"/><vers num="1.7.2"/><vers num="1.7.1"/><vers num="1.7 rc3"/><vers num="1.7 rc2"/><vers num="1.7 rc1"/><vers num="1.7 beta"/><vers num="1.7 alpha"/><vers num="1.7"/><vers num="1.6 beta"/><vers num="1.6 alpha"/><vers num="1.6"/><vers num="1.5.1"/><vers num="1.5 rc2"/><vers num="1.5 rc1"/><vers num="1.5 alpha"/><vers num="1.5"/><vers num="1.4a"/><vers num="1.4.1"/><vers num="1.4"/><vers num="1.3"/></prod><prod name="Firefox" vendor="Mozilla"><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0"/><vers num="0.9.3"/><vers num="0.9.2"/><vers num="0.9.1"/><vers edition="rc" num="0.9"/><vers num="0.9"/><vers num="0.8"/><vers num="0.10.1"/><vers num="0.10"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1161" published="2005-05-02" seq="2005-1161" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in OneWorldStore allow remote attackers to execute arbitrary SQL commands via the idProduct parameter to (1) owAddItem.asp or (2) owProductDetail.asp, (3) idCategory parameter to owListProduct.asp, or (4) bSpecials parameter to owListProduct.asp.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111352017704126&amp;w=2">20050414 Multiple multiple sql injection/errors and xss vulnerabilities in OneWorldStore</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/13181">13181</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/13182">13182</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/13183">13183</ref><ref source="OSVDB" url="http://www.osvdb.org/15518">15518</ref><ref source="OSVDB" url="http://www.osvdb.org/15519">15519</ref><ref source="OSVDB" url="http://www.osvdb.org/15520">15520</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013720">1013720</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/14969">14969</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20097">oneworldstore-product-category-sql-injection(20097)</ref><ref source="CONFIRM" url="http://www.oneworldstore.com/support_security_issue_updates.asp#April_15_2005_DCrab">http://www.oneworldstore.com/support_security_issue_updates.asp#April_15_2005_DCrab</ref></refs><vuln_soft><prod name="OneWorldStore" vendor="OneWorldStore"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="4.9" CVSS_score="5.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1162" published="2005-05-02" seq="2005-1162" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in OneWorldStore allow remote attackers to inject arbitrary web script or HTML via the (1) sEmail parameter to owContactUs.asp, (2) bSub parameter to owListProduct.asp, or the (3) Name, (4) Email, or (5) Comment fields in owProductDetail.asp.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111352017704126&amp;w=2">20050414 Multiple multiple sql injection/errors and xss vulnerabilities in OneWorldStore</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/13184">13184</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/13185">13185</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/13186">13186</ref><ref source="OSVDB" url="http://www.osvdb.org/15521">15521</ref><ref source="OSVDB" url="http://www.osvdb.org/15522">15522</ref><ref source="OSVDB" url="http://www.osvdb.org/15523">15523</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1013720">1013720</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14969">14969</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20096">oneworldstore-xss(20096)</ref><ref adv="1" source="CONFIRM" url="http://www.oneworldstore.com/support_security_issue_updates.asp#April_15_2005_DCrab">http://www.oneworldstore.com/support_security_issue_updates.asp#April_15_2005_DCrab</ref></refs><vuln_soft><prod name="OneWorldStore" vendor="OneWorldStore"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1163" published="2005-05-02" seq="2005-1163" severity="Medium" type="CVE"><desc><descript source="cve">Multiple buffer overflows in Yager 5.24 and earlier allow remote attackers execute arbitrary code via (1) a crafted nickname or (2) a packet with a large amount of data.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Luigi Auriemma" url="http://aluigi.altervista.org/adv/yagerbof-adv.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/13177">13177</ref><ref source="BID" url="http://www.securityfocus.com/bid/13178">13178</ref><ref source="OSVDB" url="http://www.osvdb.org/15507">15507</ref><ref source="OSVDB" url="http://www.osvdb.org/15508">15508</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/14967">14967</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20101">yager-datablock-bo(20101)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20100">yager-nickname-bo(20100)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111352154820865&amp;w=2">20050414 Multiple vulnerabilities in Yager 5.24</ref></refs><vuln_soft><prod name="Yager Game" vendor="Yager Development"><vers num="5.24"/><vers num="5.20"/><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1164" published="2005-05-02" seq="2005-1164" severity="Medium" type="CVE"><desc><descript source="cve">Yager 5.24 and earlier allows remote attackers to cause a denial of service (application hang) via a packet with a game header that provides less data than indicated by the length.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref source="Luigi Auriemma" url="http://aluigi.altervista.org/adv/yagerbof-adv.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/13179">13179</ref><ref source="OSVDB" url="http://www.osvdb.org/15509">15509</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14967">14967</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20104">yager-freeze-datablock-dos(20104)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111352154820865&amp;w=2">20050414 Multiple vulnerabilities in Yager 5.24</ref></refs><vuln_soft><prod name="Yager Game" vendor="Yager Development"><vers num="5.24"/><vers num="5.20"/><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1165" published="2005-05-02" seq="2005-1165" severity="Medium" type="CVE"><desc><descript source="cve">Yager 5.24 and earlier allows remote attackers to cause a denial of service (application crash) via certain malformed data.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref source="Luigi Auriemma" url="http://aluigi.altervista.org/adv/yagerbof-adv.txt"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20105">yager-corrupt-data-dos(20105)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111352154820865&amp;w=2">20050414 Multiple vulnerabilities in Yager 5.24</ref></refs><vuln_soft><prod name="Yager Game" vendor="Yager Development"><vers num="5.24"/><vers num="5.20"/><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-21" name="CVE-2005-1166" published="2005-05-02" seq="2005-1166" severity="Low" type="CVE"><desc><descript source="cve">The DNTUS26 process in Dameware NT Utilities and the DWRCS process in MiniRemote Control 4.9 and earlier stores the username and password in cleartext in memory, which could allow attackers to obtain sensitive information.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111358825101305&amp;w=2">20050415 Dameware NT Utilities and MiniRemote Control &lt;= 4.9 vulnerability</ref><ref source="MISC" url="http://www.shellsec.net/leer_advisory.php?id=7">http://www.shellsec.net/leer_advisory.php?id=7</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013725">1013725</ref><ref source="OSVDB" url="http://www.osvdb.org/15275">15275</ref></refs><vuln_soft><prod name="MiniRemote Control" vendor="DameWare Development"><vers num="4.9" prev="1"/></prod><prod name="Dameware NT Utilities" vendor="DameWare Development"><vers num="4.9" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1167" published="2005-05-02" seq="2005-1167" severity="Low" type="CVE"><desc><descript source="cve">Musicmatch 10.00.2047 and earlier store log files in the Program Files directory instead of the user profile, which may allow local users to obtain sensitive information.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111358261404682&amp;w=2">20050415 Improper log file storage in Musicmatch software</ref><ref source="MISC" url="http://www.hyperdose.com/advisories/H2005-02.txt">http://www.hyperdose.com/advisories/H2005-02.txt</ref></refs><vuln_soft><prod name="Jukebox" vendor="Musicmatch"><vers num="10.00.2047" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1168" published="2005-05-02" seq="2005-1168" severity="Medium" type="CVE"><desc><descript source="cve">DiagCollectionControl.dll in Musicmatch 10.00.2047 and earlier allows remote attackers to overwrite arbitrary files via the bstrSavePath argument.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111359007928030&amp;w=2">20050415 Arbitrary file overwrite possible by Musicmatch ActiveX control</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/13167">13167</ref></refs><vuln_soft><prod name="Jukebox" vendor="Musicmatch"><vers num="10.00.2047" prev="1"/><vers num="9.0.5059"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1169" published="2005-05-02" seq="2005-1169" severity="High" type="CVE"><desc><descript source="cve">Mafia Blog .4 BETA does not properly protect the admin directory, which allows remote attackers to execute arbitrary PHP code by using writeinfo.php to inject the code into info.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111359511826958&amp;w=2">20050415 Mafia Blog</ref><ref source="CONFIRM" url="http://chrisnowak.org/projects/mafia/">http://chrisnowak.org/projects/mafia/</ref><ref source="BID" url="http://www.securityfocus.com/bid/13194">13194</ref></refs><vuln_soft><prod name="Mafia Blog" vendor="Mafia"><vers num="4 Beta"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1170" published="2005-05-02" seq="2005-1170" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in mod.php in the datenbank module for phpBB allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111367077709726&amp;w=2">20050416 phpBB datenbank mod has XSS/SQL Injection in the id variable</ref></refs><vuln_soft><prod name="datenbank module" vendor="datenbank module"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1171" published="2005-05-02" seq="2005-1171" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in mod.php in the datenbank module for phpBB allows remote attackers to inject arbitrary web script or HTML via the id parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111367077709726&amp;w=2">20050416 phpBB datenbank mod has XSS/SQL Injection in the id variable</ref><ref source="BID" url="http://www.securityfocus.com/bid/13210">13210</ref><ref source="OSVDB" url="http://www.osvdb.org/15812">15812</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20146">phpbb-modphp-xss(20146)</ref></refs><vuln_soft><prod name="datenbank module" vendor="datenbank module"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1172" published="2005-05-02" seq="2005-1172" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in init.inc.php in Coppermine Photo Gallery 1.3.x allows remote attackers to inject arbitrary web script or HTML via the X-Forwarded-For parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111383800707880&amp;w=2">20050418 Vulnerability in Coppermine Photo Gallery 1.3.*</ref><ref patch="1" source="CONFIRM" url="http://coppermine.sourceforge.net/board/index.php?topic=17134">http://coppermine.sourceforge.net/board/index.php?topic=17134</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/13218">13218</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/15004">15004</ref></refs><vuln_soft><prod name="Coppermine Photo Gallery" vendor="Coppermine"><vers num="1.3"/><vers num="1.2.2 b"/><vers num="1.2.1"/><vers num="1.2"/><vers num="1.1 beta 2"/><vers num="1.1 .0"/><vers num="1.0 RC3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1173" published="2005-05-02" seq="2005-1173" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in PMSoftware Simple Web Server 1.0 allows remote attackers to execute arbitrary code via a long GET request.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111384806002021&amp;w=2">20050418 ERNW Security Advisory 01/2005</ref></refs><vuln_soft><prod name="Simple Web Server" vendor="PMSoftware"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1174" published="2005-07-18" seq="2005-1174" severity="Medium" type="CVE"><desc><descript source="cve">MIT Kerberos 5 (krb5) 1.3 through 1.4.1 Key Distribution Center (KDC) allows remote attackers to cause a denial of service (application crash) via a certain valid TCP connection that causes a free of unallocated memory.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112122123211974&amp;w=2">20050712 MITKRB5-SA-2005-002: buffer overflow, heap corruption in KDC</ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/259798">VU#259798</ref><ref patch="1" source="" url="http://web.mit.edu/kerberos/advisories/2005-002-patch_1.4.1.txt">http://web.mit.edu/kerberos/advisories/2005-002-patch_1.4.1.txt</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-757">DSA-757</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/Aug/msg00000.html">APPLE-SA-2005-08-15</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2005//Aug/msg00001.html">APPLE-SA-2005-08-17</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20050703-01-U.asc">20050703-01-U</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_17_sr.html">SuSE-SR:2005:017</ref><ref source="TURBO" url="http://www.turbolinux.com/security/2005/TLSA-2005-78.txt">TLSA-2005-78</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2005/0036">2005-0036</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-224-1">USN-224-1</ref><ref source="BID" url="http://www.securityfocus.com/bid/14240">14240</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/1066">ADV-2005-1066</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16041">16041</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/21327">kerberos-kdc-krb5-tcp-connection-dos(21327)</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17899">17899</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014460">1014460</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-567.html">RHSA-2005:567</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101809-1">101809</ref><ref source="AIXAPAR" url="http://www-1.ibm.com/support/docview.wss?uid=swg1IY85474">IY85474</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/2074">ADV-2006-2074</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20364">20364</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:397">oval:org.mitre.oval:def:397</ref></refs><vuln_soft><prod name="Kerberos 5" vendor="MIT"><vers num="1.3"/><vers num="1.3.1"/><vers num="1.3.2"/><vers num="1.3.3"/><vers num="1.3.4"/><vers num="1.3.5"/><vers num="1.3.6"/><vers num="1.4"/><vers num="1.4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1175" published="2005-07-18" seq="2005-1175" severity="High" type="CVE"><desc><descript source="cve">Heap-based buffer overflow in the Key Distribution Center (KDC) in MIT Kerberos 5 (krb5) 1.4.1 and earlier allows remote attackers to cause a denial of service (apllication crash) and possibly execute arbitrary code via a certain valid TCP or UDP request.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2005-002-kdc.txt">http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2005-002-kdc.txt</ref><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-757">DSA-757</ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/885830">VU#885830</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/Aug/msg00000.html">APPLE-SA-2005-08-15</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2005//Aug/msg00001.html">APPLE-SA-2005-08-17</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20050703-01-U.asc">20050703-01-U</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_17_sr.html">SuSE-SR:2005:017</ref><ref source="TURBO" url="http://www.turbolinux.com/security/2005/TLSA-2005-78.txt">TLSA-2005-78</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2005/0036">2005-0036</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-224-1">USN-224-1</ref><ref source="BID" url="http://www.securityfocus.com/bid/14236">14236</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/1066">ADV-2005-1066</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16041">16041</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/21328">kerberos-kdc-krb5-udp-tcp-bo(21328)</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17899">17899</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014460">1014460</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-562.html">RHSA-2005:562</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-567.html">RHSA-2005:567</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17135">17135</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112122123211974&amp;w=2">20050712 MITKRB5-SA-2005-002: buffer overflow, heap corruption in KDC</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101809-1">101809</ref><ref source="AIXAPAR" url="http://www-1.ibm.com/support/docview.wss?uid=swg1IY85474">IY85474</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/2074">ADV-2006-2074</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20364">20364</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:736">oval:org.mitre.oval:def:736</ref></refs><vuln_soft><prod name="Kerberos 5" vendor="MIT"><vers num="1.3"/><vers num="1.3.1"/><vers num="1.3.2"/><vers num="1.3.3"/><vers num="1.3.4"/><vers num="1.3.5"/><vers num="1.3.6"/><vers num="1.4"/><vers num="1.4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="1.2" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="2.9" CVSS_score="1.2" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1176" published="2005-05-02" seq="2005-1176" severity="Low" type="CVE"><desc><descript source="cve">Race condition in JFS2 on AIX 5.2 and 5.3, when deleting a file while I/O is still occurring for that file, may write data to a different file, which could leak sensitive information.</descript></desc><loss_types><conf/></loss_types><vuln_types><race/></vuln_types><range><local/></range><refs><ref source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY70032&amp;apar=only">IY70032</ref><ref source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY70034&amp;apar=only">IY70034</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20604">aix-jfs2-race-condition(20604)</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="5.2.0.50"/><vers num="5.2.0.54"/><vers num="5.3.0.10"/><vers num="5.3.0.20"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-09-22" name="CVE-2005-1177" published="2005-05-02" seq="2005-1177" severity="High" type="CVE"><desc><descript source="cve">Unknown vulnerability in (1) Webmin and (2) Usermin before 1.200 causes Webmin to change permissions and ownership of configuration files, with unknown impact.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref source="CONFIRM" url="http://www.webmin.com/changes.html">http://www.webmin.com/changes.html</ref><ref source="CONFIRM" url="http://www.webmin.com/uchanges.html">http://www.webmin.com/uchanges.html</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1013723">1013723</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/20607">webmin-config-file-permissions(20607)</ref></refs><vuln_soft><prod name="Usermin" vendor="Usermin"><vers num="1.140"/><vers num="1.130"/><vers num="1.120"/><vers num="1.110"/><vers num="1.100"/><vers num="1.090"/><vers num="1.080"/><vers num="1.070"/><vers num="1.060"/><vers num="1.051"/><vers num="1.040"/><vers num="1.030"/><vers num="1.020"/><vers num="1.010"/><vers num="1.000"/><vers num="0.99"/><vers num="0.98"/><vers num="0.97"/><vers num="0.96"/><vers num="0.95"/><vers num="0.94"/><vers num="0.93"/><vers num="0.92"/><vers num="0.91"/><vers num="0.9"/><vers num="0.8"/><vers num="0.7"/><vers num="0.6"/><vers num="0.5"/><vers num="0.4"/></prod><prod name="Webmin" vendor="Webmin"><vers num="1.1.40"/><vers num="1.1.30"/><vers num="1.1.20"/><vers num="1.1.10"/><vers num="1.1.00"/><vers num="1.0.90"/><vers num="1.0.80"/><vers num="1.0.70"/><vers num="1.0.60"/><vers num="1.0.51"/><vers num="1.0.40"/><vers num="1.0.30"/><vers num="1.0.20"/><vers num="1.0.10"/><vers num="1.0.00"/><vers num="0.99"/><vers num="0.98"/><vers num="0.97"/><vers num="0.96"/><vers num="0.95"/><vers num="0.94"/><vers num="0.93"/><vers num="0.92"/><vers num="0.91"/><vers num="0.90"/><vers num="0.80"/><vers num="0.7"/><vers num="0.6"/><vers num="0.5"/><vers num="0.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1178" published="2005-05-02" seq="2005-1178" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in Oracle Forms 10g allows remote attackers to execute arbitrary SQL commands via the Query/Where feature.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://www.red-database-security.com/wp/sql_injection_forms_us.pdf">http://www.red-database-security.com/wp/sql_injection_forms_us.pdf</ref><ref adv="1" source="MISC" url="http://www.securiteam.com/securitynews/5HP0I0UFFI.html">http://www.securiteam.com/securitynews/5HP0I0UFFI.html</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20080">oracle-forms-query-where-popup-sql-injection(20080)</ref></refs><vuln_soft><prod name="Oracle Forms" vendor="Oracle"><vers num="3.0"/><vers num="4.5"/><vers num="5.0"/><vers num="6.0"/><vers num="6i"/><vers num="9i"/><vers num="10g"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-25" name="CVE-2005-1179" published="2005-05-02" seq="2005-1179" severity="Medium" type="CVE"><desc><descript source="cve">Unknown vulnerability in Xerox MicroServer Web Server for various WorkCentre products including M35/M45/M55 2.028.11.000 through 2.97.20.032 and 4.84.16.000 through 4.97.20.032, Pro 35/45/55 3.028.11.000 through 3.97.20.032, Pro 65/75/90 1.001.00.060 through 1.001.02.084, and others, related to SNMP authentication, allows remote attackers to modify system configuration, a different vulnerability than CVE-2005-0703.</descript></desc><loss_types><int/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CONFIRM" url="http://www.xerox.com/downloads/usa/en/c/cert_XRX05_005.pdf">http://www.xerox.com/downloads/usa/en/c/cert_XRX05_005.pdf</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14507">14507</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/13196">13196</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/20192">xerox-workcentre-snmp-auth-bypass(20192)</ref></refs><vuln_soft><prod name="WorkCentre Pro" vendor="Xerox"><vers num="90 1.001.02.084"/><vers num="90 1.001.00.060"/><vers num="75 1.001.02.084"/><vers num="75 1.001.00.060"/><vers num="65 1.001.02.084"/><vers num="65 1.001.00.060"/><vers num="55 3.97.20.032"/><vers num="55 3.028.11.000"/><vers num="45 3.97.20.032"/><vers num="45 3.028.11.000"/><vers num="35 3.97.20.032"/><vers num="35 3.028.11.000"/><vers num="175 7.47.33.008"/><vers num="175 7.47.30.000"/><vers num="165 7.47.33.008"/><vers num="165 7.47.30.000"/></prod><prod name="WorkCentre Pro Color" vendor="Xerox"><vers num="3545 0.001.04.044"/><vers num="2636 0.001.04.044"/><vers num="2128 0.001.04.044"/></prod><prod name="WorkCentre" vendor="Xerox"><vers num="M55 4.97.20.032"/><vers num="M55 4.97.20.025"/><vers num="M55 4.84.16.000"/><vers num="M55 2.97.20.032"/><vers num="M55 2.28.11.000"/><vers num="M45 4.97.20.032"/><vers num="M45 4.97.20.025"/><vers num="M45 4.84.16.000"/><vers num="M45 2.97.20.032"/><vers num="M45 2.28.11.000"/><vers num="M35 4.97.20.032"/><vers num="M35 4.97.20.025"/><vers num="M35 4.84.16.000"/><vers num="M35 2.97.20.032"/><vers num="M35 2.28.11.000"/><vers num="M175 8.47.33.008"/><vers num="M175 8.47.30.000"/><vers num="M175 6.47.33.008"/><vers num="M175 6.47.30.000"/><vers num="M165 8.47.33.008"/><vers num="M165 8.47.30.000"/><vers num="M165 6.47.33.008"/><vers num="M165 6.47.30.000"/><vers num="40 Color 1.2.81"/><vers num="40 Color 01.02.65.1"/><vers num="40 Color 01.02.077.1"/><vers num="40 Color 01.02.058.4"/><vers num="40 Color 01.02.053.1"/><vers num="40 Color 01.00.060"/><vers num="32 Color 1.2.81"/><vers num="32 Color 01.02.077.1"/><vers num="32 Color 01.02.058.4"/><vers num="32 Color 01.02.053.1"/><vers num="32 Color 01.00.060"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1180" published="2005-05-02" seq="2005-1180" severity="Medium" type="CVE"><desc><descript source="cve">HTTP Response Splitting vulnerability in the Surveys module in PHP-Nuke 7.6 allows remote attackers to spoof web content and poison web caches via hex-encoded CRLF (&quot;%0d%0a&quot;) sequences in the forwarder parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://www.digitalparadox.org/advisories/pnuke.txt">http://www.digitalparadox.org/advisories/pnuke.txt</ref><ref source="OSVDB" url="http://www.osvdb.org/15647">15647</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14965">14965</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20116">php-nuke-http-response-splitting(20116)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111359804013536&amp;w=2">20050415 Http Response Splitting Vulnerability In PHP-NUKE 7.6 and below</ref></refs><vuln_soft><prod name="PHP-Nuke" vendor="Francisco Burzi"><vers num="7.6"/><vers num="7.5" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-08-28" name="CVE-2005-1181" published="2005-05-02" seq="2005-1181" severity="High" type="CVE"><desc><descript source="cve">** DISPUTED **  NOTE: this issue has been disputed by the vendor.  PHP remote code injection vulnerability in loader.php for Ariadne CMS 2.4 allows remote attackers to execute arbitrary PHP code by modifying the ariadne parameter to reference a URL on a remote web server that contains the code.  NOTE: the vendor has disputed this issue, saying that loader.php first requires the &quot;ariadne.inc&quot; file, which defines the $ariadne variable, and thus it cannot be modified by an attacker. In addition, CVE personnel have partially verified the dispute via source code inspection of Ariadne 2.4 as available on July 5, 2005.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="OSVDB" url="http://www.osvdb.org/15549">15549</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013721">1013721</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20611">ariadne-loaderphp-file-include(20611)</ref></refs><vuln_soft><prod name="Ariadne CMS" vendor="Ariadne"><vers num="2.4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1182" published="2005-05-02" seq="2005-1182" severity="Medium" type="CVE"><desc><descript source="cve">Unknown vulnerability in Incoming Remote Command (iSeries Access for Windows Remote Command service) in IBM OS/400 R510, R520, and R530 allows attackers to cause a denial of service (IRC shutdown) via certain inputs.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="CONFIRM" url="http://www-1.ibm.com/support/docview.wss?uid=nas29afd3991f5f290b086256fdb0053b293">http://www-1.ibm.com/support/docview.wss?uid=nas29afd3991f5f290b086256fdb0053b293</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14970">14970</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20612">ibm-irc-dos(20612)</ref></refs><vuln_soft><prod name="OS_400" vendor="IBM"><vers num="R510"/><vers num="R520"/><vers num="R530"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1183" published="2005-05-02" seq="2005-1183" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in mvnForum 1.0 RC4 allows remote attackers to inject arbitrary web script or HTML via the Search parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/13213">13213</ref><ref source="OSVDB" url="http://www.osvdb.org/15760">15760</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20613">mvnforum-search-xss(20613)</ref></refs><vuln_soft><prod name="mvnForum" vendor="mvnForum"><vers num="1.0 RC4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1184" published="2005-05-02" seq="2005-1184" severity="Medium" type="CVE"><desc><descript source="cve">The TCP/IP stack in multiple operating systems allows remote attackers to cause a denial of service (CPU consumption) via a TCP packet with the correct sequence number but the wrong Acknowledgement number, which generates a large number of &quot;keep alive&quot; packets.  NOTE: some followups indicate that this issue could not be replicated.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref source="FULLDISC" url="http://seclists.org/lists/fulldisclosure/2005/Apr/0358.html">20050416 TCP/IP Stack Vulnerability</ref><ref source="FULLDISC" url="http://seclists.org/lists/fulldisclosure/2005/Apr/0383.html">20050418 Re: TCP/IP Stack Vulnerability</ref><ref source="FULLDISC" url="http://seclists.org/lists/fulldisclosure/2005/Apr/0385.html">20050418 Re: TCP/IP Stack Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/13215">13215</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/40502">multiple-tcpip-dos(40502)</ref></refs><vuln_soft><prod name="Windows 98" vendor="Microsoft"><vers num="SE"/></prod><prod name="Windows XP" vendor="Microsoft"><vers edition="SP2" num="Home"/><vers edition="SP1" num="Home"/><vers num="Home"/><vers edition="Gold" num="Professional"/><vers edition="Gold" num="Professional"/><vers edition="Gold" num="Professional"/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers num="Enterprise 64-bit"/><vers num="Standard 64-bit"/><vers edition="SP1" num="R2"/><vers edition="64-bit" num="R2"/><vers edition="SP1" num="Datacenter 64-bit"/><vers edition="Datacenter 64-bit" num="R2"/><vers edition="SP1" num="Enterprise"/><vers edition="64-bit" num="Enterprise"/><vers edition="SP1" num="Enterprise 64-bit"/><vers edition="SP1" num="Standard"/><vers edition="64-bit" num="Standard"/><vers edition="SP1" num="Web"/><vers num="Web"/></prod><prod name="Windows NT" vendor="Microsoft"><vers num="Enterprise Server 4.0 SP6a"/><vers num="Enterprise Server 4.0 SP6"/><vers num="Enterprise Server 4.0 SP5"/><vers num="Enterprise Server 4.0 SP4"/><vers num="Enterprise Server 4.0 SP3"/><vers num="Enterprise Server 4.0 SP2"/><vers num="Enterprise Server 4.0 SP1"/><vers num="Enterprise Server 4.0"/><vers num="Server 4.0 SP6a"/><vers num="Server 4.0 SP6"/><vers num="Server 4.0 SP5"/><vers num="Server 4.0 SP4"/><vers num="Server 4.0 SP3"/><vers num="Server 4.0 SP2"/><vers num="Server 4.0 SP1"/><vers num="Server 4.0"/><vers num="Terminal Server 4.0 SP6a"/><vers num="Terminal Server 4.0 SP6"/><vers num="Terminal Server 4.0 SP5"/><vers num="Terminal Server 4.0 SP4"/><vers num="Terminal Server 4.0 SP3"/><vers num="Terminal Server 4.0 SP2"/><vers num="Terminal Server 4.0 SP1"/><vers num="Terminal Server 4.0"/><vers num="Workstation 4.0 SP6a"/><vers num="Workstation 4.0 SP6"/><vers num="Workstation 4.0 SP5"/><vers num="Workstation 4.0 SP4"/><vers num="Workstation 4.0 SP3"/><vers num="Workstation 4.0 SP2"/><vers num="Workstation 4.0 SP1"/><vers num="Workstation 4.0"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num="Advanced Server SP4"/><vers num="Advanced Server SP3"/><vers num="Advanced Server SP2"/><vers num="Advanced Server SP1"/><vers num="Advanced Server"/><vers num="Datacenter Server SP4"/><vers num="Datacenter Server SP3"/><vers num="Datacenter Server SP2"/><vers num="Datacenter Server SP1"/><vers num="Datacenter Server"/><vers num="Professional SP4"/><vers num="Professional SP3"/><vers num="Professional SP2"/><vers num="Professional SP1"/><vers num="Professional"/><vers num="Server SP4"/><vers num="Server SP3"/><vers num="Server SP2"/><vers num="Server SP1"/><vers num="Server"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-06-15" name="CVE-2005-1185" published="2005-05-02" seq="2005-1185" severity="Medium" type="CVE"><desc><descript source="cve">Unquoted Windows search path vulnerability in Musicmatch Jukebox 10.00.2047 and earlier allows local users to gain privileges via a malicious C:\program.exe file, which is run by MMFWLaunch.exe when it attempts to execute launch.exe.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref patch="1" source="MISC" url="http://www.hyperdose.com/advisories/H2005-05.txt">http://www.hyperdose.com/advisories/H2005-05.txt</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1013718">1013718</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20129">jukebox-mmfwlaunch-gain-privileges(20129)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111352290711509&amp;w=2">20050414 Trojan file issue in Musicmatch software</ref></refs><vuln_soft><prod name="Jukebox" vendor="Musicmatch"><vers num="10.00.2047" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1186" published="2005-05-02" seq="2005-1186" severity="Medium" type="CVE"><desc><descript source="cve">Musicmatch Jukebox 10.00.2047 and earlier adds the musicmatch.com domain to the Trusted Sites zone in Internet Explorer, which allows systems in the domain to conduct unauthorized activities, as demonstrated using cross-site scripting (XSS) attacks.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref patch="1" source="BUGTRAQ" url="http://seclists.org/lists/bugtraq/2005/Apr/0212.html">20050414 Trusted Site Cross Site Scripting Elevation of Privilege in Musicmatch</ref><ref patch="1" source="MISC" url="http://www.hyperdose.com/advisories/H2005-04.txt">http://www.hyperdose.com/advisories/H2005-04.txt</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1013718">1013718</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20129">jukebox-mmfwlaunch-gain-privileges(20129)</ref></refs><vuln_soft><prod name="Jukebox" vendor="Musicmatch"><vers num="10.00.2047" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1187" published="2005-05-02" seq="2005-1187" severity="Medium" type="CVE"><desc><descript source="cve">Heap-based buffer overflow in WinHex 12.05 SR-14, and possibly other versions, may allow attackers to execute arbitrary code via a long file name argument.  NOTE: since this overflow is in the command line of an unprivileged program, it is highly likely that this is not a vulnerability.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref source="MISC" url="http://www.unl0ck.org/files/papers/winhex.txt">http://www.unl0ck.org/files/papers/winhex.txt</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013727">1013727</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20139">winhex-filename-bo(20139)</ref></refs><vuln_soft><prod name="WinHex" vendor="X-Ways Software Technology AG"><vers num="12.05 SR-14"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1188" published="2005-05-02" seq="2005-1188" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in comersus_searchItem.asp in Comersus 3.90 to 4.51 allows remote attackers to inject arbitrary web script or HTML via the curPage parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://lostmon.blogspot.com/2005/04/comersus-asp-shopping-cart-variable.html">http://lostmon.blogspot.com/2005/04/comersus-asp-shopping-cart-variable.html</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/13125">13125</ref><ref source="OSVDB" url="http://www.osvdb.org/15539">15539</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013747">1013747</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20147">comersus-comersussearchitem-xss(20147)</ref></refs><vuln_soft><prod name="Comersus Cart" vendor="Comersus Open Technologies"><vers num="3.90"/><vers num="4.00"/><vers num="4.14"/><vers num="4.20b"/><vers num="4.23"/><vers num="4.27"/><vers num="4.28"/><vers num="4.29"/><vers num="4.36"/><vers num="4.47"/><vers num="4.051"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1189" published="2005-05-02" seq="2005-1189" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in WebcamXP PRO v2.16.468 and earlier allows remote attackers to inject arbitrary web script or HTML via the chat name, as demonstrated by using an IFRAME to redirect users to other sites.</descript></desc><sols><sol source="nvd">The vulnerability has reportedly been fixed in the beta version 2.16.478.</sol></sols><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="SECTRACK" url="http://securitytracker.com/id?1013753">1013753</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14999">14999</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20166">webcamxp-chat-xss(20166)</ref></refs><vuln_soft><prod name="WebcamXP PRO" vendor="WebcamXP"><vers num="2.16.467" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1190" published="2005-05-02" seq="2005-1190" severity="Medium" type="CVE"><desc><descript source="cve">WebcamXP PRO v2.16.468 and earlier allows remote attackers to cause a denial of service via a long chat name, which takes up too much display space and prevents the chat frame from being properly rendered.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1013753">1013753</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20615">webcamxp-chatname-dos(20615)</ref></refs><vuln_soft><prod name="WebcamXP PRO" vendor="WebcamXP"><vers num="2.16.468" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1191" published="2005-05-02" seq="2005-1191" severity="Medium" type="CVE"><desc><descript source="cve">The Web View DLL (webvw.dll), as used in Windows Explorer on Windows 2000 systems, does not properly filter an apostrophe (&quot;&apos;&quot;) in the author name in a document, which allows attackers to execute arbitrary script via extra attributes when Web View constructs a mailto: link for the preview pane when the user selects the file.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/396224">20050419 File Selection May Lead to Command Execution (GM#015-IE)</ref><ref patch="1" source="MISC" url="http://security.greymagic.com/security/advisories/gm015-ie">http://security.greymagic.com/security/advisories/gm015-ie</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/13248">13248</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms05-024.mspx">MS05-024</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/0509">ADV-2005-0509</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20380">windows-web-view-command-execution(20380)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval3585.html">OVAL3585</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3585">oval:org.mitre.oval:def:3585</ref></refs><vuln_soft><prod name="Windows 98" vendor="Microsoft"><vers num=""/><vers num="SE"/></prod><prod name="Windows ME" vendor="Microsoft"><vers num="a"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num="Advanced Server SP4"/><vers num="Advanced Server SP3"/><vers num="Advanced Server SP2"/><vers num="Advanced Server SP1"/><vers num="Advanced Server"/><vers num="Datacenter Server SP4"/><vers num="Datacenter Server SP3"/><vers num="Datacenter Server SP2"/><vers num="Datacenter Server SP1"/><vers num="Datacenter Server"/><vers num="Professional SP4"/><vers num="Professional SP3"/><vers num="Professional SP2"/><vers num="Professional SP1"/><vers num="Professional"/><vers num="Server SP4"/><vers num="Server SP3"/><vers num="Server SP2"/><vers num="Server SP1"/><vers num="Server"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-25" name="CVE-2005-1192" published="2005-05-02" seq="2005-1192" severity="Medium" type="CVE"><desc><descript source="cve">Unknown vulnerability in HP-UX B.11.00, B.11.04, B.11.11, B.11.22, and B.11.23, when running TCP/IP on IPv4, allows remote attackers to cause a denial of service via certain packets, related to the PMTU, a different vulnerability than CVE-2004-1060.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/><env/></vuln_types><range><network/></range><refs><ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX01137">HPSBUX01137</ref><ref source="AusCERT" url="http://www.auscert.org.au/render.html?it=5029">HP Security Bulletin HPSBUX01137 -- SSRT5954 rev.0 HP-UX TCP/IP Remote Denial of Service (DoS) </ref><ref source="BID" url="http://www.securityfocus.com/bid/13367">13367</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1407">oval:org.mitre.oval:def:1407</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1533">oval:org.mitre.oval:def:1533</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1552">oval:org.mitre.oval:def:1552</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1607">oval:org.mitre.oval:def:1607</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:935">oval:org.mitre.oval:def:935</ref><ref source="SREASON" url="http://securityreason.com/securityalert/262">262</ref></refs><vuln_soft><prod name="HP-UX" vendor="HP"><vers num="11.23"/><vers num="11.22"/><vers num="11.11"/><vers num="11.04"/><vers num="11.00"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1193" published="2005-05-16" seq="2005-1193" severity="High" type="CVE"><desc><descript source="cve">The bbencode_second_pass and make_clickable functions in bbcode.php for phpBB before 2.0.15, as used in viewtopic.php, privmsg.php, and other scripts, allow remote attackers to execute arbitrary script via a BBcode tag with a (1) javascript:, (2) applet:, (3) about:, (4) activex:, (5) chrome:, or (6) script: URI scheme, as demonstrated using the URL tag.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://seclists.org/lists/bugtraq/2005/May/0098.html">20050507 phpbb 2.0.15 released - patches high critical vuln</ref><ref source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=111552510000088&amp;w=2">20050508 phpbb 2.0.15 released - patches high critical vuln</ref><ref patch="1" source="CONFIRM" url="http://www.phpbb.com/phpBB/viewtopic.php?f=14&amp;t=288194">http://www.phpbb.com/phpBB/viewtopic.php?f=14&amp;t=288194</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/113196">VU#113196</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/13545">13545</ref><ref source="OSVDB" url="http://www.osvdb.org/16439">16439</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1013918">1013918</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/15298">15298</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20574">phpbb-url-bbcode-file-include(20574)</ref><ref source="MISC" url="http://castlecops.com/t123194-.html">http://castlecops.com/t123194-.html</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014117">1014117</ref></refs><vuln_soft><prod name="PhpBB" vendor="PhpBB Group"><vers num="2.0.0"/><vers num="2.0 RC4"/><vers num="2.0 RC3"/><vers num="2.0 RC2"/><vers num="2.0 RC1"/><vers num="2.0 Beta1"/><vers num="2.0.1"/><vers num="2.0.2"/><vers num="2.0.3"/><vers num="2.0.4"/><vers num="2.0.5"/><vers num="2.0.6d"/><vers num="2.0.6c"/><vers num="2.0.6"/><vers num="2.0.7a"/><vers num="2.0.7"/><vers num="2.0.8a"/><vers num="2.0.8"/><vers num="2.0.9"/><vers num="2.0.10"/><vers num="2.0.11"/><vers num="2.0.12"/><vers num="2.0.13"/><vers num="2.0.14"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-25" name="CVE-2005-1194" published="2005-05-04" seq="2005-1194" severity="Medium" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in the ieee_putascii function for nasm 0.98 and earlier allows attackers to execute arbitrary code via a crafted asm file, a different vulnerability than CVE-2004-1287.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-381.html">RHSA-2005:381</ref></refs><vuln_soft><prod name="Desktop" vendor="Red Hat"><vers num="3.0"/><vers num="4.0"/></prod><prod name="Enterprise Linux WS" vendor="Red Hat"><vers edition="Workstation" num="2.1"/><vers edition="Workstation" num="3.0"/><vers edition="Workstation" num="4.0"/></prod><prod name="Enterprise Linux ES" vendor="Red Hat"><vers edition="Enterprise Server" num="2.1"/><vers edition="Enterprise Server" num="3.0"/><vers edition="Enterprise Server" num="4.0"/></prod><prod name="Enterprise Linux AS" vendor="Red Hat"><vers edition="Advanced Server" num="2.1"/><vers edition="Advanced Servers" num="3.0"/><vers edition="Advanced Server" num="4.0"/></prod><prod name="Linux Advanced Workstation" vendor="Red Hat"><vers edition="IA64" num="2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1195" published="2005-05-02" seq="2005-1195" severity="High" type="CVE"><desc><descript source="cve">Multiple heap-based buffer overflows in the code used to handle (1) MMS over TCP (MMST) streams or (2) RealMedia RTSP streams in xine-lib before 1.0, and other products that use xine-lib such as MPlayer 1.0pre6 and earlier, allow remote malicious servers to execute arbitrary code.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref patch="1" source="CONFIRM" url="http://www.mplayerhq.hu/homepage/design7/news.html#vuln10">http://www.mplayerhq.hu/homepage/design7/news.html#vuln10</ref><ref patch="1" source="CONFIRM" url="http://www.mplayerhq.hu/homepage/design7/news.html#vuln11">http://www.mplayerhq.hu/homepage/design7/news.html#vuln11</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200504-19.xml">GLSA-200504-19</ref><ref source="OSVDB" url="http://www.osvdb.org/15711">15711</ref><ref source="OSVDB" url="http://www.osvdb.org/15712">15712</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/15014">15014</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20175">mplayer-mmst-stream-bo(20175)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20171">mplayer-rtsp-stream-bo(20171)</ref><ref source="BUGTRAQ" url="http://seclists.org/lists/bugtraq/2005/Apr/0337.html">20050421 xine security announcement: multiple heap overflows in MMS and Real RTSP streaming clients</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013771">1013771</ref><ref source="" url="http://cvs.sourceforge.net/viewcvs.py/xine/xine-lib/src/input/librtsp/rtsp.c?r1=1.18&amp;r2=1.19&amp;diff_format=u"></ref><ref source="" url="http://cvs.sourceforge.net/viewcvs.py/xine/xine-lib/src/input/mms.c?r1=1.55&amp;r2=1.56&amp;diff_format=u"></ref></refs><vuln_soft><prod name="xine-lib" vendor="xine"><vers num="1 rc3c"/><vers num="1 rc3b"/><vers num="1 rc3a"/><vers num="1 rc2"/><vers num="1 beta9"/><vers num="1 beta8"/><vers num="1 beta7"/><vers num="1 beta6"/><vers num="1 beta5"/><vers num="1 beta4"/><vers num="1 beta3"/><vers num="1 beta2"/><vers num="1 beta11"/><vers num="1 beta10"/><vers num="1 beta1"/></prod><prod name="MPlayer" vendor="Mplayer"><vers num="1.0 pre6" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1196" published="2005-05-02" seq="2005-1196" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in kb.php in the Knowledge Base module for phpBB allows remote attackers to obtain sensitive information and execute SQL commands via the cat parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111384185116335&amp;w=2">20050418 phpBB - Knowledge Base MOD - SQL-Injection and Full Path Disclosure</ref></refs><vuln_soft><prod name="phpBB" vendor="phpBB Group"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1197" published="2005-05-02" seq="2005-1197" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in the SYS.DBMS_CDC_IPUBLISH.CREATE_SCN_CHANGE_SET procedure in Oracle Database Server 10g allows remote attackers to execute arbitrary SQL commands via the CHANGE_SET_NAME parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CONFIRM" url="http://www.oracle.com/technology/deploy/security/pdf/cpuapr2005.pdf">http://www.oracle.com/technology/deploy/security/pdf/cpuapr2005.pdf</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA05-117A.html">TA05-117A</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/948486">VU#948486</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111385690419118&amp;w=2">20050418 [AppSecInc Team SHATTER Security Advisory] SQL Injection in CREATE_SCN_CHANGE_SET procedure</ref></refs><vuln_soft><prod name="Oracle10g Database Server" vendor="Oracle"><vers num="10.1.0.2"/><vers num="10.1.0.3"/><vers num="10.1.0.3.1"/><vers num="10.1.0.4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-08-16" name="CVE-2005-1198" published="2005-05-02" seq="2005-1198" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in apexec.pl for Anaconda Foundation Directory allows remote attackers to read arbitrary files via hex-encoded null characters (%00) in the middle of &quot;..&quot; sequences in the template parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111393495916656&amp;w=2">20050419 Directoy Traversal Attack in apexec.pl (.%00./-Bug)</ref></refs><vuln_soft><prod name="Foundation Directory" vendor="Anaconda Partners"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1199" published="2005-05-02" seq="2005-1199" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in printthread.php in UBB.Threads allows remote attackers to execute arbitrary SQL commands via the main parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/13253">13253</ref><ref source="OSVDB" url="http://www.osvdb.org/15698">15698</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/15024">15024</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111393619021575&amp;w=2">20050419 UBB Thread printthread.php SQL Injection</ref></refs><vuln_soft><prod name="Ultimate Bulletin Board" vendor="Infopop"><vers num="6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-28" name="CVE-2005-1200" published="2005-05-02" seq="2005-1200" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in main_index.php in AZ Bulletin Board (AZbb) 1.0.07a through 1.0.07c allows remote attackers to execute arbitrary PHP code by modifying the (1) dir_src or (2) abs_layer parameter to reference a URL on a remote web server that contains the code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="CONFIRM" url="http://azbb.cyaccess.com/azbb.php?1091778548">http://azbb.cyaccess.com/azbb.php?1091778548</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/15013">15013</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/20181">az-bulletin-board-file-include(20181)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111401838521857&amp;w=2">20050420 Multiple Security Issues Found In AZBB</ref><ref source="" url="http://www.gulftech.org/?node=research&amp;article_id=00068-04192005"></ref></refs><vuln_soft><prod name="AZ Bulletin Board" vendor="Azbb"><vers num="1.0.07c"/><vers num="1.0.07b"/><vers num="1.0.07a"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1201" published="2005-05-02" seq="2005-1201" severity="Medium" type="CVE"><desc><descript source="cve">Multiple directory traversal vulnerabilities in AZ Bulletin board (AZbb) before 1.0.08 allow (1) remote authenticated users with administrative privileges to delete arbitrary files via a .. (dot dot) in the URL to admin_avatar.php or admin_attachment.php or (2) remote attackers to enumerate files via a .. (dot dot) in the attachment parameter to attachment.php, which displays a different message when a file exists or does not exist.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="CONFIRM" url="http://azbb.cyaccess.com/azbb.php?1091778548">http://azbb.cyaccess.com/azbb.php?1091778548</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/15013">15013</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20180">az-bulletin-board-file-modification(20180)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20183">az-bulletin-board-file-existence(20183)</ref><ref source="OSVDB" url="http://www.osvdb.org/15701">15701</ref><ref source="OSVDB" url="http://www.osvdb.org/15702">15702</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111401838521857&amp;w=2">20050420 Multiple Security Issues Found In AZBB</ref><ref source="" url="http://www.gulftech.org/?node=research&amp;article_id=00068-04192005"></ref></refs><vuln_soft><prod name="AZ Bulletin Board" vendor="Azbb"><vers num="1.0.07d"/><vers num="1.0.07c"/><vers num="1.0.07b"/><vers num="1.0.07a"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1202" published="2005-05-02" seq="2005-1202" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in eGroupware before 1.0.0.007 allow remote attackers to inject arbitrary web script or HTML via the (1) ab_id, (2) page, (3) type, or (4) lang parameter to index.php or (5) category_id parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="CONFIRM" url="http://sourceforge.net/project/shownotes.php?release_id=320768">http://sourceforge.net/project/shownotes.php?release_id=320768</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/13212">13212</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14982">14982</ref><ref patch="1" source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200504-24.xml">GLSA-200504-24</ref><ref source="OSVDB" url="http://www.osvdb.org/15751">15751</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111401760125555&amp;w=2">20050420 Multiple eGroupware Vulnerabilities</ref><ref source="" url="http://www.gulftech.org/?node=research&amp;article_id=00069-04202005"></ref></refs><vuln_soft><prod name="eGroupWare" vendor="eGroupWare"><vers num="1.0"/><vers num="1.0.1"/><vers num="1.0.3"/><vers num="1.0.6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1203" published="2005-05-02" seq="2005-1203" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in index.php in eGroupware before 1.0.0.007 allow remote attackers to execute arbitrary SQL commands via the (1) filter or (2) cats_app parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CONFIRM" url="http://sourceforge.net/project/shownotes.php?release_id=320768">http://sourceforge.net/project/shownotes.php?release_id=320768</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/13212">13212</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/14982">14982</ref><ref adv="1" patch="1" source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200504-24.xml">GLSA-200504-24</ref><ref source="OSVDB" url="http://www.osvdb.org/15753">15753</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111401760125555&amp;w=2">20050420 Multiple eGroupware Vulnerabilities</ref><ref source="" url="http://www.gulftech.org/?node=research&amp;article_id=00069-04202005"></ref></refs><vuln_soft><prod name="eGroupWare" vendor="eGroupWare"><vers num="1.0"/><vers num="1.0.1"/><vers num="1.0.3"/><vers num="1.0.6"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1204" published="2005-05-02" seq="2005-1204" severity="Medium" type="CVE"><desc><descript source="cve">Desktop Rover 3.0, and possibly earlier versions, allows remote attackers to cause a denial of service (application crash) via a crafted packet to TCP port 61427, which causes an invalid memory access.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="MISC" url="http://www.evilpacket.net/advisories/EP-000-0003.html">http://www.evilpacket.net/advisories/EP-000-0003.html</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15032">15032</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111401676906915&amp;w=2">20050420 Neslo Desktop Rover Remote DoS Vulnerability</ref></refs><vuln_soft><prod name="Desktop Rover" vendor="Nelso Software"><vers num="3.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1205" published="2005-06-14" seq="2005-1205" severity="Medium" type="CVE"><desc><descript source="cve">The Telnet client for Microsoft Windows XP, Windows Server 2003, and Windows Services for UNIX allows remote attackers to read sensitive environment variables via the NEW-ENVIRON option with a SEND ENV_USERVAR command.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="IDEFENSE" url="http://idefense.com/application/poi/display?id=260&amp;type=vulnerabilities">20050614 Multiple Vendor Telnet Client Information Disclosure Vulnerability</ref><ref adv="1" patch="1" source="MS" url="http://www.microsoft.com/technet/Security/bulletin/ms05-033.mspx">MS05-033</ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/800829">VU#800829</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/15690/">15690</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1132.html">OVAL1132</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval605.html">OVAL605</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval784.html">OVAL784</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014203">1014203</ref><ref source="BID" url="http://www.securityfocus.com/bid/13940">13940</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1132">oval:org.mitre.oval:def:1132</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:605">oval:org.mitre.oval:def:605</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:784">oval:org.mitre.oval:def:784</ref></refs><vuln_soft><prod name="Windows Server 2003" vendor="Microsoft"><vers edition="64-bit" num="Standard"/><vers edition="64-bit" num="R2"/><vers edition="64-bit" num="Enterprise"/><vers num="Web"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1206" published="2005-06-14" seq="2005-1206" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the Server Message Block (SMB) functionality for Microsoft Windows 2000, XP SP1 and SP2, and Server 2003 and SP1 allows remote attackers to execute arbitrary code via unknown vectors, aka the &quot;Server Message Block Vulnerability.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms05-027.mspx">MS05-027</ref><ref adv="1" patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA05-165A.html">TA05-165A</ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/489397">VU#489397</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/15694">15694</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1142.html">OVAL1142</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval259.html">OVAL259</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval467.html">OVAL467</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1142">oval:org.mitre.oval:def:1142</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:259">oval:org.mitre.oval:def:259</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:467">oval:org.mitre.oval:def:467</ref></refs><vuln_soft><prod name="Windows XP" vendor="Microsoft"><vers edition="Tablet PC" num="SP1"/><vers edition="Tablet PC" num="SP2"/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers num="R2"/><vers num="SP1"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1207" published="2005-06-14" seq="2005-1207" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the Web Client service in Microsoft Windows XP and Windows Server 2003 allows remote authenticated users to execute arbitrary code via a crafted WebDAV request containing special parameters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="MS" url="http://www.microsoft.com/technet/Security/bulletin/ms05-028.mspx">MS05-028</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/15696/">15696</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1255.html">OVAL1255</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval721.html">OVAL721</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1255">oval:org.mitre.oval:def:1255</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:721">oval:org.mitre.oval:def:721</ref></refs><vuln_soft><prod name="Windows XP" vendor="Microsoft"><vers num="Gold"/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers num="R2"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-04-19" name="CVE-2005-1208" published="2005-06-14" seq="2005-1208" severity="High" type="CVE"><desc><descript source="cve">Integer overflow in Microsoft Windows 98, 2000, XP SP2 and earlier, and Server 2003 SP1 and earlier allows remote attackers to execute arbitrary code via a crafted compiled Help (.CHM) file with a large size field that triggers a heap-based buffer overflow, as demonstrated using a &quot;ms-its:&quot; URL in Internet Explorer.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2005-q2/0062.html">20050614 eEye Advisory - EEYEB-20050316 - HTML Help File Parsing Buffer Overflow</ref><ref adv="1" patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms05-026.mspx">MS05-026</ref><ref adv="1" patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA05-165A.html">TA05-165A</ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/851869">VU#851869</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/15683">15683</ref><ref source="BID" url="http://www.securityfocus.com/bid/13953">13953</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1057.html">OVAL1057</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval381.html">OVAL381</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval463.html">OVAL463</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1057">oval:org.mitre.oval:def:1057</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:381">oval:org.mitre.oval:def:381</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:463">oval:org.mitre.oval:def:463</ref></refs><vuln_soft><prod name="Windows 98" vendor="Microsoft"><vers num="Gold"/></prod><prod name="Windows XP" vendor="Microsoft"><vers edition="Tablet PC" num="SP2"/><vers edition="Tablet PC" num="SP1"/><vers edition="Gold" num="Professional"/><vers edition="Gold" num="Professional"/><vers edition="64-bit" num="Professional"/><vers edition="Gold" num="Professional"/><vers edition="SP2" num="Home"/><vers edition="SP1" num="Home"/><vers num="Home"/><vers edition="SP1" num="Embedded"/><vers num="Embedded"/><vers edition="SP1" num="64-bit Version 2003"/><vers num="64-bit Version 2003"/><vers edition="SP1" num="64-bit"/><vers num="64-bit"/><vers num="Gold"/><vers edition="SP2" num="Tablet PC"/><vers edition="SP2" num="Tablet PC"/><vers edition="SP2" num="Tablet PC"/><vers edition="SP2" num="Media Center"/><vers edition="SP1" num="Media Center"/><vers num="Media Center"/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers num="Standard 64-bit"/><vers num="Enterprise 64-bit"/><vers num="64-bit"/><vers num="R2"/><vers edition="SP1 Beta 1" num="Web"/><vers edition="SP1" num="Web"/><vers num="Web"/><vers edition="SP1 Beta 1" num="Standard"/><vers edition="SP1" num="Standard"/><vers edition="64-bit" num="Standard"/><vers edition="SP1 Beta 1" num="Enterprise"/><vers edition="SP1" num="Enterprise"/><vers edition="SP1 Beta 1" num="Enterprise 64-bit"/><vers edition="SP1" num="Enterprise 64-bit"/><vers edition="64-bit" num="Enterprise"/><vers edition="SP1 Beta 1" num="R2"/><vers edition="SP1" num="R2"/><vers edition="SP1 Beta 1" num="Datacenter 64-bit"/><vers edition="SP1" num="Datacenter 64-bit"/><vers edition="Datacenter 64-bit" num="R2"/><vers edition="64-bit" num="R2"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1211" published="2005-06-14" seq="2005-1211" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in the PNG image rendering component of Microsoft Internet Explorer allows remote attackers to execute arbitrary code via a crafted PNG file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms05-025.mspx">MS05-025</ref><ref adv="1" patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA05-165A.html">TA05-165A</ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/189754">VU#189754</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1115.html">OVAL1115</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1239.html">OVAL1239</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval258.html">OVAL258</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval770.html">OVAL770</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval782.html">OVAL782</ref><ref source="BID" url="http://www.securityfocus.com/bid/13941">13941</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014201">1014201</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1115">oval:org.mitre.oval:def:1115</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1239">oval:org.mitre.oval:def:1239</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:258">oval:org.mitre.oval:def:258</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:770">oval:org.mitre.oval:def:770</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:782">oval:org.mitre.oval:def:782</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-04-24" name="CVE-2005-1212" published="2005-06-14" seq="2005-1212" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Microsoft Step-by-Step Interactive Training (orun32.exe) allows remote attackers to execute arbitrary code via a bookmark link file (.cbo, cbl, or .cbm extension) with a long User field.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="IDEFENSE" url="http://idefense.com/application/poi/display?id=262&amp;type=vulnerabilities&amp;flashstatus=true">20050614 Microsoft Windows Interactive Training Buffer Overflow Vulnerability</ref><ref adv="1" patch="1" source="MS" url="http://www.microsoft.com/technet/Security/bulletin/ms05-031.mspx">MS05-031</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/15669/">15669</ref><ref source="IDEFENSE" url="http://idefense.com/application/poi/display?id=262&amp;type=vulnerabilities&amp;flashstatus=true">20050614 Microsoft Windows Interactive Training Buffer Overflow Vulnerability</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1224.html">OVAL1224</ref><ref source="BID" url="http://www.securityfocus.com/bid/13944">13944</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014194">1014194</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1224">oval:org.mitre.oval:def:1224</ref></refs><vuln_soft><prod name="Windows 98" vendor="Microsoft"><vers num="SE"/><vers num="Gold"/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers num="Standard 64-bit"/><vers num="Enterprise 64-bit"/><vers num="64-bit"/><vers num="R2"/><vers edition="SP1 Beta 1" num="Web"/><vers edition="SP1" num="Web"/><vers num="Web"/><vers edition="SP1 Beta 1" num="Standard"/><vers edition="SP1" num="Standard"/><vers edition="64-bit" num="Standard"/><vers edition="SP1 Beta 1" num="Enterprise"/><vers edition="SP1" num="Enterprise"/><vers edition="SP1 Beta 1" num="Enterprise 64-bit"/><vers edition="SP1" num="Enterprise 64-bit"/><vers edition="64-bit" num="Enterprise"/><vers edition="SP1 Beta 1" num="R2"/><vers edition="SP1" num="R2"/><vers edition="SP1 Beta 1" num="Datacenter 64-bit"/><vers edition="SP1" num="Datacenter 64-bit"/><vers edition="Datacenter 64-bit" num="R2"/><vers edition="64-bit" num="R2"/></prod><prod name="Windows XP" vendor="Microsoft"><vers edition="Tablet PC" num="SP2"/><vers edition="Tablet PC" num="SP1"/><vers edition="Gold" num="Professional"/><vers edition="Gold" num="Professional"/><vers edition="64-bit" num="Professional"/><vers edition="Gold" num="Professional"/><vers edition="SP2" num="Home"/><vers edition="SP1" num="Home"/><vers num="Home"/><vers edition="SP1" num="Embedded"/><vers num="Embedded"/><vers edition="SP1" num="64-bit Version 2003"/><vers num="64-bit Version 2003"/><vers edition="SP1" num="64-bit"/><vers num="64-bit"/><vers num="Gold"/><vers edition="SP2" num="Tablet PC"/><vers edition="SP2" num="Tablet PC"/><vers edition="SP2" num="Tablet PC"/><vers edition="SP2" num="Media Center"/><vers edition="SP1" num="Media Center"/><vers num="Media Center"/></prod><prod name="Windows ME" vendor="Microsoft"><vers num="SE"/><vers num=""/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num="Terminal Services SP3"/><vers num="Terminal Services SP2"/><vers num="Terminal Services SP1"/><vers num="Terminal Services"/><vers edition="FR" num="SP4"/><vers num="SP3"/><vers num="SP2"/><vers num="SP1"/><vers num="Server SP4"/><vers num="Server SP3"/><vers num="Server SP2"/><vers num="Server SP1"/><vers num="Server"/><vers num="Professional SP4"/><vers num="Professional SP3"/><vers num="Professional SP2"/><vers num="Professional SP1"/><vers num="Professional"/><vers num="Datacenter Server SP4"/><vers num="Datacenter Server SP3"/><vers num="Datacenter Server SP2"/><vers num="Datacenter Server SP1"/><vers num="Datacenter Server"/><vers num="Advanced Server SP4"/><vers num="Advanced Server SP3"/><vers num="Advanced Server SP2"/><vers num="Advanced Server SP1"/><vers num="Advanced Server"/><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1213" published="2005-06-14" seq="2005-1213" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in the news reader for Microsoft Outlook Express (MSOE.DLL) 5.5 SP2, 6, and 6 SP1 allows remote malicious NNTP servers to execute arbitrary code via a LIST response with a long second field.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=263&amp;type=vulnerabilities">20050614 Microsoft Outlook Express NNTP Response Parsing Buffer Overflow Vulnerability</ref><ref adv="1" patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms05-030.mspx">MS05-030</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1088.html">OVAL1088</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval167.html">OVAL167</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval989.html">OVAL989</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/130614">VU#130614</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014200">1014200</ref><ref source="BID" url="http://www.securityfocus.com/bid/13951">13951</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1088">oval:org.mitre.oval:def:1088</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:167">oval:org.mitre.oval:def:167</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:989">oval:org.mitre.oval:def:989</ref></refs><vuln_soft><prod name="Outlook Express" vendor="Microsoft"><vers num="5.5 SP2"/><vers num="6.0"/><vers num="6.0 SP1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-04-19" name="CVE-2005-1214" published="2005-06-14" seq="2005-1214" severity="Medium" type="CVE"><desc><descript source="cve">Microsoft Agent allows remote attackers to spoof trusted Internet content and execute arbitrary code by disguising security prompts on a malicious Web page.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms05-032.mspx">MS05-032</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/15689">15689</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1194.html">OVAL1194</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval682.html">OVAL682</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval906.html">OVAL906</ref><ref source="BID" url="http://www.securityfocus.com/bid/13948">13948</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1194">oval:org.mitre.oval:def:1194</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:682">oval:org.mitre.oval:def:682</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:906">oval:org.mitre.oval:def:906</ref></refs><vuln_soft><prod name="Windows 98" vendor="Microsoft"><vers num="SE"/><vers num="Gold"/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers num="Standard 64-bit"/><vers num="Enterprise 64-bit"/><vers num="64-bit"/><vers num="R2"/><vers edition="SP1 Beta 1" num="Web"/><vers edition="SP1" num="Web"/><vers num="Web"/><vers edition="SP1 Beta 1" num="Standard"/><vers edition="SP1" num="Standard"/><vers edition="64-bit" num="Standard"/><vers edition="SP1 Beta 1" num="Enterprise"/><vers edition="SP1" num="Enterprise"/><vers edition="SP1 Beta 1" num="Enterprise 64-bit"/><vers edition="SP1" num="Enterprise 64-bit"/><vers edition="64-bit" num="Enterprise"/><vers edition="SP1 Beta 1" num="R2"/><vers edition="SP1" num="R2"/><vers edition="SP1 Beta 1" num="Datacenter 64-bit"/><vers edition="SP1" num="Datacenter 64-bit"/><vers edition="Datacenter 64-bit" num="R2"/><vers edition="64-bit" num="R2"/></prod><prod name="Windows XP" vendor="Microsoft"><vers edition="Tablet PC" num="SP2"/><vers edition="Tablet PC" num="SP1"/><vers edition="Gold" num="Professional"/><vers edition="Gold" num="Professional"/><vers edition="64-bit" num="Professional"/><vers edition="Gold" num="Professional"/><vers edition="SP2" num="Home"/><vers edition="SP1" num="Home"/><vers num="Home"/><vers edition="SP1" num="Embedded"/><vers num="Embedded"/><vers edition="SP1" num="64-bit Version 2003"/><vers num="64-bit Version 2003"/><vers edition="SP1" num="64-bit"/><vers num="64-bit"/><vers num="Gold"/><vers edition="SP2" num="Tablet PC"/><vers edition="SP2" num="Tablet PC"/><vers edition="SP2" num="Tablet PC"/><vers edition="SP2" num="Media Center"/><vers edition="SP1" num="Media Center"/><vers num="Media Center"/></prod><prod name="Windows ME" vendor="Microsoft"><vers num="SE"/><vers num=""/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num="Terminal Services SP3"/><vers num="Terminal Services SP2"/><vers num="Terminal Services SP1"/><vers num="Terminal Services"/><vers edition="FR" num="SP4"/><vers num="SP3"/><vers num="SP2"/><vers num="SP1"/><vers num="Server SP4"/><vers num="Server SP3"/><vers num="Server SP2"/><vers num="Server SP1"/><vers num="Server"/><vers num="Professional SP4"/><vers num="Professional SP3"/><vers num="Professional SP2"/><vers num="Professional SP1"/><vers num="Professional"/><vers num="Datacenter Server SP4"/><vers num="Datacenter Server SP3"/><vers num="Datacenter Server SP2"/><vers num="Datacenter Server SP1"/><vers num="Datacenter Server"/><vers num="Advanced Server SP4"/><vers num="Advanced Server SP3"/><vers num="Advanced Server SP2"/><vers num="Advanced Server SP1"/><vers num="Advanced Server"/><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1215" published="2005-06-14" seq="2005-1215" severity="High" type="CVE"><desc><descript source="cve">Microsoft ISA Server 2000 allows remote attackers to poison the ISA cache or bypass content restriction policies via a malformed HTTP request packet containing multiple Content-Length headers.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="MS" url="http://www.microsoft.com/technet/Security/bulletin/ms05-034.mspx">MS05-034</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/15693/">15693</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1145.html">OVAL1145</ref><ref source="BID" url="http://www.securityfocus.com/bid/13956">13956</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014193">1014193</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1145">oval:org.mitre.oval:def:1145</ref></refs><vuln_soft><prod name="ISA Server" vendor="Microsoft"><vers num="2000"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1216" published="2005-06-14" seq="2005-1216" severity="High" type="CVE"><desc><descript source="cve">Microsoft ISA Server 2000 allows remote attackers to connect to services utilizing the NetBIOS protocol via a NetBIOS connection with an ISA Server that uses the NetBIOS (all) predefined packet filter.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="MS" url="http://www.microsoft.com/technet/Security/bulletin/ms05-034.mspx">MS05-034</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/15693/">15693</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/367077">VU#367077</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval468.html">OVAL468</ref><ref source="BID" url="http://www.securityfocus.com/bid/13954">13954</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014193">1014193</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:468">oval:org.mitre.oval:def:468</ref></refs><vuln_soft><prod name="ISA Server" vendor="Microsoft"><vers num="2000"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1218" published="2005-08-10" seq="2005-1218" severity="Medium" type="CVE"><desc><descript source="cve">The Microsoft Windows kernel in Microsoft Windows 2000 Server, Windows XP, and Windows Server 2003 allows remote attackers to cause a denial of service (crash) via crafted Remote Desktop Protocol (RDP) requests.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="MISC" url="http://security-protocols.com/modules.php?name=News&amp;file=article&amp;sid=2783">http://security-protocols.com/modules.php?name=News&amp;file=article&amp;sid=2783</ref><ref source="MLIST" url="https://www.immunitysec.com/pipermail/dailydave/2005-July/002188.html">[Dailydave] 20050714 SPIKE actually scores.</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112146383919436&amp;w=2">20050715 Any info on potential 0day RDP vuln?</ref><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms05-041.mspx">MS05-041</ref><ref patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA05-221A.html">TA05-221A</ref><ref adv="1" patch="1" source="" url="http://www.microsoft.com/technet/security/advisory/904797.mspx">http://www.microsoft.com/technet/security/advisory/904797.mspx</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/14259">14259</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/490628">VU#490628</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval100092.html">OVAL100092</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100092">oval:org.mitre.oval:def:100092</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:180">oval:org.mitre.oval:def:180</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:346">oval:org.mitre.oval:def:346</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:376">oval:org.mitre.oval:def:376</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:609">oval:org.mitre.oval:def:609</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:618">oval:org.mitre.oval:def:618</ref></refs><vuln_soft><prod name="Windows XP" vendor="Microsoft"><vers edition="64-bit" num="Professional"/><vers edition="Gold" num="Professional"/><vers edition="Gold" num="Professional"/><vers edition="Gold" num="Professional"/><vers edition="SP2" num="Home"/><vers edition="SP1" num="Home"/><vers num="Home"/><vers edition="SP1" num="64-bit Version 2003"/><vers num="64-bit Version 2003"/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers num="Standard 64-bit"/><vers num="Enterprise 64-bit"/><vers edition="Datacenter 64-bit" num="R2"/><vers edition="SP1" num="Web"/><vers num="Web"/><vers edition="SP1" num="Standard"/><vers edition="64-bit" num="Standard"/><vers edition="SP1" num="Enterprise 64-bit"/><vers edition="SP1" num="Enterprise"/><vers edition="64-bit" num="Enterprise"/><vers edition="SP1" num="Datacenter 64-bit"/><vers edition="SP1" num="R2"/><vers edition="64-bit" num="R2"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num="Server SP4"/><vers num="Server SP3"/><vers num="Server SP2"/><vers num="Server SP1"/><vers num="Server"/><vers num="Datacenter Server SP4"/><vers num="Datacenter Server SP3"/><vers num="Datacenter Server SP2"/><vers num="Datacenter Server SP1"/><vers num="Datacenter Server"/><vers num="Advanced Server SP4"/><vers num="Advanced Server SP3"/><vers num="Advanced Server SP2"/><vers num="Advanced Server SP1"/><vers num="Advanced Server"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1219" published="2005-07-12" seq="2005-1219" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the Microsoft Color Management Module for Windows allows remote attackers to execute arbitrary code via an image with crafted ICC profile format tags.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="MS" url="http://www.microsoft.com/technet/Security/bulletin/ms05-036.mspx">MS05-036</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/16004/">16004</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA05-193A.html">TA05-193A</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/720742">VU#720742</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval330.html">OVAL330</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval440.html">OVAL440</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval769.html">OVAL769</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1125.html">OVAL1125</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1280.html">OVAL1280</ref><ref source="BID" url="http://www.securityfocus.com/bid/14214">14214</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:330">oval:org.mitre.oval:def:330</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:440">oval:org.mitre.oval:def:440</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:769">oval:org.mitre.oval:def:769</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1125">oval:org.mitre.oval:def:1125</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1280">oval:org.mitre.oval:def:1280</ref></refs><vuln_soft><prod name="Color Management Module" vendor="Microsoft"><vers edition="Windows" num="gold"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1220" published="2005-05-02" seq="2005-1220" severity="High" type="CVE"><desc><descript source="cve">Shoutbox SCRIPT 3.0.2 and earlier allows remote attackers to obtain sensitive information via a direct request to db/settings.dat, which displays usernames and password hashes.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref source="OSVDB" url="http://www.osvdb.org/15695">15695</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15015">15015</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20177">knusperleicht-settings-info-disclosure(20177)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111402253108991&amp;w=2">20050419 Shoutbox SCRIPT &lt;= 3.0.2 Administrative MD5 Username and Password Retrieval [x0n3-h4ck]</ref></refs><vuln_soft><prod name="Shoutbox SCRIPT" vendor="knusperleicht"><vers num="3.0.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1221" published="2005-05-02" seq="2005-1221" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in login.asp for Ecommerce-Carts EcommPro 3.0 allows remote attackers to execute arbitrary SQL commands via the password field.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MISC" url="http://www.ihssecurity.com/download/advisory/ecomerce-cart.txt">http://www.ihssecurity.com/download/advisory/ecomerce-cart.txt</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20200">ecomm-pro-sql-injection(20200)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111402179605925&amp;w=2">20050419 Ecommerce-Carts SQL injection vulnerability ( IHSTeam )</ref></refs><vuln_soft><prod name="EcommPro" vendor="Ecommerce-Carts"><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-21" name="CVE-2005-1222" published="2005-05-02" seq="2005-1222" severity="High" type="CVE"><desc><descript source="cve">cat_for_gen.php in Annuaire Netref 4.2 allows remote attackers to execute arbitrary PHP code by setting the ad_direct parameter to reference cat_for_gen.php, then including the code in the m_for_racine parameter, which is then written to cat_for_gen.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="OSVDB" url="http://www.osvdb.org/15717">15717</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/15040">15040</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20198">netref-catforgen-code-execution(20198)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111403947305600&amp;w=2">20050419 Annuaire Netref v4.2 [ fwrite php ] vulnerability</ref></refs><vuln_soft><prod name="Netref" vendor="Netref"><vers num="4.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-08-28" name="CVE-2005-1223" published="2005-05-02" seq="2005-1223" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in Ocean12 Calendar manager 1.01 allow remote attackers to execute arbitrary SQL commands via the Admin_id field.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="SECTRACK" url="http://www.securitytracker.com/alerts/2005/Apr/1013762.html">1013762</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15026">15026</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20174">ocean12-calendar-manager-sql-injection(20174)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111401502007772&amp;w=2">20050420 [HSC Security Group] Ocean12 Calendar manager 1.01 SQL injection</ref></refs><vuln_soft><prod name="Calendar Manager Pro" vendor="Ocean12 Technologies"><vers num="1.01"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-25" name="CVE-2005-1224" published="2005-05-02" seq="2005-1224" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in DUware DUportal Pro 3.4 allow remote attackers to execute arbitrary SQL commands via the (1) nChannel parameter to default.asp, cat.asp, or detail.asp, (2) the iChannel parameter to search.asp, default.asp, result.asp, cat.asp, or detail.asp (3) the iCat parameter to cat.asp or detail.asp, (4) the iData parameter to detail.asp or result.asp, the (5) POL_ID, (6) POL_PARENT, (7) POL_CATEGORY, (8) CHA_NAME, or (9) CHA_ID parameters to inc_vote.asp, or the (10) tfm_order or (11) tfm_orderby parameters to toppages.asp, a different set of vulnerabilities than CVE-2005-1236.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://www.digitalparadox.org/advisories/dup.txt">http://www.digitalparadox.org/advisories/dup.txt</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15044">15044</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20197">duportal-multiple-sql-injection(20197)</ref><ref source="MISC" url="http://www.securiteam.com/windowsntfocus/5TP0O0AFFQ.html">http://www.securiteam.com/windowsntfocus/5TP0O0AFFQ.html</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15031">15031</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111401172901705&amp;w=2">20050420 DUportal Pro 3.4 has MANY Sql injection and Sql Errors.</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/453316/100/0/threaded">20061202 [Aria-Security Team] DuWare DuPortal SQL Injection Vuln</ref><ref source="BID" url="http://www.securityfocus.com/bid/13285">13285</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/30671">duportal-default-cat-sql-injection(30671)</ref></refs><vuln_soft><prod name="DUportal" vendor="DUware"><vers num="3.4"/><vers num="SQL 3.4"/><vers num="Pro 3.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1225" published="2005-05-02" seq="2005-1225" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in Coppermine Photo Gallery 1.3.2 allows remote attackers to execute arbitrary SQL commands via the favs parameter to (1) init.inc.php or (2) zipdownload.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MISC" url="http://www.waraxe.us/advisory-42.html">http://www.waraxe.us/advisory-42.html</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/15004">15004</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20205">coppermine-initincphp-sql-injection(20205)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111402186304179&amp;w=2">20050420 [waraxe-2005-SA#042] - Multiple vulnerabilities in Coppermine Photo Gallery 1.3.2</ref></refs><vuln_soft><prod name="Coppermine Photo Gallery" vendor="Coppermine"><vers num="1.3.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1226" published="2005-05-02" seq="2005-1226" severity="High" type="CVE"><desc><descript source="cve">Coppermine Photo Gallery 1.3.2 stores passwords in plaintext, which allows remote attackers to obtain sensitive information.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref patch="1" source="MISC" url="http://www.waraxe.us/advisory-42.html">http://www.waraxe.us/advisory-42.html</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/20206">coppermine-password-plaintext(20206)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111402186304179&amp;w=2">20050420 [waraxe-2005-SA#042] - Multiple vulnerabilities in Coppermine Photo Gallery 1.3.2</ref></refs><vuln_soft><prod name="Coppermine Photo Gallery" vendor="Coppermine"><vers num="1.3.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1227" published="2005-04-20" seq="2005-1227" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in PHProjekt 4.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the chatroom text submission form.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="OSVDB" url="http://www.osvdb.org/15720">15720</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15039">15039</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20212">phprojekt-url-tag-xss(20212)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111402374504496&amp;w=2">20050420 Secure Science Corporation Application Software Advisory 055</ref></refs><vuln_soft><prod name="PHProjekt" vendor="PHProjekt"><vers num="4.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1228" published="2005-05-02" seq="2005-1228" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in gunzip -N in gzip 1.2.4 through 1.3.5 allows remote attackers to write to arbitrary directories via a .. (dot dot) in the original filename within a compressed file.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="CONFIRM" url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=305255">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=305255</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/15047">15047</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20199">gzip-n-directory-traversal(20199)</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-752">DSA-752</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval382.html">OVAL382</ref><ref source="SCO" url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.58/SCOSA-2005.58.txt">SCOSA-2005.58</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18100">18100</ref><ref source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2005-357.html">RHSA-2005:357</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111402732406477&amp;w=2">20050420 gzip directory traversal vulnerability</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101816-1">101816</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2006//Aug/msg00000.html">APPLE-SA-2006-08-01</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21253">21253</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/3101">ADV-2006-3101</ref><ref source="OSVDB" url="http://www.osvdb.org/15721">15721</ref><ref source="BID" url="http://www.securityfocus.com/bid/19289">19289</ref><ref source="SLACKWARE" url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2006&amp;m=slackware-security.555852">SSA:2006-262</ref><ref source="SECUNIA" url="http://secunia.com/advisories/22033">22033</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:382">oval:org.mitre.oval:def:382</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:170">oval:org.mitre.oval:def:170</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-214A.html">
TA06-214A</ref></refs><vuln_soft><prod name="gzip" vendor="GNU"><vers num="1.2.4"/><vers num="1.3.3"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1229" published="2005-05-02" seq="2005-1229" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in cpio 2.6 and earlier allows remote attackers to write to arbitrary directories via a .. (dot dot) in a cpio file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/><input/></vuln_types><range><local/></range><refs><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20204">cpio-directory-traversal(20204)</ref><ref source="SCO" url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.32/SCOSA-2005.32.txt">SCOSA-2005.32</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-189-1">USN-189-1</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-846">DSA-846</ref><ref source="SCO" url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2006.2/SCOSA-2006.2.txt">SCOSA-2006.2</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18290">18290</ref><ref source="FREEBSD" url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-06:03.cpio.asc">FreeBSD-SA-06:03</ref><ref source="BID" url="http://www.securityfocus.com/bid/13291">13291</ref><ref source="OSVDB" url="http://www.osvdb.org/17939">17939</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18395">18395</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17123">17123</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16998">16998</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111403177526312&amp;w=2">20050420 cpio directory traversal vulnerability</ref><ref source="SUSE" url="http://lists.suse.com/archive/suse-security-announce/2006-May/0004.html">SUSE-SR:2006:010</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20117">20117</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2007:233">MDKSA-2007:233</ref><ref source="SECUNIA" url="http://secunia.com/advisories/27857">27857</ref></refs><vuln_soft><prod name="cpio" vendor="GNU"><vers num="2.6" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1230" published="2005-05-02" seq="2005-1230" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in Yawcam 0.2.5 allows remote attackers to read arbitrary files via &quot;..\&quot; (dot dot backslash) sequences in a GET request.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MISC" url="http://www.autistici.org/fdonato/advisory/Yawcam0.2.5-adv.txt">http://www.autistici.org/fdonato/advisory/Yawcam0.2.5-adv.txt</ref><ref source="OSVDB" url="http://www.osvdb.org/15732">15732</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15052">15052</ref><ref patch="1" source="YAWCAM" url="http://www.yawcam.com/download.php">N/A</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111410564915961&amp;w=2">20050421 directory traversal in Yawcam 0.2.5</ref></refs><vuln_soft><prod name="Yawcam" vendor="Magnus Lundvall"><vers num="0.2.5"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1231" published="2005-05-02" seq="2005-1231" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in the NewTerm function in GlossaryModel.php in JAWS 0.4 allows remote attackers to inject arbitrary web script or HTML via the (1) term or (2) description.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="FULLDISC" url="http://seclists.org/lists/fulldisclosure/2005/Apr/0416.html">20050418 XSS bug in JAWS gadget Glossary (0.4-latestbeta (beta 2))</ref><ref patch="1" source="MISC" url="http://www.securiteam.com/unixfocus/5RP0M0AFFS.html">http://www.securiteam.com/unixfocus/5RP0M0AFFS.html</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/13254">13254</ref></refs><vuln_soft><prod name="JAWS" vendor="JAWS"><vers num="0.3"/><vers num="0.4"/><vers num="0.5 beta2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1232" published="2005-05-02" seq="2005-1232" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Sun Java System Web Proxy Server (aka Sun ONE Proxy Server) 3.6 SP6 allows remote attackers to execute arbitrary code via unknown vectors.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57763-1">57763</ref></refs><vuln_soft><prod name="Java System Web Proxy Server" vendor="Sun"><vers num="3.6 SP6"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1233" published="2005-04-20" seq="2005-1233" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in PHP Labs proFile allows remote attackers to inject arbitrary web script or HTML via the (1) dir or (2) file parameters.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://www.snkenjoi.com/secadv/secadv7.txt">http://www.snkenjoi.com/secadv/secadv7.txt</ref><ref adv="1" source="MISC" url="http://www.frsirt.com/english/advisories/2005/0370">http://www.frsirt.com/english/advisories/2005/0370</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/13276">13276</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/13282">13282</ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/15697">15697</ref><ref adv="1" source="SECTRACK" url="http://securitytracker.com/id?1013756">1013756</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/15027">15027</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/20169">profile-indexphp-xss(20169)</ref></refs><vuln_soft><prod name="proFile" vendor="PHP Labs"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1234" published="2005-05-02" seq="2005-1234" severity="Medium" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in phpbb-Auction allow remote attackers to execute arbitrary SQL commands via the (1) u parameter to auction_rating.php or (2) ar parameter to action_offer.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MISC" url="http://www.snkenjoi.com/secadv/secadv9.txt">http://www.snkenjoi.com/secadv/secadv9.txt</ref><ref source="CONFIRM" url="http://www.phpbb-auction.com/sutra5600.html">http://www.phpbb-auction.com/sutra5600.html</ref><ref source="BID" url="http://www.securityfocus.com/bid/13283">13283</ref><ref source="BID" url="http://www.securityfocus.com/bid/13284">13284</ref><ref source="OSVDB" url="http://www.osvdb.org/15704">15704</ref><ref source="OSVDB" url="http://www.osvdb.org/15705">15705</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013779">1013779</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/15029">15029</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20203">phpbb-auction-sql-injection(20203)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/441190/100/0/threaded">20060725 PHP-Auction SQL injection</ref><ref source="" url="http://www.aria-security.net/advisory/phpauction.txt"></ref></refs><vuln_soft><prod name="phpbb-auction" vendor="phpBB Group"><vers num="1.0m"/><vers num="1.2m"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1235" published="2005-05-02" seq="2005-1235" severity="Medium" type="CVE"><desc><descript source="cve">auction_my_auctions.php in phpbb-Auction 1.2m and earlier allows remote attackers to obtain sensitive information via an invalid mode parameter, which leaks the full path in a PHP error message.</descript></desc><sols><sol source="nvd">Fixed updated version on http://www.phpbb-auction.com/</sol></sols><loss_types><conf/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="MISC" url="http://www.snkenjoi.com/secadv/secadv9.txt">http://www.snkenjoi.com/secadv/secadv9.txt</ref><ref patch="1" source="CONFIRM" url="http://www.phpbb-auction.com/sutra5600.html">http://www.phpbb-auction.com/sutra5600.html</ref><ref source="OSVDB" url="http://www.osvdb.org/15706">15706</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013779">1013779</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15029">15029</ref></refs><vuln_soft><prod name="phpbb-auction" vendor="phpBB Group"><vers num="1.2m"/><vers num="1.0m"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-25" name="CVE-2005-1236" published="2005-05-02" seq="2005-1236" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in DUware DUportal 3.1.2 and 3.1.2 SQL allow remote attackers to execute arbitrary SQL commands via the (1) iChannel parameter to channel.asp or search.asp, (2) iData parameter to detail.asp or inc_rating.asp, (3) iCat parameter to detail.asp or type.asp, (4) DAT_PARENT parameter to inc_poll_voting.asp, or (5) iRate parameter to inc_rating.asp, a different set of vulnerabilities than CVE-2005-1224.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MISC" url="http://www.digitalparadox.org/advisories/dup.txt">http://www.digitalparadox.org/advisories/dup.txt</ref><ref source="BID" url="http://www.securityfocus.com/bid/13288">13288</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15044">15044</ref></refs><vuln_soft><prod name="DUportal" vendor="DUware"><vers num="3.1.2"/><vers num="3.1.2 SQL"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1237" published="2005-05-02" seq="2005-1237" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in news.php in FlexPHPNews 0.0.3 allows remote attackers to execute arbitrary SQL commands via the newsid parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MISC" url="http://www.frsirt.com/english/advisories/2005/0373">http://www.frsirt.com/english/advisories/2005/0373</ref><ref source="BID" url="http://www.securityfocus.com/bid/13297">13297</ref><ref source="OSVDB" url="http://www.osvdb.org/15715">15715</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14905">14905</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20214">flexphpnews-newsphp-sql-injection(20214)</ref><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3631">

3631</ref><ref source="VIM" url="http://www.attrition.org/pipermail/vim/2007-April/001506.html">
20070411 Rediscovery: Flexphpnews news.php/newsid SQL injection</ref><ref source="BID" url="http://www.securityfocus.com/bid/23247">
23247</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33362">
flexphpnew-news-sql-injection(33362)</ref></refs><vuln_soft><prod name="FlexPHPNews" vendor="China-on-site"><vers num="0.0.3" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1238" published="2005-05-02" seq="2005-1238" severity="High" type="CVE"><desc><descript source="cve">By design, the built-in FTP server for iSeries AS/400 systems does not support a restricted document root, which allows attackers to read or write arbitrary files, including sensitive QSYS databases, via a full pathname in a GET or PUT request.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/><design/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/396628">20050420 Canonicalization and directory traversal in iSeries FTP security products</ref><ref source="MISC" url="http://www.venera.com/downloads/Canonicalization_problems_in_iSeries_FTP_security.pdf">http://www.venera.com/downloads/Canonicalization_problems_in_iSeries_FTP_security.pdf</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20260">multiple-vendor-security-bypass(20260)</ref></refs><vuln_soft><prod name="iSeries" vendor="IBM"><vers num="AS_400"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1239" published="2005-05-02" seq="2005-1239" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in the third party tool from Raz-Lee, as used to secure the iSeries AS/400 FTP server, allows remote attackers to access arbitrary files, including those from qsys.lib, via &quot;..&quot; sequences in a GET request.</descript></desc><sols><sol source="nvd">Fix is available on http://www.razlee.com/</sol></sols><loss_types><conf/></loss_types><vuln_types><access/><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/396628">20050420 Canonicalization and directory traversal in iSeries FTP security products</ref><ref source="MISC" url="http://www.venera.com/downloads/Canonicalization_problems_in_iSeries_FTP_security.pdf">http://www.venera.com/downloads/Canonicalization_problems_in_iSeries_FTP_security.pdf</ref><ref source="BID" url="http://www.securityfocus.com/bid/13310">13310</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20260">multiple-vendor-security-bypass(20260)</ref></refs><vuln_soft><prod name="Security+++" vendor="Raz-Lee"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1240" published="2005-04-20" seq="2005-1240" severity="High" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in the third party tool from Castlehill, as used to secure the iSeries AS/400 FTP server, allows remote attackers to access arbitrary files, including those from qsys.lib, via &quot;..&quot; sequences in a GET request.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/396628">20050420 Canonicalization and directory traversal in iSeries FTP security products</ref><ref source="MISC" url="http://www.venera.com/downloads/Canonicalization_problems_in_iSeries_FTP_security.pdf">http://www.venera.com/downloads/Canonicalization_problems_in_iSeries_FTP_security.pdf</ref><ref source="Security Tracker" url="http://securitytracker.com/alerts/2005/Apr/1013806.html">Castlehill Secure/Net May Let Remote Users Bypass AS/400 FTP Access Controls</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20260">multiple-vendor-security-bypass(20260)</ref></refs><vuln_soft><prod name="Secure/Net" vendor="Castlehill"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1241" published="2005-04-20" seq="2005-1241" severity="High" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in the third party tool from Powertech, as used to secure the iSeries AS/400 FTP server, allows remote attackers to access arbitrary files, including those from qsys.lib, via &quot;..&quot; sequences in a GET request.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/396628">20050420 Canonicalization and directory traversal in iSeries FTP security products</ref><ref source="MISC" url="http://www.venera.com/downloads/Canonicalization_problems_in_iSeries_FTP_security.pdf">http://www.venera.com/downloads/Canonicalization_problems_in_iSeries_FTP_security.pdf</ref><ref source="BID" url="http://www.securityfocus.com/bid/13312">13312</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20260">multiple-vendor-security-bypass(20260)</ref></refs><vuln_soft><prod name="PowerLock NetworkSecurity" vendor="Powertech"><vers num="4.7.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1242" published="2005-05-02" seq="2005-1242" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in the third party tool from Bsafe, as used to secure the iSeries AS/400 FTP server, allows remote attackers to access arbitrary files, including those from qsys.lib, via &quot;..&quot; sequences in a GET request.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/396628">20050420 Canonicalization and directory traversal in iSeries FTP security products</ref><ref source="MISC" url="http://www.venera.com/downloads/Canonicalization_problems_in_iSeries_FTP_security.pdf">http://www.venera.com/downloads/Canonicalization_problems_in_iSeries_FTP_security.pdf</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20260">multiple-vendor-security-bypass(20260)</ref></refs><vuln_soft><prod name="Global Security" vendor="Bsafe"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1243" published="2005-05-02" seq="2005-1243" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in the third party tool from SafeStone, as used to secure the iSeries AS/400 FTP server, allows remote attackers to access arbitrary files, including those from qsys.lib, via &quot;..&quot; sequences in a GET request.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/396628">20050420 Canonicalization and directory traversal in iSeries FTP security products</ref><ref source="MISC" url="http://www.venera.com/downloads/Canonicalization_problems_in_iSeries_FTP_security.pdf">http://www.venera.com/downloads/Canonicalization_problems_in_iSeries_FTP_security.pdf</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20260">multiple-vendor-security-bypass(20260)</ref></refs><vuln_soft><prod name="AxcessIT" vendor="SafeStone Technologies"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1244" published="2005-04-20" seq="2005-1244" severity="High" type="CVE"><desc><descript source="cve">** DISPUTED **  Directory traversal vulnerability in the third party tool from NetIQ, as used to secure the iSeries AS/400 FTP server, allows remote attackers to access arbitrary files, including those from qsys.lib, via &quot;..&quot; sequences in a GET request.  NOTE: the vendor has disputed this issue, saying that &quot;neither NetIQ Security Manager nor our iSeries Security Solutions are vulnerable.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/396628">20050420 Canonicalization and directory traversal in iSeries FTP security products</ref><ref source="MISC" url="http://www.venera.com/downloads/Canonicalization_problems_in_iSeries_FTP_security.pdf">http://www.venera.com/downloads/Canonicalization_problems_in_iSeries_FTP_security.pdf</ref><ref source="OSVDB" url="http://www.osvdb.org/15791">15791</ref><ref adv="1" source="SECTRACK" url="http://securitytracker.com/id?1013810">1013810</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20260">multiple-vendor-security-bypass(20260)</ref></refs><vuln_soft><prod name="PSSecure" vendor="NetIQ"><vers num="7.5"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1245" published="2005-05-02" seq="2005-1245" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in MediaWiki before 1.4.2, when using HTML Tidy ($wgUseTidy), allows remote attackers to inject arbitrary web script or HTML via unknown vectors.</descript></desc><loss_types><int/></loss_types><vuln_types><input/><env/></vuln_types><range><network/></range><refs><ref patch="1" source="CONFIRM" url="http://sourceforge.net/project/shownotes.php?release_id=322146">http://sourceforge.net/project/shownotes.php?release_id=322146</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/13301">13301</ref><ref source="OSVDB" url="http://www.osvdb.org/15719">15719</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/14993">14993</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20210">mediawiki-unknown-xss(20210)</ref></refs><vuln_soft><prod name="MediaWiki" vendor="MediaWiki"><vers num="1.3"/><vers num="1.3.1"/><vers num="1.3.2"/><vers num="1.3.3"/><vers num="1.3.4"/><vers num="1.3.5"/><vers num="1.3.6"/><vers num="1.3.7"/><vers num="1.3.8"/><vers num="1.3.9"/><vers num="1.3.10"/><vers num="1.3.11"/><vers num="1.4 beta5"/><vers num="1.4 beta4"/><vers num="1.4 beta3"/><vers num="1.4 beta2"/><vers num="1.4 beta1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-12-06" name="CVE-2005-1246" published="2005-04-24" seq="2005-1246" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in the snmppd_log function in snmppd_util.c for snmppd 0.4.5 and earlier may allow remote attackers to cause a denial of service or execute arbitrary code via format string specifiers that are not properly handled in a syslog call.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/><input/></vuln_types><range><network/></range><refs><ref patch="1" source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2005-q2/0022.html">20050425 [INetCop Security Advisory] Snmppd potentially format string vulnerability.</ref><ref patch="1" source="MISC" url="http://x82.inetcop.org/h0me/adv1sor1es/INCSA.2005-0x82-027-SNMPPD.txt">http://x82.inetcop.org/h0me/adv1sor1es/INCSA.2005-0x82-027-SNMPPD.txt</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15120">15120</ref></refs><vuln_soft><prod name="snmppd" vendor="Vladislav Bogdanov"><vers num="0.4.1"/><vers num="0.4.2"/><vers num="0.4.3 special"/><vers num="0.4.3"/><vers num="0.4.4"/><vers num="0.4.5"/><vers num="0.4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1247" published="2004-01-15" seq="2005-1247" severity="Medium" type="CVE"><desc><descript source="cve">webadmin.exe in Novell Nsure Audit 1.0.1 allows remote attackers to cause a denial of service via malformed ASN.1 packets in corrupt client certificates to an SSL server, as demonstrated using an exploit for the OpenSSL ASN.1 parsing vulnerability.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/><exception/></vuln_types><range><network/></range><refs><ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2005-q2/0021.html">20050424 [CIRT.DK - Advisory] Novell Nsure Audit 1.0.1 Denial of Service</ref><ref adv="1" source="MISC" url="http://www.cirt.dk/advisories/cirt-31-advisory.pdf">http://www.cirt.dk/advisories/cirt-31-advisory.pdf</ref><ref source="CONFIRM" url="http://support.novell.com/cgi-bin/search/searchtid.cgi?/10097379.htm">http://support.novell.com/cgi-bin/search/searchtid.cgi?/10097379.htm</ref><ref source="BUGTRAQ" url="http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2004-01/0126.html">20040115 OpenSSL ASN.1 parsing bugs PoC / brute forcer</ref></refs><vuln_soft><prod name="Nsure Audit" vendor="Novell"><vers num="1.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1248" published="2005-05-16" seq="2005-1248" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Apple iTunes before 4.8 allows remote attackers to execute arbitrary code via a crafted MPEG4 file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/May/msg00003.html">APPLE-SA-2005-05-09</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/13565">13565</ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/16243">16243</ref><ref adv="1" patch="1" source="SECTRACK" url="http://securitytracker.com/id?1013927">1013927</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/15310">15310</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/20498">apple-itunes-mpeg4-bo(20498)</ref><ref source="MISC" url="http://www.ngssoftware.com/advisories/itunes.txt">http://www.ngssoftware.com/advisories/itunes.txt</ref><ref source="CONFIRM" url="http://docs.info.apple.com/article.html?artnum=301596">http://docs.info.apple.com/article.html?artnum=301596</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/0504">ADV-2005-0504</ref></refs><vuln_soft><prod name="iTunes" vendor="Apple"><vers num="4.2.72"/><vers num="4.5"/><vers num="4.6"/><vers num="4.7"/><vers num="4.7.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-08-30" name="CVE-2005-1249" published="2005-05-25" seq="2005-1249" severity="Medium" type="CVE"><desc><descript source="cve">The IMAP daemon (IMAPD32.EXE) in Ipswitch Collaboration Suite (ICS) allows remote attackers to cause a denial of service (CPU consumption) via an LSUB command with a large number of null characters, which causes an infinite loop.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=245&amp;type=vulnerabilities">20050524 Ipswitch IMail IMAP LSUB DoS Vulnerability</ref><ref patch="1" source="CONFIRM" url="http://www.ipswitch.com/support/imail/releases/imail_professional/im82hf2.html">http://www.ipswitch.com/support/imail/releases/imail_professional/im82hf2.html</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014047">1014047</ref></refs><vuln_soft><prod name="Ipswitch Collaboration Suite" vendor="Ipswitch"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1250" published="2005-06-22" seq="2005-1250" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in the logon screen of the web front end (NmConsole/Login.asp) for IpSwitch WhatsUp Professional 2005 SP1 allows remote attackers to execute arbitrary SQL commands via the (1) User Name field (sUserName parameter) or (2) Password (sPassword parameter).</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=268&amp;type=vulnerabilities">20050622 IpSwitch WhatsUp Professional 2005 (SP1) SQL Injection Vulnerability</ref><ref adv="1" patch="1" source="CONFIRM" url="http://www.ipswitch.com/forums/shwmessage.aspx?ForumID=20&amp;MessageID=7699">http://www.ipswitch.com/forums/shwmessage.aspx?ForumID=20&amp;MessageID=7699</ref><ref source="MISC" url="http://secunia.com/secunia_research/2005-13/advisory/">http://secunia.com/secunia_research/2005-13/advisory/</ref><ref source="MISC" url="http://www.corsaire.com/advisories/c050323-001.txt">http://www.corsaire.com/advisories/c050323-001.txt</ref></refs><vuln_soft><prod name="WhatsUp" vendor="Ipswitch"><vers num="Professional 2005 SP1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1252" published="2005-05-25" seq="2005-1252" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in the Web Calendaring server in Ipswitch Imail 8.13, and other versions before IMail Server 8.2 Hotfix 2, allows remote attackers to read arbitrary files via &quot;..\&quot; (dot dot backslash) sequences in the query string argument in a GET request to a non-existent .jsp file.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/><design/></vuln_types><range><network/></range><refs><ref adv="1" source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=242&amp;type=vulnerabilities">20050524 Ipswitch IMail Web Calendaring Arbitrary File Read Vulnerability</ref><ref patch="1" source="CONFIRM" url="http://www.ipswitch.com/support/imail/releases/imail_professional/im82hf2.html">http://www.ipswitch.com/support/imail/releases/imail_professional/im82hf2.html</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014047">1014047</ref></refs><vuln_soft><prod name="IMail Server" vendor="Ipswitch"><vers num="8.2 Hotfix 2" prev="1"/></prod><prod name="Imail" vendor="Ipswitch"><vers num="8.13"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1254" published="2005-05-25" seq="2005-1254" severity="Medium" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in the IMAP server for Ipswitch IMail 8.12 and 8.13, and other versions before IMail Server 8.2 Hotfix 2, allows remote authenticated users to cause a denial of service (crash) via a SELECT command with a large argument.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=241&amp;type=vulnerabilities">20050524 Ipswitch IMail IMAP SELECT Command DoS Vulnerability</ref><ref patch="1" source="CONFIRM" url="http://www.ipswitch.com/support/imail/releases/imail_professional/im82hf2.html">http://www.ipswitch.com/support/imail/releases/imail_professional/im82hf2.html</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014047">1014047</ref></refs><vuln_soft><prod name="IMail" vendor="Ipswitch"><vers num="8.12"/><vers num="8.13"/><vers num="Server 8.2 Hotfix 2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-08-30" name="CVE-2005-1255" published="2005-05-25" seq="2005-1255" severity="High" type="CVE"><desc><descript source="cve">Multiple stack-based buffer overflows in the IMAP server in IMail 8.12 and 8.13 in Ipswitch Collaboration Suite (ICS), and other versions before IMail Server 8.2 Hotfix 2, allow remote attackers to execute arbitrary code via a LOGIN command with (1) a long username argument or (2) a long username argument that begins with a special character.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=243&amp;type=vulnerabilities">20050524 Ipswitch IMail IMAP LOGIN Remote Buffer Overflow Vulnerabilities</ref><ref patch="1" source="CONFIRM" url="http://www.ipswitch.com/support/imail/releases/imail_professional/im82hf2.html">http://www.ipswitch.com/support/imail/releases/imail_professional/im82hf2.html</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014047">1014047</ref></refs><vuln_soft><prod name="IMail Server" vendor="Ipswitch"><vers num="8.2 Hotfix 2" prev="1"/></prod><prod name="Ipswitch Collaboration Suite" vendor="Ipswitch"><vers num=""/></prod><prod name="IMail" vendor="Ipswitch"><vers num="8.12"/><vers num="8.13"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-08-30" name="CVE-2005-1256" published="2005-05-25" seq="2005-1256" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in the IMAP daemon (IMAPD32.EXE) in IMail 8.13 in Ipswitch Collaboration Suite (ICS), and other versions before IMail Server 8.2 Hotfix 2, allows remote authenticated users to execute arbitrary code via a STATUS command with a long mailbox name.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=244&amp;type=vulnerabilities">20050524 Ipswitch IMail IMAP STATUS Remote Buffer Overflow Vulnerability</ref><ref patch="1" source="CONFIRM" url="http://www.ipswitch.com/support/imail/releases/imail_professional/im82hf2.html">http://www.ipswitch.com/support/imail/releases/imail_professional/im82hf2.html</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014047">1014047</ref></refs><vuln_soft><prod name="IMail Server" vendor="Ipswitch"><vers num="8.2 Hotfix 2" prev="1"/></prod><prod name="Ipswitch Collaboration Suite" vendor="Ipswitch"><vers num=""/></prod><prod name="IMail" vendor="Ipswitch"><vers num="8.13"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1260" published="2005-05-19" seq="2005-1260" severity="Medium" type="CVE"><desc><descript source="cve">bzip2 allows remote attackers to cause a denial of service (hard drive consumption) via a crafted bzip2 file that causes an infinite loop (a.k.a &quot;decompression bomb&quot;).</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111643860900873&amp;w=2">20050517 [USN-127-1] bzip2 vulnerabilities</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-741">DSA-741</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-127-1">USN-127-1</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval749.html">OVAL749</ref><ref source="FEDORA" url="http://www.fedoralegacy.org/updates/FC2/2005-11-14-FLSA_2005_158801__Updated_bzip2_packages_fix_security_issues.html">FLSA:158801</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-474.html">RHSA-2005:474</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20060301-01.U.asc">20060301-01-U</ref><ref source="BID" url="http://www.securityfocus.com/bid/13657">13657</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19183">19183</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:749">oval:org.mitre.oval:def:749</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=307041"></ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2007/Nov/msg00002.html">APPLE-SA-2007-11-14</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-103118-1">103118</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-319A.html">TA07-319A</ref><ref source="BID" url="http://www.securityfocus.com/bid/26444">26444</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/3525">ADV-2007-3525</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/3868">ADV-2007-3868</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15447">15447</ref><ref source="SECUNIA" url="http://secunia.com/advisories/27274">27274</ref><ref source="SECUNIA" url="http://secunia.com/advisories/27643">27643</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-200191-1">200191</ref></refs><vuln_soft><prod name="bzip2" vendor="bzip"><vers num=""/></prod><prod name="Ubuntu Linux" vendor="Ubuntu"><vers num="4.10"/><vers num="5.04"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1261" published="2005-05-11" seq="2005-1261" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in the URL parsing function in Gaim before 1.3.0 allows remote attackers to execute arbitrary code via an instant message (IM) with a large URL.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/><exception/></vuln_types><range><network/></range><refs><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-432.html">RHSA-2005:432</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/0519">ADV-2005-0519</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/426078/100/0/threaded">FLSA:158543</ref><ref source="BID" url="http://www.securityfocus.com/bid/13590">13590</ref><ref adv="1" patch="1" source="CONFIRM" url="http://gaim.sourceforge.net/security/index.php?id=16">http://gaim.sourceforge.net/security/index.php?id=16</ref><ref adv="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-429.html">RHSA-2005:429</ref></refs><vuln_soft><prod name="Gaim" vendor="Rob Flynn"><vers num="1.2.1"/><vers num="1.2.0"/><vers num="1.1.4"/><vers num="1.1.3"/><vers num="1.1.2"/><vers num="1.1.1"/><vers num="1.1.0"/><vers num="1.0.3"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0.0"/><vers num="0.82.1"/><vers num="0.82"/><vers num="0.81"/><vers num="0.80"/><vers num="0.79"/><vers num="0.78"/><vers num="0.77"/><vers num="0.76"/><vers num="0.75"/><vers num="0.74"/><vers num="0.73"/><vers num="0.72"/><vers num="0.71"/><vers num="0.70"/><vers num="0.69"/><vers num="0.68"/><vers num="0.67"/><vers num="0.66"/><vers num="0.65"/><vers num="0.64"/><vers num="0.63"/><vers num="0.62"/><vers num="0.61"/><vers num="0.60"/><vers num="0.59.1"/><vers num="0.59"/><vers num="0.58"/><vers num="0.57"/><vers num="0.56"/><vers num="0.55"/><vers num="0.54"/><vers num="0.53"/><vers num="0.52"/><vers num="0.51"/><vers num="0.50"/><vers num="0.10.3"/><vers num="0.10"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1262" published="2005-05-11" seq="2005-1262" severity="Medium" type="CVE"><desc><descript source="cve">Gaim 1.2.1 and earlier allows remote attackers to cause a denial of service (application crash) via a malformed MSN message.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CONFIRM" url="http://gaim.sourceforge.net/security/index.php?id=17">http://gaim.sourceforge.net/security/index.php?id=17</ref><ref adv="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-429.html">RHSA-2005:429</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/0519">ADV-2005-0519</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/426078/100/0/threaded">FLSA:158543</ref><ref source="BID" url="http://www.securityfocus.com/bid/13591">13591</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_36_sudo.html">SUSE-SA:2005:036</ref></refs><vuln_soft><prod name="Gaim" vendor="Rob Flynn"><vers num="1.2.1"/><vers num="1.2.0"/><vers num="1.1.4"/><vers num="1.1.3"/><vers num="1.1.2"/><vers num="1.1.1"/><vers num="1.1.0"/><vers num="1.0.3"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0.0"/><vers num="0.82.1"/><vers num="0.82"/><vers num="0.81"/><vers num="0.80"/><vers num="0.79"/><vers num="0.78"/><vers num="0.77"/><vers num="0.76"/><vers num="0.75"/><vers num="0.74"/><vers num="0.73"/><vers num="0.72"/><vers num="0.71"/><vers num="0.70"/><vers num="0.69"/><vers num="0.68"/><vers num="0.67"/><vers num="0.66"/><vers num="0.65"/><vers num="0.64"/><vers num="0.63"/><vers num="0.62"/><vers num="0.61"/><vers num="0.60"/><vers num="0.59.1"/><vers num="0.59"/><vers num="0.58"/><vers num="0.57"/><vers num="0.56"/><vers num="0.55"/><vers num="0.54"/><vers num="0.53"/><vers num="0.52"/><vers num="0.51"/><vers num="0.50"/><vers num="0.10.3"/><vers num="0.10"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1263" published="2005-05-11" seq="2005-1263" severity="High" type="CVE"><desc><descript source="cve">The elf_core_dump function in binfmt_elf.c for Linux kernel 2.x.x to 2.2.27-rc2, 2.4.x to 2.4.31-pre1, and 2.6.x to 2.6.12-rc4 allows local users to execute arbitrary code via an ELF binary that, in certain conditions involving the create_elf_tables function, causes a negative length argument to pass a signed integer comparison, leading to a buffer overflow.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref source="MISC" url="http://www.isec.pl/vulnerabilities/isec-0023-coredump.txt">http://www.isec.pl/vulnerabilities/isec-0023-coredump.txt</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/0524">ADV-2005-0524</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/397966">20050511 Linux kernel ELF core dump privilege elevation</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1122.html">OVAL1122</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-472.html">RHSA-2005:472</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-529.html">RHSA-2005:529</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-551.html">RHSA-2005:551</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/428028/100/0/threaded">FLSA:157459-1</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/428058/100/0/threaded">FLSA:157459-2</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/427980/100/0/threaded">FLSA:157459-3</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19185">19185</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1122">oval:org.mitre.oval:def:1122</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20060402-01-U">
20060402-01-U</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19607">
19607</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.2"/><vers num="2.2.1"/><vers num="2.2.2"/><vers num="2.2.3"/><vers num="2.2.4"/><vers num="2.2.5"/><vers num="2.2.6"/><vers num="2.2.7"/><vers num="2.2.8"/><vers num="2.2.9"/><vers num="2.2.10"/><vers num="2.2.11"/><vers num="2.2.12"/><vers num="2.2.13"/><vers num="2.2.14"/><vers num="2.2.15"/><vers num="2.2.16"/><vers num="2.2.17"/><vers num="2.2.18"/><vers num="2.2.19"/><vers num="2.2.20"/><vers num="2.2.21"/><vers num="2.2.22"/><vers num="2.2.23"/><vers num="2.2.24"/><vers num="2.2.27 rc2"/><vers num="2.4.0 test9"/><vers num="2.4.0 test8"/><vers num="2.4.0 test7"/><vers num="2.4.0 test6"/><vers num="2.4.0 test5"/><vers num="2.4.0 test4"/><vers num="2.4.0 test3"/><vers num="2.4.0 test2"/><vers num="2.4.0 test12"/><vers num="2.4.0 test11"/><vers num="2.4.0 test10"/><vers num="2.4.0 test1"/><vers num="2.4.0"/><vers num="2.4.1"/><vers num="2.4.2"/><vers num="2.4.3"/><vers num="2.4.4"/><vers num="2.4.5"/><vers num="2.4.6"/><vers num="2.4.7"/><vers num="2.4.8"/><vers num="2.4.9"/><vers num="2.4.10"/><vers num="2.4.11"/><vers num="2.4.12"/><vers num="2.4.13"/><vers num="2.4.14"/><vers num="2.4.15"/><vers num="2.4.16"/><vers num="2.4.17"/><vers num="2.4.18 pre-8"/><vers num="2.4.18 pre-7"/><vers num="2.4.18 pre-6"/><vers num="2.4.18 pre5"/><vers num="2.4.18 pre4"/><vers num="2.4.18 pre3"/><vers num="2.4.18 pre2"/><vers num="2.4.18 pre1"/><vers edition="x86" num="2.4.18"/><vers num="2.4.18"/><vers num="2.4.19 -pre6"/><vers num="2.4.19 -pre5"/><vers num="2.4.19 -pre4"/><vers num="2.4.19 -pre3"/><vers num="2.4.19 -pre2"/><vers num="2.4.19 -pre1"/><vers num="2.4.19"/><vers num="2.4.20"/><vers num="2.4.21 pre7"/><vers num="2.4.21 pre4"/><vers num="2.4.21 pre1"/><vers num="2.4.21"/><vers num="2.4.22"/><vers num="2.4.23 -pre9"/><vers num="2.4.23 -ow2"/><vers num="2.4.23"/><vers num="2.4.24 ow1"/><vers num="2.4.24"/><vers num="2.4.25"/><vers num="2.4.26"/><vers num="2.4.27 -pre5"/><vers num="2.4.27 -pre4"/><vers num="2.4.27 -pre3"/><vers num="2.4.27 -pre2"/><vers num="2.4.27 -pre1"/><vers num="2.4.27"/><vers num="2.4.28"/><vers num="2.4.29 -rc2"/><vers num="2.4.30"/><vers num="2.4.31-pre1"/><vers num="2.6 .10"/><vers num="2.6 -test9-CVS"/><vers num="2.6 -test9"/><vers num="2.6 -test8"/><vers num="2.6 -test7"/><vers num="2.6 -test6"/><vers num="2.6 -test5"/><vers num="2.6 -test4"/><vers num="2.6 -test3"/><vers num="2.6 -test2"/><vers num="2.6 -test11"/><vers num="2.6 -test10"/><vers num="2.6 -test1"/><vers num="2.6"/><vers num="2.6.1 -rc2"/><vers num="2.6.1 -rc1"/><vers num="2.6.1"/><vers num="2.6.2"/><vers num="2.6.3"/><vers num="2.6.4"/><vers num="2.6.5"/><vers num="2.6.6-rc1"/><vers num="2.6.6"/><vers num="2.6.7 rc1"/><vers num="2.6.7"/><vers num="2.6.8-rc3"/><vers num="2.6.8-rc2"/><vers num="2.6.8-rc1"/><vers num="2.6.8"/><vers edition="2.6.20" num="2.6.9"/><vers num="2.6.10 rc2"/><vers num="2.6.11"/><vers num="2.6.12-rc4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-25" name="CVE-2005-1264" published="2005-05-17" seq="2005-1264" severity="High" type="CVE"><desc><descript source="cve">Raw character devices (raw.c) in the Linux kernel 2.6.x call the wrong function before passing an ioctl to the block device, which crosses security boundaries by making kernel address space accessible from user space, a similar vulnerability to CVE-2005-1589.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="MLIST" url="http://marc.theaimsgroup.com/?l=linux-kernel&amp;m=111630512512222">[linux-kernel] 20050517 [PATCH] Fix root hole in raw device</ref><ref adv="1" patch="1" source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2005-q2/0045.html">20050516 Linux kernel pktcdvd and rawdevice ioctl break user space limit vulnerability</ref><ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2005-q2/0046.html">20050517 Re: Linux kernel pktcdvd and rawdevice ioctl break user space limit vulnerability</ref><ref source="CONFIRM" url="http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.11.10">http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.11.10</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/0557">ADV-2005-0557</ref><ref source="BID" url="http://www.securityfocus.com/bid/13651">13651</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-420.html">RHSA-2005:420</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/427980/100/0/threaded">FLSA:157459-3</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.6 -test9-CVS"/><vers num="2.6 -test9"/><vers num="2.6 -test8"/><vers num="2.6 -test7"/><vers num="2.6 -test6"/><vers num="2.6 -test5"/><vers num="2.6 -test4"/><vers num="2.6 -test3"/><vers num="2.6 -test2"/><vers num="2.6 -test11"/><vers num="2.6 -test10"/><vers num="2.6 -test1"/><vers num="2.6"/><vers num="2.6.1 -rc2"/><vers num="2.6.1 -rc1"/><vers num="2.6.1"/><vers num="2.6.2"/><vers num="2.6.3"/><vers num="2.6.4"/><vers num="2.6.5"/><vers num="2.6.6-rc1"/><vers num="2.6.6"/><vers num="2.6.7 rc1"/><vers num="2.6.7"/><vers num="2.6.8-rc3"/><vers num="2.6.8-rc2"/><vers num="2.6.8-rc1"/><vers num="2.6.8"/><vers edition="2.6.20" num="2.6.9"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1265" published="2005-06-16" seq="2005-1265" severity="Low" type="CVE"><desc><descript source="cve">The mmap function in the Linux Kernel 2.6.10 can be used to create memory maps with a start address beyond the end address, which allows local users to cause a denial of service (kernel crash).</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><local/></range><refs><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-137-1">USN-137-1</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-922">DSA-922</ref><ref source="BID" url="http://www.securityfocus.com/bid/13893">13893</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18056">18056</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014152">1014152</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-514.html">RHSA-2005:514</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/427980/100/0/threaded">FLSA:157459-3</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17073">17073</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.6.10"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1266" published="2005-06-15" seq="2005-1266" severity="Medium" type="CVE"><desc><descript source="cve">Apache SpamAssassin 3.0.1, 3.0.2, and 3.0.3 allows remote attackers to cause a denial of service (CPU consumption and slowdown) via a message with a long Content-Type header without any boundaries.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="CONFIRM" url="http://www.vuxml.org/freebsd/cc4ce06b-e01c-11d9-a8bd-000cf18bbe54.html">http://www.vuxml.org/freebsd/cc4ce06b-e01c-11d9-a8bd-000cf18bbe54.html</ref><ref patch="1" source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200506-17.xml">GLSA-200506-17</ref><ref patch="1" source="MISC" url="http://bugs.gentoo.org/show_bug.cgi?id=94722">http://bugs.gentoo.org/show_bug.cgi?id=94722</ref><ref source="MLIST" url="http://mail-archives.apache.org/mod_mbox/spamassassin-announce/200506.mbox/%3c17072.35054.586017.822288@proton.pathname.com%3e">[spamassassin-announce] 20050615 Denial of Service Vulnerability in Apache SpamAssassin 3.0.1-3.0.3</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-736">DSA-736</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:106">MDKSA-2005:106</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-498.html">RHSA-2005:498</ref><ref source="BID" url="http://www.securityfocus.com/bid/13978">
13978</ref></refs><vuln_soft><prod name="SpamAssassin" vendor="Apache Software Foundation"><vers num="3.0.1"/><vers num="3.0.2"/><vers num="3.0.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1267" published="2005-06-10" seq="2005-1267" severity="Medium" type="CVE"><desc><descript source="cve">The bgp_update_print function in tcpdump 3.x does not properly handle a -1 return value from the decode_prefix4 function, which allows remote attackers to cause a denial of service (infinite loop) via a crafted BGP packet.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="MISC" url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=159208">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=159208</ref><ref adv="1" patch="1" source="FEDORA" url="http://www.redhat.com/archives/fedora-announce-list/2005-June/msg00007.html">FEDORA-2005-406</ref><ref adv="1" patch="1" source="TRUSTIX" url="http://www.trustix.org/errata/2005/0028/">2005-0028</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/15634/">15634</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-854">DSA-854</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17118">17118</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-505.html">RHSA-2005:505</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/430292/100/0/threaded">FLSA:156139</ref><ref source="BID" url="http://www.securityfocus.com/bid/13906">
13906</ref></refs><vuln_soft><prod name="Secure Linux" vendor="Trustix"><vers num="2.2"/><vers num="2.1"/></prod><prod name="Linux" vendor="Gentoo"><vers num=""/></prod><prod name="Mandrake Linux" vendor="MandrakeSoft"><vers edition="x86_64" num="10.2"/><vers num="10.2"/><vers edition="x86_64" num="10.1"/><vers num="10.1"/></prod><prod name="Secure Enterprise Linux" vendor="Trustix"><vers num="2.0"/></prod><prod name="tcpdump" vendor="LBL"><vers num="3.9.1"/><vers num="3.9"/><vers num="3.8.3"/><vers num="3.8.2"/><vers num="3.8.1"/><vers num="3.7.2"/><vers num="3.7.1"/><vers num="3.7"/><vers num="3.6.3"/><vers num="3.6.2"/><vers num="3.5.2"/><vers num="3.5 alpha"/><vers num="3.5"/><vers num="3.4a6"/><vers num="3.4"/></prod><prod name="Fedora" vendor="Red Hat"><vers num="Core 4.0"/><vers num="Core 3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1268" published="2005-08-05" seq="2005-1268" severity="Medium" type="CVE"><desc><descript source="cve">Off-by-one error in the mod_ssl Certificate Revocation List (CRL) verification callback in Apache, when configured to use a CRL, allows remote attackers to cause a denial of service (child process crash) via a CRL that causes a buffer overflow of one null byte.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/><other/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=163013">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=163013</ref><ref adv="1" patch="1" source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:129">MDKSA-2005:129</ref><ref patch="1" source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2005-582.html">RHSA-2005:582</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-805">DSA-805</ref><ref source="TRUSTIX" url="http://lists.trustix.org/pipermail/tsl-announce/2005-October/000354.html">TSLSA-2005-0059</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1346.html">OVAL1346</ref><ref source="BID" url="http://www.securityfocus.com/bid/14366">14366</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102198-1">102198</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0789">ADV-2006-0789</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19072">19072</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/428138/100/0/threaded">HPSBUX02074</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-081.htm"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/19185">19185</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_46_apache.html">SUSE-SA:2005:046</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_18_sr.html">SUSE-SR:2005:018</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1346">oval:org.mitre.oval:def:1346</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1714">oval:org.mitre.oval:def:1714</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1747">oval:org.mitre.oval:def:1747</ref><ref source="SREASON" url="http://securityreason.com/securityalert/604">604</ref></refs><vuln_soft><prod name="Apache" vendor="Apache Software Foundation"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1269" published="2005-06-16" seq="2005-1269" severity="Medium" type="CVE"><desc><descript source="cve">Gaim before 1.3.1 allows remote attackers to cause a denial of service (application crash) via a Yahoo! message with non-ASCII characters in a file name.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="CONFIRM" url="http://gaim.sourceforge.net/security/?id=18">http://gaim.sourceforge.net/security/?id=18</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-139-1">USN-139-1</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200506-11.xml">GLSA-200506-11</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:099">MDKSA-2005:099</ref><ref source="BID" url="http://www.securityfocus.com/bid/13931">13931</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-734">DSA-734</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval744.html">OVAL744</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/426078/100/0/threaded">FLSA:158543</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-518.html">RHSA-2005:518</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_36_sudo.html">SUSE-SA:2005:036</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:744">oval:org.mitre.oval:def:744</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:099">MDKSA-2005:099</ref></refs><vuln_soft><prod name="Gaim" vendor="Rob Flynn"><vers num="1.3.0"/><vers num="1.2.1"/><vers num="1.2.0"/><vers num="1.1.4"/><vers num="1.1.3"/><vers num="1.1.2"/><vers num="1.1.1"/><vers num="1.1.0"/><vers num="1.0.3"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0.0"/><vers num="1.0"/><vers num="0.82.1"/><vers num="0.82"/><vers num="0.81"/><vers num="0.80"/><vers num="0.79"/><vers num="0.78"/><vers num="0.77"/><vers num="0.76"/><vers num="0.75"/><vers num="0.74"/><vers num="0.73"/><vers num="0.72"/><vers num="0.71"/><vers num="0.70"/><vers num="0.69"/><vers num="0.68"/><vers num="0.67"/><vers num="0.66"/><vers num="0.65"/><vers num="0.64"/><vers num="0.63"/><vers num="0.62"/><vers num="0.61"/><vers num="0.60"/><vers num="0.59.1"/><vers num="0.59"/><vers num="0.58"/><vers num="0.57"/><vers num="0.56"/><vers num="0.55"/><vers num="0.54"/><vers num="0.53"/><vers num="0.52"/><vers num="0.51"/><vers num="0.50"/><vers num="0.10.3"/><vers num="0.10"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-01-03" name="CVE-2005-1270" published="2005-04-26" seq="2005-1270" severity="Low" type="CVE"><desc><descript source="cve">The (1) check_update.sh and (2) rkhunter script in Rootkit Hunter before 1.2.3-r1 create temporary files with predictable file names, which allows local users to overwrite arbitrary files via a symlink attack.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200504-25.xml">GLSA-200504-25</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/13399">13399</ref><ref source="OSVDB" url="http://www.osvdb.org/15861">15861</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15127">15127</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20279">rootkit-hunter-checkupdate-symlink(20279)</ref></refs><vuln_soft><prod name="Rootkit Hunter" vendor="Gentoo"><vers num="1.2"/><vers num="1.2.1"/><vers num="1.2.2"/><vers num="1.2.3"/></prod></vuln_soft></entry><entry modified="2005-10-25" name="CVE-2005-1271" published="2005-05-12" reject="1" seq="2005-1271" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2005-1343.  Reason: This candidate is a reservation duplicate of CVE-2005-1343.  Notes: All CVE users should reference CVE-2005-1343 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript></desc><refs/></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1272" published="2005-08-05" seq="2005-1272" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in the Backup Agent for Microsoft SQL Server in BrightStor ARCserve Backup Agent for SQL Server 11.0 allows remote attackers to execute arbitrary code via a long string sent to port (1) 6070 or (2) 6050.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://www3.ca.com/securityadvisor/vulninfo/vuln.aspx?id=33239">http://www3.ca.com/securityadvisor/vulninfo/vuln.aspx?id=33239</ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/279774">VU#279774</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/14453">14453</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/21656">brightstor-enterprise-backup-bo(21656)</ref><ref source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=287&amp;type=vulnerabilities&amp;flashstatus=true">20050803 CA BrightStor ARCserve Backup Agent for MS SQL Server Buffer Overflow</ref></refs><vuln_soft><prod name="BrightStor Enterprise Backup" vendor="Computer Associates"><vers num="10.5"/><vers num="10.0"/></prod><prod name="BrightStor Enterprise Backup Serverless Backup" vendor="Computer Associates"><vers num="10.5"/><vers num="10.0"/></prod><prod name="BrightStor ARCserve Backup Agent SQL" vendor="Computer Associates"><vers num="11.1"/><vers num="11.0"/><vers num="9.0 1"/></prod><prod name="BrightStor Enterprise Backup Agent SQL" vendor="Computer Associates"><vers num="10.5"/><vers num="10.0"/></prod><prod name="BrightStor ARCserve Backup Agent Exchange" vendor="Computer Associates"><vers num="11.1"/><vers num="11.0"/><vers num="9.0.1"/></prod><prod name="BrightStor ARCserve Backup Agent SAP" vendor="Computer Associates"><vers num="11.1 r3"/><vers num="11.0 r3"/><vers num="9.0.1 r3"/></prod><prod name="BrightStor Enterprise Backup Agent SAP" vendor="Computer Associates"><vers num="10.5 r3"/><vers num="10.0 r3"/></prod><prod name="BrightStor Enterprise Backup Agent Oracle" vendor="Computer Associates"><vers num="10.5"/><vers num="10.0"/></prod><prod name="BrightStor ARCServe Backup Oracle" vendor="Computer Associates"><vers num="11.1"/><vers num="11.0"/><vers num="9.0 1"/></prod><prod name="BrightStor ARCServe Backup Windows" vendor="Computer Associates"><vers num="11.1"/><vers num="11.0"/><vers num="9.0 1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-03-28" name="CVE-2005-1274" published="2005-04-26" seq="2005-1274" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in the getIfHeader function in the WebDAV functionality in MySQL MaxDB before 7.5.00.26 allows remote attackers to execute arbitrary code via an HTTP unlock request and a long &quot;If&quot; parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=236&amp;type=vulnerabilities">20050426 MySQL MaxDB Webtool Remote &apos;If&apos; Stack Overflow Vulnerability</ref></refs><vuln_soft><prod name="MaxDB" vendor="MySQL"><vers num="7.5.00.25"/><vers num="7.5.00.23" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1275" published="2005-04-25" seq="2005-1275" severity="Medium" type="CVE"><desc><descript source="cve">Heap-based buffer overflow in the ReadPNMImage function in pnm.c for ImageMagick 6.2.1 and earlier allows remote attackers to cause a denial of service (application crash) via a PNM file with a small colors value.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://seclists.org/lists/bugtraq/2005/Apr/0407.html">20050424 [Overflow.pl] ImageMagick ReadPNMImage() Heap Overflow</ref><ref source="MISC" url="http://www.overflow.pl/adv/imheapoverflow.txt">http://www.overflow.pl/adv/imheapoverflow.txt</ref><ref source="MISC" url="http://bugs.gentoo.org/show_bug.cgi?id=90423">http://bugs.gentoo.org/show_bug.cgi?id=90423</ref><ref patch="1" source="CONFIRM" url="http://www.imagemagick.org/script/changelog.php">http://www.imagemagick.org/script/changelog.php</ref><ref source="BID" url="http://www.securityfocus.com/bid/13351">13351</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:107">MDKSA-2005:107</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval711.html">OVAL711</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-413.html">RHSA-2005:413</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:711">oval:org.mitre.oval:def:711</ref></refs><vuln_soft><prod name="ImageMagick" vendor="ImageMagick"><vers num="6.0"/><vers num="6.0.1"/><vers num="6.0.2.5"/><vers num="6.0.2"/><vers num="6.0.3"/><vers num="6.0.4"/><vers num="6.0.5"/><vers num="6.0.6"/><vers num="6.0.7"/><vers num="6.0.8"/><vers num="6.1"/><vers num="6.1.1.6"/><vers num="6.1.2"/><vers num="6.1.3"/><vers num="6.1.4"/><vers num="6.1.5"/><vers num="6.1.6"/><vers num="6.1.7"/><vers num="6.1.8"/><vers num="6.2.0.7"/><vers num="6.2.0.4"/><vers num="6.2"/><vers num="6.2.1"/></prod><prod name="GraphicsMagick" vendor="GraphicsMagick"><vers num="1.0"/><vers num="1.0.6"/><vers num="1.1"/><vers num="1.1.3"/><vers num="1.1.4"/><vers num="1.1.5"/></prod></vuln_soft></entry><entry modified="2005-10-25" name="CVE-2005-1277" published="2005-06-28" reject="1" seq="2005-1277" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2005-1766.  Reason: This candidate is a duplicate of CVE-2005-1766.  Notes: This duplicate occurred due to insufficient coordination across three separate parties.  All CVE users should reference CVE-2005-1766 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><user_init/></range><refs/></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1278" published="2005-05-02" seq="2005-1278" severity="Medium" type="CVE"><desc><descript source="cve">The isis_print function, as called by isoclns_print, in tcpdump 3.9.1 and earlier allows remote attackers to cause a denial of service (infinite loop) via a zero length, as demonstrated using a GRE packet.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/396932">20050426 tcpdump[v3.8.x/v3.9.1]: ISIS, BGP, and LDP infinite loop DOS exploits.</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-417.html">RHSA-2005:417</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-421.html">RHSA-2005:421</ref><ref source="SCO" url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.60/SCOSA-2005.60.txt">SCOSA-2005.60</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18146">18146</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15125">15125</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/430292/100/0/threaded">FLSA:156139</ref><ref source="BID" url="http://www.securityfocus.com/bid/13392">
13392</ref></refs><vuln_soft><prod name="tcpdump" vendor="LBL"><vers num="3.9.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1279" published="2005-05-02" seq="2005-1279" severity="Medium" type="CVE"><desc><descript source="cve">tcpdump 3.8.3 and earlier allows remote attackers to cause a denial of service (infinite loop) via a crafted (1) BGP packet, which is not properly handled by RT_ROUTING_INFO, or (2) LDP packet, which is not properly handled by the ldp_print function.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/396932">20050426 tcpdump[v3.8.x/v3.9.1]: ISIS, BGP, and LDP infinite loop DOS exploits.</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-417.html">RHSA-2005:417</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-421.html">RHSA-2005:421</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-850">DSA-850</ref><ref source="SCO" url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.60/SCOSA-2005.60.txt">SCOSA-2005.60</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18146">18146</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15125">15125</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17101">17101</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/430292/100/0/threaded">FLSA:156139</ref><ref source="BID" url="http://www.securityfocus.com/bid/13389">
13389</ref></refs><vuln_soft><prod name="tcpdump" vendor="LBL"><vers num="3.8.3" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1280" published="2005-05-02" seq="2005-1280" severity="Medium" type="CVE"><desc><descript source="cve">The rsvp_print function in tcpdump 3.9.1 and earlier allows remote attackers to cause a denial of service (infinite loop) via a crafted RSVP packet of length 4.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/396930">20050426 tcpdump(/ethereal)[]: (RSVP) rsvp_print() infinite loop DOS.</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-417.html">RHSA-2005:417</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-421.html">RHSA-2005:421</ref><ref source="SCO" url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.60/SCOSA-2005.60.txt">SCOSA-2005.60</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18146">18146</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15125">15125</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/430292/100/0/threaded">FLSA:156139</ref><ref source="BID" url="http://www.securityfocus.com/bid/13390">
13390</ref></refs><vuln_soft><prod name="tcpdump" vendor="LBL"><vers num="3.9.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1281" published="2005-04-26" seq="2005-1281" severity="Medium" type="CVE"><desc><descript source="cve">Ethereal 0.10.10 and earlier allows remote attackers to cause a denial of service (infinite loop) via a crafted RSVP packet of length 4.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/396930">20050426 tcpdump(/ethereal)[]: (RSVP) rsvp_print() infinite loop DOS.</ref><ref source="Security Focus" url="http://www.securityfocus.com/bid/13391">Ethereal RSVP Decoding Routines Denial Of Service Vulnerability</ref></refs><vuln_soft><prod name="Ethereal" vendor="Ethereal Group"><vers num="0.8"/><vers num="0.8.13"/><vers num="0.8.14"/><vers num="0.8.15"/><vers num="0.8.18"/><vers num="0.8.19"/><vers num="0.9"/><vers num="0.9.1"/><vers num="0.9.2"/><vers num="0.9.3"/><vers num="0.9.4"/><vers num="0.9.5"/><vers num="0.9.6"/><vers num="0.9.7"/><vers num="0.9.8"/><vers num="0.9.9"/><vers num="0.9.10"/><vers num="0.9.11"/><vers num="0.9.12"/><vers num="0.9.13"/><vers num="0.9.14"/><vers num="0.9.15"/><vers num="0.9.16"/><vers num="0.10.10"/><vers num="0.10"/><vers num="0.10.1"/><vers num="0.10.2"/><vers num="0.10.3"/><vers num="0.10.4"/><vers num="0.10.5"/><vers num="0.10.6"/><vers num="0.10.7"/><vers num="0.10.8"/><vers num="0.10.9"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-27" name="CVE-2005-1282" published="2005-05-02" seq="2005-1282" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Argosoft Mail Server Pro 1.8.7.6 allow remote attackers to inject arbitrary web script or HTML via (1) the src parameter in an IMG tag, (2) User settings, or (3) Address book input boxes in the webmail interface.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/13326">13326</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15100">15100</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20225">argosoft-mail-server-html-tag-filter-xss(20225)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111419001527077&amp;w=2">20050422 Multiple vulnerabilities in Argosoft Mail Server 1.8.7.6</ref></refs><vuln_soft><prod name="ArGoSoft Mail Server" vendor="ArGoSoft"><vers edition="Pro" num="1.8.7.6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-27" name="CVE-2005-1283" published="2005-04-22" seq="2005-1283" severity="High" type="CVE"><desc><descript source="cve">Multiple directory traversal vulnerabilities in Argosoft Mail Server Pro 1.8.7.6 allow remote authenticated users to (1) read arbitrary files via the UIDL parameter to the msg script or (2) copy or move the user&apos;s .eml file to arbitrary locations via the delete script, a different vulnerability than CVE-2005-0367.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/><input/></vuln_types><range><network/></range><refs><ref source="OSVDB" url="http://www.osvdb.org/15821">15821</ref><ref source="OSVDB" url="http://www.osvdb.org/15823">15823</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20229">argosoft-mail-server-dir-traversal(20229)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20226">argosoft-mail-server-eml-files-dir-traversal(20226)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111419001527077&amp;w=2">20050422 Multiple vulnerabilities in Argosoft Mail Server 1.8.7.6</ref></refs><vuln_soft><prod name="ArGoSoft Mail Server" vendor="ArGoSoft"><vers edition="Pro" num="1.8.7.6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-27" name="CVE-2005-1284" published="2005-05-02" seq="2005-1284" severity="High" type="CVE"><desc><descript source="cve">The addnew script in Argosoft Mail Server Pro 1.8.7.6 allows remote attackers to create arbitrary accounts, even if &quot;Allow Creation of Accounts From the Web Interface&quot; is disabled, via a direct HTTP POST request.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/13323">13323</ref><ref source="OSVDB" url="http://www.osvdb.org/15822">15822</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20228">argosoft-mail-server-add-new-mail-account(20228)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111419001527077&amp;w=2">20050422 Multiple vulnerabilities in Argosoft Mail Server 1.8.7.6</ref></refs><vuln_soft><prod name="ArGoSoft Mail Server" vendor="ArGoSoft"><vers edition="Pro" num="1.8.7.6"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1285" published="2005-04-22" seq="2005-1285" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in thread.php in WoltLab Burning Board 2.3.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the hilight parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="SECUNIA" url="http://secunia.com/advisories/15058">15058</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013790">1013790</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111420516900814&amp;w=2">20050422 [SePro Bugtraq] WBB - WoltLab Burning Board &lt;= 2.3.1 - XSS</ref><ref source="BID" url="http://www.securityfocus.com/bid/13325">13325</ref></refs><vuln_soft><prod name="Burning Board" vendor="WoltLab"><vers num="2.3.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="1.2" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="2.9" CVSS_score="1.2" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-04-20" name="CVE-2005-1286" published="2005-05-02" seq="2005-1286" severity="Low" type="CVE"><desc><descript source="cve">Unquoted Windows search path vulnerability in BitDefender 8 allows local users to prevent BitDefender from starting by creating a malicious C:\program.exe, possibly due to the lack of quoting of the full pathname when executing a process.</descript></desc><loss_types><avail/></loss_types><vuln_types><race/></vuln_types><range><local/></range><refs><ref source="OSVDB" url="http://www.osvdb.org/15818">15818</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15076">15076</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111420400316397&amp;w=2">20050422 BitDefender 8 - Race condition vulnerability</ref></refs><vuln_soft><prod name="BitDefender Antivirus" vendor="SOFTWIN"><vers num="Professional Plus 8"/><vers num="Standard 8"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1287" published="2005-04-23" seq="2005-1287" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in BK Forum 4.0 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to member.asp, (2) forum parameter to forum.asp, or (3) various parameters in register.asp.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MISC" url="http://www.digitalparadox.org/advisories/bkdev.txt">http://www.digitalparadox.org/advisories/bkdev.txt</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15072">15072</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013793">1013793</ref><ref source="OSVDB" url="http://www.osvdb.org/15784">15784</ref><ref source="OSVDB" url="http://www.osvdb.org/15785">15785</ref><ref source="OSVDB" url="http://www.osvdb.org/15786">15786</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111428133317901&amp;w=2">20050423 Multiple Sql injection vulnerabilities in BK Forum v.4</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431659/100/0/threaded">20060421 BK Forum &lt;&lt;--V.4.0 SQL Injection</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431863/100/0/threaded">20060423 BK Forum &lt;= 4.0 Remote SQL Injection</ref></refs><vuln_soft><prod name="BK Forum" vendor="BK Dev"><vers num="4" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1288" published="2005-05-02" seq="2005-1288" severity="High" type="CVE"><desc><descript source="cve">inc_login_check.asp ACS Blog 0.8 through 1.1.3 allows remote attackers to gain administrator privileges via the &quot;in&quot; value in a cookie.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="SECUNIA" url="http://secunia.com/advisories/15105">15105</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013795">1013795</ref><ref source="OSVDB" url="http://www.osvdb.org/15787">15787</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111428190921388&amp;w=2">20050423 ACSblog bug</ref></refs><vuln_soft><prod name="ACS Blog" vendor="ASP Press"><vers num="0.8"/><vers num="0.9"/><vers num="1.0"/><vers num="1.0.1"/><vers num="1.0.2"/><vers num="1.0.3"/><vers num="1.1b"/><vers num="1.1"/><vers num="1.1.1"/><vers num="1.1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1289" published="2005-05-02" seq="2005-1289" severity="High" type="CVE"><desc><descript source="cve">index.cgi in E-Cart 2004 1.1 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) art and possibly (2) cat parameters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="SECUNIA" url="http://secunia.com/advisories/15054">15054</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013780">1013780</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111428818425864&amp;w=2">20050423 E-Cart v1.1 Remote Command Execution</ref></refs><vuln_soft><prod name="E-Cart" vendor="E-cart"><vers num="2004 1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1290" published="2005-05-02" seq="2005-1290" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in phpBB 2.0.14 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) u parameter to profile.php, (2) highlight parameter to viewtopic.php, or (3) forumname or forumdesc parameters to admin_forums.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MISC" url="http://neosecurityteam.net/Advisories/Advisory-14.txt">http://neosecurityteam.net/Advisories/Advisory-14.txt</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111428283721756&amp;w=2">20050423 -==phpBB 2.0.14 Multiple Vulnerabilities==-</ref></refs><vuln_soft><prod name="phpBB" vendor="phpBB Group"><vers num="2.0.14"/><vers num="2.0.13"/><vers num="2.0.12"/><vers num="2.0.11"/><vers num="2.0.10"/><vers num="2.0.9"/><vers num="2.0.8"/><vers num="2.0.8a"/><vers num="2.0.7"/><vers num="2.0.6"/><vers num="2.0.5"/><vers num="2.0.4"/><vers num="2.0.3"/><vers num="2.0.2"/><vers num="2.0.1"/><vers num="2.0.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1291" published="2005-04-23" seq="2005-1291" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in CartWIZ ASP Cart allow remote attackers to execute arbitrary SQL commands via the idProduct parameter to (1) addToCart.asp or (2) productDetails.asp, the (3) priceFrom, (4) idCategory, or (5) priceTo parameter to searchResults.asp, or (6) the idParentCategory parameter to productCatalogSubCats.asp.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="SECUNIA" url="http://secunia.com/advisories/15055">15055</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20246">cartwiz-multiple-sql-injection(20246)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013792">1013792</ref><ref source="OSVDB" url="http://www.osvdb.org/15771">15771</ref><ref source="OSVDB" url="http://www.osvdb.org/15772">15772</ref><ref source="OSVDB" url="http://www.osvdb.org/15773">15773</ref><ref source="OSVDB" url="http://www.osvdb.org/15774">15774</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111428393022389&amp;w=2">20050423 Multiple Sql injection and XSS in CartWIZ ASP Cart</ref></refs><vuln_soft><prod name="ASP Cart" vendor="CartWIZ"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-08-28" name="CVE-2005-1292" published="2005-05-02" seq="2005-1292" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in CartWIZ ASP Cart allow remote attackers to inject arbitrary web script or HTML via the idProduct parameter to (1) tellAFriend.asp or (2) addToWishlist.asp, redirect parameter to (3) access.asp or (4) login.asp, message parameter to (5) login.asp or (6) error.asp, or (7) sku or (8) name parameter to searchResults.asp.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="SECUNIA" url="http://secunia.com/advisories/15055">15055</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20249">cartwiz-multiple-script-xss(20249)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013792">1013792</ref><ref source="OSVDB" url="http://www.osvdb.org/15775">15775</ref><ref source="OSVDB" url="http://www.osvdb.org/15776">15776</ref><ref source="OSVDB" url="http://www.osvdb.org/15777">15777</ref><ref source="OSVDB" url="http://www.osvdb.org/15778">15778</ref><ref source="OSVDB" url="http://www.osvdb.org/15780">15780</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111428393022389&amp;w=2">20050423 Multiple Sql injection and XSS in CartWIZ ASP Cart</ref></refs><vuln_soft><prod name="CartWIZ" vendor="Elemental Software"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1293" published="2005-05-02" seq="2005-1293" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in default.asp in StorePortal 2.63 allow remote attackers to execute arbitrary SQL commands via the (1) language, (2) bpic, (3) idcategory, (4) content, (5) keyword, or (6) idproduct parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MISC" url="http://digitalparadox.org/advisories/storeportal.txt">http://digitalparadox.org/advisories/storeportal.txt</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15071">15071</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111445131808328&amp;w=2">20050424 Multiple SQL Injections in StorePortal 2.63</ref></refs><vuln_soft><prod name="StorePortal" vendor="StorePortal"><vers num="2.63"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1294" published="2005-04-24" seq="2005-1294" severity="High" type="CVE"><desc><descript source="cve">The affix_sock_register in the Affix Bluetooth Protocol Stack for Linux might allow local users to gain privileges via a socket call with a negative protocol value, which is used as an array index.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><local/></range><refs><ref source="MISC" url="http://www.digitalmunition.com/DMA%5B2005-0423a%5D.txt">http://www.digitalmunition.com/DMA%5B2005-0423a%5D.txt</ref><ref patch="1" source="CONFIRM" url="http://affix.sourceforge.net/patch_hci_3_2_0">http://affix.sourceforge.net/patch_hci_3_2_0</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111445064725591&amp;w=2">20050424 DMA[2005-0423a] - &apos;Nokia Affix Bluetooth Integer Underflow&apos;</ref></refs><vuln_soft><prod name="Affix" vendor="Nokia"><vers num="3.2.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-12-06" name="CVE-2005-1295" published="2005-04-25" seq="2005-1295" severity="High" type="CVE"><desc><descript source="cve">include.cgi script allows remote attackers to read arbitrary files via a full pathname in the argument.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111445189816161&amp;w=2">20050425 remote command execution in include.cgi script</ref></refs><vuln_soft><prod name="include.cgi" vendor="include.cgi"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-12-06" name="CVE-2005-1296" published="2005-04-25" seq="2005-1296" severity="High" type="CVE"><desc><descript source="cve">include.cgi script allows remote attackers to execute arbitrary commands via shell metacharacters in the argument.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111445189816161&amp;w=2">20050425 remote command execution in include.cgi script</ref></refs><vuln_soft><prod name="include.cgi" vendor="include.cgi"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-12-06" name="CVE-2005-1297" published="2005-04-25" seq="2005-1297" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in the include.cgi script allows remote attackers to inject arbitrary web script or HTML via the argument.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111445189816161&amp;w=2">20050425 remote command execution in include.cgi script</ref></refs><vuln_soft><prod name="include.cgi" vendor="include.cgi"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-12-06" name="CVE-2005-1298" published="2005-04-25" seq="2005-1298" severity="High" type="CVE"><desc><descript source="cve">The inserter.cgi script allows remote attackers to read arbitrary files via a full pathname in the argument.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="Nessus" url="http://www.nessus.org/plugins/index.php?view=single&amp;id=18149">inserter.cgi File Inclusion and Command Execution Vulnerabilities</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111444807013846&amp;w=2">20050425 remote command execution in inserter.cgi script</ref></refs><vuln_soft><prod name="inserter.cgi" vendor="inserter.cgi"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-12-06" name="CVE-2005-1299" published="2005-04-25" seq="2005-1299" severity="High" type="CVE"><desc><descript source="cve">The inserter.cgi script allows remote attackers to execute arbitrary commands via shell metacharacters in the argument.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="Nessus" url="http://www.nessus.org/plugins/index.php?view=single&amp;id=18149">inserter.cgi File Inclusion and Command Execution Vulnerabilities</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111444807013846&amp;w=2">20050425 remote command execution in inserter.cgi script</ref></refs><vuln_soft><prod name="inserter.cgi" vendor="inserter.cgi"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-12-06" name="CVE-2005-1300" published="2005-04-25" seq="2005-1300" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in the inserter.cgi script allows remote attackers to inject arbitrary web script or HTML via the argument.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="Nessus" url="http://www.nessus.org/plugins/index.php?view=single&amp;id=18149">inserter.cgi File Inclusion and Command Execution Vulnerabilities</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111444807013846&amp;w=2">20050425 remote command execution in inserter.cgi script</ref></refs><vuln_soft><prod name="inserter.cgi" vendor="inserter.cgi"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1301" published="2005-04-13" seq="2005-1301" severity="Low" type="CVE"><desc><descript source="cve">nProtect:Netizen 2005.3.17.1 does not properly verify that the update module is downloaded from an authorized site, which allows remote malicious web sites to write arbitrary files.</descript></desc><loss_types><int/></loss_types><vuln_types><access/></vuln_types><range><network/><user_init/></range><refs><ref patch="1" source="MISC" url="http://www.lac.co.jp/business/sns/intelligence/SNSadvisory_e/80_e.html">http://www.lac.co.jp/business/sns/intelligence/SNSadvisory_e/80_e.html</ref><ref source="MISC" url="http://jvn.jp/jp/JVN%23AF02FB4B/index.html">http://jvn.jp/jp/JVN%23AF02FB4B/index.html</ref><ref source="OSVDB" url="http://www.osvdb.org/15788">15788</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15101">15101</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111444390329376&amp;w=2">20050425 [SNS Advisory No.80] nProtect:Netizen Arbitrary File Download Vulnerability</ref></refs><vuln_soft><prod name="Netizen" vendor="nProtect"><vers num="2005.3.17.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1302" published="2005-05-02" seq="2005-1302" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in Confixx 3.08 and earlier allows remote attackers to execute arbitrary SQL commands via the &quot;change user&quot; field.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="OSVDB" url="http://www.osvdb.org/15815">15815</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15121">15121</ref><ref source="BID" url="http://www.securityfocus.com/bid/13355">13355</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111444886429814&amp;w=2">20050425 Sql Injection in Confixx 3.06 &amp; 3.08 &amp; 3.?? ?</ref><ref source="SREASON" url="http://securityreason.com/securityalert/694">694</ref></refs><vuln_soft><prod name="Confixx" vendor="SWSoft"><vers num="Pro 3"/><vers num="3.0.6"/><vers num="3.0.8"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-12-06" name="CVE-2005-1303" published="2005-04-24" seq="2005-1303" severity="High" type="CVE"><desc><descript source="cve">The citat.pl script allows remote attackers to read arbitrary files via a full pathname in the argument.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111445477910178&amp;w=2">20050424 remote command execution in citat.pl script</ref></refs><vuln_soft><prod name="citat.pl" vendor="citat.pl"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1304" published="2005-05-02" seq="2005-1304" severity="High" type="CVE"><desc><descript source="cve">The citat.pl script allows remote attackers to execute arbitrary files via shell metacharacters in the argument.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111445477910178&amp;w=2">20050424 remote command execution in citat.pl script</ref></refs><vuln_soft><prod name="citat.pl" vendor="citat.pl"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1305" published="2005-05-02" seq="2005-1305" severity="Medium" type="CVE"><desc><descript source="cve">The hyper.cgi script allows remote attackers to read arbitrary files via a full pathname in the argument.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111445410220152&amp;w=2">20050424 hyper.cgi script file show bug</ref></refs><vuln_soft><prod name="hyper.cgi" vendor="hyper.cgi"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1306" published="2005-06-15" seq="2005-1306" severity="Medium" type="CVE"><desc><descript source="cve">The Adobe Reader control in Adobe Reader and Acrobat 7.0 and 7.0.1 allows remote attackers to determine the existence of files via Javascript containing XML script, aka the &quot;XML External Entity vulnerability.&quot;</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CONFIRM" url="http://www.adobe.com/support/techdocs/331710.html">http://www.adobe.com/support/techdocs/331710.html</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/13962">13962</ref></refs><vuln_soft><prod name="Acrobat" vendor="Adobe"><vers num="7.0.1"/><vers num="7.0"/></prod><prod name="Acrobat Reader" vendor="Adobe"><vers num="7.0.1"/><vers num="7.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-28" name="CVE-2005-1307" published="2005-05-17" seq="2005-1307" severity="High" type="CVE"><desc><descript source="cve">The (1) stopserver.sh and (2) startserver.sh scripts in Adobe Version Cue on Mac OS X uses the current working directory to find and execute the productname.sh script, which allows local users to execute arbitrary code by copying and calling the scripts from a user-controlled directory.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/><exception/></vuln_types><range><local/></range><refs><ref source="MISC" url="http://www.securiteam.com/exploits/5EP0D20FQC.html">http://www.securiteam.com/exploits/5EP0D20FQC.html</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111627622403544&amp;w=2">20050516 Mac OS X - Adobe Version Cue local root exploit [c version exploit]</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2004-12/0040.html">20041206 Local root exploit on Mac OS X with Adobe Version Cue</ref><ref source="" url="http://www.adobe.com/support/techdocs/331621.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/11833">11833</ref><ref source="OSVDB" url="http://www.osvdb.org/12297">12297</ref><ref source="OSVDB" url="http://www.osvdb.org/12298">12298</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1012446">1012446</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13399">13399</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18445">version-cue-gain-privileges(18445)</ref></refs><vuln_soft><prod name="Mac OS X" vendor="Apple"><vers num="10.3.6"/></prod><prod name="Version Cue" vendor="Adobe"><vers num="Gold"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1308" published="2005-04-15" seq="2005-1308" severity="High" type="CVE"><desc><descript source="cve">SqWebMail allows remote attackers to inject arbitrary web script or HTML via CRLF sequences in the redirect parameter followed by the desired script or HTML.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/13374">13374</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15119">15119</ref></refs><vuln_soft><prod name="SqWebMail" vendor="Inter7"><vers num="3.4.1"/><vers num="3.5.0"/><vers num="3.5.1"/><vers num="3.5.2"/><vers num="3.5.3"/><vers num="3.6.0"/><vers num="3.6.1"/><vers num="4.0.4 2004-05-24"/><vers num="4.0.5"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1309" published="2005-05-02" seq="2005-1309" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in bBlog 0.7.4 allows remote attackers to inject arbitrary web script or HTML via the (1) entry title field or (2) comment body text.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="OSVDB" url="http://www.osvdb.org/15754">15754</ref><ref source="OSVDB" url="http://www.osvdb.org/15755">15755</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013811">1013811</ref><ref source="" url="http://sourceforge.net/tracker/index.php?func=detail&amp;aid=1188735&amp;group_id=81992&amp;atid=564683"></ref></refs><vuln_soft><prod name="bBlog" vendor="Eaden McKee"><vers num="0.7.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1310" published="2005-04-23" seq="2005-1310" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in bBlog 0.7.4 allows remote attackers to execute arbitrary SQL commands via the postid parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="OSVDB" url="http://www.osvdb.org/15756">15756</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013811">1013811</ref><ref source="" url="http://sourceforge.net/tracker/index.php?func=detail&amp;aid=1188735&amp;group_id=81992&amp;atid=564683"></ref></refs><vuln_soft><prod name="bBLog" vendor="Eaden McKee"><vers num="0.7.4"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1311" published="2005-05-02" seq="2005-1311" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Yappa-NG before 2.3.2 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="CONFIRM" url="http://sourceforge.net/project/shownotes.php?release_id=323206">http://sourceforge.net/project/shownotes.php?release_id=323206</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/13372">13372</ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/15828">15828</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/15107">15107</ref></refs><vuln_soft><prod name="yappa-ng" vendor="yappa-ng"><vers num="0.9"/><vers num="1.0"/><vers num="1.1"/><vers num="1.2"/><vers num="1.3"/><vers num="1.4"/><vers num="1.5"/><vers num="1.6"/><vers num="2.0.0"/><vers num="2.0.1"/><vers num="2.1.0"/><vers num="2.2.0"/><vers num="2.2.1"/><vers num="2.2.2"/><vers num="2.3.0"/><vers num="2.3.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-28" name="CVE-2005-1312" published="2005-04-24" seq="2005-1312" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in Yappa-NG before 2.3.2 allows remote attackers to execute arbitrary PHP code via unknown vectors.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="CONFIRM" url="http://sourceforge.net/project/shownotes.php?release_id=323206">http://sourceforge.net/project/shownotes.php?release_id=323206</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/13371">13371</ref><ref source="OSVDB" url="http://www.osvdb.org/15829">15829</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/15107">15107</ref></refs><vuln_soft><prod name="yappa-ng" vendor="yappa-ng"><vers num="0.9"/><vers num="1.0"/><vers num="1.1"/><vers num="1.2"/><vers num="1.3"/><vers num="1.4"/><vers num="1.5"/><vers num="1.6"/><vers num="2.0.0"/><vers num="2.0.1"/><vers num="2.1.0"/><vers num="2.2.0"/><vers num="2.2.1"/><vers num="2.2.2"/><vers num="2.3.0"/><vers num="2.3.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1313" published="2005-05-02" seq="2005-1313" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Horde Passwd module before 2.2.2 allows remote attackers to inject arbitrary web script or HTML via the parent&apos;s frame page title.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="MLIST" url="http://lists.horde.org/archives/sork/Week-of-Mon-20050418/002147.html">[sork] 20050422 Passwd 2.2.2 (final)</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/15075">15075</ref><ref source="" url="http://cvs.horde.org/diff.php/passwd/docs/CHANGES?r1=1.1.1.1.2.28&amp;r2=1.1.1.1.2.33&amp;ty=h"></ref></refs><vuln_soft><prod name="Passwd" vendor="Horde"><vers num="2.2.1"/><vers num="2.2"/><vers num="2.1"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1314" published="2005-05-02" seq="2005-1314" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Horde Kronolith module before 1.1.4 allows remote attackers to inject arbitrary web script or HTML via the parent&apos;s frame page title.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="MLIST" url="http://lists.horde.org/archives/kronolith/Week-of-Mon-20050418/005347.html">[kronolith] 20050422 Kronolith 1.1.4 (final)</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/15080">15080</ref><ref source="" url="http://cvs.horde.org/diff.php/kronolith/docs/CHANGES?r1=1.69.2.39&amp;r2=1.69.2.41&amp;ty=h"></ref></refs><vuln_soft><prod name="Kronolith" vendor="Horde"><vers num="1.1.3"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1315" published="2005-05-02" seq="2005-1315" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Horde Turba module before 1.2.5 allows remote attackers to inject arbitrary web script or HTML via the parent&apos;s frame page title.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="MLIST" url="http://lists.horde.org/archives/turba/Week-of-Mon-20050418/004182.html">[turba] 20050422 Turba 1.2.5 (final)</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/15074">15074</ref><ref source="" url="http://cvs.horde.org/diff.php/turba/docs/CHANGES?r1=1.61.2.74&amp;r2=1.61.2.77&amp;ty=h"></ref></refs><vuln_soft><prod name="Turba" vendor="Horde"><vers num="1.2.4"/><vers num="1.2.3"/><vers num="1.2.3 rc1"/><vers num="1.2.2"/><vers num="1.2.1"/><vers num="1.2.1 rc1"/><vers num="1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1316" published="2005-05-02" seq="2005-1316" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Horde Accounts module before 2.1.2 allows remote attackers to inject arbitrary web script or HTML via the parent&apos;s frame page title.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="MLIST" url="http://lists.horde.org/archives/sork/Week-of-Mon-20050418/002147.html">[sork] 20050422 Accounts 2.1.2 (final)</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/15081">15081</ref><ref source="" url="http://cvs.horde.org/diff.php/accounts/docs/CHANGES?r1=1.1.1.1.2.15&amp;r2=1.1.1.1.2.18&amp;ty=h"></ref></refs><vuln_soft><prod name="Accounts" vendor="Horde"><vers num="2.1.1"/><vers num="2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1317" published="2005-04-25" seq="2005-1317" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Horde Chora module before 1.2.3 allows remote attackers to inject arbitrary web script or HTML via the parent&apos;s frame page title.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/><input/></vuln_types><range><network/></range><refs><ref patch="1" source="MLIST" url="http://lists.horde.org/archives/chora/Week-of-Mon-20050418/004050.html">20050422 Chora 1.2.3 (final)</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15083">15083</ref><ref source="" url="http://cvs.horde.org/diff.php/chora/docs/CHANGES?r1=1.45.2.34&amp;r2=1.45.2.37&amp;ty=h"></ref></refs><vuln_soft><prod name="Chora" vendor="Horde"><vers num="1.2.2"/><vers num="1.2"/><vers num="1.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1318" published="2005-05-02" seq="2005-1318" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Horde Forwards E-Mail Forwarding Manager before 2.2.2 allows remote attackers to inject arbitrary web script or HTML via the parent&apos;s frame page title.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="MLIST" url="http://lists.horde.org/archives/sork/Week-of-Mon-20050418/002145.html">[sork] 20050422 Forwards 2.2.2 (final)</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/15082">15082</ref><ref source="" url="http://cvs.horde.org/diff.php/forwards/docs/CHANGES?r1=1.1.1.1.2.20&amp;r2=1.1.1.1.2.23&amp;ty=h"></ref></refs><vuln_soft><prod name="Forwards" vendor="Horde"><vers num="2.2.1"/><vers num="2.2"/><vers num="2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1319" published="2005-05-02" seq="2005-1319" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Horde IMP Webmail client before 3.2.8 allows remote attackers to inject arbitrary web script or HTML via the parent&apos;s frame page title.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="MLIST" url="http://lists.horde.org/archives/imp/Week-of-Mon-20050418/041912.html">[imp] 20050422 IMP 3.2.8 (final)</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/15080">15080</ref><ref source="" url="http://cvs.horde.org/diff.php/imp/docs/CHANGES?r1=1.389.2.119&amp;r2=1.389.2.125&amp;ty=h"></ref></refs><vuln_soft><prod name="IMP" vendor="Horde"><vers num="3.2.7"/><vers num="3.2.7 rc1"/><vers num="3.2.6"/><vers num="3.2.5"/><vers num="3.2.4"/><vers num="3.2.3"/><vers num="3.2.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1320" published="2005-05-02" seq="2005-1320" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Horde Mnemo Note Manager before 1.1.4 allows remote attackers to inject arbitrary web script or HTML via the parent&apos;s frame page title.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MLIST" url="http://lists.horde.org/archives/mnemo/Week-of-Mon-20050418/000166.html">[mnemo] 20050422 Mnemo 1.1.4 (final)</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/15078">15078</ref><ref source="" url="http://cvs.horde.org/diff.php/mnemo/docs/CHANGES?r1=1.4.2.31&amp;r2=1.4.2.33&amp;ty=h"></ref></refs><vuln_soft><prod name="Mnemo" vendor="Horde"><vers num="1.1.3"/><vers num="1.1.2"/><vers num="1.1.1"/><vers num="1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1321" published="2005-05-02" seq="2005-1321" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Horde Vacation module before 2.2.2 allows remote attackers to inject arbitrary web script or HTML via the parent&apos;s frame page title.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="MLIST" url="http://lists.horde.org/archives/sork/Week-of-Mon-20050418/002148.html">[sork] 20050422 Vacation 2.2.2 (final)</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/15073">15073</ref><ref source="" url="http://cvs.horde.org/diff.php/vacation/docs/CHANGES?r1=1.1.1.1.2.21&amp;r2=1.1.1.1.2.26&amp;ty=h"></ref></refs><vuln_soft><prod name="Vaction" vendor="Horde"><vers num="2.2.1"/><vers num="2.2"/><vers num="2.1"/><vers num="1.0a"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1322" published="2005-05-02" seq="2005-1322" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Horde Nag Task List Manager before 1.1.3 allows remote attackers to inject arbitrary web script or HTML via the parent&apos;s frame page title.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="MLIST" url="http://lists.horde.org/archives/nag/Week-of-Mon-20050418/000756.html">[nag] 20050422 Nag 1.1.3 (final)</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/15079">15079</ref><ref source="" url="http://cvs.horde.org/diff.php/nag/docs/CHANGES?r1=1.54.2.33&amp;r2=1.54.2.35&amp;ty=h"></ref></refs><vuln_soft><prod name="Nag" vendor="Horde"><vers num="1.1.2"/><vers num="1.1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1323" published="2005-05-02" seq="2005-1323" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in NetFtpd for NetTerm 5.1.1 and earlier allows remote attackers to execute arbitrary code via a long USER command.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/396959">20050426 ADV: NetTerms NetFtpd 4.2.2 Buffer Overflow + PoC Exploit</ref><ref source="CONFIRM" url="http://www.securenetterm.com/html/what_s_new.html">http://www.securenetterm.com/html/what_s_new.html</ref><ref source="BID" url="http://www.securityfocus.com/bid/13396">13396</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/0407">ADV-2005-0407</ref><ref source="OSVDB" url="http://www.osvdb.org/15865">15865</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15140">15140</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20285">netterm-netftpd-user-bo(20285)</ref></refs><vuln_soft><prod name="NetTerm" vendor="InterSoft"><vers num="4.2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1324" published="2005-05-02" seq="2005-1324" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in index.php for phpMyVisites allow remote attackers to inject arbitrary web script or HTML via the (1) part, (2) per, or (3) site parameters.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="MISC" url="http://www.frsirt.com/english/advisories/2005/0378">http://www.frsirt.com/english/advisories/2005/0378</ref><ref source="OSVDB" url="http://www.osvdb.org/15789">15789</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15084">15084</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20255">phpmyvisites-index-xss(20255)</ref></refs><vuln_soft><prod name="phpMyVisites" vendor="Matthieu Aubry"><vers num="1.3"/><vers num="1.2 Beta"/><vers num="1.2.2"/><vers num="1.2.1"/><vers num="1.2"/><vers num="1.1"/><vers num="1.0"/><vers num="0.1 Beta"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1325" published="2005-05-02" seq="2005-1325" severity="Medium" type="CVE"><desc><descript source="cve">set_lang.php in phpMyVisites 1.3 allows remote attackers to read and include arbitrary files via the mylang parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/13370">13370</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111454298603060&amp;w=2">20050426 [exploits] phpMyVisites 1.3 local file retrieval</ref><ref source="" url="http://cvs.sourceforge.net/viewcvs.py/phpmyvisites/phpmyvisites/include/set_lang.php?r1=1.5&amp;r2=1.6"></ref></refs><vuln_soft><prod name="phpMyVisites" vendor="Matthieu Aubry"><vers num="1.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1326" published="2005-05-02" seq="2005-1326" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in VooDoo cIRCle BOTNET before 1.0.33 allows remote authenticated attackers to cause a denial of service (client crash) via a crafted packet.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref patch="1" source="CONFIRM" url="http://sourceforge.net/project/shownotes.php?release_id=323254">http://sourceforge.net/project/shownotes.php?release_id=323254</ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/15830">15830</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15110">15110</ref></refs><vuln_soft><prod name="VooDoo cIRCle" vendor="VooDoo cIRCle"><vers num="1.0.32"/><vers num="1.0.31"/><vers num="1.0.30"/><vers num="1.0.29"/><vers num="1.0.28"/><vers num="1.0.27"/><vers num="1.0.26"/><vers num="1.0.25"/><vers num="1.0.24"/><vers num="1.0.23"/><vers num="1.0.22"/><vers num="1.0.21"/><vers num="1.0.20"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1327" published="2005-05-02" seq="2005-1327" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in pms.php for Woltlab Burning Board 2.3.1 PL2 and earlier allows remote attackers to inject arbitrary web script or HTML via the folderid parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/396858">20050424 WoltLab Burning Board 2.3.1</ref><ref source="BID" url="http://www.securityfocus.com/bid/13353">13353</ref></refs><vuln_soft><prod name="Burning Board" vendor="Woltlab"><vers num="2.3.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1328" published="2005-05-02" seq="2005-1328" severity="Medium" type="CVE"><desc><descript source="cve">OneWorldStore allows remote attackers to cause a denial of service (application crash) via a direct request to owConnections/chksettings.asp.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref patch="1" source="MISC" url="http://lostmon.blogspot.com/2005/04/oneworldstore-critical-failure.html">http://lostmon.blogspot.com/2005/04/oneworldstore-critical-failure.html</ref><ref patch="1" source="CONFIRM" url="http://www.oneworldstore.com/support_security_issue_updates.asp#April_20_2005_Lostmon">http://www.oneworldstore.com/support_security_issue_updates.asp#April_20_2005_Lostmon</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/13322">13322</ref><ref source="OSVDB" url="http://www.osvdb.org/15724">15724</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013782">1013782</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15057">15057</ref></refs><vuln_soft><prod name="OneWorldStore" vendor="OneWorldStore"><vers num="Free"/><vers num="Basic"/><vers num="SOHO"/><vers num="Business"/><vers num="Enterprise"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1329" published="2005-05-02" seq="2005-1329" severity="Medium" type="CVE"><desc><descript source="cve">owOfflineCC.asp in OneWorldStore allows remote attackers to obtain sensitive information by modifying the idOrder parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="MISC" url="http://lostmon.blogspot.com/2005/04/oneworldstore-user-information.html">http://lostmon.blogspot.com/2005/04/oneworldstore-user-information.html</ref><ref patch="1" source="CONFIRM" url="http://www.oneworldstore.com/support_security_issue_updates.asp#April_24_2005_Lostmon">http://www.oneworldstore.com/support_security_issue_updates.asp#April_24_2005_Lostmon</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/13361">13361</ref><ref source="OSVDB" url="http://www.osvdb.org/15781">15781</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1013796">1013796</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/15104">15104</ref></refs><vuln_soft><prod name="OneWorldStore" vendor="OneWorldStore"><vers num="Free"/><vers num="Basic"/><vers num="SOHO"/><vers num="Business"/><vers num="Enterprise"/></prod></vuln_soft></entry><entry CVSS_base_score="4.9" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.9" CVSS_score="4.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2008-01-03" name="CVE-2005-1330" published="2005-05-04" seq="2005-1330" severity="Medium" type="CVE"><desc><descript source="cve">AppKit in Mac OS X 10.3.9 allows attackers to cause a denial of service (Cocoa application crash) via a malformed TIFF image that causes the NXSeek to use an incorrect offset, leading to an unhandled exception.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><local/></range><refs><ref adv="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/May/msg00001.html">APPLE-SA-2005-05-03</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.3.9"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.3.9"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1331" published="2005-05-04" seq="2005-1331" severity="Medium" type="CVE"><desc><descript source="cve">The AppleScript Editor in Mac OS X 10.3.9 does not properly display script code for an applescript: URI, which can result in code that is different than the actual code that would be run, which could allow remote attackers to trick users into executing malicious code via certain URI characters such as NULL, control characters, and homographs.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/><user_init/></range><refs><ref source="MISC" url="http://remahl.se/david/vuln/010/">http://remahl.se/david/vuln/010/</ref><ref patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/May/msg00001.html">APPLE-SA-2005-05-03</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/13480">13480</ref><ref patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/0455">ADV-2005-0455</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/15227">15227</ref></refs><vuln_soft><prod name="Script Editor" vendor="Apple"><vers num="2.0.0"/></prod><prod name="Mac OS X Server" vendor="Apple"><vers num="10.3"/><vers num="10.3.1"/><vers num="10.3.2"/><vers num="10.3.3"/><vers num="10.3.4"/><vers num="10.3.5"/><vers num="10.3.6"/><vers num="10.3.7"/><vers num="10.3.8"/><vers num="10.3.9"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.3"/><vers num="10.3.1"/><vers num="10.3.2"/><vers num="10.3.3"/><vers num="10.3.4"/><vers num="10.3.5"/><vers num="10.3.6"/><vers num="10.3.7"/><vers num="10.3.8"/><vers num="10.3.9"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1332" published="2005-05-04" seq="2005-1332" severity="High" type="CVE"><desc><descript source="cve">Bluetooth-enabled systems in Mac OS X 10.3.9 enables the Bluetooth file exchange service by default, which allows remote attackers to access files without the user being notified, and local users to access files via the default directory.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/May/msg00001.html">APPLE-SA-2005-05-03</ref><ref adv="1" source="CONFIRM" url="http://docs.info.apple.com/article.html?artnum=301381">http://docs.info.apple.com/article.html?artnum=301381</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA05-136A.html">TA05-136A</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/258390">VU#258390</ref><ref source="" url="http://www.digitalmunition.com/DMA%5B2005-0502a%5D.txt"></ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.3.9"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.3.9"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-10-30" name="CVE-2005-1333" published="2005-05-04" seq="2005-1333" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in the Bluetooth file and object exchange (OBEX) services in Mac OS X 10.3.9 allows remote attackers to read arbitrary files.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/May/msg00001.html">APPLE-SA-2005-05-03</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/Jun/msg00000.html">APPLE-SA-2005-06-08</ref><ref source="" url="http://www.digitalmunition.com/DMA%5B2005-0502a%5D.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/13491">13491</ref></refs><vuln_soft><prod name="Mac OS X" vendor="Apple"><vers num="10.3.9"/></prod></vuln_soft></entry><entry modified="2005-10-25" name="CVE-2005-1334" published="2005-06-03" reject="1" seq="2005-1334" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2005-1579.  Reason: This candidate is a duplicate of CVE-2005-1579.  Notes: All CVE users should reference CVE-2005-1579 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript></desc><refs/></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1335" published="2005-05-04" seq="2005-1335" severity="High" type="CVE"><desc><descript source="cve">Unknown vulnerability in Mac OS X 10.3.9 allows local users to gain privileges via (1) chfn, (2) chpass, and (3) chsh, which &quot;use external helper programs in an insecure manner.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/May/msg00001.html">APPLE-SA-2005-05-03</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA05-136A.html">TA05-136A</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/331694">VU#331694</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.3.9"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.3.9"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1336" published="2005-05-04" seq="2005-1336" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in the Foundation framework for Mac OS X 10.3.9 allows local users to execute arbitrary code via a long environment variable.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/May/msg00001.html">APPLE-SA-2005-05-03</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA05-136A.html">TA05-136A</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/582934">VU#582934</ref></refs><vuln_soft><prod name="Mac OS X" vendor="Apple"><vers num="10.3.9"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1337" published="2005-05-04" seq="2005-1337" severity="High" type="CVE"><desc><descript source="cve">Apple Help Viewer 2.0.7 and 3.0.0 in Mac OS X 10.3.9 allows remote attackers to read and execute arbitrary scrpts with less restrictive privileges via a help:// URI.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://remahl.se/david/vuln/004/">http://remahl.se/david/vuln/004/</ref><ref adv="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/May/msg00001.html">APPLE-SA-2005-05-03</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.3.9"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.3.9"/></prod><prod name="Apple Help Viewer" vendor="Apple"><vers num="2.0.7"/><vers num="3.0.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1338" published="2005-05-04" seq="2005-1338" severity="Medium" type="CVE"><desc><descript source="cve">Mac OS X 10.3.9, when using an LDAP server that does not use ldap_extended_operation, may store initial LDAP passwords for new accounts in plaintext.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/May/msg00001.html">APPLE-SA-2005-05-03</ref></refs><vuln_soft><prod name="Mac OS X" vendor="Apple"><vers num="10.3.9"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1339" published="2005-05-04" seq="2005-1339" severity="High" type="CVE"><desc><descript source="cve">lukemftpd in Mac OS X 10.3.9 allows remote authenticated users to escape the chroot environment by logging in with their full name.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/May/msg00001.html">APPLE-SA-2005-05-03</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.3.9"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.3.9"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1340" published="2005-05-04" seq="2005-1340" severity="High" type="CVE"><desc><descript source="cve">The HTTP proxy service in Server Admin for Mac OS X 10.3.9 does not restrict access when it is enabled, which allows remote attackers to use the proxy.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/May/msg00001.html">APPLE-SA-2005-05-03</ref></refs><vuln_soft><prod name="Mac OS X" vendor="Apple"><vers num="10.3.9"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1341" published="2005-05-04" seq="2005-1341" severity="Medium" type="CVE"><desc><descript source="cve">Apple Terminal 1.4.4 allows attackers to execute arbitrary commands via terminal escape sequences.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><design/></vuln_types><range><network/><user_init/></range><refs><ref source="MISC" url="http://remahl.se/david/vuln/012/">http://remahl.se/david/vuln/012/</ref><ref patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/May/msg00001.html">APPLE-SA-2005-05-03</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/994510">VU#994510</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/13480">13480</ref><ref patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/0455">ADV-2005-0455</ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/16083">16083</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1013882">1013882</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/15227">15227</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.3"/><vers num="10.3.1"/><vers num="10.3.2"/><vers num="10.3.3"/><vers num="10.3.4"/><vers num="10.3.5"/><vers num="10.3.6"/><vers num="10.3.7"/><vers num="10.3.8"/><vers num="10.3.9"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.3"/><vers num="10.3.1"/><vers num="10.3.2"/><vers num="10.3.3"/><vers num="10.3.4"/><vers num="10.3.5"/><vers num="10.3.6"/><vers num="10.3.7"/><vers num="10.3.8"/><vers num="10.3.9"/></prod><prod name="Terminal" vendor="Apple"><vers num="1.4.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1342" published="2005-05-04" seq="2005-1342" severity="High" type="CVE"><desc><descript source="cve">The x-man-page: URI handler for Apple Terminal 1.4.4 in Mac OS X 10.3.9 does not cleanse terminal escape sequences, which allows remote attackers to execute arbitrary commands.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://remahl.se/david/vuln/011/">http://remahl.se/david/vuln/011/</ref><ref adv="1" patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/May/msg00001.html">APPLE-SA-2005-05-03</ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/356070">VU#356070</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/13480">13480</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/0455">ADV-2005-0455</ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/16084">16084</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/15227">15227</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA05-136A.html">TA05-136A</ref></refs><vuln_soft><prod name="Mac OS X" vendor="Apple"><vers num="10.3.9"/><vers num="10.3.8"/><vers num="10.3.7"/><vers num="10.3.6"/><vers num="10.3.5"/><vers num="10.3.4"/><vers num="10.3.3"/><vers num="10.3.2"/><vers num="10.3.1"/><vers num="10.3"/></prod><prod name="Terminal" vendor="Apple"><vers num="1.4.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1343" published="2005-05-03" seq="2005-1343" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in the VPN daemon (vpnd) for Mac OS X before 10.3.9 allows local users to execute arbitrary code via a long -i (Server_id) argument.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/May/msg00001.html">APPLE-SA-2005-05-03</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/Jun/msg00000.html">APPLE-SA-2005-06-08</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA05-136A.html">TA05-136A</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/706838">VU#706838</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.3.9"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.3.9"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1344" published="2005-05-02" seq="2005-1344" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in htdigest in Apache 2.0.52 may allow attackers to execute arbitrary code via a long realm argument.  NOTE: since htdigest is normally only locally accessible and not setuid or setgid, there are few attack vectors which would lead to an escalation of privileges, unless htdigest is executed from a CGI program.  Therefore this may not be a vulnerability.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="MISC" url="http://www.lucaercoli.it/advs/htdigest.txt">http://www.lucaercoli.it/advs/htdigest.txt</ref><ref source="MISC" url="http://www.securiteam.com/unixfocus/5EP061FEKC.html">http://www.securiteam.com/unixfocus/5EP061FEKC.html</ref><ref source="OSVDB" url="http://www.osvdb.org/12848">12848</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/May/msg00001.html">APPLE-SA-2005-05-03</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2005//Aug/msg00000.html">APPLE-SA-2005-08-15</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2005//Aug/msg00001.html">APPLE-SA-2005-08-17</ref><ref source="BID" url="http://www.securityfocus.com/bid/13537">13537</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/Aug/msg00000.html">APPLE-SA-2005-08-15</ref></refs><vuln_soft><prod name="Apache" vendor="Apache Software Foundation"><vers num="2.0.52"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1345" published="2005-05-02" seq="2005-1345" severity="High" type="CVE"><desc><descript source="cve">Squid 2.5.STABLE9 and earlier does not trigger a fatal error when it identifies missing or invalid ACLs in the http_access configuration, which could lead to less restrictive ACLs than intended by the administrator.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref patch="1" source="CONFIRM" url="http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE9-acl_error">http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE9-acl_error</ref><ref source="CONFIRM" url="http://www.squid-cache.org/bugs/show_bug.cgi?id=1255">http://www.squid-cache.org/bugs/show_bug.cgi?id=1255</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000948">CLA-2005:948</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-721">DSA-721</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-415.html">RHSA-2005:415</ref><ref source="FEDORA" url="http://fedoranews.org/updates/FEDORA--.shtml">FLSA-2006:152809</ref></refs><vuln_soft><prod name="Squid" vendor="Squid"><vers num="2.5.STABLE9"/><vers num="2.5.STABLE8"/><vers num="2.5.STABLE7"/><vers num="2.5.STABLE6"/><vers num="2.5.STABLE5"/><vers num="2.5.STABLE4"/><vers num="2.5.STABLE3"/><vers num="2.5.STABLE2"/><vers num="2.5.STABLE1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-28" name="CVE-2005-1346" published="2005-05-02" seq="2005-1346" severity="Low" type="CVE"><desc><descript source="cve">Multiple Symantec AntiVirus products, including Norton AntiVirus 2005 11.0.0, Web Security Web Security 3.0.1.72, Mail Security for SMTP 4.0.5.66, AntiVirus Scan Engine 4.3.7.27, SAV/Filter for Domino NT 3.1.1.87, and Mail Security for Exchange 4.5.4.743, when running on Windows, allows remote attackers to cause a denial of service (component crash) and avoid detection via a crafted RAR file.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="CONFIRM" url="http://securityresponse.symantec.com/avcenter/security/Content/2005.04.27.html">http://securityresponse.symantec.com/avcenter/security/Content/2005.04.27.html</ref></refs><vuln_soft><prod name="Norton Internet Security" vendor="Symantec"><vers num="2005 Contains NAV 11.0.0"/></prod><prod name="Symantec Mail Security SMTP" vendor="Symantec"><vers num="4.0.5.66"/></prod><prod name="Symantec SAV_Filter Domino NT" vendor="Symantec"><vers num="3.1.1.87"/></prod><prod name="Symantec Mail Security Exchange" vendor="Symantec"><vers num="4.5.4.743"/></prod><prod name="Norton System Works" vendor="Symantec"><vers num="2005 Contains NAV 11.0.0"/></prod><prod name="Symantec AntiVirus Scan Engine" vendor="Symantec"><vers num="4.3.7.27"/></prod><prod name="Symantec Web Security" vendor="Symantec"><vers num="3.0.1.72"/></prod><prod name="Norton AntiVirus" vendor="Symantec"><vers num="2005 11.0.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-06-15" name="CVE-2005-1347" published="2005-05-02" seq="2005-1347" severity="Low" type="CVE"><desc><descript source="cve">** UNVERIFIABLE **  NOTE: this issue describes a problem that can not be independently verified as of 20050421.  Adobe Acrobat reader (AcroRd32.exe) 6.0 and earlier allows remote attackers to cause a denial of service (&quot;Invalid-ID-Handle-Error&quot; error) and modify memory beginning at a particular address, possibly allowing the execution of arbitrary code, via a crafted PDF file.  NOTE: the vendor has stated that the reporter refused to provide sufficient details to confirm the issue.  In addition, due to the lack of details in the original advisory, an independent verification is not possible.  Finally, the reliability of the original reporter is unknown.  This item has only been assigned a CVE identifier for tracking purposes, and to serve as a concrete example of the newly defined UNVERIFIABLE and PRERELEASE content decisions in CVE, which must be discussed by the Editorial Board. Without additional details or independent verification by reliable sources, it is highly likely that this item will be REJECTED.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/><exception/></vuln_types><range><network/><user_init/></range><refs><ref source="MISC" url="http://www.alphahackers.com/advisories/acrobat6.txt">http://www.alphahackers.com/advisories/acrobat6.txt</ref><ref source="OSVDB" url="http://www.osvdb.org/15850">15850</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013774">1013774</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20216">acrobat-reader-invalid-id-handle-bo(20216)</ref></refs><vuln_soft><prod name="Acrobat Reader" vendor="Adobe"><vers num="6.0"/><vers num="5.0.10"/><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-07-24" name="CVE-2005-1348" published="2005-05-02" seq="2005-1348" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in HTTPMail in MailEnable Enterprise 1.04 and earlier and Professional 1.54 and earlier allows remote attackers to execute arbitrary code via a long HTTP Authorization header.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111445834220015&amp;w=2">20050424 MailEnable HTTPS Buffer Overflow [x0n3-h4ck]</ref><ref source="" url="http://www.x0n3-h4ck.org/upload/x0n3-h4ck_mailenable_https.pl"></ref><ref source="OSVDB" url="http://www.osvdb.org/15737">15737</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013786">1013786</ref></refs><vuln_soft><prod name="MailEnable Professional" vendor="MailEnable"><vers num="1.54" prev="1"/></prod><prod name="MailEnable Enterprise" vendor="MailEnable"><vers num="1.04" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1349" published="2005-05-02" seq="2005-1349" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Convert-UUlib (Convert::UUlib) before 1.051 allows remote attackers to execute arbitrary code via a malformed parameter to a read operation.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200504-26.xml">GLSA-200504-26</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/15130">15130</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/20275">convert-uulib-bo(20275)</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:022">MDKSA-2006:022</ref><ref source="BID" url="http://www.securityfocus.com/bid/13401">13401</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:022">MDKSA-2006:022</ref></refs><vuln_soft><prod name="Convert UUlib" vendor="Perl"><vers num="1.050" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-08-16" name="CVE-2005-1350" published="2005-05-02" seq="2005-1350" severity="Medium" type="CVE"><desc><descript source="cve">The ad.cgi script allows remote attackers to read arbitrary files via a full pathname in the argument.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111446285915444&amp;w=2">20050424 remote command execution in ad.cgi script</ref></refs><vuln_soft><prod name="ad.cgi" vendor="Leif M. Wright"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-08-16" name="CVE-2005-1351" published="2005-05-02" seq="2005-1351" severity="High" type="CVE"><desc><descript source="cve">The ad.cgi script allows remote attackers to execute arbitrary commands via shell metacharacters in the argument.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111446285915444&amp;w=2">20050424 remote command execution in ad.cgi script</ref></refs><vuln_soft><prod name="ad.cgi" vendor="Leif M. Wright"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-08-16" name="CVE-2005-1352" published="2005-05-02" seq="2005-1352" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in the ad.cgi script allows remote attackers to inject arbitrary web script or HTML via the argument.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111446285915444&amp;w=2">20050424 remote command execution in ad.cgi script</ref></refs><vuln_soft><prod name="ad.cgi" vendor="Leif M. Wright"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1353" published="2005-05-02" seq="2005-1353" severity="Medium" type="CVE"><desc><descript source="cve">The forum.pl script allows remote attackers to read arbitrary files via a full pathname in the argument.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111446056205059&amp;w=2">20050424 remote command execution in forum.pl script</ref></refs><vuln_soft><prod name="forum.pl" vendor="forum.pl"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1354" published="2005-05-02" seq="2005-1354" severity="High" type="CVE"><desc><descript source="cve">The forum.pl script allows remote attackers to execute arbitrary commands via shell metacharacters in the argument.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111446056205059&amp;w=2">20050424 remote command execution in forum.pl script</ref></refs><vuln_soft><prod name="forum.pl" vendor="forum.pl"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-25" name="CVE-2005-1355" published="2005-05-02" seq="2005-1355" severity="Medium" type="CVE"><desc><descript source="cve">includer.cgi in The Includer allows remote attackers to read arbitrary files via a full pathname in the argument, a similar vulnerability to CVE-2005-0801.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111445548126797&amp;w=2">20050424 remote command execution in includer.cgi script</ref></refs><vuln_soft><prod name="includer.cgi" vendor="includer.cgi"><vers num="1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1356" published="2005-05-02" seq="2005-1356" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in includer.cgi script in The Includer allows remote attackers to inject arbitrary web script or HTML via the argument.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111445548126797&amp;w=2">20050424 remote command execution in includer.cgi script</ref></refs><vuln_soft><prod name="includer.cgi" vendor="includer.cgi"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1357" published="2005-05-02" seq="2005-1357" severity="Medium" type="CVE"><desc><descript source="cve">text.cgi script allows remote attackers to read arbitrary files via a full pathname in the argument.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111445867315415&amp;w=2">20050425 remote command execution in text.cgi script</ref></refs><vuln_soft><prod name="text.cgi" vendor="text.cgi"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1358" published="2005-05-02" seq="2005-1358" severity="High" type="CVE"><desc><descript source="cve">text.cgi script allows remote attackers to execute arbitrary commands via shell metacharacters in the argument.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111445867315415&amp;w=2">20050425 remote command execution in text.cgi script</ref></refs><vuln_soft><prod name="text.cgi" vendor="text.cgi"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1359" published="2005-05-02" seq="2005-1359" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in text.cgi script allows remote attackers to inject arbitrary web script or HTML via the argument.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111445867315415&amp;w=2">20050425 remote command execution in text.cgi script</ref></refs><vuln_soft><prod name="text.cgi" vendor="text.cgi"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-28" name="CVE-2005-1360" published="2005-05-02" seq="2005-1360" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in error.php in GrayCMS 1.1 allows remote attackers to execute arbitrary PHP code by modifying the path_prefix parameter to reference a URL on a remote web server that contains the code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/13381">13381</ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/15860">15860</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15133">15133</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20278">graycms-pathprefix-error-include(20278)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111454354214982&amp;w=2">20050426 GrayCMS php code injection</ref></refs><vuln_soft><prod name="GrayCMS" vendor="GrayCMS"><vers num="1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1361" published="2005-05-02" seq="2005-1361" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in MetaCart e-Shop 8.0 allow remote attackers to execute arbitrary SQL commands via the (1) intProdID parameter in product.asp or (2) strCatalog_NAME parameter to productsByCategory.asp.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/13376">13376</ref><ref source="BID" url="http://www.securityfocus.com/bid/13377">13377</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20283">metacart-eshop-sql-injection(20283)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111453994718211&amp;w=2">20050426 Multiple SQL Injections in MetaCart e-Shop V-8</ref></refs><vuln_soft><prod name="MetaCart e-Shop" vendor="MetaLinks"><vers num="8.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1362" published="2005-05-02" seq="2005-1362" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in MetaCart 2.0 for Paypal allow remote attackers to execute arbitrary SQL commands via the (1) intProdID parameter to product.asp, (2) intCatalogID or (3) strSubCatalogID parameters to productsByCategory.asp, (4) chkText, (5) strText, (6) chkPrice, (7) intPrice, (8) chkCat, or (9) strCat parameters to searchAction.asp.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/13377">13377</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111454090503662&amp;w=2">20050426 Multiple SQL Injections in MetaCart2 for SQL Server Special Edition U.K</ref></refs><vuln_soft><prod name="MetaCart2" vendor="MetaLinks"><vers num="Paypal"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1363" published="2005-05-02" seq="2005-1363" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in MetaCart 2.0 for PayFlow allow remote attackers to execute arbitrary commands via (1) intCatalogID, (2) strSubCatalogID, or (3) strSubCatalog_NAME parameter to productsByCategory.asp, (4) curCatalogID, (5) strSubCatalog_NAME, (6) intCatalogID, or (7) page parameter to productsByCategory.asp or (8) intProdID parameter to product.asp.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/13377">13377</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111454142832023&amp;w=2">20050426 MetaCart2 for PayFlow Multiple Sql Injection Vulnerabilities</ref></refs><vuln_soft><prod name="MetaCart2" vendor="MetaLinks"><vers num="PayFlow Link"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1364" published="2005-05-02" seq="2005-1364" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in MetaBid Auctions allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password fields in logIn.asp, or (3) intAuctionID parameter to item.asp.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MISC" url="http://digitalparadox.org/advisories/metabid.txt">http://digitalparadox.org/advisories/metabid.txt</ref><ref source="BID" url="http://www.securityfocus.com/bid/13395">13395</ref><ref source="OSVDB" url="http://www.osvdb.org/15868">15868</ref><ref source="OSVDB" url="http://www.osvdb.org/15869">15869</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/15136">15136</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20286">metabid-item-login-sql-injection(20286)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111454192928364&amp;w=2">20050426 Multiple SQL Injections in MetaBid Auctions</ref></refs><vuln_soft><prod name="MetaBID Auctions" vendor="MetaLinks"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-05-12" name="CVE-2005-1365" published="2005-05-16" seq="2005-1365" severity="High" type="CVE"><desc><descript source="cve">Pico Server (pServ) 3.2 and earlier allows remote attackers to execute arbitrary commands via a URL with multiple leading &quot;/&quot; (slash) characters and &quot;..&quot; sequences.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/><design/></vuln_types><range><network/></range><refs><ref adv="1" source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=111625635716712&amp;w=2">20050516 Advisory: Pico Server (pServ) Remote Command Injection</ref><ref source="CONFIRM" url="http://sourceforge.net/project/shownotes.php?release_id=327708">http://sourceforge.net/project/shownotes.php?release_id=327708</ref><ref source="BID" url="http://www.securityfocus.com/bid/13642">13642</ref><ref adv="1" source="MISC" url="http://www.redteam-pentesting.de/advisories/rt-sa-2005-010.txt">http://www.redteam-pentesting.de/advisories/rt-sa-2005-010.txt</ref></refs><vuln_soft><prod name="Pico Server" vendor="Pico Server"><vers num="3.2"/><vers num="3.1"/><vers num="3.0"/><vers num="3.0 Beta 3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-05-04" name="CVE-2005-1366" published="2005-05-16" seq="2005-1366" severity="High" type="CVE"><desc><descript source="cve">Pico Server (pServ) 3.2 and earlier allows remote attackers to obtain the source code for CGI scripts via &quot;dirname/../cgi-bin&quot; in a URL.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/><design/></vuln_types><range><network/></range><refs><ref adv="1" source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=111625623909003&amp;w=2">20050516 Pico Server (pServ) Information Disclosure Of CGI Sources</ref><ref source="CONFIRM" url="http://sourceforge.net/project/shownotes.php?release_id=327708">http://sourceforge.net/project/shownotes.php?release_id=327708</ref><ref source="BID" url="http://www.securityfocus.com/bid/13638">13638</ref><ref adv="1" source="MISC" url="http://www.redteam-pentesting.de/advisories/rt-sa-2005-011.txt">http://www.redteam-pentesting.de/advisories/rt-sa-2005-011.txt</ref></refs><vuln_soft><prod name="Pico Server" vendor="Pico Server"><vers num="3.2"/><vers num="3.1"/><vers num="3.0"/><vers num="3.0 Beta 3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-05-04" name="CVE-2005-1367" published="2005-05-16" seq="2005-1367" severity="High" type="CVE"><desc><descript source="cve">Pico Server (pServ) 3.2 and earlier allows local users to read arbitrary files as the pServ user via a symlink to a file outside of the web document root.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=111625623909003&amp;w=2">20050516 Pico Server (pServ) Local Information Disclosure</ref><ref adv="1" source="MISC" url="http://www.redteam-pentesting.de/advisories/rt-sa-2005-012.txt">http://www.redteam-pentesting.de/advisories/rt-sa-2005-012.txt</ref></refs><vuln_soft><prod name="Pico Server" vendor="Pico Server"><vers num="3.2"/><vers num="3.1"/><vers num="3.0"/><vers num="3.0 Beta 3"/></prod></vuln_soft></entry><entry CVSS_base_score="1.2" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="2.9" CVSS_score="1.2" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1368" published="2005-05-02" seq="2005-1368" severity="Low" type="CVE"><desc><descript source="cve">The key_user_lookup function in security/keys/key.c in Linux kernel 2.6.10 to 2.6.11.8 may allow attackers to cause a denial of service (oops) via SMP.</descript></desc><loss_types><avail/></loss_types><vuln_types><race/></vuln_types><range><local/></range><refs><ref patch="1" source="CONFIRM" url="http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.11.8">http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.11.8</ref><ref source="CONFIRM" url="http://linux.bkbits.net:8080/linux-2.6/cset%40423078fafVa6mAyny23YZ87hDipmTw">http://linux.bkbits.net:8080/linux-2.6/cset%40423078fafVa6mAyny23YZ87hDipmTw</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/427980/100/0/threaded">FLSA:157459-3</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.6.11.7"/><vers num="2.6.11.6"/><vers num="2.6.11.5"/><vers num="2.6.11.4"/><vers num="2.6.11.3"/><vers num="2.6.11.2"/><vers num="2.6.11.1"/><vers num="2.6.11"/><vers num="2.6 -test9-CVS"/><vers num="2.6 -test9"/><vers num="2.6 -test8"/><vers num="2.6 -test7"/><vers num="2.6 -test6"/><vers num="2.6 -test5"/><vers num="2.6 -test4"/><vers num="2.6 -test3"/><vers num="2.6 -test2"/><vers num="2.6 -test11"/><vers num="2.6 -test10"/><vers num="2.6 -test1"/><vers num="2.6"/><vers num="2.6.1 -rc2"/><vers num="2.6.1 -rc1"/><vers num="2.6.1"/><vers num="2.6.2"/><vers num="2.6.3"/><vers num="2.6.4"/><vers num="2.6.5"/><vers num="2.6.6"/><vers num="2.6.7"/><vers num="2.6.8"/><vers num="2.6.8.1"/><vers num="2.6.9"/><vers num="2.6.10"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1369" published="2005-05-02" seq="2005-1369" severity="Low" type="CVE"><desc><descript source="cve">The (1) it87 and (2) via686a drivers in I2C for Linux 2.6.x before 2.6.11.8, and 2.6.12 before 2.6.12-rc2, create the sysfs &quot;alarms&quot; file with write permissions, which allows local users to cause a denial of service (CPU consumption) by attempting to write to the file, which does not have an associated store function.</descript></desc><loss_types><avail/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref patch="1" source="CONFIRM" url="http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.11.8">http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.11.8</ref><ref source="CONFIRM" url="http://lkml.org/lkml/2005/4/20/159">http://lkml.org/lkml/2005/4/20/159</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/427980/100/0/threaded">FLSA:157459-3</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.6.0"/><vers num="2.6.1"/><vers num="2.6.1-rc1"/><vers num="2.6.1-rc2"/><vers num="2.6.10"/><vers num="2.6.10-rc2"/><vers num="2.6.11"/><vers num="2.6.12-rc1"/><vers num="2.6.2"/><vers num="2.6.3"/><vers num="2.6.4"/><vers num="2.6.5"/><vers num="2.6.6"/><vers num="2.6.7"/><vers num="2.6.8"/><vers num="2.6.8.1"/><vers num="2.6.9"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1370" published="2005-05-03" seq="2005-1370" severity="High" type="CVE"><desc><descript source="cve">Unknown vulnerability in Radia Management Agent (RMA) in HP OpenView Radia Management Portal (RMP) 1.x and 2.x allows remote attackers to execute arbitrary commands via unknown vectors.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref patch="1" source="HP" url="http://archives.neohapsis.com/archives/bugtraq/2005-04/0490.html">HPSBMA01138</ref><ref source="BID" url="http://www.securityfocus.com/bid/13414">13414</ref><ref source="OSVDB" url="http://www.osvdb.org/15960">15960</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1013829">1013829</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15089">15089</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20307">hp-openview-radia-gain-access(20307)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111471365231909&amp;w=2">20050428 High risk flaw in HP OpenView Radia Management Agent</ref></refs><vuln_soft><prod name="OpenView Radia Management Portal" vendor="HP"><vers num="2"/><vers num="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-09-05" name="CVE-2005-1371" published="2005-05-03" seq="2005-1371" severity="High" type="CVE"><desc><descript source="cve">BPFTPServer service in BulletProof FTP Server 2.4.0.31 does not properly drop privileges before opening files through the Help menu, which allows local users to gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/><env/></vuln_types><range><local/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/13410">13410</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/0419">ADV-2005-0419</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15152">15152</ref><ref source="OSVDB" url="http://www.osvdb.org/15898">15898</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20301">bpftp-gain-privilege(20301)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111464474828477&amp;w=2">20050427 Privilege escalation in BulletProof FTP Server v2.4.0.31</ref></refs><vuln_soft><prod name="BulletProof FTP Server" vendor="BulletProof"><vers num="2.4.0.31"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1372" published="2005-05-03" seq="2005-1372" severity="Medium" type="CVE"><desc><descript source="cve">nvstatsmngr.exe process in BakBone NetVault 7.1 does not properly drop privileges before opening files, which allows local users to gain privileges via the Help menu.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/13408">13408</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/0420">ADV-2005-0420</ref><ref source="OSVDB" url="http://www.osvdb.org/15900">15900</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15158/">15158</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20302">bakbone-netvault-gain-privileges(20302)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111464410324243&amp;w=2">20050427 Privilege escalation in BakBone NetVault 7.1</ref></refs><vuln_soft><prod name="NetVault" vendor="BakBone"><vers num="7.1.1"/><vers num="7.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-06-15" name="CVE-2005-1373" published="2005-05-03" seq="2005-1373" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in index.php in Dream4 Koobi CMS 4.2.3 allow remote attackers to execute arbitrary SQL commands via the (1) q or (2) p parameters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/13412">13412</ref><ref source="BID" url="http://www.securityfocus.com/bid/13413">13413</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14696">14696</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20293">koobi-parameter-search-sql-injection(20293)</ref><ref source="OSVDB" url="http://www.osvdb.org/15997">15997</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111464009913703&amp;w=2">20050427 SQL-injections in koobi-cms</ref></refs><vuln_soft><prod name="Koobi CMS" vendor="Dream4"><vers num="4.2.3"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-06-15" name="CVE-2005-1374" published="2005-05-03" seq="2005-1374" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Claroline 1.5.3 through 1.6 Release Candidate 1, and possibly Dokeos, allow remote attackers to inject arbitrary web script or HTML via (1) exercise_result.php, (2) exercice_submit.php, (3) agenda.php, (4) learningPathList.php, (5) learningPathAdmin.php, (6) learningPath.php, (7) userLog.php, (8) tool parameter to toolaccess_details.php, (9) data parameter to user_access_details.php, or (10) coursePath parameter to myagenda.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CONFIRM" url="http://www.claroline.net/news.php#85">http://www.claroline.net/news.php#85</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/13407">13407</ref><ref adv="1" patch="1" source="SECTRACK" url="http://securitytracker.com/id?1013822">1013822</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/15161">15161</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/20295">claroline-multiple-scripts-xss(20295)</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15725">15725</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111464607103407&amp;w=2">20050427 ZRCSA-200501 - Multiple vulnerabilities in Claroline</ref></refs><vuln_soft><prod name="Claroline" vendor="Claroline"><vers num="1.5.3"/><vers num="1.6 rc1"/><vers num="1.6 beta"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2007-01-24" name="CVE-2005-1375" published="2005-05-03" seq="2005-1375" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in Claroline 1.5.3 through 1.6 Release Candidate 1, and possibly Dokeos, allow remote attackers to execute arbitrary SQL commands via (1) learningPath.php, (2) learningPathAdmin.php, (3) learnPath_details.php, (4) modules_pool.php, (5) module.php, (6) uInfo parameter in userInfo.php, or (7) exo_id parameter to exercises_details.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="CONFIRM" url="http://www.claroline.net/news.php#85">http://www.claroline.net/news.php#85</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/13407">13407</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1013822">1013822</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/15161">15161</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/20298">claroline-multiple-sql-injection(20298)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111464607103407&amp;w=2">20050427 ZRCSA-200501 - Multiple vulnerabilities in Claroline</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15725">15725</ref></refs><vuln_soft><prod name="Claroline" vendor="Claroline"><vers num="1.5.3"/><vers num="1.6 beta"/><vers num="1.6 rc1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-08-28" name="CVE-2005-1376" published="2005-05-03" seq="2005-1376" severity="High" type="CVE"><desc><descript source="cve">Multiple directory traversal vulnerabilities in (1) document.php or (2) insertMyDoc.php in Claroline 1.5.3 through 1.6 Release Candidate 1, and possibly Dokeos, allow remote project administrators to upload arbitrary files.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref patch="1" source="CONFIRM" url="http://www.claroline.net/news.php#85">http://www.claroline.net/news.php#85</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/13407">13407</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1013822">1013822</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/15161">15161</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/20287">claroline-document-directory-traversal(20287)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111464607103407&amp;w=2">20050427 ZRCSA-200501 - Multiple vulnerabilities in Claroline</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15725">15725</ref></refs><vuln_soft><prod name="Claroline" vendor="Claroline"><vers num="1.5.3"/><vers num="1.6 beta"/><vers num="1.6 rc1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-28" name="CVE-2005-1377" published="2005-05-03" seq="2005-1377" severity="High" type="CVE"><desc><descript source="cve">Multiple PHP remote file inclusion vulnerabilities in Claroline 1.5.3 through 1.6 Release Candidate 1, and possibly Dokeos, allow remote attackers to execute arbitrary PHP code via unknown vectors.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="CONFIRM" url="http://www.claroline.net/news.php#85">http://www.claroline.net/news.php#85</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/13407">13407</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1013822">1013822</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/15161">15161</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/20300">claroline-file-include(20300)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111464607103407&amp;w=2">20050427 ZRCSA-200501 - Multiple vulnerabilities in Claroline</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15725">15725</ref></refs><vuln_soft><prod name="Claroline" vendor="Claroline"><vers num="1.5.3"/><vers num="1.6 beta"/><vers num="1.6 rc1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1378" published="2005-05-03" seq="2005-1378" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in posting_notes.php in the notes module for phpBB allows remote attackers to execute arbitrary SQL commands via the p parameter, which is used in the $post_id variable, and other attack vectors.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/13417">13417</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/0416">ADV-2005-0416</ref><ref source="OSVDB" url="http://www.osvdb.org/15899">15899</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013827">1013827</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15154/">15154</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20303">phpbb-notes-module-sql-injection(20303)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111471606518372&amp;w=2">20050427 phpBB Notes Mod SQL Injection Vulnerability</ref><ref source="" url="http://www.gulftech.org/?node=research&amp;article_id=00070-04272005"></ref></refs><vuln_soft><prod name="phpBB Personal Notes Module" vendor="Oxpus"><vers num="1.4.6" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1379" published="2005-05-03" seq="2005-1379" severity="Medium" type="CVE"><desc><descript source="cve">The LAM runtime environment package (lam-runtime-7.0.6-2mdk) on Mandrake Linux installs the mpi user without a password, which allows local users to gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/13431">13431</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111472262231060&amp;w=2">20050428 insecure user account lam-runtime-7.0.6-2mdk rpm</ref></refs><vuln_soft><prod name="Mandrake lam-runtime" vendor="MandrakeSoft"><vers num="7.0.6.2mdk"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1380" published="2005-05-03" seq="2005-1380" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in BEA Admin Console 8.1 allows remote attackers to execute arbitrary web script or HTML via the server parameter to a JndiFramesetAction action.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://www.red-database-security.com/advisory/bea_css_in_admin_console.html">http://www.red-database-security.com/advisory/bea_css_in_admin_console.html</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/13400">13400</ref><ref source="OSVDB" url="http://www.osvdb.org/15895">15895</ref><ref adv="1" source="SECTRACK" url="http://securitytracker.com/alerts/2005/Apr/1013817.html">1013817</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/15128">15128</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/20276">weblogic-jndiframesetaction-xss(20276)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111472745503010&amp;w=2">20050428 Cross Site Scripting in BEA Admin Console</ref></refs><vuln_soft><prod name="WebLogic Server" vendor="BEA Systems"><vers num="8.1 SP4"/><vers num="8.1 SP3"/><vers num="8.1 SP2"/><vers num="8.1 SP1"/><vers num="8.1"/><vers edition="Win32" num="8.1 SP4"/><vers edition="Win32" num="8.1 SP3"/><vers edition="Win32" num="8.1 SP2"/><vers edition="Win32" num="8.1 SP1"/><vers edition="Win32" num="8.1"/></prod><prod name="WebLogic Express" vendor="BEA Systems"><vers num="8.1 SP4"/><vers num="8.1 SP3"/><vers num="8.1 SP2"/><vers num="8.1 SP1"/><vers num="8.1"/><vers edition="Win32" num="8.1 SP4"/><vers edition="Win32" num="8.1 SP3"/><vers edition="Win32" num="8.1 SP2"/><vers edition="Win32" num="8.1 SP1"/><vers edition="Win32" num="8.1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1381" published="2005-05-03" seq="2005-1381" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Oracle Webcache 9i allow remote attackers to inject arbitrary web script or HTML via the (1) cache_dump_file or (2) PartialPageErrorPage parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://www.red-database-security.com/advisory/oracle_webcache_CSS_vulnerabilities.html">http://www.red-database-security.com/advisory/oracle_webcache_CSS_vulnerabilities.html</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/13421">13421</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/13422">13422</ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/15910">15910</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/15143">15143</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/20309">oracle9ias-application-cache-xss(20309)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111472423409560&amp;w=2">20050428 Cross Site Scripting in Oracle Webcache 9i Adminstrator Application</ref></refs><vuln_soft><prod name="Oracle9iAS Web Cache" vendor="Oracle"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1382" published="2005-05-03" seq="2005-1382" severity="Medium" type="CVE"><desc><descript source="cve">The webcacheadmin module in Oracle Webcache 9i allows remote attackers to corrupt arbitrary files via a full pathname in the cache_dump_file parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://www.red-database-security.com/advisory/oracle_webcache_append_file_vulnerabilitiy.html">http://www.red-database-security.com/advisory/oracle_webcache_append_file_vulnerabilitiy.html</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/13420">13420</ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/15909">15909</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/15143">15143</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/20310">oracle9ias-application-cache-file-corruption(20310)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111472615519295&amp;w=2">20050428 File appending vulnerability in Oracle Webcache 9i</ref></refs><vuln_soft><prod name="Oracle9iAS Web Cache" vendor="Oracle"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1383" published="2005-05-03" seq="2005-1383" severity="High" type="CVE"><desc><descript source="cve">The OHS component 1.0.2 through 10.x, when UseWebcacheIP is disabled, in Oracle Application Server allows remote attackers to bypass HTTP Server mod_access restrictions via a request to the webcache TCP port 7778.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref patch="1" source="MISC" url="http://www.red-database-security.com/advisory/oracle_webcache_bypass.html">http://www.red-database-security.com/advisory/oracle_webcache_bypass.html</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/13418">13418</ref><ref patch="1" source="OSVDB" url="http://www.osvdb.org/15908">15908</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15143">15143</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/20311">oracle9ias-application-cache-url-bypass(20311)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111472266123952&amp;w=2">20050428 Webcache Client Requests Bypass OHS mod_access Restrictions</ref></refs><vuln_soft><prod name="Oracle10g Application Server" vendor="Oracle"><vers num="10.1.0.3.1"/><vers num="10.1.0.3"/><vers num="10.1.0.2"/><vers num="10.1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-03-29" name="CVE-2005-1384" published="2005-05-03" seq="2005-1384" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in phpCoin 1.2.2 allow remote attackers to execute arbitrary SQL commands via the (1) search parameter to index.php, (2) phpcoinsessid parameter to login.php, (3) id, (4) dtopic_id, or (5) dcat_id to mod.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://digitalparadox.org/viewadvisories.ah?view=36">http://digitalparadox.org/viewadvisories.ah?view=36</ref><ref source="BID" url="http://www.securityfocus.com/bid/13433">13433</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/0423">ADV-2005-0423</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013834">1013834</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20308">phpcoin-multiple-sql-injection(20308)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111473522804665&amp;w=2">20050428 Multiple Sql injections in phpCoin v1.2.2 and below</ref><ref source="" url="http://pridels.blogspot.com/2006/03/phpcoin-poc.html"></ref><ref source="" url="http://pridels0.blogspot.com/2006/03/phpcoin-poc.html"></ref></refs><vuln_soft><prod name="phpCOIN" vendor="COINSoft Technologies"><vers num="1.2"/><vers num="1.2.1b"/><vers num="1.2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1385" published="2005-05-03" seq="2005-1385" severity="Low" type="CVE"><desc><descript source="cve">Safari 1.3 allows remote attackers to cause a denial of service (application crash) via a long https URL that triggers a NULL pointer dereference.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><design/></vuln_types><range><network/><user_init/></range><refs><ref source="OSVDB" url="http://www.osvdb.org/16006">16006</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013835">1013835</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111473570624498&amp;w=2">20050428 Safari HTTPS Overflow</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111479346119272&amp;w=2">20050429  Re: Safari HTTPS Overflow</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111479299730011&amp;w=2">20050429 Re: Safari HTTPS Overflow</ref></refs><vuln_soft><prod name="Safari" vendor="Apple"><vers num="1.3_312"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1386" published="2005-05-03" seq="2005-1386" severity="Medium" type="CVE"><desc><descript source="cve">PHP-Nuke 7.6 and earlier allows remote attackers to obtain sensitive information via a direct request to (1) ipban.php, (2) db.php, (3) lang-norwegian.php, (4) lang-indonesian.php, (5) lang-greek.php, (6) a request to Web_Links with the portuguese language (lang-portuguese.php), (7) a request to Web_Links with the indonesian language (lang-indonesian.php), (8) a request to the survey module with the indonesian language (lang-indonesian.php), (9) a request to the Reviews module with the portuguese language, or (10) a request to the Journal module with the portuguese language, which reveal the path in an error message.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111478982629035&amp;w=2">20050429 Multiples Full Path Disclosure in php-nuke 7.6 (and below)</ref></refs><vuln_soft><prod name="PHP-Nuke" vendor="Francisco Burzi"><vers num="6.0"/><vers num="6.5 RC3"/><vers num="6.5 RC2"/><vers num="6.5 RC1"/><vers num="6.5 FINAL"/><vers num="6.5 Beta1"/><vers num="6.5"/><vers num="6.6"/><vers num="6.7"/><vers num="6.9"/><vers num="7.0 FINAL"/><vers num="7.0"/><vers num="7.1"/><vers num="7.2"/><vers num="7.3"/><vers num="7.4"/><vers num="7.5"/><vers num="7.6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1387" published="2005-05-03" seq="2005-1387" severity="High" type="CVE"><desc><descript source="cve">Cocktail 3.5.4 and possibly earlier in Mac OS X passes the administrative password on the command line to sudo in cleartext, which allows local users to gain sensitive information by running listing processes.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/13449">13449</ref><ref source="OSVDB" url="http://www.osvdb.org/16046">16046</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15201">15201</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111480898530362&amp;w=2">20050429 Mac OS X Cocktail 3.5.4 admin password disclosure</ref></refs><vuln_soft><prod name="Cocktail" vendor="Kristofer Szymanski"><vers num="3.5.4"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1388" published="2005-05-03" seq="2005-1388" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in SURVIVOR before 0.9.6 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="CONFIRM" url="http://www.columbia.edu/acis/dev/projects/survivor/doc/todo.html#changelog">http://www.columbia.edu/acis/dev/projects/survivor/doc/todo.html#changelog</ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/15905">15905</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/13415">13415</ref></refs><vuln_soft><prod name="Survivor" vendor="Survivor"><vers num="0.9.5a"/></prod></vuln_soft></entry><entry modified="2005-10-25" name="CVE-2005-1389" published="2005-05-03" reject="1" seq="2005-1389" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2005-0175.  Reason: This candidate is a duplicate of CVE-2005-0175.  Notes: All CVE users should reference CVE-2005-0175 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><refs/></entry><entry modified="2005-10-25" name="CVE-2005-1390" published="2005-05-03" reject="1" seq="2005-1390" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2005-0174.  Reason: This candidate is a duplicate of CVE-2005-0174.  Notes: All CVE users should reference CVE-2005-0174 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript></desc><loss_types><int/></loss_types><vuln_types><input bound="1"/></vuln_types><refs/></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-25" name="CVE-2005-1391" published="2005-05-03" seq="2005-1391" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the add_port function in APSIS Pound 1.8.2 and earlier allows remote attackers to execute arbitrary code via a long Host HTTP header.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="MLIST" url="http://www.apsis.ch/pound/pound_list/archive/2005/2005-04/1114516112000">20050426 remote buffer overflow in pound 1.8.2 + question abotu Host header</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200504-29.xml">GLSA-200504-29</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/13436">13436</ref><ref patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/0437">ADV-2005-0437</ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/15963">15963</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013824">1013824</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15142">15142</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20316">pound-addport-bo(20316)</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-934">DSA-934</ref><ref source="" url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=307852"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/15202">15202</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15679">15679</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18381">18381</ref></refs><vuln_soft><prod name="Pound" vendor="Apsis"><vers num="1.8.2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1392" published="2005-05-03" seq="2005-1392" severity="Medium" type="CVE"><desc><descript source="cve">The SQL install script in phpMyAdmin 2.6.2 is created with world-readable permissions, which allows local users to obtain the initial database password by reading the script.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200504-30.xml">GLSA-200504-30</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/0436">ADV-2005-0436</ref><ref source="OSVDB" url="http://www.osvdb.org/16053">16053</ref></refs><vuln_soft><prod name="phpMyAdmin" vendor="phpMyAdmin"><vers num="2.6.2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1393" published="2005-05-03" seq="2005-1393" severity="Medium" type="CVE"><desc><descript source="cve">Multiple buffer overflows in ArcGIS for ESRI ArcInfo Workstation 9.0 allow local users to execute arbitrary code via long command line arguments to (1) asmaster, (2) asuser, (3) asutility, (4) se, or (5) asrecovery.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref patch="1" source="MISC" url="http://www.digitalmunition.com/DMA%5B2005-0425a%5D.txt">http://www.digitalmunition.com/DMA%5B2005-0425a%5D.txt</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013852">1013852</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15196">15196</ref><ref source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=111489411524630&amp;w=2">20050430 DMA[2005-0425a] - &apos;ESRI ArcGIS 9.x multiple local vulnerabilities</ref><ref source="" url="http://support.esri.com/index.cfm?fa=downloads.patchesServicePacks.viewPatch&amp;PID=14&amp;MetaID=1015"></ref></refs><vuln_soft><prod name="ArcInfo Workstation" vendor="ESRI"><vers num="9.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1394" published="2005-05-03" seq="2005-1394" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in ArcGIS for ESRI ArcInfo Workstation 9.0 allows local users to gain privileges via format string specifiers in the ARCHOME environment variable to (1) wservice or (2) lockmgr.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref patch="1" source="MISC" url="http://www.digitalmunition.com/DMA%5B2005-0425a%5D.txt">http://www.digitalmunition.com/DMA%5B2005-0425a%5D.txt</ref><ref adv="1" patch="1" source="SECTRACK" url="http://securitytracker.com/id?1013852">1013852</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/15196">15196</ref><ref source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=111489411524630&amp;w=2">20050430 DMA[2005-0425a] - &apos;ESRI ArcGIS 9.x multiple local vulnerabilities</ref><ref source="" url="http://support.esri.com/index.cfm?fa=downloads.patchesServicePacks.viewPatch&amp;PID=14&amp;MetaID=1015"></ref></refs><vuln_soft><prod name="ArcGIS" vendor="ESRI"><vers num="9.0"/></prod><prod name="ArcInfo Workstation" vendor="ESRI"><vers num="9.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1395" published="2005-05-03" seq="2005-1395" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Ce/Ceterm (aka ARPUS/Ce) 2.5.4 and earlier may allow local users to gain privileges via a long (1) XAPPLRESLANGPATH or (2) XAPPLRESDIR environment variable, or (3) command line argument.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref patch="1" source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-May/033705.html">20050501 DMA[2005-0501a] - ARPUS/Ce setuid buffer overflow and file overwrite</ref><ref patch="1" source="MISC" url="http://www.digitalmunition.com/DMA%5B2005-0501a%5D.txt">http://www.digitalmunition.com/DMA[2005-0501a].txt</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013855">1013855</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/15197">15197</ref></refs><vuln_soft><prod name="Ce_Ceterm" vendor="SWLink"><vers num="2.5.4"/><vers num="2.5.3"/><vers num="2.5.2"/><vers num="2.5.1"/><vers num="2.5"/><vers num="2.4"/><vers num="2.3.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="1.2" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="2.9" CVSS_score="1.2" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1396" published="2005-05-03" seq="2005-1396" severity="Low" type="CVE"><desc><descript source="cve">Race condition in Ce/Ceterm (aka ARPUS/Ce) 2.5.4 and earlier allows local users to write to arbitrary files via a symlink attack on the ce_edit_log temporary file.</descript></desc><sols><sol source="nvd">Upgrade to version 2.6</sol></sols><loss_types><int/></loss_types><vuln_types><race/></vuln_types><range><local/></range><refs><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-May/033705.html">20050501 DMA[2005-0501a] - ARPUS/Ce setuid buffer overflow and file overwrite</ref><ref adv="1" source="MISC" url="http://www.digitalmunition.com/DMA%5B2005-0501a%5D.txt">http://www.digitalmunition.com/DMA[2005-0501a].txt</ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/16050">16050</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013855">1013855</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/15197">15197</ref></refs><vuln_soft><prod name="Ce_Ceterm" vendor="SWLink"><vers num="2.5.4"/><vers num="2.5.3"/><vers num="2.5.2"/><vers num="2.5.1"/><vers num="2.5"/><vers num="2.4"/><vers num="2.3.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1397" published="2005-05-03" seq="2005-1397" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in search.php for PHP-Calendar before 0.10.3 allows remote attackers to execute arbitrary SQL commands via unknown vectors.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="CONFIRM" url="http://sourceforge.net/project/shownotes.php?release_id=323483">http://sourceforge.net/project/shownotes.php?release_id=323483</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/13405">13405</ref><ref patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/0418">ADV-2005-0418</ref><ref source="OSVDB" url="http://www.osvdb.org/15866">15866</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/15116">15116</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/20297">php-calendar-searchphp-sql-injection(20297)</ref></refs><vuln_soft><prod name="PHP-Calendar" vendor="PHP-Calendar"><vers num="0.1"/><vers num="0.2"/><vers num="0.3"/><vers num="0.4"/><vers num="0.5"/><vers num="0.6"/><vers num="0.7"/><vers num="0.8"/><vers num="0.9"/><vers num="0.9.1"/><vers num="0.10"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1398" published="2005-05-03" seq="2005-1398" severity="Medium" type="CVE"><desc><descript source="cve">phpcart.php in PHPCart 3.2 allows remote attackers to change product price information by modifying the (1) price or (2) postage parameters.</descript></desc><loss_types><int/></loss_types><vuln_types><input/><design/></vuln_types><range><network/></range><refs><ref source="MISC" url="http://lostmon.blogspot.com/2005/04/phpcart-price-manipulation.html">http://lostmon.blogspot.com/2005/04/phpcart-price-manipulation.html</ref><ref source="BID" url="http://www.securityfocus.com/bid/13406">13406</ref><ref source="OSVDB" url="http://www.osvdb.org/15859">15859</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/15147">15147</ref></refs><vuln_soft><prod name="PHPCart" vendor="PHPCart"><vers num="3.2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1399" published="2005-05-06" seq="2005-1399" severity="Medium" type="CVE"><desc><descript source="cve">FreeBSD 4.6 to 4.11 and 5.x to 5.4 uses insecure default permissions for the /dev/iir device, which allows local users to execute restricted ioctl calls to read or modify data on hardware that is controlled by the iir driver.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><config/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="FREEBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-05:06.iir.asc">FreeBSD-SA-05:06</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="4.6"/><vers num="4.7"/><vers num="4.8"/><vers num="4.9"/><vers num="4.10"/><vers num="4.11"/><vers num="5.1"/><vers num="5.2"/><vers num="5.3"/><vers num="5.4"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1400" published="2005-05-06" seq="2005-1400" severity="Medium" type="CVE"><desc><descript source="cve">The i386_get_ldt system call in FreeBSD 4.7 to 4.11 and 5.x to 5.4 allows local users to access sensitive kernel memory via arguments with negative or very large values.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input bound="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="FreeBSD-SA-05" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-05:07.ldt.asc">07</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="4.7"/><vers num="4.8"/><vers num="4.9"/><vers num="4.10"/><vers num="4.11"/><vers num="5.1"/><vers num="5.2"/><vers num="5.3"/><vers num="5.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1401" published="2005-05-03" seq="2005-1401" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in the client for Mtp-Target 1.2.2 and earlier allows remote attackers to execute arbitrary code via game messages or other text.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/><design/></vuln_types><range><network/></range><refs><ref source="Luigi Auriemma" url="http://aluigi.altervista.org/adv/mtpbugs-adv.txt"></ref><ref source="BUGTRAQ" url="http://www.security-focus.com/archive/1/397304">20050501 Clients format string and server crash in Mtp-Target 1.2.2</ref></refs><vuln_soft><prod name="Mtp-Target" vendor="Mtp-Target"><vers num="1.2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1402" published="2005-05-03" seq="2005-1402" severity="Medium" type="CVE"><desc><descript source="cve">Integer signedness error in certain older versions of the NeL library, as used in Mtp-Target 1.2.2 and earlier, and possibly other products, allows remote attackers to cause a denial of service (memory consumption or server crash) via a negative value in a STLport call, which is not caught by a signed comparison.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/><design/></vuln_types><range><network/></range><refs><ref source="Luigi Auriemma" url="http://aluigi.altervista.org/adv/mtpbugs-adv.txt"></ref><ref source="BUGTRAQ" url="http://www.security-focus.com/archive/1/397304">20050501 Clients format string and server crash in Mtp-Target 1.2.2</ref></refs><vuln_soft><prod name="Mtp-Target" vendor="Mtp-Target"><vers num="1.2.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1403" published="2005-05-03" seq="2005-1403" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in JustWilliam&apos;s Amazon Webstore 04050100 allow remote attackers to inject arbitrary web script or HTML via the (1) image parameter to closeup.php, the (2) currentIsExpanded or (3) searchFor parameters to index.php, (4) the currentNumber parameter to software_CAD_Technical_60002_uk.htm, or (5) a cookie.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/><design/></vuln_types><range><network/></range><refs><ref source="MISC" url="http://lostmon.blogspot.com/2005/04/amazon-webstore-script-injection-and.html">http://lostmon.blogspot.com/2005/04/amazon-webstore-script-injection-and.html</ref><ref source="BID" url="http://www.securityfocus.com/bid/13427">13427</ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/15894">15894</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013836">1013836</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/15155">15155</ref><ref source="OSVDB" url="http://www.osvdb.org/15892">15892</ref></refs><vuln_soft><prod name="Amazon Webstore" vendor="Just Williams"><vers num="04050100"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1404" published="2005-05-03" seq="2005-1404" severity="Medium" type="CVE"><desc><descript source="cve">MyPHP Forum 1.0 allows remote attackers to spoof the username by modifying the (1) nbuser parameter to post.php or (2) sender parameter to privmsg.php.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://www.securityfocus.org/archive/1/397025">20050426 myPHP Forum v3 (possible v1 &amp; 2 also) Identification spoof</ref><ref source="BID" url="http://www.securityfocus.com/bid/13430">13430</ref><ref adv="1" patch="1" source="OSVDB" url="http://www.osvdb.org/15902">15902</ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/15903">15903</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/15166">15166</ref></refs><vuln_soft><prod name="MyPHP Forum" vendor="MyPHP Forum"><vers num="1.0"/><vers num="2.0"/><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1405" published="2005-05-03" seq="2005-1405" severity="Low" type="CVE"><desc><descript source="cve">HTTP response splitting vulnerability in the @SetHTTPHeader function in Lotus Domino 6.5.x before 6.5.4 and 6.0.x before 6.0.5 allows attackers to poison the web cache via malicious applications.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref source="OSVDB" url="http://www.osvdb.org/15365">15365</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1013839">1013839</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/14879">14879</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20045">lotus-sethttpheader-injection(20045)</ref><ref source="" url="http://www-1.ibm.com/support/docview.wss?rs=463&amp;uid=swg21202437"></ref></refs><vuln_soft><prod name="Lotus Notes" vendor="IBM"><vers num="6.5.3"/><vers num="6.5.2"/><vers num="6.5.1"/><vers num="6.5"/><vers num="6.0.4"/><vers num="6.0.3"/><vers num="6.0.2"/><vers num="6.0.1"/><vers num="6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1406" published="2005-05-06" seq="2005-1406" severity="Medium" type="CVE"><desc><descript source="cve">The kernel in FreeBSD 4.x to 4.11 and 5.x to 5.4 does not properly clear certain fixed-length buffers when copying variable-length data for use by applications, which could allow those applications to read previously used sensitive memory.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="FREEBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-05:08.kmem.asc">FreeBSD-SA-05:08</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/Oct/msg00000.html">APPLE-SA-2005-10-31</ref><ref source="BID" url="http://www.securityfocus.com/bid/15252">15252</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/2256">ADV-2005-2256</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17368">17368</ref><ref source="BID" url="http://www.securityfocus.com/bid/13526">13526</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="4.1"/><vers num="4.2"/><vers num="4.3"/><vers num="4.4"/><vers num="4.5"/><vers num="4.6"/><vers num="4.7"/><vers num="4.8"/><vers num="4.9"/><vers num="4.10"/><vers num="4.11"/><vers num="5.1"/><vers num="5.2"/><vers num="5.3"/><vers num="5.4"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1407" published="2005-05-03" seq="2005-1407" severity="Medium" type="CVE"><desc><descript source="cve">Skype for Windows 1.2.0.0 to 1.2.0.46 allows local users to bypass the identity check for an authorized application, then call arbitrary Skype API functions by modifying or replacing that application.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CONFIRM" url="http://www.skype.com/security/ssa-2005-01.html">http://www.skype.com/security/ssa-2005-01.html</ref></refs><vuln_soft><prod name="Skype" vendor="Skype Technologies"><vers num="1.2.0.0"/><vers num="1.2.0.37"/><vers num="1.2.0.41"/><vers num="1.2.0.46"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1408" published="2005-05-26" seq="2005-1408" severity="Medium" type="CVE"><desc><descript source="cve">Apple Keynote 2.0 and 2.0.1 allows remote attackers to read arbitrary files via the keynote: URI handler in a crafted Keynote presentation.</descript></desc><loss_types><conf/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref patch="1" source="MISC" url="http://remahl.se/david/vuln/016/">http://remahl.se/david/vuln/016/</ref><ref adv="1" patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/May/msg00005.html">APPLE-SA-2005-05-25</ref><ref source="David Remahl" url="http://remahl.se/david/vuln/016/demo.html">Demonstration of exploit</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014053">1014053</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15508">15508</ref></refs><vuln_soft><prod name="Keynote" vendor="Apple"><vers num="2.0"/><vers num="2.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1409" published="2005-05-03" seq="2005-1409" severity="High" type="CVE"><desc><descript source="cve">PostgreSQL 7.3.x through 8.0.x gives public EXECUTE access to certain character conversion functions, which allows unprivileged users to call those functions with malicious values, with unknown impact, aka the &quot;Character conversion vulnerability.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref patch="1" source="CONFIRM" url="http://www.postgresql.org/about/news.315">http://www.postgresql.org/about/news.315</ref><ref patch="1" source="MLIST" url="http://archives.postgresql.org/pgsql-announce/2005-05/msg00001.php">[pgsql-announce] 20050502 IMPORTANT: two new PostgreSQL security problems found</ref><ref patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/0453">ADV-2005-0453</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval676.html">OVAL676</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-433.html">RHSA-2005:433</ref><ref source="BID" url="http://www.securityfocus.com/bid/13476">13476</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_36_sudo.html">SUSE-SA:2005:036</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:676">oval:org.mitre.oval:def:676</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/426302/30/6680/threaded">
FLSA-2006:157366</ref></refs><vuln_soft><prod name="PostgreSQL" vendor="PostgreSQL"><vers num="8.0"/><vers num="8.0.1"/><vers num="8.0.2"/><vers num="7.4"/><vers num="7.4.1"/><vers num="7.4.2"/><vers num="7.4.3"/><vers num="7.4.4"/><vers num="7.4.5"/><vers num="7.4.6"/><vers num="7.4.7"/><vers num="7.3"/><vers num="7.3.1"/><vers num="7.3.2"/><vers num="7.3.3"/><vers num="7.3.4"/><vers num="7.3.5"/><vers num="7.3.6"/><vers num="7.3.7"/><vers num="7.3.8"/><vers num="7.3.9"/><vers num="7.2.1"/><vers num="7.2.2"/><vers num="7.2.3"/><vers num="7.2.4"/><vers num="7.2.5"/><vers num="7.2.6"/><vers num="7.2.7"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1410" published="2005-05-03" seq="2005-1410" severity="Low" type="CVE"><desc><descript source="cve">The tsearch2 module in PostgreSQL 7.4 through 8.0.x declares the (1) dex_init, (2) snb_en_init, (3) snb_ru_init, (4) spell_init, and (5) syn_init functions as &quot;internal&quot; even when they do not take an internal argument, which allows attackers to cause a denial of service (application crash) and possibly have other impacts via SQL commands that call other functions that accept internal arguments.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref patch="1" source="CONFIRM" url="http://www.postgresql.org/about/news.315">http://www.postgresql.org/about/news.315</ref><ref patch="1" source="MLIST" url="http://archives.postgresql.org/pgsql-announce/2005-05/msg00001.php">[pgsql-announce] 20050502 IMPORTANT: two new PostgreSQL security problems found</ref><ref patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/0453">ADV-2005-0453</ref><ref patch="1" source="securityfocus" url="http://www.securityfocus.com/bid/13475">bid13475</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1086.html">OVAL1086</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-433.html">RHSA-2005:433</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_36_sudo.html">SUSE-SA:2005:036</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1086">oval:org.mitre.oval:def:1086</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/426302/30/6680/threaded">
FLSA-2006:157366</ref></refs><vuln_soft><prod name="PostgreSQL" vendor="PostgreSQL"><vers num="7.4"/><vers num="7.4.3"/><vers num="7.4.5"/><vers num="7.4.6"/><vers num="7.4.7"/><vers num="8.0"/><vers num="8.0.1"/><vers num="8.0.2"/></prod><prod name="Secure Enterprise Linux" vendor="Trustix"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1411" published="2005-05-03" seq="2005-1411" severity="Medium" type="CVE"><desc><descript source="cve">Cybration ICUII 7.0 stores passwords in plaintext in the world-readable icuii.ini file, which allows local users to gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref source="MISC" url="http://osvdb.org/ref/14/14688-icuii.txt">http://osvdb.org/ref/14/14688-icuii.txt</ref><ref source="BID" url="http://www.securityfocus.com/bid/13441">13441</ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/14688">14688</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013828">1013828</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15171">15171</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/20321">icuii-password-disclosure(20321)</ref></refs><vuln_soft><prod name="ICUII" vendor="Cybration"><vers num="7.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1412" published="2005-05-03" seq="2005-1412" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in verify.asp for Ecomm Professional Guestbook 3.x allows remote attackers to execute arbitrary SQL commands via the AdminPWD parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="OSVDB" url="http://www.osvdb.org/15967">15967</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/15190">15190</ref></refs><vuln_soft><prod name="Professional Guestbook" vendor="Ecomm"><vers num="3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1413" published="2005-05-03" seq="2005-1413" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in enVivo!CMS allow remote attackers to execute arbitrary SQL commands and gain privileges via the (1) username or (2) password parameters to admin_login.asp, or the (3) searchstring and possibly (4) ID parameters to default.asp.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MISC" url="http://digitalparadox.org/viewadvisories.ah?view=37">http://digitalparadox.org/viewadvisories.ah?view=37</ref><ref source="BID" url="http://www.securityfocus.com/bid/13437">13437</ref><ref source="BID" url="http://www.securityfocus.com/bid/13439">13439</ref><ref source="BID" url="http://www.securityfocus.com/bid/13440">13440</ref><ref source="OSVDB" url="http://www.osvdb.org/15965">15965</ref><ref source="OSVDB" url="http://www.osvdb.org/15966">15966</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15173">15173</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013843">1013843</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20313">envivo-username-password-sql-injection(20313)</ref><ref source="OSVDB" url="http://www.osvdb.org/15964">15964</ref><ref source="FULLDISC" url="http://marc.info/?l=full-disclosure&amp;m=118414271202945&amp;w=2">20070711 durito: enVivo!CMS SQL injection</ref><ref source="" url="http://securityvulns.ru/Rdocument425.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/24860">24860</ref></refs><vuln_soft><prod name="enVivo!CMS" vendor="EnvivoSoft"><vers num="3.54"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1414" published="2005-05-03" seq="2005-1414" severity="Medium" type="CVE"><desc><descript source="cve">ExoticSoft FilePocket 1.2 stores sensitive proxy information, including proxy passwords, in plaintext in the registry, which allows local users to gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/13445">13445</ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/14685">14685</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013823">1013823</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26187">
filepocket-registry-plaintext-password(26187)</ref></refs><vuln_soft><prod name="FilePocket" vendor="ExoticSoft"><vers num="1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1415" published="2005-05-03" seq="2005-1415" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in GlobalSCAPE Secure FTP Server 3.0.2 allows remote authenticated users to execute arbitrary code via a long FTP command.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" other="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2005-04/0674.html">20050501 Remote buffer overflow in GlobalScape Secure FTP server 3.0.2</ref><ref patch="1" source="CONFIRM" url="http://www.cuteftp.com/gsftps/history.asp">http://www.cuteftp.com/gsftps/history.asp</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/13454">13454</ref></refs><vuln_soft><prod name="Secure FTP Server" vendor="GlobalSCAPE"><vers num="3.0.2"/><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-08-23" name="CVE-2005-1416" published="2005-05-03" seq="2005-1416" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in 04WebServer 1.81 allows remote attackers to read files outside of the web root but within the installation folder.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/0448">ADV-2005-0448</ref><ref source="OSVDB" url="http://www.osvdb.org/16067">16067</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15230">15230</ref><ref source="" url="http://osvdb.org/ref/16/16067-04webserver.txt"></ref><ref source="" url="http://www.soft3304.net/04WebServer/Security.html"></ref></refs><vuln_soft><prod name="04WebServer" vendor="Soft3304"><vers num="1.81"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1417" published="2005-05-03" seq="2005-1417" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in MaxWebPortal 2.x, 1.35, and other versions allow remote attackers to execute arbitrary SQL commands via (1) article_popular.asp, (2) arguments to dl_popular.asp, (3) arguments to links_popular.asp, (4) arguments to pic_popular.asp, (5) article_rate.asp, (6) dl_rate.asp, (7) links_rate.asp, (8) pic_rates.asp, (9) article_toprated.asp, (10) dl_toprated.asp, (11) links_toprated.asp, (12) arguments to pic_toprated.asp, or (13) the TOPIC_ID or Forum_ID parameters to custom_link.asp.</descript></desc><sols><sol source="nvd">The vulnerabilities have been partially fixed in versions 1.3.5 and 2.0. The remaining vulnerabilities will reportedly be fixed in the upcoming 2.1 version.</sol></sols><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="CONFIRM" url="http://www.maxwebportal.info/downloads/mwp_security_fixes.zip">http://www.maxwebportal.info/downloads/mwp_security_fixes.zip</ref><ref source="BID" url="http://www.securityfocus.com/bid/13466">13466</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013845">1013845</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15214">15214</ref><ref source="" url="http://www.maxwebportal.info/topic.asp?TOPIC_ID=2482&amp;FORUM_ID=1&amp;CAT_ID=1&amp;Forum_Title=General+Chat&amp;Topic_Title=Security+Update"></ref></refs><vuln_soft><prod name="MaxWebPortal" vendor="MaxWebPortal"><vers num="1.3.0"/><vers num="1.3.1"/><vers num="1.3.2"/><vers num="1.3.3"/><vers num="1.3.5"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1418" published="2005-05-03" seq="2005-1418" severity="Medium" type="CVE"><desc><descript source="cve">NetLeaf Limited NotJustBrowsing 1.0.3 stores the View Lock Password in plaintext in the notjustbrowsing.prf file, which allows local users to gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/13442">13442</ref><ref source="OSVDB" url="http://www.osvdb.org/14687">14687</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013826">1013826</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15184">15184</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20319">notjustbrowsing-password-disclosure(20319)</ref></refs><vuln_soft><prod name="NotJustBrowsing" vendor="NetLeaf Limited"><vers num="1.0.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-08-28" name="CVE-2005-1419" published="2005-05-03" seq="2005-1419" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in the admin login panel for Ocean12 Mailing List Manager 1.06 allows remote attackers to execute arbitrary SQL commands via the Admin_id parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2005-04/0491.html">20050428 [HSC Security Group] Ocean12 Mailing List Manager Pro SQL injection</ref><ref source="OSVDB" url="http://www.osvdb.org/15959">15959</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013833">1013833</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/15178">15178</ref></refs><vuln_soft><prod name="Mailing List Manager" vendor="Ocean12 Technologies"><vers num="1.06"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-22" name="CVE-2005-1420" published="2005-05-03" seq="2005-1420" severity="Medium" type="CVE"><desc><descript source="cve">Raysoft/Raybase Video Cam Server 1.0.0 beta allows remote attackers to determine the full pathname of the server via a request for an invalid page, as demonstrated using &quot;%20&quot; (hex-encoded space).</descript></desc><loss_types><conf/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref source="MISC" url="http://www.autistici.org/fdonato/advisory/VideoCamServer1.0.0-adv.txt">http://www.autistici.org/fdonato/advisory/VideoCamServer1.0.0-adv.txt</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013860">1013860</ref></refs><vuln_soft><prod name="Video Cam Server" vendor="Raysoft"><vers num="1.0.0 Beta"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-22" name="CVE-2005-1421" published="2005-05-03" seq="2005-1421" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in Raysoft/Raybase Video Cam Server 1.0.0 beta allows remote attackers to read arbitrary files via &quot;..&quot; (dot dot) sequences in an HTTP request.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MISC" url="http://www.autistici.org/fdonato/advisory/VideoCamServer1.0.0-adv.txt">http://www.autistici.org/fdonato/advisory/VideoCamServer1.0.0-adv.txt</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013860">1013860</ref></refs><vuln_soft><prod name="Video Cam Server" vendor="Raysoft"><vers num="1.0.0 Beta"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-22" name="CVE-2005-1422" published="2005-05-03" seq="2005-1422" severity="High" type="CVE"><desc><descript source="cve">Raysoft/Raybase Video Cam Server 1.0.0 beta allows remote attackers to conduct administrator operations and cause a denial of service (server or camera shutdown) via a direct request to admin.html.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MISC" url="http://www.autistici.org/fdonato/advisory/VideoCamServer1.0.0-adv.txt">http://www.autistici.org/fdonato/advisory/VideoCamServer1.0.0-adv.txt</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013860">1013860</ref></refs><vuln_soft><prod name="Video Cam Server" vendor="Raysoft"><vers num="1.0.0 Beta"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1423" published="2005-05-03" seq="2005-1423" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in the mail program in 602LAN SUITE 2004.0.05.0413 allows remote attackers to cause a denial of service and determine the presence of arbitrary files via .. sequences in the A parameter.</descript></desc><loss_types><avail/><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="OSVDB" url="http://www.osvdb.org/16069">16069</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15231">15231</ref></refs><vuln_soft><prod name="602LAN Suite" vendor="Software602"><vers num="2004.0.05.0413"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1424" published="2005-05-03" seq="2005-1424" severity="Low" type="CVE"><desc><descript source="cve">StumbleInside GoText 1.01 stores sensitive username, mail address,and phone number information in plaintext in the GoText.bin file, which allows local users to obtain that information.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/13443">13443</ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/14686">14686</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013825">1013825</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20315">gotext-user-information-disclosure(20315)</ref></refs><vuln_soft><prod name="GoText" vendor="StumbleInside"><vers num="1.01"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1425" published="2005-05-03" seq="2005-1425" severity="High" type="CVE"><desc><descript source="cve">Uapplication Uguestbook stores the database under the web document root, which allows remote attackers to obtain sensitive information via a direct request to guestbook.mdb.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="OSVDB" url="http://www.osvdb.org/15995">15995</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013830">1013830</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20314">uapplication-information-disclosure(20314)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/456240/100/0/threaded">20070107 Uguestbook Remote Password Disclosure Vulnerability</ref></refs><vuln_soft><prod name="Uguestbook" vendor="Uapplication"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1426" published="2005-05-03" seq="2005-1426" severity="Medium" type="CVE"><desc><descript source="cve">Uapplication Ublog Reload stores the database under the web document root, which allows remote attackers to obtain sensitive information via a direct request to blog.msb.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref source="OSVDB" url="http://www.osvdb.org/15996">15996</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013830">1013830</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20314">uapplication-information-disclosure(20314)</ref></refs><vuln_soft><prod name="Ublog" vendor="Uapplication"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1427" published="2005-05-03" seq="2005-1427" severity="High" type="CVE"><desc><descript source="cve">Uapplication Uphotogallery stores the database under the web document root, which allows remote attackers to obtain sensitive information via a direct request to uphotogallery.mdb.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="OSVDB" url="http://www.osvdb.org/15994">15994</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013830">1013830</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20314">uapplication-information-disclosure(20314)</ref></refs><vuln_soft><prod name="Uphotogallery" vendor="Uapplication"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1428" published="2005-05-03" seq="2005-1428" severity="High" type="CVE"><desc><descript source="cve">edit_image.asp in Uapplication Uphotogallery allows remote attackers to upload arbitrary files.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref source="SECTRACK" url="http://securitytracker.com/id?1013830">1013830</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20314">uapplication-information-disclosure(20314)</ref></refs><vuln_soft><prod name="Uphotogallery" vendor="Uapplication"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1429" published="2005-05-03" seq="2005-1429" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in login.asp in WWWguestbook 1.1 allows remote attackers to execute arbitrary SQL commands via the password parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/13404">13404</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013837">1013837</ref><ref source="OSVDB" url="http://www.osvdb.org/15968">15968</ref></refs><vuln_soft><prod name="WWWGuestBook" vendor="AbcZone.it"><vers num="1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="3.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="4.9" CVSS_score="3.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1430" published="2005-05-03" seq="2005-1430" severity="Low" type="CVE"><desc><descript source="cve">Mac OS X 10.3.x and earlier uses insecure permissions for a pseudo terminal tty (pty) that is managed by a non-setuid program, which allows local users to read or modify sessions of other users.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="BUGTRAQ" url="http://www.security-focus.com/archive/1/397306">20050501 Insecure pty permissions in OS X &lt; 10.4</ref><ref patch="1" source="bid" url="http://www.securityfocus.com/bid/13467">13467</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.0"/><vers num="10.1"/><vers num="10.1.1"/><vers num="10.1.2"/><vers num="10.1.3"/><vers num="10.1.4"/><vers num="10.1.5"/><vers num="10.2"/><vers num="10.2.1"/><vers num="10.2.2"/><vers num="10.2.3"/><vers num="10.2.4"/><vers num="10.2.5"/><vers num="10.2.6"/><vers num="10.2.7"/><vers num="10.2.8"/><vers num="10.3"/><vers num="10.3.1"/><vers num="10.3.2"/><vers num="10.3.3"/><vers num="10.3.4"/><vers num="10.3.5"/><vers num="10.3.6"/><vers num="10.3.7"/><vers num="10.3.8"/><vers num="10.3.9"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.0"/><vers num="10.0.1"/><vers num="10.0.2"/><vers num="10.0.3"/><vers num="10.0.4"/><vers num="10.1"/><vers num="10.1.1"/><vers num="10.1.2"/><vers num="10.1.3"/><vers num="10.1.4"/><vers num="10.1.5"/><vers num="10.2"/><vers num="10.2.1"/><vers num="10.2.2"/><vers num="10.2.3"/><vers num="10.2.4"/><vers num="10.2.5"/><vers num="10.2.6"/><vers num="10.2.7"/><vers num="10.2.8"/><vers num="10.3"/><vers num="10.3.1"/><vers num="10.3.2"/><vers num="10.3.3"/><vers num="10.3.4"/><vers num="10.3.5"/><vers num="10.3.6"/><vers num="10.3.7"/><vers num="10.3.8"/><vers num="10.3.9"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1431" published="2005-05-03" seq="2005-1431" severity="Medium" type="CVE"><desc><descript source="cve">The &quot;record packet parsing&quot; in GnuTLS 1.2 before 1.2.3 and 1.0 before 1.0.25 allows remote attackers to cause a denial of service, possibly related to padding bytes in gnutils_cipher.c.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/><exception/></vuln_types><range><network/></range><refs><ref source="MLIST" url="http://lists.gnupg.org/pipermail/gnutls-dev/2005-April/000858.html">[gnutls-dev] 20050428 GnuTLS 1.2.3 and 1.0.25 </ref><ref source="OSVDB" url="http://www.osvdb.org/16054">16054</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013861">1013861</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15193">15193</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20328">gnutls-record-parsing-dos(20328)</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-430.html">RHSA-2005:430</ref></refs><vuln_soft><prod name="GnuTLS" vendor="GNU"><vers num="1.2.0"/><vers num="1.2.1"/><vers num="1.2.2"/><vers num="1.0.18"/><vers num="1.0.19"/><vers num="1.0.20"/><vers num="1.0.21"/><vers num="1.0.22"/><vers num="1.0.23"/><vers num="1.0.24"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1433" published="2005-05-03" seq="2005-1433" severity="Medium" type="CVE"><desc><descript source="cve">Multiple unknown vulnjerabilities HP OpenView Event Correlation Services (OV ECS) 3.32 and 3.33 allow attackers to cause a denial of service or execute arbitrary code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><range><local/></range><refs><ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBMA01141">HPSBMA01141</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/15226">15226</ref></refs><vuln_soft><prod name="OpenView Event Correlation Services" vendor="HP"><vers num="3.3"/><vers num="3.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1434" published="2005-05-03" seq="2005-1434" severity="High" type="CVE"><desc><descript source="cve">Multiple unknown vulnerabilities in OpenView Network Node Manager (OV NNM) 6.2, 6.4, 7.01, and 7.50 allow attackers to cause a denial of service or execute arbitrary code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><range><network/></range><refs><ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBMA01140">HPSBMA01140</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/15223">15223</ref></refs><vuln_soft><prod name="OpenView Network Node Manager" vendor="HP"><vers num="6.2"/><vers num="6.4"/><vers num="7.01"/><vers num="7.50"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1435" published="2005-05-03" seq="2005-1435" severity="High" type="CVE"><desc><descript source="cve">Open WebMail (OWM) before 2.51 20050430 allows remote authenticated users to execute arbitrary commands via shell metacharacters in a filename.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="CONFIRM" url="http://sourceforge.net/forum/message.php?msg_id=3128678">http://sourceforge.net/forum/message.php?msg_id=3128678</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1013859">1013859</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/15225">15225</ref></refs><vuln_soft><prod name="Open WebMail" vendor="Open WebMail"><vers num="2.51" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1436" published="2005-05-03" seq="2005-1436" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in osTicket allow remote attackers to inject arbitrary web script or HTML via (1) the t parameter to view.php, (2) the osticket_title parameter to header.php, (3) the em parameter to admin_login.php, (4) the e parameter to user_login.php, (5) the err parameter to open_submit.php, or (6) the name and subject fields when adding a ticket.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MISC" url="http://www.gulftech.org/?node=research&amp;article_id=00071-05022005">http://www.gulftech.org/?node=research&amp;article_id=00071-05022005</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15216">15216</ref><ref patch="1" source="osTicket" url="http://www.osticket.com/downloads.php">Downloads</ref><ref source="OSVDB" url="http://www.osvdb.org/16270">16270</ref><ref source="OSVDB" url="http://www.osvdb.org/16271">16271</ref><ref source="OSVDB" url="http://www.osvdb.org/16272">16272</ref><ref source="OSVDB" url="http://www.osvdb.org/16273">16273</ref><ref source="OSVDB" url="http://www.osvdb.org/16274">16274</ref></refs><vuln_soft><prod name="osTicket" vendor="osTicket"><vers num="1.3.0"/><vers num="1.2.7"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1437" published="2005-05-03" seq="2005-1437" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in osTicket allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to admin.php or (2) cat parameter to view.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MISC" url="http://www.gulftech.org/?node=research&amp;article_id=00071-05022005">http://www.gulftech.org/?node=research&amp;article_id=00071-05022005</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15216">15216</ref><ref source="OSVDB" url="http://www.osvdb.org/16277">16277</ref></refs><vuln_soft><prod name="osTicket" vendor="osTicket"><vers num="1.x"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-28" name="CVE-2005-1438" published="2005-05-03" seq="2005-1438" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in main.php in osTicket allows remote attackers to execute arbitrary PHP code via the include_dir parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MISC" url="http://www.gulftech.org/?node=research&amp;article_id=00071-05022005">http://www.gulftech.org/?node=research&amp;article_id=00071-05022005</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15216">15216</ref><ref source="OSVDB" url="http://www.osvdb.org/16278">16278</ref></refs><vuln_soft><prod name="osTicket" vendor="osTicket"><vers num="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1439" published="2005-05-03" seq="2005-1439" severity="High" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in attachments.php in osTicket allows remote attackers to read arbitrary files via .. sequences in the file parameter.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MISC" url="http://www.gulftech.org/?node=research&amp;article_id=00071-05022005">http://www.gulftech.org/?node=research&amp;article_id=00071-05022005</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15216">15216</ref><ref source="OSVDB" url="http://www.osvdb.org/16279">16279</ref></refs><vuln_soft><prod name="osTicket" vendor="osTicket"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1440" published="2005-05-03" seq="2005-1440" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in ViArt Shop Enterprise 2.1.6 allow remote attackers to inject arbitrary web script or HTML via (1) various parameters to basket.php, (2) the nickname, email, topic, and message fields in forum.php, as demonstrated using forum_new_thread.php and forum_thread.php, (3) the page parameter to page.php, (4) category_id and item_id parameters to reviews.php, (5) the category_id parameter to product_details.php, (6) the category_id or search_string parameters to products.php, or (7) the rp or page parameters to news_view.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MISC" url="http://lostmon.blogspot.com/2005/04/viart-shop-enterprise-multiple.html">http://lostmon.blogspot.com/2005/04/viart-shop-enterprise-multiple.html</ref><ref source="BID" url="http://www.securityfocus.com/bid/13462">13462</ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/15951">15951</ref><ref source="OSVDB" url="http://www.osvdb.org/15952">15952</ref><ref source="OSVDB" url="http://www.osvdb.org/15953">15953</ref><ref source="OSVDB" url="http://www.osvdb.org/15954">15954</ref><ref source="OSVDB" url="http://www.osvdb.org/15955">15955</ref><ref source="OSVDB" url="http://www.osvdb.org/15956">15956</ref><ref source="OSVDB" url="http://www.osvdb.org/15957">15957</ref><ref source="OSVDB" url="http://www.osvdb.org/15958">15958</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013853">1013853</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15181">15181</ref></refs><vuln_soft><prod name="ViArt Shop Enterprise" vendor="CodetoSell"><vers num="2.1.6"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1441" published="2005-05-03" seq="2005-1441" severity="Medium" type="CVE"><desc><descript source="cve">Format string vulnerability in Lotus Domino 6.0.x before 6.0.5 and 6.5.x before 6.5.4 allows remote attackers to cause a denial of service via the Notes protocol (NRPC).</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="CONFIRM" url="http://www-1.ibm.com/support/docview.wss?rs=463&amp;uid=swg21202525">http://www-1.ibm.com/support/docview.wss?rs=463&amp;uid=swg21202525</ref><ref source="BID" url="http://www.securityfocus.com/bid/13446">13446</ref><ref source="OSVDB" url="http://www.osvdb.org/15366">15366</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013842">1013842</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14879">14879</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20043">lotus-nrpc-format-string(20043)</ref></refs><vuln_soft><prod name="Lotus Domino" vendor="IBM"><vers num="6.0"/><vers num="6.0.1"/><vers num="6.0.2 CF2"/><vers num="6.0.2"/><vers num="6.0.3"/><vers num="6.5.0"/><vers num="6.5.1"/><vers num="6.5.2"/><vers num="6.5.3"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1442" published="2005-05-03" seq="2005-1442" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in the Lotus Notes client for Domino 6.5 before 6.5.4 and 6.0 before 6.0.5 allows local users to cause a denial of service (client crash) and possibly execute arbitrary code via the NOTES.INI file.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input bound="1"/></vuln_types><range><local/></range><refs><ref patch="1" source="CONFIRM" url="http://www-1.ibm.com/support/docview.wss?rs=463&amp;uid=swg21202526">http://www-1.ibm.com/support/docview.wss?rs=463&amp;uid=swg21202526</ref><ref source="BID" url="http://www.securityfocus.com/bid/13447">13447</ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/15367">15367</ref><ref source="SECUNIA" url="http://secunia.com/advisories/1013841">1013841</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20044">lotus-notesini-bo(20044)</ref></refs><vuln_soft><prod name="Lotus Notes" vendor="IBM"><vers num="6.0"/><vers num="6.0.1"/><vers num="6.0.2"/><vers num="6.0.3"/><vers num="6.0.4"/><vers num="6.5"/><vers num="6.5.1"/><vers num="6.5.2"/><vers num="6.5.3"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1443" published="2005-05-03" seq="2005-1443" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in index.php for Invision Power Board (IPB) 2.0.3 and 2.1 Alpha 2 allows remote attackers to inject arbitrary web script or HTML via the (1) act, (2) Members, (3) calendar, or (4) HID parameters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="SECTRACK" url="http://securitytracker.com/id?1013863">1013863</ref></refs><vuln_soft><prod name="Invision Power Board" vendor="Invision Power Services"><vers num="2.0.3"/><vers num="2.1 Alpha2"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1444" published="2005-05-03" seq="2005-1444" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in SitePanel 2.6.1 and earlier (SitePanel2) allows remote attackers to inject arbitrary web script or HTML via (1) the v, show, or sec_name parameters to main.php, (2) the inadmin, newsev, or postid parameters to 5.php, or (3) the id parameter to 0.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="MISC" url="http://www.gulftech.org/?node=research&amp;article_id=00072-05032005">http://www.gulftech.org/?node=research&amp;article_id=00072-05032005</ref><ref source="MISC" url="http://forum.sitepanel2.com/index.php?showtopic=271">http://forum.sitepanel2.com/index.php?showtopic=271</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/15213">15213</ref><ref source="OSVDB" url="http://www.osvdb.org/16262">16262</ref><ref source="OSVDB" url="http://www.osvdb.org/16263">16263</ref><ref source="OSVDB" url="http://www.osvdb.org/16264">16264</ref></refs><vuln_soft><prod name="SitePanel" vendor="SitePanel"><vers num="2.6.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1445" published="2005-05-03" seq="2005-1445" severity="Medium" type="CVE"><desc><descript source="cve">Multiple directory traversal vulnerabilities in SitePanel 2.6.1 and earlier (SitePanel2) allows remote attackers to (1) delete arbitrary files via the id parameter in a rmattach action to 5.php, or (2) read arbitrary files via the lang parameter to index.php.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="MISC" url="http://www.gulftech.org/?node=research&amp;article_id=00072-05032005">http://www.gulftech.org/?node=research&amp;article_id=00072-05032005</ref><ref source="MISC" url="http://forum.sitepanel2.com/index.php?showtopic=271">http://forum.sitepanel2.com/index.php?showtopic=271</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/15213">15213</ref><ref source="OSVDB" url="http://www.osvdb.org/16266">16266</ref></refs><vuln_soft><prod name="SitePanel" vendor="SitePanel"><vers num="2.6.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1446" published="2005-05-03" seq="2005-1446" severity="High" type="CVE"><desc><descript source="cve">SitePanel 2.6.1 and earlier (SitePanel2) allows remote attackers to upload and execute arbitrary files such as PHP scripts via an attachment to a trouble ticket.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="MISC" url="http://www.gulftech.org/?node=research&amp;article_id=00072-05032005">http://www.gulftech.org/?node=research&amp;article_id=00072-05032005</ref><ref source="MISC" url="http://forum.sitepanel2.com/index.php?showtopic=271">http://forum.sitepanel2.com/index.php?showtopic=271</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/15213">15213</ref></refs><vuln_soft><prod name="SitePanel" vendor="SitePanel"><vers num="2.6.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-28" name="CVE-2005-1447" published="2005-05-03" seq="2005-1447" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in main.php in SitePanel 2.6.1 and earlier (SitePanel2) allows remote attackers to execute arbitrary PHP code via the p parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="MISC" url="http://www.gulftech.org/?node=research&amp;article_id=00072-05032005">http://www.gulftech.org/?node=research&amp;article_id=00072-05032005</ref><ref source="MISC" url="http://forum.sitepanel2.com/index.php?showtopic=271">http://forum.sitepanel2.com/index.php?showtopic=271</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/15213">15213</ref><ref source="OSVDB" url="http://www.osvdb.org/16268">16268</ref></refs><vuln_soft><prod name="SitePanel" vendor="SitePanel"><vers num="2.6.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1448" published="2005-05-03" seq="2005-1448" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in the BBCode plugin for Serendipity before 0.8 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="CONFIRM" url="http://www.s9y.org/63.html#A9">http://www.s9y.org/63.html#A9</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/13411">13411</ref><ref patch="1" source="OSVDB" url="http://www.osvdb.org/15876">15876</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/15145">15145</ref></refs><vuln_soft><prod name="Serendipity" vendor="S9Y"><vers num="0.7 rc1"/><vers num="0.7 Beta4"/><vers num="0.7 Beta2"/><vers num="0.7 beta3"/><vers num="0.7 beta1"/><vers num="0.7"/><vers num="0.7.1"/><vers num="0.8 Beta6"/><vers num="0.8 Beta5"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1449" published="2005-05-03" seq="2005-1449" severity="High" type="CVE"><desc><descript source="cve">Unknown vulnerability in serendipity_config_local.inc.php for Serendipity before 0.8 has unknown impact.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref patch="1" source="CONFIRM" url="http://www.s9y.org/63.html#A9">http://www.s9y.org/63.html#A9</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/15145">15145</ref></refs><vuln_soft><prod name="Serendipity" vendor="S9Y"><vers num="0.7 rc1"/><vers num="0.7 Beta4"/><vers num="0.7 Beta2"/><vers num="0.7 beta3"/><vers num="0.7 beta1"/><vers num="0.7"/><vers num="0.7.1"/><vers num="0.8 Beta6"/><vers num="0.8 Beta5"/><vers num="0.6 pl3"/><vers num="0.5 pl1"/><vers num="0.4"/><vers num="0.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1450" published="2005-05-03" seq="2005-1450" severity="High" type="CVE"><desc><descript source="cve">Unknown vulnerability in &quot;the function used to validate path-names for uploading media&quot; in Serendipity before 0.8 has unknown impact.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="CONFIRM" url="http://www.s9y.org/63.html#A9">http://www.s9y.org/63.html#A9</ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/15877">15877</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/15145">15145</ref></refs><vuln_soft><prod name="Serendipity" vendor="S9Y"><vers num="0.7.1"/><vers num="0.7"/><vers num="0.6 pl3"/><vers num="0.5 pl1"/><vers num="0.4"/><vers num="0.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1451" published="2005-05-03" seq="2005-1451" severity="High" type="CVE"><desc><descript source="cve">The media manager in Serendipity before 0.8 allows remote attackers to upload and execute arbitrary (1) .php or (2) .shtml files.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="CONFIRM" url="http://www.s9y.org/63.html#A9">http://www.s9y.org/63.html#A9</ref><ref source="OSVDB" url="http://www.osvdb.org/15878">15878</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/15145">15145</ref></refs><vuln_soft><prod name="Serendipity" vendor="S9Y"><vers num="0.8 Beta 6"/><vers num="0.8 Beta 5"/><vers num="0.7.1"/><vers num="0.7 rc1"/><vers num="0.7 Beta4"/><vers num="0.7 beta3"/><vers num="0.7 Beta2"/><vers num="0.7 beta1"/><vers num="0.7"/><vers num="0.6 pl3"/><vers num="0.5 pl1"/><vers num="0.4"/><vers num="0.3"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1452" published="2005-05-03" seq="2005-1452" severity="High" type="CVE"><desc><descript source="cve">Serendipity before 0.8 allows Chief users to &quot;hide plugins installed by other users.&quot;</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref patch="1" source="CONFIRM" url="http://www.s9y.org/63.html#A9">http://www.s9y.org/63.html#A9</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15145">15145</ref></refs><vuln_soft><prod name="Serendipity" vendor="S9Y"><vers num="0.7.1"/><vers num="0.7"/><vers num="0.6 pl3"/><vers num="0.5 pl1"/><vers num="0.4"/><vers num="0.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1453" published="2005-05-05" seq="2005-1453" severity="Medium" type="CVE"><desc><descript source="cve">fetchnews in leafnode 1.9.48 to 1.11.1 allows remote NNTP servers to cause a denial of service (crash) by closing the connection while fetchnews is reading (1) an article header or (2) an article body, which also prevents fetchnews from querying other servers.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref patch="1" source="CONFIRM" url="http://leafnode.sourceforge.net/leafnode-SA-2005-01.txt">http://leafnode.sourceforge.net/leafnode-SA-2005-01.txt</ref><ref patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/0468">ADV-2005-0468</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/15252">15252</ref></refs><vuln_soft><prod name="Leafnode" vendor="Leafnode"><vers num="1.9.48"/><vers num="1.9.52"/><vers num="1.9.53"/><vers num="1.10.0"/><vers num="1.11.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1454" published="2005-05-19" seq="2005-1454" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in the radius_xlat function in the SQL module for FreeRADIUS 1.0.2 and earlier allows remote authenticated users to execute arbitrary SQL commands via (1) group_membership_query, (2) simul_count_query, or (3) simul_verify_query configuration entries.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200505-13.xml">GLSA-200505-13</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/13540">13540</ref><ref source="SECTRACK" url="http://www.securitytracker.com/alerts/2005/May/1013909.html">1013909</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20449">freeradius-xlat-sql-injection(20449)</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_14_sr.html">SUSE-SR:2005:014</ref><ref source="FULLDISC" url="http://www.derkeiler.com/Mailing-Lists/Full-Disclosure/2005-05/0492.html">20050520 ERRATA: [ GLSA 200505-13 ] FreeRADIUS: SQL injection and Denial of Service vulnerability</ref><ref source="" url="http://www.freeradius.org/security.html">http://www.freeradius.org/security.html</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-524.html">RHSA-2005:524</ref></refs><vuln_soft><prod name="FreeRADIUS" vendor="FreeRADIUS"><vers num="1.0.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1455" published="2005-05-19" seq="2005-1455" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the sql_escape_func function in the SQL module for FreeRADIUS 1.0.2 and earlier allows remote attackers to cause a denial of service (crash).</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200505-13.xml">GLSA-200505-13</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/13541">13541</ref><ref source="SECTRACK" url="http://www.securitytracker.com/alerts/2005/May/1013909.html">1013909</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20450">freeradius-sqlescapefunc-bo(20450)</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_14_sr.html">SUSE-SR:2005:014</ref><ref source="FULLDISC" url="http://www.derkeiler.com/Mailing-Lists/Full-Disclosure/2005-05/0492.html">20050520 ERRATA: [ GLSA 200505-13 ] FreeRADIUS: SQL injection and Denial of Service vulnerability</ref><ref source="" url="http://www.freeradius.org/security.html">http://www.freeradius.org/security.html</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-524.html">RHSA-2005:524</ref></refs><vuln_soft><prod name="FreeRADIUS" vendor="FreeRADIUS"><vers num="1.0.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1456" published="2005-05-05" seq="2005-1456" severity="Medium" type="CVE"><desc><descript source="cve">Multiple unknown vulnerabilities in the (1) DHCP and (2) Telnet dissectors in Ethereal before 0.10.11 allow remote attackers to cause a denial of service (abort).</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/><design/></vuln_types><range><network/></range><refs><ref adv="1" source="CONFIRM" url="http://www.ethereal.com/appnotes/enpa-sa-00019.html">http://www.ethereal.com/appnotes/enpa-sa-00019.html</ref><ref source="CONFIRM" url="http://www.ethereal.com/news/item_20050504_01.html">http://www.ethereal.com/news/item_20050504_01.html</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00003.html">FLSA-2006:152922</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-427.html">RHSA-2005:427</ref><ref source="BID" url="http://www.securityfocus.com/bid/13504">13504</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000963">CLSA-2005:963</ref></refs><vuln_soft><prod name="Ethereal" vendor="Ethereal Group"><vers num="0.8"/><vers num="0.8.13"/><vers num="0.8.14"/><vers num="0.8.15"/><vers num="0.8.18"/><vers num="0.8.19"/><vers num="0.9"/><vers num="0.9.1"/><vers num="0.9.2"/><vers num="0.9.3"/><vers num="0.9.4"/><vers num="0.9.5"/><vers num="0.9.6"/><vers num="0.9.7"/><vers num="0.9.8"/><vers num="0.9.9"/><vers num="0.9.10"/><vers num="0.9.11"/><vers num="0.9.12"/><vers num="0.9.13"/><vers num="0.9.14"/><vers num="0.9.15"/><vers num="0.9.16"/><vers num="0.10"/><vers num="0.10.1"/><vers num="0.10.2"/><vers num="0.10.3"/><vers num="0.10.4"/><vers num="0.10.5"/><vers num="0.10.6"/><vers num="0.10.7"/><vers num="0.10.8"/><vers num="0.10.9"/><vers num="0.10.10"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1457" published="2005-05-05" seq="2005-1457" severity="Medium" type="CVE"><desc><descript source="cve">Multiple unknown vulnerabilities in the (1) AIM, (2) LDAP, (3) FibreChannel, (4) GSM_MAP, (5) SRVLOC, and (6) NTLMSSP dissectors in Ethereal before 0.10.11 allow remote attackers to cause a denial of service (crash).</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CONFIRM" url="http://www.ethereal.com/appnotes/enpa-sa-00019.html">http://www.ethereal.com/appnotes/enpa-sa-00019.html</ref><ref adv="1" source="CONFIRM" url="http://www.ethereal.com/news/item_20050504_01.html">http://www.ethereal.com/news/item_20050504_01.html</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00003.html">FLSA-2006:152922</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-427.html">RHSA-2005:427</ref><ref source="BID" url="http://www.securityfocus.com/bid/13504">13504</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000963">CLSA-2005:963</ref></refs><vuln_soft><prod name="Ethereal" vendor="Ethereal Group"><vers num="0.8"/><vers num="0.8.13"/><vers num="0.8.14"/><vers num="0.8.15"/><vers num="0.8.18"/><vers num="0.8.19"/><vers num="0.9"/><vers num="0.9.1"/><vers num="0.9.2"/><vers num="0.9.3"/><vers num="0.9.4"/><vers num="0.9.5"/><vers num="0.9.6"/><vers num="0.9.7"/><vers num="0.9.8"/><vers num="0.9.9"/><vers num="0.9.10"/><vers num="0.9.11"/><vers num="0.9.12"/><vers num="0.9.13"/><vers num="0.9.14"/><vers num="0.9.15"/><vers num="0.9.16"/><vers num="0.10"/><vers num="0.10.1"/><vers num="0.10.2"/><vers num="0.10.3"/><vers num="0.10.4"/><vers num="0.10.5"/><vers num="0.10.6"/><vers num="0.10.7"/><vers num="0.10.8"/><vers num="0.10.9"/><vers num="0.10.10"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1458" published="2005-05-05" seq="2005-1458" severity="Medium" type="CVE"><desc><descript source="cve">Multiple unknown &quot;other problems&quot; in the KINK dissector in Ethereal before 0.10.11 have unknown impact and attack vectors.</descript></desc><loss_types><avail/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CONFIRM" url="http://www.ethereal.com/appnotes/enpa-sa-00019.html">http://www.ethereal.com/appnotes/enpa-sa-00019.html</ref><ref adv="1" patch="1" source="CONFIRM" url="http://www.ethereal.com/news/item_20050504_01.html">http://www.ethereal.com/news/item_20050504_01.html</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00003.html">FLSA-2006:152922</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-427.html">RHSA-2005:427</ref><ref source="BID" url="http://www.securityfocus.com/bid/13504">13504</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000963">CLSA-2005:963</ref></refs><vuln_soft><prod name="Ethereal" vendor="Ethereal Group"><vers num="0.8"/><vers num="0.8.13"/><vers num="0.8.14"/><vers num="0.8.15"/><vers num="0.8.18"/><vers num="0.8.19"/><vers num="0.9"/><vers num="0.9.1"/><vers num="0.9.2"/><vers num="0.9.3"/><vers num="0.9.4"/><vers num="0.9.5"/><vers num="0.9.6"/><vers num="0.9.7"/><vers num="0.9.8"/><vers num="0.9.9"/><vers num="0.9.10"/><vers num="0.9.11"/><vers num="0.9.12"/><vers num="0.9.13"/><vers num="0.9.14"/><vers num="0.9.15"/><vers num="0.9.16"/><vers num="0.10"/><vers num="0.10.1"/><vers num="0.10.2"/><vers num="0.10.3"/><vers num="0.10.4"/><vers num="0.10.5"/><vers num="0.10.6"/><vers num="0.10.7"/><vers num="0.10.8"/><vers num="0.10.9"/><vers num="0.10.10"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1459" published="2005-05-05" seq="2005-1459" severity="Medium" type="CVE"><desc><descript source="cve">Multiple unknown vulnerabilities in the (1) WSP, (2) BER, (3) SMB, (4) NDPS, (5) IAX2, (6) RADIUS, (7) TCAP, (8) MRDISC, (9) 802.3 Slow, (10) SMBMailslot, or (11) SMB PIPE dissectors in Ethereal before 0.10.11 allow remote attackers to cause a denial of service (assert error).</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CONFIRM" url="http://www.ethereal.com/appnotes/enpa-sa-00019.html">http://www.ethereal.com/appnotes/enpa-sa-00019.html</ref><ref adv="1" patch="1" source="CONFIRM" url="http://www.ethereal.com/news/item_20050504_01.html">http://www.ethereal.com/news/item_20050504_01.html</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00003.html">FLSA-2006:152922</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-427.html">RHSA-2005:427</ref><ref source="BID" url="http://www.securityfocus.com/bid/13504">13504</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000963">CLSA-2005:963</ref></refs><vuln_soft><prod name="Ethereal" vendor="Ethereal Group"><vers num="0.8"/><vers num="0.8.13"/><vers num="0.8.14"/><vers num="0.8.15"/><vers num="0.8.18"/><vers num="0.8.19"/><vers num="0.9"/><vers num="0.9.1"/><vers num="0.9.2"/><vers num="0.9.3"/><vers num="0.9.4"/><vers num="0.9.5"/><vers num="0.9.6"/><vers num="0.9.7"/><vers num="0.9.8"/><vers num="0.9.9"/><vers num="0.9.10"/><vers num="0.9.11"/><vers num="0.9.12"/><vers num="0.9.13"/><vers num="0.9.14"/><vers num="0.9.15"/><vers num="0.9.16"/><vers num="0.10"/><vers num="0.10.1"/><vers num="0.10.2"/><vers num="0.10.3"/><vers num="0.10.4"/><vers num="0.10.5"/><vers num="0.10.6"/><vers num="0.10.7"/><vers num="0.10.8"/><vers num="0.10.9"/><vers num="0.10.10"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1460" published="2005-05-05" seq="2005-1460" severity="Medium" type="CVE"><desc><descript source="cve">Multiple unknown dissectors in Ethereal before 0.10.11 allow remote attackers to cause a denial of service (assert error) via an invalid protocol tree item length.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CONFIRM" url="http://www.ethereal.com/appnotes/enpa-sa-00019.html">http://www.ethereal.com/appnotes/enpa-sa-00019.html</ref><ref adv="1" patch="1" source="CONFIRM" url="http://www.ethereal.com/news/item_20050504_01.html">http://www.ethereal.com/news/item_20050504_01.html</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00003.html">FLSA-2006:152922</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-427.html">RHSA-2005:427</ref><ref source="BID" url="http://www.securityfocus.com/bid/13504">13504</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000963">CLSA-2005:963</ref></refs><vuln_soft><prod name="Ethereal" vendor="Ethereal Group"><vers num="0.8"/><vers num="0.8.13"/><vers num="0.8.14"/><vers num="0.8.15"/><vers num="0.8.18"/><vers num="0.8.19"/><vers num="0.9"/><vers num="0.9.1"/><vers num="0.9.2"/><vers num="0.9.3"/><vers num="0.9.4"/><vers num="0.9.5"/><vers num="0.9.6"/><vers num="0.9.7"/><vers num="0.9.8"/><vers num="0.9.9"/><vers num="0.9.10"/><vers num="0.9.11"/><vers num="0.9.12"/><vers num="0.9.13"/><vers num="0.9.14"/><vers num="0.9.15"/><vers num="0.9.16"/><vers num="0.10"/><vers num="0.10.1"/><vers num="0.10.2"/><vers num="0.10.3"/><vers num="0.10.4"/><vers num="0.10.5"/><vers num="0.10.6"/><vers num="0.10.7"/><vers num="0.10.8"/><vers num="0.10.9"/><vers num="0.10.10"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1461" published="2005-05-05" seq="2005-1461" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in the (1) SIP, (2) CMIP, (3) CMP, (4) CMS, (5) CRMF, (6) ESS, (7) OCSP, (8) X.509, (9) ISIS, (10) DISTCC, (11) FCELS, (12) Q.931, (13) NCP, (14) TCAP, (15) ISUP, (16) MEGACO, (17) PKIX1Explitit, (18) PKIX_Qualified, (19) Presentation dissectors in Ethereal before 0.10.11 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="CONFIRM" url="http://www.ethereal.com/appnotes/enpa-sa-00019.html">http://www.ethereal.com/appnotes/enpa-sa-00019.html</ref><ref source="CONFIRM" url="http://www.ethereal.com/news/item_20050504_01.html">http://www.ethereal.com/news/item_20050504_01.html</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00003.html">FLSA-2006:152922</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-427.html">RHSA-2005:427</ref><ref source="BID" url="http://www.securityfocus.com/bid/13504">13504</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000963">CLSA-2005:963</ref></refs><vuln_soft><prod name="Ethereal" vendor="Ethereal Group"><vers num="0.9.9"/><vers num="0.9.8"/><vers num="0.9.7"/><vers num="0.9.6"/><vers num="0.9.5"/><vers num="0.9.4"/><vers num="0.9.3"/><vers num="0.9.2"/><vers num="0.9.16"/><vers num="0.9.15"/><vers num="0.9.14"/><vers num="0.9.13"/><vers num="0.9.12"/><vers num="0.9.11"/><vers num="0.9.10"/><vers num="0.9.1"/><vers num="0.9"/><vers num="0.8.19"/><vers num="0.8.18"/><vers num="0.8.15"/><vers num="0.8.14"/><vers num="0.8.13"/><vers num="0.8"/><vers num="0.10.9"/><vers num="0.10.8"/><vers num="0.10.7"/><vers num="0.10.6"/><vers num="0.10.5"/><vers num="0.10.4"/><vers num="0.10.3"/><vers num="0.10.2"/><vers num="0.10.10"/><vers num="0.10.1"/><vers num="0.10.0"/><vers num="0.10"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-02-26" name="CVE-2005-1462" published="2005-05-05" seq="2005-1462" severity="High" type="CVE"><desc><descript source="cve">Double free vulnerability in the ICEP dissector in Ethereal before 0.10.11 may allow remote attackers to execute arbitrary code.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CONFIRM" url="http://www.ethereal.com/appnotes/enpa-sa-00019.html">http://www.ethereal.com/appnotes/enpa-sa-00019.html</ref><ref adv="1" patch="1" source="CONFIRM" url="http://www.ethereal.com/news/item_20050504_01.html">http://www.ethereal.com/news/item_20050504_01.html</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00003.html">FLSA-2006:152922</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-427.html">RHSA-2005:427</ref><ref source="BID" url="http://www.securityfocus.com/bid/13504">13504</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000963">CLSA-2005:963</ref></refs><vuln_soft><prod name="Ethereal" vendor="Ethereal Group"><vers num="0.8"/><vers num="0.8.13"/><vers num="0.8.14"/><vers num="0.8.15"/><vers num="0.8.18"/><vers num="0.8.19"/><vers num="0.9"/><vers num="0.9.1"/><vers num="0.9.2"/><vers num="0.9.3"/><vers num="0.9.4"/><vers num="0.9.5"/><vers num="0.9.6"/><vers num="0.9.7"/><vers num="0.9.8"/><vers num="0.9.9"/><vers num="0.9.10"/><vers num="0.9.11"/><vers num="0.9.12"/><vers num="0.9.13"/><vers num="0.9.14"/><vers num="0.9.15"/><vers num="0.9.16"/><vers num="0.10"/><vers num="0.10.1"/><vers num="0.10.2"/><vers num="0.10.3"/><vers num="0.10.4"/><vers num="0.10.5"/><vers num="0.10.6"/><vers num="0.10.7"/><vers num="0.10.8"/><vers num="0.10.9"/><vers num="0.10.10"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1463" published="2005-05-05" seq="2005-1463" severity="High" type="CVE"><desc><descript source="cve">Multiple format string vulnerabilities in the (1) DHCP and (2) ANSI A dissectors in Ethereal before 0.10.11 may allow remote attackers to execute arbitrary code.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CONFIRM" url="http://www.ethereal.com/appnotes/enpa-sa-00019.html">http://www.ethereal.com/appnotes/enpa-sa-00019.html</ref><ref adv="1" patch="1" source="CONFIRM" url="http://www.ethereal.com/news/item_20050504_01.html">http://www.ethereal.com/news/item_20050504_01.html</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00003.html">FLSA-2006:152922</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-427.html">RHSA-2005:427</ref><ref source="BID" url="http://www.securityfocus.com/bid/13504">13504</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000963">CLSA-2005:963</ref></refs><vuln_soft><prod name="Ethereal" vendor="Ethereal Group"><vers num="0.8"/><vers num="0.8.13"/><vers num="0.8.14"/><vers num="0.8.15"/><vers num="0.8.18"/><vers num="0.8.19"/><vers num="0.9"/><vers num="0.9.1"/><vers num="0.9.2"/><vers num="0.9.3"/><vers num="0.9.4"/><vers num="0.9.5"/><vers num="0.9.6"/><vers num="0.9.7"/><vers num="0.9.8"/><vers num="0.9.9"/><vers num="0.9.10"/><vers num="0.9.11"/><vers num="0.9.12"/><vers num="0.9.13"/><vers num="0.9.14"/><vers num="0.9.15"/><vers num="0.9.16"/><vers num="0.10"/><vers num="0.10.1"/><vers num="0.10.2"/><vers num="0.10.3"/><vers num="0.10.4"/><vers num="0.10.5"/><vers num="0.10.6"/><vers num="0.10.7"/><vers num="0.10.8"/><vers num="0.10.9"/><vers num="0.10.10"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1464" published="2005-05-05" seq="2005-1464" severity="Medium" type="CVE"><desc><descript source="cve">Multiple unknown vulnerabilities in the (1) KINK, (2) L2TP, (3) MGCP, (4) EIGRP, (5) DLSw, (6) MEGACO, (7) LMP, and (8) RSVP dissectors in Ethereal before 0.10.11 allow remote attackers to cause a denial of service (infinite loop).</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="CONFIRM" url="http://www.ethereal.com/appnotes/enpa-sa-00019.html">http://www.ethereal.com/appnotes/enpa-sa-00019.html</ref><ref source="CONFIRM" url="http://www.ethereal.com/news/item_20050504_01.html">http://www.ethereal.com/news/item_20050504_01.html</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00003.html">FLSA-2006:152922</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-427.html">RHSA-2005:427</ref><ref source="BID" url="http://www.securityfocus.com/bid/13504">13504</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000963">CLSA-2005:963</ref></refs><vuln_soft><prod name="Ethereal" vendor="Ethereal Group"><vers num="0.9.9"/><vers num="0.9.8"/><vers num="0.9.7"/><vers num="0.9.6"/><vers num="0.9.5"/><vers num="0.9.4"/><vers num="0.9.3"/><vers num="0.9.2"/><vers num="0.9.16"/><vers num="0.9.15"/><vers num="0.9.14"/><vers num="0.9.13"/><vers num="0.9.12"/><vers num="0.9.11"/><vers num="0.9.10"/><vers num="0.9.1"/><vers num="0.9"/><vers num="0.8.19"/><vers num="0.8.18"/><vers num="0.8.15"/><vers num="0.8.14"/><vers num="0.8.13"/><vers num="0.8"/><vers num="0.10.9"/><vers num="0.10.8"/><vers num="0.10.7"/><vers num="0.10.6"/><vers num="0.10.5"/><vers num="0.10.4"/><vers num="0.10.3"/><vers num="0.10.2"/><vers num="0.10.10"/><vers num="0.10.1"/><vers num="0.10.0"/><vers num="0.10"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1465" published="2005-05-05" seq="2005-1465" severity="Medium" type="CVE"><desc><descript source="cve">Unknown vulnerability in the NCP dissector in Ethereal before 0.10.11 allow remote attackers to cause a denial of service (long loop).</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CONFIRM" url="http://www.ethereal.com/appnotes/enpa-sa-00019.html">http://www.ethereal.com/appnotes/enpa-sa-00019.html</ref><ref adv="1" patch="1" source="CONFIRM" url="http://www.ethereal.com/news/item_20050504_01.html">http://www.ethereal.com/news/item_20050504_01.html</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00003.html">FLSA-2006:152922</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-427.html">RHSA-2005:427</ref><ref source="BID" url="http://www.securityfocus.com/bid/13504">13504</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000963">CLSA-2005:963</ref></refs><vuln_soft><prod name="Ethereal" vendor="Ethereal Group"><vers num="0.8"/><vers num="0.8.13"/><vers num="0.8.14"/><vers num="0.8.15"/><vers num="0.8.18"/><vers num="0.8.19"/><vers num="0.9"/><vers num="0.9.1"/><vers num="0.9.2"/><vers num="0.9.3"/><vers num="0.9.4"/><vers num="0.9.5"/><vers num="0.9.6"/><vers num="0.9.7"/><vers num="0.9.8"/><vers num="0.9.9"/><vers num="0.9.10"/><vers num="0.9.11"/><vers num="0.9.12"/><vers num="0.9.13"/><vers num="0.9.14"/><vers num="0.9.15"/><vers num="0.9.16"/><vers num="0.10"/><vers num="0.10.1"/><vers num="0.10.2"/><vers num="0.10.3"/><vers num="0.10.4"/><vers num="0.10.5"/><vers num="0.10.6"/><vers num="0.10.7"/><vers num="0.10.8"/><vers num="0.10.9"/><vers num="0.10.10"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1466" published="2005-05-05" seq="2005-1466" severity="Medium" type="CVE"><desc><descript source="cve">Unknown vulnerability in the DICOM dissector in Ethereal before 0.10.11 allows remote attackers to cause a denial of service (large memory allocation) via unknown vectors.</descript></desc><loss_types><avail/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CONFIRM" url="http://www.ethereal.com/appnotes/enpa-sa-00019.html">http://www.ethereal.com/appnotes/enpa-sa-00019.html</ref><ref adv="1" patch="1" source="CONFIRM" url="http://www.ethereal.com/news/item_20050504_01.html">http://www.ethereal.com/news/item_20050504_01.html</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00003.html">FLSA-2006:152922</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-427.html">RHSA-2005:427</ref><ref source="BID" url="http://www.securityfocus.com/bid/13504">13504</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000963">CLSA-2005:963</ref></refs><vuln_soft><prod name="Ethereal" vendor="Ethereal Group"><vers num="0.8"/><vers num="0.8.13"/><vers num="0.8.14"/><vers num="0.8.15"/><vers num="0.8.18"/><vers num="0.8.19"/><vers num="0.9"/><vers num="0.9.1"/><vers num="0.9.2"/><vers num="0.9.3"/><vers num="0.9.4"/><vers num="0.9.5"/><vers num="0.9.6"/><vers num="0.9.7"/><vers num="0.9.8"/><vers num="0.9.9"/><vers num="0.9.10"/><vers num="0.9.11"/><vers num="0.9.12"/><vers num="0.9.13"/><vers num="0.9.14"/><vers num="0.9.15"/><vers num="0.9.16"/><vers num="0.10"/><vers num="0.10.1"/><vers num="0.10.2"/><vers num="0.10.3"/><vers num="0.10.4"/><vers num="0.10.5"/><vers num="0.10.6"/><vers num="0.10.7"/><vers num="0.10.8"/><vers num="0.10.9"/><vers num="0.10.10"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1467" published="2005-05-05" seq="2005-1467" severity="Medium" type="CVE"><desc><descript source="cve">Unknown vulnerability in the NDPS dissector in Ethereal before 0.10.11 allows remote attackers to cause a denial of service (memory exhaustion) via unknown vectors.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="CONFIRM" url="http://www.ethereal.com/appnotes/enpa-sa-00019.html">http://www.ethereal.com/appnotes/enpa-sa-00019.html</ref><ref source="CONFIRM" url="http://www.ethereal.com/news/item_20050504_01.html">http://www.ethereal.com/news/item_20050504_01.html</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00003.html">FLSA-2006:152922</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-427.html">RHSA-2005:427</ref><ref source="BID" url="http://www.securityfocus.com/bid/13504">13504</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000963">CLSA-2005:963</ref></refs><vuln_soft><prod name="Ethereal" vendor="Ethereal Group"><vers num="0.9.9"/><vers num="0.9.8"/><vers num="0.9.7"/><vers num="0.9.6"/><vers num="0.9.5"/><vers num="0.9.4"/><vers num="0.9.3"/><vers num="0.9.2"/><vers num="0.9.16"/><vers num="0.9.15"/><vers num="0.9.14"/><vers num="0.9.13"/><vers num="0.9.12"/><vers num="0.9.11"/><vers num="0.9.10"/><vers num="0.9.1"/><vers num="0.9"/><vers num="0.8.19"/><vers num="0.8.18"/><vers num="0.8.15"/><vers num="0.8.14"/><vers num="0.8.13"/><vers num="0.8"/><vers num="0.10.9"/><vers num="0.10.8"/><vers num="0.10.7"/><vers num="0.10.6"/><vers num="0.10.5"/><vers num="0.10.4"/><vers num="0.10.3"/><vers num="0.10.2"/><vers num="0.10.10"/><vers num="0.10.1"/><vers num="0.10.0"/><vers num="0.10"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-06-19" name="CVE-2005-1468" published="2005-05-05" seq="2005-1468" severity="Medium" type="CVE"><desc><descript source="cve">Multiple unknown vulnerabilities in the (1) WSP, (2) Q.931, (3) H.245, (4) KINK, (5) MGCP, (6) RPC, (7) SMBMailslot, and (8) SMB NETLOGON dissectors in Ethereal before 0.10.11 allow remote attackers to cause a denial of service (crash) via unknown vectors that lead to a null dereference.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CONFIRM" url="http://www.ethereal.com/appnotes/enpa-sa-00019.html">http://www.ethereal.com/appnotes/enpa-sa-00019.html</ref><ref adv="1" patch="1" source="CONFIRM" url="http://www.ethereal.com/news/item_20050504_01.html">http://www.ethereal.com/news/item_20050504_01.html</ref><ref adv="1" patch="1" source="FEDORA" url="http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00003.html">FLSA-2006:152922</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-427.html">RHSA-2005:427</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/13504">13504</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000963">CLSA-2005:963</ref></refs><vuln_soft><prod name="Ethereal" vendor="Ethereal Group"><vers num="0.8"/><vers num="0.8.13"/><vers num="0.8.14"/><vers num="0.8.15"/><vers num="0.8.18"/><vers num="0.8.19"/><vers num="0.9"/><vers num="0.9.1"/><vers num="0.9.2"/><vers num="0.9.3"/><vers num="0.9.4"/><vers num="0.9.5"/><vers num="0.9.6"/><vers num="0.9.7"/><vers num="0.9.8"/><vers num="0.9.9"/><vers num="0.9.10"/><vers num="0.9.11"/><vers num="0.9.12"/><vers num="0.9.13"/><vers num="0.9.14"/><vers num="0.9.15"/><vers num="0.9.16"/><vers num="0.10"/><vers num="0.10.1"/><vers num="0.10.2"/><vers num="0.10.3"/><vers num="0.10.4"/><vers num="0.10.5"/><vers num="0.10.6"/><vers num="0.10.7"/><vers num="0.10.8"/><vers num="0.10.9"/><vers num="0.10.10"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1469" published="2005-05-05" seq="2005-1469" severity="Medium" type="CVE"><desc><descript source="cve">Unknown vulnerability in the GSM dissector in Ethereal before 0.10.11 allows remote attackers to cause the dissector to access an invalid pointer.</descript></desc><loss_types><avail/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CONFIRM" url="http://www.ethereal.com/appnotes/enpa-sa-00019.html">http://www.ethereal.com/appnotes/enpa-sa-00019.html</ref><ref adv="1" patch="1" source="CONFIRM" url="http://www.ethereal.com/news/item_20050504_01.html">http://www.ethereal.com/news/item_20050504_01.html</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00003.html">FLSA-2006:152922</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-427.html">RHSA-2005:427</ref><ref source="BID" url="http://www.securityfocus.com/bid/13504">13504</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000963">CLSA-2005:963</ref></refs><vuln_soft><prod name="Ethereal" vendor="Ethereal Group"><vers num="0.8"/><vers num="0.8.13"/><vers num="0.8.14"/><vers num="0.8.15"/><vers num="0.8.18"/><vers num="0.8.19"/><vers num="0.9"/><vers num="0.9.1"/><vers num="0.9.2"/><vers num="0.9.3"/><vers num="0.9.4"/><vers num="0.9.5"/><vers num="0.9.6"/><vers num="0.9.7"/><vers num="0.9.8"/><vers num="0.9.9"/><vers num="0.9.10"/><vers num="0.9.11"/><vers num="0.9.12"/><vers num="0.9.13"/><vers num="0.9.14"/><vers num="0.9.15"/><vers num="0.9.16"/><vers num="0.10"/><vers num="0.10.1"/><vers num="0.10.2"/><vers num="0.10.3"/><vers num="0.10.4"/><vers num="0.10.5"/><vers num="0.10.6"/><vers num="0.10.7"/><vers num="0.10.8"/><vers num="0.10.9"/><vers num="0.10.10"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1470" published="2005-05-05" seq="2005-1470" severity="Medium" type="CVE"><desc><descript source="cve">Multiple unknown vulnerabilities in the (1) TZSP, (2) MGCP, (3) ISUP, (4) SMB, or (5) Bittorrent dissectors in Ethereal before 0.10.11 allow remote attackers to cause a denial of service (segmentation fault) via unknown vectors.</descript></desc><loss_types><avail/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CONFIRM" url="http://www.ethereal.com/appnotes/enpa-sa-00019.html">http://www.ethereal.com/appnotes/enpa-sa-00019.html</ref><ref adv="1" patch="1" source="CONFIRM" url="http://www.ethereal.com/news/item_20050504_01.html">http://www.ethereal.com/news/item_20050504_01.html</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00003.html">FLSA-2006:152922</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-427.html">RHSA-2005:427</ref><ref source="BID" url="http://www.securityfocus.com/bid/13504">13504</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000963">CLSA-2005:963</ref></refs><vuln_soft><prod name="Ethereal" vendor="Ethereal Group"><vers num="0.8"/><vers num="0.8.13"/><vers num="0.8.14"/><vers num="0.8.15"/><vers num="0.8.18"/><vers num="0.8.19"/><vers num="0.9"/><vers num="0.9.1"/><vers num="0.9.2"/><vers num="0.9.3"/><vers num="0.9.4"/><vers num="0.9.5"/><vers num="0.9.6"/><vers num="0.9.7"/><vers num="0.9.8"/><vers num="0.9.9"/><vers num="0.9.10"/><vers num="0.9.11"/><vers num="0.9.12"/><vers num="0.9.13"/><vers num="0.9.14"/><vers num="0.9.15"/><vers num="0.9.16"/><vers num="0.10"/><vers num="0.10.1"/><vers num="0.10.2"/><vers num="0.10.3"/><vers num="0.10.4"/><vers num="0.10.5"/><vers num="0.10.6"/><vers num="0.10.7"/><vers num="0.10.8"/><vers num="0.10.9"/><vers num="0.10.10"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1471" published="2005-05-06" seq="2005-1471" severity="High" type="CVE"><desc><descript source="cve">Heap-based buffer overflow in RSA SecurID Web Agent 5, 5.2, and 5.3 allows remote attackers to execute arbitrary code via crafted chunked-encoding data.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="SECUNIA" url="http://secunia.com/advisories/15222">15222</ref><ref source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=111537013104724&amp;w=2">20050506 [SEC-1 LTD] RSA SecurID Web Agent Heap Overflow</ref></refs><vuln_soft><prod name="SecurID Web Agent" vendor="RSA"><vers num="5"/><vers num="5.2"/><vers num="5.3"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1472" published="2005-05-19" seq="2005-1472" severity="Low" type="CVE"><desc><descript source="cve">Certain system calls in Apple Mac OS X 10.4.1 do not properly enforce the permissions of certain directories without the POSIX read bit set, but with the execute bits set for group or other, which allows local users to list files in otherwise restricted directories.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/May/msg00004.html">APPLE-SA-2005-05-19</ref></refs><vuln_soft><prod name="Mac OS X" vendor="Apple"><vers num="10.4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1473" published="2005-06-13" seq="2005-1473" severity="Medium" type="CVE"><desc><descript source="cve">SecurityAgent in Apple Mac OS X 10.4.1 allows attackers with physical access to bypass the locked screensaver and launch background applications by opening a URL from a text input field.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/May/msg00004.html">APPLE-SA-2005-05-19</ref></refs><vuln_soft><prod name="Mac OS X" vendor="Apple"><vers num="10.4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-25" name="CVE-2005-1474" published="2005-06-13" seq="2005-1474" severity="High" type="CVE"><desc><descript source="cve">Dashboard in Apple Mac OS X 10.4.1 allows remote attackers to install widgets via Safari without prompting the user, a different vulnerability than CVE-2005-1933.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/May/msg00004.html">APPLE-SA-2005-05-19</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/13694">13694</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.4"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.4.1"/><vers num="10.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1475" published="2005-06-16" seq="2005-1475" severity="High" type="CVE"><desc><descript source="cve">The XMLHttpRequest object in Opera 8.0 Final Build 1095 allows remote attackers to bypass access restrictions and perform unauthorized actions on other domains via a redirect.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="MISC" url="http://secunia.com/secunia_research/2005-4/advisory/">http://secunia.com/secunia_research/2005-4/advisory/</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/15008">15008</ref><ref source="BID" url="http://www.securityfocus.com/bid/13970">
13970</ref></refs><vuln_soft><prod name="Opera Web Browser" vendor="Opera Software"><vers num="8.0 Final Build 1095"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-25" name="CVE-2005-1476" published="2005-05-09" seq="2005-1476" severity="Medium" type="CVE"><desc><descript source="cve">Firefox 1.0.3 allows remote attackers to execute arbitrary Javascript in other domains by using an IFRAME and causing the browser to navigate to a previous javascript: URL, which can lead to arbitrary code execution when combined with CVE-2005-1477.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="MISC" url="http://greyhatsecurity.org/firefox.htm">http://greyhatsecurity.org/firefox.htm</ref><ref source="MISC" url="http://greyhatsecurity.org/vulntests/ffrc.htm">http://greyhatsecurity.org/vulntests/ffrc.htm</ref><ref adv="1" source="CONFIRM" url="http://www.mozilla.org/security/announce/mfsa2005-42.html">http://www.mozilla.org/security/announce/mfsa2005-42.html</ref><ref source="MISC" url="https://bugzilla.mozilla.org/show_bug.cgi?id=293302">https://bugzilla.mozilla.org/show_bug.cgi?id=293302</ref><ref source="MISC" url="https://bugzilla.mozilla.org/show_bug.cgi?id=292691">https://bugzilla.mozilla.org/show_bug.cgi?id=292691</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/0493">ADV-2005-0493</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/15292">15292</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/534710">VU#534710</ref><ref source="BID" url="http://www.securityfocus.com/bid/13544">13544</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013913">1013913</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20443">mozilla-javascript-code-execution(20443)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval100002.html">OVAL100002</ref><ref source="SCO" url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.49/SCOSA-2005.49.txt">SCOSA-2005.49</ref><ref source="BID" url="http://www.securityfocus.com/bid/15495">15495</ref><ref source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=111553138007647&amp;w=2">20050508 Firefox Remote Compromise Leaked</ref><ref source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=111556301530553&amp;w=2">20050508 Firefox Remote Compromise Technical Details</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-434.html">RHSA-2005:434</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-435.html">RHSA-2005:435</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100002">oval:org.mitre.oval:def:100002</ref></refs><vuln_soft><prod name="Firefox" vendor="Mozilla"><vers num="1.0.3" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-25" name="CVE-2005-1477" published="2005-05-09" seq="2005-1477" severity="Medium" type="CVE"><desc><descript source="cve">The install function in Firefox 1.0.3 allows remote web sites on the browser&apos;s whitelist, such as update.mozilla.org or addon.mozilla.org, to execute arbitrary Javascript with chrome privileges, leading to arbitrary code execution on the system when combined with vulnerabilities such as CVE-2005-1476, as demonstrated using a javascript: URL as the package icon and a cross-site scripting (XSS) attack on a vulnerable whitelist site.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="MISC" url="http://greyhatsecurity.org/firefox.htm">http://greyhatsecurity.org/firefox.htm</ref><ref source="MISC" url="http://greyhatsecurity.org/vulntests/ffrc.htm">http://greyhatsecurity.org/vulntests/ffrc.htm</ref><ref source="CONFIRM" url="http://www.mozilla.org/security/announce/mfsa2005-42.html">http://www.mozilla.org/security/announce/mfsa2005-42.html</ref><ref source="MISC" url="https://bugzilla.mozilla.org/show_bug.cgi?id=293302">https://bugzilla.mozilla.org/show_bug.cgi?id=293302</ref><ref source="MISC" url="https://bugzilla.mozilla.org/show_bug.cgi?id=292691">https://bugzilla.mozilla.org/show_bug.cgi?id=292691</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/0493">ADV-2005-0493</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/15292">15292</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/648758">VU#648758</ref><ref source="BID" url="http://www.securityfocus.com/bid/13544">13544</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013913">1013913</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20443">mozilla-javascript-code-execution(20443)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval100001.html">OVAL100001</ref><ref source="SCO" url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.49/SCOSA-2005.49.txt">SCOSA-2005.49</ref><ref source="BID" url="http://www.securityfocus.com/bid/15495">15495</ref><ref source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=111553138007647&amp;w=2">20050508 Firefox Remote Compromise Leaked</ref><ref source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=111556301530553&amp;w=2">20050508 Firefox Remote Compromise Technical Details</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-434.html">RHSA-2005:434</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-435.html">RHSA-2005:435</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100001">oval:org.mitre.oval:def:100001</ref></refs><vuln_soft><prod name="Firefox" vendor="Mozilla"><vers num="1.0.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1478" published="2005-05-11" seq="2005-1478" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in dSMTP (dsmtp.exe) in DMail 3.1a allows remote attackers to execute arbitrary code via format string specifiers in the xtellmail command.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MISC" url="http://www.security.org.sg/vuln/dmail31a.html">http://www.security.org.sg/vuln/dmail31a.html</ref><ref source="BID" url="http://www.securityfocus.com/bid/13505">13505</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013885">1013885</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/15242">15242</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20414">dmail-dsmtpexe-format-string(20414)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111531804617905&amp;w=2">20050505 dSMTP - SMTP Mail Server 3.1b Linux Remote Root Format String Exploit</ref></refs><vuln_soft><prod name="DMail" vendor="NetWin"><vers num="3.1b"/><vers num="3.1a"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-20" name="CVE-2005-1479" published="2005-05-11" seq="2005-1479" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in jgs_portal.php in JGS-Portal 3.0.1 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/13451">13451</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013866">1013866</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/15219">15219</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20371">jgsportal-sql-injection(20371)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111506870504598&amp;w=2">20050430 JGS-Portal 3.0.1 SQL-Injection</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111627681218415&amp;w=2">20050516 [SePro Bugtraq] WBB Portal - JGS-Portal &lt;= 3.0.2 - Multiple Vulnerabilities (09.05.05)</ref></refs><vuln_soft><prod name="JGS-Portal" vendor="JGS-XA"><vers num="3.0.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1480" published="2005-05-11" seq="2005-1480" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in RaidenFTPD before 2.4.2241 allows remote attackers to read arbitrary files via a &quot;..\\&quot; (dot dot backslash) in the urlget site command.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/13292">13292</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/15037">15037</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/20368">raidenftpd-directory-traversal(20368)</ref><ref source="OSVDB" url="http://www.osvdb.org/15713">15713</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111507556127582&amp;w=2">20050502 Directory Traversal Vuln - RaidenFTPD 2.4 &lt; Build 2241</ref><ref source="" url="http://forum.raidenftpd.com/showflat.php?Board=UBB13&amp;Number=45685"></ref></refs><vuln_soft><prod name="RaidenFTPD" vendor="Raiden Professional Servers"><vers num="2.4.2240" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1481" published="2005-05-11" seq="2005-1481" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in Aaron Outpost ASP Inline Corporate Calendar allow remote attackers to execute arbitrary SQL commands via the Event_ID parameter to (1) defer.asp or (2) details.asp.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="SECUNIA" url="http://secunia.com/advisories/15239">15239</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20416">asp-inline-corporate-calendar-sql-injection(20416)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013884">1013884</ref><ref source="OSVDB" url="http://www.osvdb.org/16192">16192</ref><ref source="OSVDB" url="http://www.osvdb.org/16193">16193</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111530675909673&amp;w=2">20050503 [HSC Security Group] ASP Inline Corporate Calendar SQL injection</ref></refs><vuln_soft><prod name="ASP Inline Corporate Calendar" vendor="AaronOutpost"><vers num="3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1482" published="2005-05-11" seq="2005-1482" severity="High" type="CVE"><desc><descript source="cve">ArticleLive 2005 allows remote attackers to gain privileges by modifying the (1) auth and (2) userId fields in a cookie.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MISC" url="http://www.digitalparadox.org/advisories/inal.txt">http://www.digitalparadox.org/advisories/inal.txt</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/13493">13493</ref><ref adv="1" source="SECTRACK" url="http://securitytracker.com/id?1013895">1013895</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15250">15250</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20431">articlelive-bypass-security(20431)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111530871724865&amp;w=2">20050503 Authentication bypass, sql injections and xss in ArticleLive 2005</ref></refs><vuln_soft><prod name="ArticleLive" vendor="Interspire"><vers num="2005"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1483" published="2005-05-11" seq="2005-1483" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in ArticleLive 2005 allow remote attackers to inject arbitrary web script or HTML via the (1) Query, (2) Username, (3) LastName, (4) Biography, or (5) BlogId parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/13493">13493</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013895">1013895</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15250">15250</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20430">articlelive-multiple-xss(20430)</ref><ref source="OSVDB" url="http://www.osvdb.org/16183">16183</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111530871724865&amp;w=2">20050503 Authentication bypass, sql injections and xss in ArticleLive 2005</ref></refs><vuln_soft><prod name="ArticleLive" vendor="Interspire"><vers num="2005"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1484" published="2005-05-11" seq="2005-1484" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in Golden FTP server pro 2.52 allows remote attackers to read arbitrary files via a &quot;\..&quot; (forward slash dot dot) with a leading &apos;&quot;&apos; (double quote) in the GET command.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/13479">13479</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15175">15175</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20668">goldenftp-dotdot-directory-traversal(20668)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111530871716145&amp;w=2">20050504 Golden Ftp Server Pro - Directory Traversal Vuln</ref></refs><vuln_soft><prod name="Golden FTP Server" vendor="KMiNT21 Software"><vers num="1.00b"/><vers num="1.20b"/><vers num="1.30b"/><vers num="1.31b"/><vers num="1.92"/><vers num="2.0.5b"/><vers num="2.0.2b"/><vers num="2.10"/><vers num="2.16"/><vers num="2.52"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1485" published="2005-05-11" seq="2005-1485" severity="Medium" type="CVE"><desc><descript source="cve">Golden FTP Server Pro allows 2.52 allows remote attackers to obtain sensitive information via a GET request for a file that does not exist, which reveals the absolute path of the FTP server in the resulting FTP error message.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref source="SECUNIA" url="http://secunia.com/advisories/15175/">15175</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20674">goldenftp-information-disclosure(20674)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111530871716145&amp;w=2">20050504 Golden Ftp Server Pro - Directory Traversal Vuln</ref></refs><vuln_soft><prod name="Golden FTP Server" vendor="KMiNT21 Software"><vers num="2.52"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2008-01-03" name="CVE-2005-1486" published="2005-05-11" seq="2005-1486" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting vulnerabilities in FishCart 3.1 allow remote attackers to inject arbitrary web script or HTML via the (1) trackingnum, (2) reqagree, or (3) m parameter to upstracking.php or (4) nlst parameter to display.php.  NOTE: the vendor was not able to reproduce some of the reported vectors but believes that they have been addressed.  The original researcher is known to be unreliable.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MISC" url="http://www.digitalparadox.org/advisories/fishc.txt">http://www.digitalparadox.org/advisories/fishc.txt</ref><ref source="BID" url="http://www.securityfocus.com/bid/13499">13499</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/15232/">15232</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20384">fishcart-multiple-xss(20384)</ref><ref source="OSVDB" url="http://www.osvdb.org/16280">16280</ref><ref source="OSVDB" url="http://www.osvdb.org/16281">16281</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111530799109755&amp;w=2">20050504 Multiple SQL injections and XSS in FishCart 3.1</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/457754/100/200/threaded">20070123 Re: Multiple SQL injections and XSS in FishCart 3.1</ref><ref source="MLIST" url="http://www.fishcart.org/archives/200505/msg00028.html">[fishcart] 20050521 Re: Concerned about security</ref></refs><vuln_soft><prod name="FishCart" vendor="FishNet"><vers num="3.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-01-03" name="CVE-2005-1487" published="2005-05-11" seq="2005-1487" severity="High" type="CVE"><desc><descript source="cve">** DISPUTED **  Multiple SQL injection vulnerabilities in FishCart 3.1 allow remote attackers to execute arbitrary SQL commands via the (1) cartid parameter to upstnt.php or (2) psku parameter to display.php.  NOTE: the vendor disputes this report, saying that they are forced SQL errors.  The original researcher is known to be unreliable.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://www.digitalparadox.org/advisories/fishc.txt">http://www.digitalparadox.org/advisories/fishc.txt</ref><ref source="BID" url="http://www.securityfocus.com/bid/13499">13499</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15232/">15232</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20386">fishcart-multiple-sql-injection(20386)</ref><ref source="OSVDB" url="http://www.osvdb.org/16282">16282</ref><ref source="OSVDB" url="http://www.osvdb.org/16283">16283</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111530799109755&amp;w=2">20050504 Multiple SQL injections and XSS in FishCart 3.1</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/457754/100/200/threaded">20070123 Re: Multiple SQL injections and XSS in FishCart 3.1</ref></refs><vuln_soft><prod name="FishCart" vendor="FishNet"><vers num="3.1"/></prod></vuln_soft></entry><entry CVSS_base_score="1.9" CVSS_exploit_subscore="3.4" CVSS_impact_subscore="2.9" CVSS_score="1.9" CVSS_vector="(AV:L/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1488" published="2005-05-11" seq="2005-1488" severity="Low" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Merak Mail Server 8.0.3 with Icewarp Web Mail 5.4.2 allow remote authenticated users to inject arbitrary web script or HTML via (1) the E-mail address, Note, or Public Certificate fields to address.html, (2) addressaction.html, (3) the Signature field to settings.html, or (4) the Shared calendars to calendarsettings.html.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20467">merak-icewarp-script-xss(20467)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111530933016434&amp;w=2">20050504 Multiple vulnerabilities in Merak Mail Server 8.0.3 with Icewarp Web Mail 5.4.2</ref></refs><vuln_soft><prod name="Web Mail" vendor="Icewarp"><vers num="5.4.2"/></prod><prod name="Mail Server" vendor="Merak"><vers num="8.0.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1489" published="2005-05-11" seq="2005-1489" severity="Medium" type="CVE"><desc><descript source="cve">Unknown vulnerability in Merak Mail Server 8.0.3 with Icewarp Web Mail 5.4.2 allows remote authenticated users to obtain the full path of the server via certain requests to (1) calendar_addevent.html, (2) calendar_event.html, or (3) calendar_task.html.</descript></desc><loss_types><conf/></loss_types><range><network/></range><refs><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/15249">15249</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20469">merak-icewarp-script-path-disclosure(20469)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111530933016434&amp;w=2">20050504 Multiple vulnerabilities in Merak Mail Server 8.0.3 with Icewarp Web Mail 5.4.2</ref></refs><vuln_soft><prod name="Web Mail" vendor="Icewarp"><vers num="5.4.2"/></prod><prod name="Mail Server" vendor="Merak"><vers num="8.0.3"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1490" published="2005-05-11" seq="2005-1490" severity="Low" type="CVE"><desc><descript source="cve">Merak Mail Server 8.0.3 with Icewarp Web Mail 5.4.2, when the mailbox.dat file does not exist, allows remote authenticated users to determine if a file exists via the folder parameter to attachment.html.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref source="SECUNIA" url="http://secunia.com/advisories/15249">15249</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20472">merak-icewarp-file-existence(20472)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111530933016434&amp;w=2">20050504 Multiple vulnerabilities in Merak Mail Server 8.0.3 with Icewarp Web Mail 5.4.2</ref></refs><vuln_soft><prod name="Web Mail" vendor="Icewarp"><vers num="5.4.2"/></prod><prod name="Mail Server" vendor="Merak"><vers num="8.0.3"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1491" published="2005-05-11" seq="2005-1491" severity="Medium" type="CVE"><desc><descript source="cve">Merak Mail Server 8.0.3 with Icewarp Web Mail 5.4.2 allows remote authenticated users to (1) move their home directory via viewaction.html or (2) move arbitrary files via the importfile parameter to importaction.html.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref source="SECUNIA" url="http://secunia.com/advisories/15249">15249</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20471">merak-icewarp-directory-relocation(20471)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111530933016434&amp;w=2">20050504 Multiple vulnerabilities in Merak Mail Server 8.0.3 with Icewarp Web Mail 5.4.2</ref></refs><vuln_soft><prod name="Web Mail" vendor="Icewarp"><vers num="5.4.2"/></prod><prod name="Mail Server" vendor="Merak"><vers num="8.0.3"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-27" name="CVE-2005-1492" published="2005-05-11" seq="2005-1492" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in user.cgi in Gossamer Threads Links SQL 2.x and 3.0 allows remote attackers to inject arbitrary web script or HTML via the url parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="CONFIRM" url="http://gossamer-threads.com/perl/gforum/gforum.cgi?post=281029;">http://gossamer-threads.com/perl/gforum/gforum.cgi?post=281029;</ref><ref adv="1" source="CONFIRM" url="http://www.gossamer-threads.com/forum/Gossamer_Links_3.0.1_Released_P280986/">http://www.gossamer-threads.com/forum/Gossamer_Links_3.0.1_Released_P280986/</ref><ref source="BID" url="http://www.securityfocus.com/bid/13484">13484</ref><ref source="OSVDB" url="http://www.osvdb.org/16189">16189</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1013891">1013891</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15253">15253</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20415">links-usercgi-addcgi-xss(20415)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111531023916998&amp;w=2">20050504 Gossamer Threads Links SQL login XSS Vulnerability</ref></refs><vuln_soft><prod name="Gossamer Threads Links-SQL" vendor="Gossamer Threads"><vers num="3.0"/></prod><prod name="Gossamer Threads Links" vendor="Gossamer Threads"><vers num="2.0"/><vers num="2.2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1493" published="2005-05-11" seq="2005-1493" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in SimpleCam 1.2 allows remote attackers to read arbitrary files via a ..\ (dot dot backslash) in the URL.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="MISC" url="http://www.autistici.org/fdonato/advisory/SimpleCam1.2-adv.txt">http://www.autistici.org/fdonato/advisory/SimpleCam1.2-adv.txt</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/13495">13495</ref><ref patch="1" source="SECTRACK" url="http://www.securitytracker.com/alerts/2005/May/1013888.html">1013888</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20411">simplecam-dotdot-directory-traversal(20411)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111531466319161&amp;w=2">20050504 directory traversal in SimpleCam 1.2</ref></refs><vuln_soft><prod name="SimpleCam" vendor="Dead Pirate Software"><vers num="1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1494" published="2005-05-11" seq="2005-1494" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in admin.cgi in MegaBook 2.0 and 2.1 allow remote attackers to inject arbitrary web script or HTML via the (1) entryid or (2) password parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/397809">20050508 Re: MegaBook V2.0 - Cross Site Scripting Exploit</ref><ref source="BID" url="http://www.securityfocus.com/bid/13522">13522</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20669">megabook-admincgi-xss(20669)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111531609618182&amp;w=2">20050505 MegaBook V2.0 - Cross Site Scripting Exploit</ref></refs><vuln_soft><prod name="MegaBook" vendor="MegaBook"><vers num="2.0"/><vers num="2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-05-01" name="CVE-2005-1495" published="2005-05-11" seq="2005-1495" severity="High" type="CVE"><desc><descript source="cve">Oracle Database 9i and 10g disables Fine Grained Audit (FGA) after the SYS user executes a SELECT statement on an FGA object, which makes it easier for attackers to escape detection.</descript></desc><sols><sol source="nvd">Applying patchset 10.1.0.4 is fixing this issue for Oracle 10g. Oracle 9i is still vulnerable.</sol></sols><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://www.red-database-security.com/advisory/oracle-fine-grained-auditing-issue.html">http://www.red-database-security.com/advisory/oracle-fine-grained-auditing-issue.html</ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/777773">VU#777773</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/20407">oracle-audit-data-manipulation(20407)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111531683824209&amp;w=2">20050505 Oracle 9i / 10g Fine Grained Auditing Issue</ref></refs><vuln_soft><prod name="Oracle9i" vendor="Oracle"><vers num="9.0"/><vers num="9.0.1.4"/><vers num="9.0.1.3"/><vers num="9.0.1.2"/><vers num="9.0.1"/><vers num="9.0.2"/><vers num="9.2.0.2"/><vers num="9.2.0.1"/><vers num="Release 2 9.2.2"/><vers num="Release 2 9.2.1"/></prod><prod name="Oracle10g" vendor="Oracle"><vers num="Enterprise 10.1.0.3.1"/><vers num="Enterprise 10.1.0.3"/><vers num="Enterprise 10.1.0.2"/><vers num="Personal 10.1.0.3.1"/><vers num="Personal 10.1.0.3"/><vers num="Personal 10.1.0.2"/><vers num="Standard 10.1.0.3.1"/><vers num="Standard 10.1.0.3"/><vers num="Standard 10.1.0.2"/></prod><prod name="Oracle10g Application Server" vendor="Oracle"><vers num="10.1.0.3.1"/><vers num="10.1.0.3"/><vers num="10.1.0.2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-05-01" name="CVE-2005-1496" published="2005-05-11" seq="2005-1496" severity="Medium" type="CVE"><desc><descript source="cve">The DBMS_Scheduler in Oracle 10g allows remote attackers with CREATE JOB privileges to gain additional privileges by changing SESSION_USER to the SYS user.</descript></desc><sols><sol source="nvd">Applying patchset 10.1.0.4 is fixing this issue.</sol></sols><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref patch="1" source="MISC" url="http://www.red-database-security.com/exploits/oracle_exploit_dbms_scheduler_select_user.html">http://www.red-database-security.com/exploits/oracle_exploit_dbms_scheduler_select_user.html</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/13509">13509</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20410">oracle10g-gain-privileges(20410)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111531740305049&amp;w=2">20050505 Oracle 10g DBMS_SCHEDULER SESSION_USER issue</ref></refs><vuln_soft><prod name="Oracle10g" vendor="Oracle"><vers num="Enterprise 10.1.0.3.1"/><vers num="Enterprise 10.1.0.3"/><vers num="Enterprise 10.1.0.2"/><vers num="Personal 10.1.0.3.1"/><vers num="Personal 10.1.0.3"/><vers num="Personal 10.1.0.2"/><vers num="Standard 10.1.0.3.1"/><vers num="Standard 10.1.0.3"/><vers num="Standard 10.1.0.2"/></prod><prod name="Oracle10g Application Server" vendor="Oracle"><vers num="10.1.0.3.1"/><vers num="10.1.0.3"/><vers num="10.1.0.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1497" published="2005-05-11" seq="2005-1497" severity="Medium" type="CVE"><desc><descript source="cve">index.php in myBloggie 2.1.1 allows remote attackers to obtain sensitive information via an invalid post_id parameter, which reveals the path in an error message.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref source="MISC" url="http://mywebland.com/forums/showtopic.php?t=180">http://mywebland.com/forums/viewtopic.php?t=180</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/20433">mybloggie-postid-path-disclosure(20433)</ref><ref source="MISC" url="http://mywebland.com/forums/viewtopic.php?t=180">http://mywebland.com/forums/viewtopic.php?t=180</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111531904608224&amp;w=2">20050505 Multiple vulnerabilities in myBloggie 2.1.1</ref></refs><vuln_soft><prod name="myBloggie" vendor="myWebland"><vers num="2.1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1498" published="2005-05-11" seq="2005-1498" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in myBloggie 2.1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) year parameter in viewmode.php, or the (2) cat_id, (3) month_no, or (4) post_id parameter in index.php, which are not properly sanitized before they are displayed in an error message.  NOTE: issues 2, 3, and 4 may be due to a problem in associated products rather than myBloggie itself.</descript></desc><sols><sol source="nvd">Download newest myBloggie from http://mywebland.com/</sol></sols><loss_types><int/></loss_types><vuln_types><input/><env/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/13507">13507</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20434">mybloggie-viewmodephp-xss(20434)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20436">mybloggie-script-injection(20436)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111531904608224&amp;w=2">20050505 Multiple vulnerabilities in myBloggie 2.1.1</ref></refs><vuln_soft><prod name="myBloggie" vendor="myWebland"><vers num="2.1.1"/><vers num="2.1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1499" published="2005-05-11" seq="2005-1499" severity="High" type="CVE"><desc><descript source="cve">delcomment.php in myBloggie 2.1.1 allows remote attackers to delete arbitrary comments by modifying the comment_id parameter.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><access/><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/13507">13507</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14980">14980</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/20437">mybloggie-delcomment-bypass-security(20437)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111531904608224&amp;w=2">20050505 Multiple vulnerabilities in myBloggie 2.1.1</ref></refs><vuln_soft><prod name="myBloggie" vendor="myWebland"><vers num="2.1.1"/><vers num="2.1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-01-03" name="CVE-2005-1500" published="2005-05-11" seq="2005-1500" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in myBloggie 2.1.1 allow remote attackers to execute arbitrary SQL commands via (1) the keyword parameter in search.php; or (2) the date_no parameter in viewdate mode, (3) the cat_id parameter in viewcat mode, the (4) month_no or (5) year parameter in viewmonth mode, or (6) post_id parameter in viewid mode to index.php.  NOTE: item (1) was discovered to affect 2.1.3 as well.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/13507">13507</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/14980">14980</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20439">mybloggie-sql-injection(20439)</ref><ref source="BID" url="http://www.securityfocus.com/bid/15017">15017</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111531904608224&amp;w=2">20050505 Multiple vulnerabilities in myBloggie 2.1.1</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111722848308367&amp;w=2">20050527 SQL Injection Exploit for myBloggie 2.1.1 - 2.1.2</ref></refs><vuln_soft><prod name="myBloggie" vendor="myWebland"><vers num="2.1.1"/><vers num="2.1.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1501" published="2005-05-11" seq="2005-1501" severity="High" type="CVE"><desc><descript source="cve">MidiCart PHP Shopping Cart allows remote attackers to obtain sensitive information via a direct request to (1) search_list.php, (2) item_list.php, or (3) item_show.php, which reveal the path in a PHP error message.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/><exception/></vuln_types><range><network/></range><refs><ref source="MISC" url="http://www.hackgen.org/advisories/hackgen-2005-004.txt">http://www.hackgen.org/advisories/hackgen-2005-004.txt</ref><ref source="OSVDB" url="http://www.osvdb.org/16172">16172</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20425">midicart-path-disclosure(20425)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111533057918993&amp;w=2">20050505 [hackgen-2005-#004] - Multiple bugs in MidiCart PHP Shopping Cart</ref></refs><vuln_soft><prod name="MidiCart PHP Shopping Cart" vendor="Midicart Software"><vers num="a"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1502" published="2005-05-11" seq="2005-1502" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in MidiCart PHP Shopping Cart allows remote attackers to inject arbitrary web script or HTML via the (1) searchstring parameter to search_list.php or the (2) secondgroup or (3) maingroup parameters to item_list.php.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MISC" url="http://www.hackgen.org/advisories/hackgen-2005-004.txt">http://www.hackgen.org/advisories/hackgen-2005-004.txt</ref><ref source="BID" url="http://www.securityfocus.com/bid/13516">13516</ref><ref source="BID" url="http://www.securityfocus.com/bid/13517">13517</ref><ref source="BID" url="http://www.securityfocus.com/bid/13518">13518</ref><ref source="OSVDB" url="http://www.osvdb.org/16173">16173</ref><ref source="OSVDB" url="http://www.osvdb.org/16174">16174</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15269">15269</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20427">midicart-xss(20427)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111533057918993&amp;w=2">20050505 [hackgen-2005-#004] - Multiple bugs in MidiCart PHP Shopping Cart</ref></refs><vuln_soft><prod name="MidiCart PHP Shopping Cart" vendor="Midicart Software"><vers num="a"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1503" published="2005-05-11" seq="2005-1503" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in MidiCart PHP Shopping Cart allow remote attackers to execute arbitrary SQL commands via the (1) searchstring parameter to search_list.php, the (2) maingroup or (3) secondgroup parameters to item_list.php, or (4) code_no parameter to item_show.php.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://www.hackgen.org/advisories/hackgen-2005-004.txt">http://www.hackgen.org/advisories/hackgen-2005-004.txt</ref><ref source="BID" url="http://www.securityfocus.com/bid/13512">13512</ref><ref source="BID" url="http://www.securityfocus.com/bid/13513">13513</ref><ref source="BID" url="http://www.securityfocus.com/bid/13514">13514</ref><ref source="BID" url="http://www.securityfocus.com/bid/13515">13515</ref><ref source="OSVDB" url="http://www.osvdb.org/16175">16175</ref><ref source="OSVDB" url="http://www.osvdb.org/16176">16176</ref><ref source="OSVDB" url="http://www.osvdb.org/16177">16177</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15269">15269</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20428">midicart-sql-injection(20428)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111533057918993&amp;w=2">20050505 [hackgen-2005-#004] - Multiple bugs in MidiCart PHP Shopping Cart</ref></refs><vuln_soft><prod name="MidiCart PHP Shopping Cart" vendor="Midicart Software"><vers num="a"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1504" published="2005-05-11" seq="2005-1504" severity="Medium" type="CVE"><desc><descript source="cve">GameSpy SDK CD-Key Validation Toolkit, as used by many online games, allows remote attackers to bypass the CD key validation by sending a spoofed \disc\ command, which tells the server the CD key is no longer in use.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="Luigi Auriemma" url="http://aluigi.altervista.org/adv/gskeyinuse-adv.txt"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/15254/">15254</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20422">gamespy-sdk-cdkey-gain-access(20422)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111539740212818&amp;w=2">20050504 Gamespy cd-key validation system: Cd-key never in use</ref></refs><vuln_soft><prod name="cd-key validation system" vendor="Gamespy"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1505" published="2005-05-11" seq="2005-1505" severity="High" type="CVE"><desc><descript source="cve">The new account wizard in Mail.app 2.0 in Mac OS 10.4, when configuring an IMAP mail account and checking the credentials, does not prompt the user to use SSL until after the password has already been sent, which causes the password to be sent in plaintext.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20670">mailapp-account-wizard-plaintext-password(20670)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111539448630095&amp;w=2">20050504 Mac OS 10.4: new-account-wizzard in Mail 2.0 sends clear-text passwords</ref></refs><vuln_soft><prod name="Mail" vendor="Apple"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1506" published="2005-05-11" seq="2005-1506" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in out.php in CJ Ultra (CJUltra) Plus 1.0.3 and 1.0.4 allows remote attackers to execute arbitrary SQL commands via the perm parameter.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="SECUNIA" url="http://secunia.com/advisories/15281">15281</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111539589013911&amp;w=2">20050505 Sql Injection in CJ Ultra Plus v1.0.3-1.0.4</ref></refs><vuln_soft><prod name="Ultra Plus" vendor="CJ"><vers num="1.0.3"/><vers num="1.0.4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1507" published="2005-05-11" seq="2005-1507" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in the Tomcat plugin in 4d WebSTAR 5.33 and 5.4 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long URL.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/13538">13538</ref><ref source="OSVDB" url="http://www.osvdb.org/16154">16154</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15278">15278</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20478">4d-webstar-plugin-bo(20478)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111541709402784&amp;w=2">20050506 4d WebSTAR 5.x Web Server Mac OS X Buffer Overflow</ref></refs><vuln_soft><prod name="WebSTAR" vendor="4D"><vers num="5.3.3"/><vers num="5.4"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-25" name="CVE-2005-1508" published="2005-05-11" seq="2005-1508" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in PwsPHP 1.2.2 allow remote attackers to inject arbitrary web script or HTML via the (1) month or (2) annee parameters to the news module, (3) nbractif or (4) annee parameters to the stats module, (5) id parameter to profil.php, (6) mb_lettre or (7) lettre parameter to memberlist.php, or (8) chaine_search, or (9) auteur_search parameter to the recherche module.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="OSVDB" url="http://www.osvdb.org/16228">16228</ref><ref source="OSVDB" url="http://www.osvdb.org/16229">16229</ref><ref source="OSVDB" url="http://www.osvdb.org/16230">16230</ref><ref source="OSVDB" url="http://www.osvdb.org/16231">16231</ref><ref source="OSVDB" url="http://www.osvdb.org/16232">16232</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/15315">15315</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/0503">ADV-2005-0503</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20500">pwsphp-mulitple-scripts-xss(20500)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111565808024581&amp;w=2">20050507 PwsPHP v1.2.2 Final - Multiples vulnerabilities</ref></refs><vuln_soft><prod name="PwsPHP" vendor="PwsPHP"><vers num="1.2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-25" name="CVE-2005-1509" published="2005-05-11" seq="2005-1509" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in profil.php in PwsPHP 1.2.2 allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="OSVDB" url="http://www.osvdb.org/16233">16233</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15315">15315</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20501">pwsphp-id-sql-injection(20501)</ref><ref source="BID" url="http://www.securityfocus.com/bid/13563">13563</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111565808024581&amp;w=2">20050507 PwsPHP v1.2.2 Final - Multiples vulnerabilities</ref></refs><vuln_soft><prod name="PwsPHP" vendor="PwsPHP"><vers num="1.2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-25" name="CVE-2005-1510" published="2005-05-11" seq="2005-1510" severity="High" type="CVE"><desc><descript source="cve">PwsPHP 1.2.2 allows remote attackers to obtain sensitive information via a direct request to the admin directory, which reveals the path in an error message.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="OSVDB" url="http://www.osvdb.org/16234">16234</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15315">15315</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111565808024581&amp;w=2">20050507 PwsPHP v1.2.2 Final - Multiples vulnerabilities</ref></refs><vuln_soft><prod name="PwsPHP" vendor="PwsPHP"><vers num="1.2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-25" name="CVE-2005-1511" published="2005-05-11" seq="2005-1511" severity="High" type="CVE"><desc><descript source="cve">PwsPHP 1.2.2 allows remote attackers to bypass authentication and post arbitrary comments via the Pseudo cookie.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref source="OSVDB" url="http://www.osvdb.org/16235">16235</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15315">15315</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20503">pwsphp-cookie-spoof-identity(20503)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111565808024581&amp;w=2">20050507 PwsPHP v1.2.2 Final - Multiples vulnerabilities</ref></refs><vuln_soft><prod name="PwsPHP" vendor="PwsPHP"><vers num="1.2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-25" name="CVE-2005-1512" published="2005-05-11" seq="2005-1512" severity="High" type="CVE"><desc><descript source="cve">The Admin panel in PwsPHP 1.2.2 does not properly verify uploaded picture files, which allows remote attackers to upload and possibly execute arbitrary files.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="OSVDB" url="http://www.osvdb.org/16236">16236</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/15315">15315</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20508">pwsphp-admin-panel-file-upload(20508)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111565808024581&amp;w=2">20050507 PwsPHP v1.2.2 Final - Multiples vulnerabilities</ref></refs><vuln_soft><prod name="PwsPHP" vendor="PwsPHP"><vers num="1.2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1513" published="2005-05-11" seq="2005-1513" severity="Medium" type="CVE"><desc><descript source="cve">Integer overflow in the stralloc_readyplus function in qmail, when running on 64 bit platforms with a large amount of virtual memory, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a large SMTP request.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2005-05/0101.html">20050506 64 bit qmail fun</ref><ref source="MISC" url="http://www.guninski.com/where_do_you_want_billg_to_go_today_4.html">http://www.guninski.com/where_do_you_want_billg_to_go_today_4.html</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013911">1013911</ref></refs><vuln_soft><prod name="Qmail" vendor="Dan Bernstein"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1514" published="2005-05-11" seq="2005-1514" severity="Medium" type="CVE"><desc><descript source="cve">commands.c in qmail, when running on 64 bit platforms with a large amount of virtual memory, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long SMTP command without a space character, which causes an array to be referenced with a negative index.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2005-05/0101.html">20050506 64 bit qmail fun</ref><ref source="MISC" url="http://www.guninski.com/where_do_you_want_billg_to_go_today_4.html">http://www.guninski.com/where_do_you_want_billg_to_go_today_4.html</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013911">1013911</ref></refs><vuln_soft><prod name="Qmail" vendor="Dan Bernstein"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1515" published="2005-05-11" seq="2005-1515" severity="Medium" type="CVE"><desc><descript source="cve">Integer signedness error in the qmail_put and substdio_put functions in qmail, when running on 64 bit platforms with a large amount of virtual memory, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a large number of SMTP RCPT TO commands.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2005-05/0101.html">20050506 64 bit qmail fun</ref><ref source="MISC" url="http://www.guninski.com/where_do_you_want_billg_to_go_today_4.html">http://www.guninski.com/where_do_you_want_billg_to_go_today_4.html</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013911">1013911</ref></refs><vuln_soft><prod name="Qmail" vendor="Dan Bernstein"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1516" published="2005-05-11" seq="2005-1516" severity="High" type="CVE"><desc><descript source="cve">DList (dlist.exe) in DMail 3.1a allows remote attackers to bypass authentication, read log files, and shutdown the system via a sendlog command with an incorrect password hash, which is not properly handled by the _cmd_sendlog function.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/><design/></vuln_types><range><network/></range><refs><ref source="MISC" url="http://www.security.org.sg/vuln/dmail31a.html">http://www.security.org.sg/vuln/dmail31a.html</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/13497">13497</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/15242">15242</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/20412">dmail-dlist-bypass-authentication(20412)</ref></refs><vuln_soft><prod name="DMail" vendor="NetWin"><vers num="3.1a"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1517" published="2005-05-11" seq="2005-1517" severity="High" type="CVE"><desc><descript source="cve">Unknown vulnerability in Cisco Firewall Services Module (FWSM) 2.3.1 and earlier, when using URL, FTP, or HTTPS filtering exceptions, allows certain TCP packets to bypass access control lists (ACLs).</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-sa-20050511-url.shtml">20050511 FWSM URL Filtering Solution TCP ACL Bypass Vulnerability</ref><ref patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/0527">ADV-2005-0527</ref></refs><vuln_soft><prod name="Firewall Services Module" vendor="Cisco"><vers num="2.3.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1518" published="2005-05-11" seq="2005-1518" severity="Low" type="CVE"><desc><descript source="cve">Unknown vulnerability in Solaris 7 through 9, when using Federated Naming Services (FNS), autofs, and FNS X.500 configuration, allows local users to cause a denial of service (automountd crash) when &quot;accessing&quot; /xfn/_x500.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57786-1">57786</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/0517">ADV-2005-0517</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers edition="x86" num="9.0"/><vers edition="SPARC" num="9.0"/><vers num="8.2"/><vers num="8.1"/><vers edition="x86" num="8.0"/><vers num="8.0"/><vers edition="x86" num="7.0"/><vers num="7.0"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1519" published="2005-05-11" seq="2005-1519" severity="Medium" type="CVE"><desc><descript source="cve">Squid 2.5 STABLE9 and earlier, when the DNS client port is unfiltered and the environment does not prevent IP spoofing, allows remote attackers to spoof DNS lookups.</descript></desc><loss_types><avail/><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref patch="1" source="CONFIRM" url="http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE9-dns_query">http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE9-dns_query</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/0521">ADV-2005-0521</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/15294">15294</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-announce-list/2005-May/msg00025.html">FEDORA-2005-373</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-751">DSA-751</ref><ref source="FEDORA" url="http://fedoranews.org/updates/FEDORA--.shtml">FLSA-2006:152809</ref><ref source="BID" url="http://www.securityfocus.com/bid/13592">13592</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-489.html">RHSA-2005:489</ref></refs><vuln_soft><prod name="Squid" vendor="Squid"><vers num="2.5 Stable9" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1520" published="2005-05-26" seq="2005-1520" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the header_get_field_name function in header.c for GNU Mailutils 0.5 and 0.6, and other versions before 0.6.90, allows remote attackers to execute arbitrary code via a crafted e-mail.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref patch="1" source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=249&amp;type=vulnerabilities">20050525 GNU Mailutils 0.6 mail header_get_field_name() Buffer Overflow Vulnerability</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/13766">13766</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/15442">15442</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-732">DSA-732</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014052">1014052</ref></refs><vuln_soft><prod name="Mailutils" vendor="GNU"><vers num="0.5"/><vers num="0.6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1521" published="2005-05-26" seq="2005-1521" severity="High" type="CVE"><desc><descript source="cve">Integer overflow in the fetch_io function of the imap4d server in GNU Mailutils 0.5 and 0.6, and other versions before 0.6.90, allows remote attackers to execute arbitrary code via a partial message request with a large value in the END parameter, which leads to a heap-based buffer overflow.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref patch="1" source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=248&amp;type=vulnerabilities">20050525 GNU Mailutils 0.6 imap4d fetch_io Heap overflow Vulnerability</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/13763">13763</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/15442">15442</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-732">DSA-732</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014052">1014052</ref></refs><vuln_soft><prod name="Mailutils" vendor="GNU"><vers num="0.5"/><vers num="0.6"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1522" published="2005-05-26" seq="2005-1522" severity="Medium" type="CVE"><desc><descript source="cve">The imap4d server for GNU Mailutils 0.5 and 0.6, and other versions before 0.6.90, allows authenticated remote users to cause a denial of service (CPU consumption) via a large range value in the FETCH command.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref patch="1" source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=247&amp;type=vulnerabilities">20050525 GNU Mailutils 0.6 imap4d FETCH Commad Resource Consumption DoS Vulnerability</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/13765">13765</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/15442">15442</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-732">DSA-732</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014052">1014052</ref></refs><vuln_soft><prod name="Mailutils" vendor="GNU"><vers num="0.5"/><vers num="0.6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1523" published="2005-05-26" seq="2005-1523" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in imap4d server in GNU Mailutils 0.5 and 0.6, and other versions before 0.6.90, allows remote attackers to execute arbitrary code via format string specifiers in the command tag for IMAP commands.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=246&amp;type=vulnerabilities">20050525 GNU Mailutils 0.6 imap4d Format String Vulnerability</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/13764">13764</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/15442">15442</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-732">DSA-732</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014052">1014052</ref></refs><vuln_soft><prod name="Mailutils" vendor="GNU"><vers num="0.5"/><vers num="0.6"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-08-28" name="CVE-2005-1524" published="2005-06-22" seq="2005-1524" severity="Medium" type="CVE"><desc><descript source="cve">PHP file inclusion vulnerability in top_graph_header.php in Cacti 0.8.6d and possibly earlier versions allows remote attackers to execute arbitrary PHP code via the config[library_path] parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=265&amp;type=vulnerabilities&amp;flashstatus=true">20050622 Multiple Vendor Cacti Remote File Inclusion Vulnerability</ref><ref adv="1" patch="1" source="CONFIRM" url="http://www.cacti.net/release_notes_0_8_6e.php">http://www.cacti.net/release_notes_0_8_6e.php</ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200506-20.xml">GLSA-200506-20</ref><ref source="CONECTIVA" url="http://distro.conectiva.com/atualizacoes/index.php?id=a&amp;anuncio=000978">CLSA-2005:978</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-764">DSA-764</ref><ref source="OSVDB" url="http://www.osvdb.org/17426">17426</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014252">1014252</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15490">15490</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15931">15931</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16136">16136</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/21118">cacti-topgraphheader-file-include(21118)</ref></refs><vuln_soft><prod name="Cacti" vendor="The Cacti Group"><vers num="0.8.6d" prev="1"/><vers num="0.8.5a"/><vers num="0.8.4"/><vers num="0.8.3a"/><vers num="0.8.3"/><vers num="0.8.2a"/><vers num="0.8.2"/><vers num="0.8.1"/><vers num="0.8"/><vers num="0.6.8a"/><vers num="0.6.8"/><vers num="0.6.7"/><vers num="0.6.6"/><vers num="0.6.5"/><vers num="0.6.4"/><vers num="0.6.3"/><vers num="0.6.2"/><vers num="0.6.1"/><vers num="0.6"/><vers num="0.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-08-28" name="CVE-2005-1525" published="2005-06-22" seq="2005-1525" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in config_settings.php for Cacti before 0.8.6e allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=267&amp;type=vulnerabilities&amp;flashstatus=true">20050622 Multiple Vendor Cacti Multiple SQL Injection Vulnerabilities</ref><ref adv="1" patch="1" source="CONFIRM" url="http://www.cacti.net/release_notes_0_8_6e.php">http://www.cacti.net/release_notes_0_8_6e.php</ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200506-20.xml">GLSA-200506-20</ref><ref source="OSVDB" url="http://www.osvdb.org/17424">17424</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/21120">cacti-configsettings-sql-injection(21120)</ref><ref source="CONECTIVA" url="http://distro.conectiva.com/atualizacoes/index.php?id=a&amp;anuncio=000978">CLSA-2005:978</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-764">DSA-764</ref><ref source="BID" url="http://www.securityfocus.com/bid/14027">14027</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014252">1014252</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15490">15490</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15931">15931</ref></refs><vuln_soft><prod name="Cacti" vendor="The Cacti Group"><vers num="0.8.6d" prev="1"/><vers num="0.8.5a"/><vers num="0.8.4"/><vers num="0.8.3a"/><vers num="0.8.3"/><vers num="0.8.2a"/><vers num="0.8.2"/><vers num="0.8.1"/><vers num="0.8"/><vers num="0.6.8a"/><vers num="0.6.8"/><vers num="0.6.7"/><vers num="0.6.6"/><vers num="0.6.5"/><vers num="0.6.4"/><vers num="0.6.3"/><vers num="0.6.2"/><vers num="0.6.1"/><vers num="0.6"/><vers num="0.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-27" name="CVE-2005-1526" published="2005-06-22" seq="2005-1526" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in config_settings.php in Cacti before 0.8.6e allows remote attackers to execute arbitrary PHP code via the config[include_path] parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=266&amp;type=vulnerabilities">20050622 Multiple Vendor Cacti config_settings.php Remote Code Execution Vulnerability</ref><ref adv="1" patch="1" source="CONFIRM" url="http://www.cacti.net/release_notes_0_8_6e.php">http://www.cacti.net/release_notes_0_8_6e.php</ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200506-20.xml">GLSA-200506-20</ref><ref source="CONECTIVA" url="http://distro.conectiva.com/atualizacoes/index.php?id=a&amp;anuncio=000978">CLSA-2005:978</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-764">DSA-764</ref><ref source="BID" url="http://www.securityfocus.com/bid/14028">14028</ref><ref source="OSVDB" url="http://www.osvdb.org/17425">17425</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014252">1014252</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15490">15490</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15931">15931</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/21119">cacti-configsettings-file-include(21119)</ref></refs><vuln_soft><prod name="Cacti" vendor="The Cacti Group"><vers num="0.8.6d" prev="1"/><vers num="0.8.5a"/><vers num="0.8.4"/><vers num="0.8.3a"/><vers num="0.8.3"/><vers num="0.8.2a"/><vers num="0.8.2"/><vers num="0.8.1"/><vers num="0.8"/><vers num="0.6.8a"/><vers num="0.6.8"/><vers num="0.6.7"/><vers num="0.6.6"/><vers num="0.6.5"/><vers num="0.6.4"/><vers num="0.6.3"/><vers num="0.6.2"/><vers num="0.6.1"/><vers num="0.6"/><vers num="0.5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1527" published="2005-08-15" seq="2005-1527" severity="Medium" type="CVE"><desc><descript source="cve">Eval injection vulnerability in awstats.pl in AWStats 6.4 and earlier, when a URLPlugin is enabled, allows remote attackers to execute arbitrary Perl code via the HTTP Referrer, which is used in a $url parameter that is inserted into an eval function call.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-167-1">USN-167-1</ref><ref adv="1" source="MISC" url="http://www.securiteam.com/unixfocus/5DP0J00GKE.html">http://www.securiteam.com/unixfocus/5DP0J00GKE.html</ref><ref source="BID" url="http://www.securityfocus.com/bid/14525">14525</ref><ref patch="1" source="OSVDB" url="http://www.osvdb.org/18696">18696</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1014636">1014636</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/16412">16412</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/21769">awstats-eval-execute-commands(21769)</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-892">DSA-892</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17463">17463</ref><ref source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=290&amp;type=vulnerabilities&amp;flashstatus=false">20050809 AWStats ShowInfoURL Remote Command Execution Vulnerability</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_19_sr.html">SUSE-SR:2005:019</ref></refs><vuln_soft><prod name="AWStats" vendor="AWStats"><vers num="6.3"/><vers num="6.2"/><vers num="6.1"/><vers num="6.0"/><vers num="5.9"/><vers num="5.8"/><vers num="5.7"/><vers num="5.6"/><vers num="5.5"/><vers num="5.4"/><vers num="5.3"/><vers num="5.2"/><vers num="5.1"/><vers num="5.0"/></prod><prod name="Ubuntu Linux" vendor="Ubuntu"><vers edition="powerpc" num="5.04"/><vers edition="i386" num="5.04"/><vers edition="amd64" num="5.04"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-12" name="CVE-2005-1528" published="2005-12-31" seq="2005-1528" severity="High" type="CVE"><desc><descript source="cve">Untrusted search path vulnerability in the crttrap command in QNX Neutrino RTOS 6.2.1 allows local users to load arbitrary libraries via a LD_LIBRARY_PATH environment variable that references a malicious library.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" source="IDEFENSE" url="http://www.idefense.com/intelligence/vulnerabilities/display.php?id=379">20060207 QNX Neutrino RTOS crttrap Arbitrary Library Loading Vulnerability</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0474">ADV-2006-0474</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18750">18750</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015599">1015599</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24560">qnx-crttrap-privilege-elevation(24560)</ref><ref source="BID" url="http://www.securityfocus.com/bid/16539">16539</ref></refs><vuln_soft><prod name="RTOS" vendor="QNX"><vers num="6.2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-08-16" name="CVE-2005-1530" published="2005-07-19" seq="2005-1530" severity="Medium" type="CVE"><desc><descript source="cve">Sophos Anti-Virus 5.0.1, with &quot;Scan inside archive files&quot; enabled, allows remote attackers to cause a denial of service (CPU consumption by infinite loop) via a Bzip2 archive with a large &apos;Extra field length&apos; value.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=283&amp;type=vulnerabilities&amp;flashstatus=true">20050714 Sophos Anti-Virus Zip File Handling DoS Vulnerability</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/14270">14270</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/21373">sophos-bzip2-dos(21373)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014488">1014488</ref></refs><vuln_soft><prod name="Sophos MailMonitor" vendor="Sophos"><vers num="2.1"/><vers num="2.0"/></prod><prod name="Sophos PureMessage Anti-Virus" vendor="Sophos"><vers num="4.6"/></prod><prod name="Sophos Anti-Virus" vendor="Sophos"><vers num="5.0.1"/><vers num="3.91"/><vers num="3.90"/><vers num="3.86"/><vers num="3.85"/><vers num="3.84"/><vers num="3.83"/><vers num="3.82"/><vers num="3.81"/><vers num="3.80"/><vers num="3.79"/><vers num="3.78d"/><vers num="3.78"/><vers num="3.4.6"/></prod><prod name="Sophos MailMonitor for Notes_Domino" vendor="Sophos"><vers num=""/></prod><prod name="Sophos Small Business Suite" vendor="Sophos"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1531" published="2005-05-12" seq="2005-1531" severity="High" type="CVE"><desc><descript source="cve">Firefox before 1.0.4 and Mozilla Suite before 1.7.8 does not properly implement certain security checks for script injection, which allows remote attackers to execute script via &quot;Wrapped&quot; javascript: URLs, as demonstrated using (1) a javascript: URL in a view-source: URL, (2) a javascript: URL in a jar: URL, or (3) &quot;a nested variant.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="CONFIRM" url="http://www.mozilla.org/security/announce/mfsa2005-43.html">http://www.mozilla.org/security/announce/mfsa2005-43.html</ref><ref patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/0530">ADV-2005-0530</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013962">1013962</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013963">1013963</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval100015.html">OVAL100015</ref><ref source="SCO" url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.49/SCOSA-2005.49.txt">SCOSA-2005.49</ref><ref source="BID" url="http://www.securityfocus.com/bid/15495">15495</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-434.html">RHSA-2005:434</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-435.html">RHSA-2005:435</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100015">oval:org.mitre.oval:def:100015</ref><ref source="BID" url="http://www.securityfocus.com/bid/13641">
13641</ref></refs><vuln_soft><prod name="Mozilla" vendor="Mozilla"><vers num="1.7.7"/><vers num="1.7.6"/><vers num="1.7.5"/><vers num="1.7.3"/><vers num="1.7.2"/><vers num="1.7.1"/><vers num="1.7"/><vers num="1.7 rc3"/><vers num="1.7 rc2"/><vers num="1.7 rc1"/><vers num="1.7 beta"/><vers num="1.7 alpha"/><vers num="1.6"/><vers num="1.6 beta"/><vers num="1.6 alpha"/><vers num="1.5.1"/><vers num="1.5"/><vers num="1.5 rc2"/><vers num="1.5 rc1"/><vers num="1.5 alpha"/><vers num="1.4.1"/><vers num="1.4" prev="1"/></prod><prod name="Firefox" vendor="Mozilla"><vers num="1.0.3"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0"/><vers num="0.10"/><vers num="0.10.1"/><vers num="0.9.3"/><vers num="0.9.2"/><vers num="0.9.1"/><vers edition="rc" num="0.9"/><vers num="0.9"/><vers num="0.8"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-06-15" name="CVE-2005-1532" published="2005-05-12" seq="2005-1532" severity="High" type="CVE"><desc><descript source="cve">Firefox before 1.0.4 and Mozilla Suite before 1.7.8 do not properly limit privileges of Javascript eval and Script objects in the calling context, which allows remote attackers to conduct unauthorized activities via &quot;non-DOM property overrides,&quot; a variant of CVE-2005-1160.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref source="CONFIRM" url="http://www.mozilla.org/security/announce/mfsa2005-44.html">http://www.mozilla.org/security/announce/mfsa2005-44.html</ref><ref patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/0530">ADV-2005-0530</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013965">1013965</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013964">1013964</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval100014.html">OVAL100014</ref><ref source="SCO" url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.49/SCOSA-2005.49.txt">SCOSA-2005.49</ref><ref source="BID" url="http://www.securityfocus.com/bid/15495">15495</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-601.html">RHSA-2005:601</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_04_25.html">SUSE-SA:2006:022</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19823">19823</ref><ref source="BID" url="http://www.securityfocus.com/bid/13645">13645</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-434.html">RHSA-2005:434</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-435.html">RHSA-2005:435</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100014">oval:org.mitre.oval:def:100014</ref></refs><vuln_soft><prod name="Mozilla" vendor="Mozilla"><vers num="1.7.7"/><vers num="1.7.6"/><vers num="1.7.5"/><vers num="1.7.3"/><vers num="1.7.2"/><vers num="1.7.1"/><vers num="1.7 rc3"/><vers num="1.7 rc2"/><vers num="1.7 rc1"/><vers num="1.7 Beta"/><vers num="1.7 alpha"/><vers num="1.7"/><vers num="1.6 Beta"/><vers num="1.6 alpha"/><vers num="1.6"/><vers num="1.5.1"/><vers num="1.5 rc2"/><vers num="1.5 rc1"/><vers num="1.5 alpha"/><vers num="1.5"/><vers num="1.4a"/><vers num="1.4.1"/><vers num="1.4"/><vers num="1.3"/></prod><prod name="Firefox" vendor="Mozilla"><vers num="1.0.3"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0"/><vers num="0.9.3"/><vers num="0.9.2"/><vers num="0.9.1"/><vers edition="rc" num="0.9"/><vers num="0.9"/><vers num="0.8"/><vers num="0.10.1"/><vers num="0.10"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1543" published="2005-05-25" seq="2005-1543" severity="High" type="CVE"><desc><descript source="cve">Multiple stack-based and heap-based buffer overflows in Remote Management authentication (zenrem32.exe) on Novell ZENworks 6.5 Desktop and Server Management, ZENworks for Desktops 4.x, ZENworks for Servers 3.x, and Remote Management allows remote attackers to execute arbitrary code via (1) unspecified vectors, (2) type 1 authentication requests, and (3) type 2 authentication requests.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111645317713662&amp;w=2">20050518 NOVELL ZENWORKS MULTIPLE =?utf-8?Q?REM=C3=98TE?= STACK &amp; HEAP OVERFLOWS</ref><ref adv="1" source="MISC" url="http://www.rem0te.com/public/images/zen.pdf">http://www.rem0te.com/public/images/zen.pdf</ref><ref source="CONFIRM" url="http://support.novell.com/cgi-bin/search/searchtid.cgi?/10097644.htm">http://support.novell.com/cgi-bin/search/searchtid.cgi?/10097644.htm</ref><ref source="BID" url="http://www.securityfocus.com/bid/13678">13678</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/0571">ADV-2005-0571</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014005">1014005</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15433">15433</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20644">novell-zenwork-remote-management-1-bo(20644)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20639">novell-zenwork-remote-management-bo(20639)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20645">novell-zenwork-remote-management-2-bo(20645)</ref></refs><vuln_soft><prod name="ZENworks for Desktops" vendor="Novell"><vers num="3.2 SP2"/><vers num="4.0"/><vers num="4.0.1"/></prod><prod name="ZENworks Desktop Management" vendor="Novell"><vers num="6.5"/></prod><prod name="ZENworks Server Management" vendor="Novell"><vers num="6.5"/></prod><prod name="ZENworks Remote Management" vendor="Novell"><vers num=""/></prod><prod name="ZENworks for Servers" vendor="Novell"><vers num="3.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1544" published="2005-05-14" seq="2005-1544" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in libTIFF before 3.7.2 allows remote attackers to execute arbitrary code via a TIFF file with a malformed BitsPerSample tag.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="MISC" url="http://bugzilla.remotesensing.org/show_bug.cgi?id=843">http://bugzilla.remotesensing.org/show_bug.cgi?id=843</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200505-07.xml">GLSA-200505-07</ref><ref patch="1" source="MISC" url="http://bugs.gentoo.org/show_bug.cgi?id=91584">http://bugs.gentoo.org/show_bug.cgi?id=91584</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15320">15320</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/20533">libtiff-bitspersample-bo(20533)</ref><ref source="SCO" url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.34/SCOSA-2005.34.txt">SCOSA-2005.34</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16872">16872</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:042">MDKSA-2006:042</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18943">18943</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-755">DSA-755</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-130-1">USN-130-1</ref><ref source="BID" url="http://www.securityfocus.com/bid/13585">13585</ref><ref source="OSVDB" url="http://www.osvdb.org/16350">16350</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013944">1013944</ref><ref source="SCO" url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2006.3/SCOSA-2006.3.txt">SCOSA-2006.3</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18289">18289</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:042">MDKSA-2006:042</ref></refs><vuln_soft><prod name="libTIFF" vendor="libTIFF"><vers num="3.7.1"/><vers num="3.7.0"/><vers num="3.6.1"/><vers num="3.6.0"/><vers num="3.5.7"/><vers num="3.5.6"/><vers num="3.5.5"/><vers num="3.5.4"/><vers num="3.5.3"/><vers num="3.5.2"/><vers num="3.5.1"/><vers num="3.4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1545" published="2005-05-14" seq="2005-1545" severity="Medium" type="CVE"><desc><descript source="cve">Integer overflow in the ELF parser in HT Editor before 0.8.0 allows remote attackers to execute arbitrary code via a crafted ELF file, which leads to a heap-based buffer overflow.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/><user_init/></range><refs><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200505-08.xml">GLSA-200505-08</ref><ref source="Security Focus" url="http://www.securityfocus.com/bid/13584">HT Editor ELF Parser Unspecified Remote Heap Overflow Vulnerability</ref><ref source="Secunia" url="http://secunia.com/advisories/15304/">HT Editor ELF and PE Parser Vulnerabilities</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-743">DSA-743</ref></refs><vuln_soft><prod name="HT Editor" vendor="HT Editor"><vers num="0.8.0"/><vers num="0.7.5"/><vers num="0.7.4"/><vers num="0.7.3"/><vers num="0.7.2"/><vers num="0.7.1"/><vers num="0.7.0"/><vers num="0.6.0b"/><vers num="0.6.0"/><vers num="0.5.0"/><vers num="0.4.5"/><vers num="0.4.4d"/><vers num="0.4.4c"/><vers num="0.4.4b"/><vers num="0.4.4"/><vers num="0.4.3"/><vers num="0.4.2"/><vers num="0.4.1"/><vers num="0.4.0"/><vers num="0.3.992"/><vers num="0.3.991"/><vers num="2000-01-14"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1546" published="2005-05-14" seq="2005-1546" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in the PE parser in HT Editor before 0.8.0 allows remote attackers to execute arbitrary code via a crafted PE file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200505-08.xml">GLSA-200505-08</ref><ref source="Secunia" url="http://secunia.com/advisories/15304/">HT Editor ELF and PE Parser Vulnerabilities</ref><ref source="Security Focus" url="http://www.securityfocus.com/bid/13587">HT Editor PE Parser Unspecified Remote Buffer Overflow Vulnerability</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-743">DSA-743</ref></refs><vuln_soft><prod name="HT Editor" vendor="HT Editor"><vers num="0.8.0"/><vers num="0.7.5"/><vers num="0.7.4"/><vers num="0.7.3"/><vers num="0.7.2"/><vers num="0.7.1"/><vers num="0.7.0"/><vers num="0.6.0b"/><vers num="0.6.0"/><vers num="0.5.0"/><vers num="0.4.5"/><vers num="0.4.4d"/><vers num="0.4.4c"/><vers num="0.4.4b"/><vers num="0.4.4"/><vers num="0.4.3"/><vers num="0.4.2"/><vers num="0.4.1"/><vers num="0.4.0"/><vers num="0.3.992"/><vers num="0.3.991"/><vers num="2000-01-14"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1547" published="2005-05-14" seq="2005-1547" severity="High" type="CVE"><desc><descript source="cve">Heap-based buffer overflow in the demo version of Bakbone Netvault, and possibly other versions, allows remote attackers to execute arbitrary commands via a large packet to port 20031.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/><exception/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111600439331242&amp;w=2">20050512 Netvault Remote Heap Overflow (another one)</ref><ref source="Secunia" url="http://secunia.com/advisories/15158/">BakBone NetVault Buffer Overflow Vulnerabilities</ref></refs><vuln_soft><prod name="Netvault" vendor="Bakbone"><vers num="7.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1548" published="2005-05-14" seq="2005-1548" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in index.php in Advanced Guestbook 2.3.1 allows remote attackers to execute arbitrary SQL commands via the entry parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111566565621193&amp;w=2">20050508 Advanced Guestbook 2.3.1</ref><ref source="BID" url="http://www.securityfocus.com/bid/13548">13548</ref></refs><vuln_soft><prod name="Advanced Guestbook" vendor="Advanced Guestbook"><vers num="2.3.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1549" published="2005-05-14" seq="2005-1549" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in easymsgb.pl in Easy Message Board allows remote attackers to read arbitrary files via a .. (dot dot) in the print parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111566691005844&amp;w=2">20050508 Easy Message Board Directory Traversal and Remote Command</ref><ref source="MISC" url="http://www.soulblack.com.ar/repo/papers/easymsgb_advisory.txt">http://www.soulblack.com.ar/repo/papers/easymsgb_advisory.txt</ref><ref source="BID" url="http://www.securityfocus.com/bid/13551">13551</ref><ref source="OSVDB" url="http://www.osvdb.org/16162">16162</ref></refs><vuln_soft><prod name="Easy Message Board" vendor="Colored Scripts"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1550" published="2005-05-14" seq="2005-1550" severity="High" type="CVE"><desc><descript source="cve">easymsgb.pl in Easy Message Board allows remote attackers to execute arbitrary commands via shell metacharacters in the print parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111566691005844&amp;w=2">20050508 Easy Message Board Directory Traversal and Remote Command</ref><ref source="MISC" url="http://www.soulblack.com.ar/repo/papers/easymsgb_advisory.txt">http://www.soulblack.com.ar/repo/papers/easymsgb_advisory.txt</ref><ref source="BID" url="http://www.securityfocus.com/bid/13555">13555</ref><ref source="OSVDB" url="http://www.osvdb.org/16163">16163</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15295">15295</ref></refs><vuln_soft><prod name="Easy Message Board" vendor="Colored Scripts"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-08-16" name="CVE-2005-1551" published="2005-05-14" seq="2005-1551" severity="Medium" type="CVE"><desc><descript source="cve">Sophos Anti-Virus 3.93 does not check downloaded files for viruses when they have only been written, which creates a race condition and may allow remote attackers to bypass virus protection if the file is executed before the antivirus starts on system reboot.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><race/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111566827411376&amp;w=2">20050509 Viruses can evade Sophos Anti-Virus</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20519">sophos-download-virus-undetected(20519)</ref></refs><vuln_soft><prod name="Sophos Anti-Virus" vendor="Sophos"><vers num="3.93"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1552" published="2005-05-14" seq="2005-1552" severity="Medium" type="CVE"><desc><descript source="cve">GeoVision Digital Video Surveillance System 6.04, 6.1 and 7.0, when set to create JPEG images, does not properly protect an image even when a password and username is assigned, which may allow remote attackers to gain sensitive information via a direct request to the image.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111574131105737&amp;w=2">20050510 Esqo advisory: GeoVision Digital Video Surveillance System - Multiple authentication issues</ref><ref adv="1" source="MISC" url="http://www.esqo.com/research/advisories/2005/100505-1.txt">http://www.esqo.com/research/advisories/2005/100505-1.txt</ref><ref source="BID" url="http://www.securityfocus.com/bid/13571">13571</ref><ref source="OSVDB" url="http://www.osvdb.org/16340">16340</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15330">15330</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20537">geovision-authentication(20537)</ref></refs><vuln_soft><prod name="Digital Surveillance System" vendor="GeoVision"><vers num="6.0.4"/><vers num="6.1"/><vers num="7.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1553" published="2005-05-14" seq="2005-1553" severity="High" type="CVE"><desc><descript source="cve">GeoVision Digital Video Surveillance System 6.04, 6.1 and 7.0 uses a weak encryption scheme to encrypt passwords, which allows remote attackers to obtain the password via sniffing.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111574131105737&amp;w=2">20050510 Esqo advisory: GeoVision Digital Video Surveillance System - Multiple authentication issues</ref><ref patch="1" source="MISC" url="http://www.esqo.com/research/advisories/2005/100505-1.txt">http://www.esqo.com/research/advisories/2005/100505-1.txt</ref><ref source="OSVDB" url="http://www.osvdb.org/16341">16341</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20538">geovision-authentication-plaintext(20538)</ref></refs><vuln_soft><prod name="Digital Surveillance System" vendor="GeoVision"><vers num="6.0.4"/><vers num="6.1"/><vers num="7.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-22" name="CVE-2005-1554" published="2005-05-14" seq="2005-1554" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in view_user.php in WowBB 1.6, 1.61, and 1.62 allows remote attackers to execute arbitrary SQL commands via the sort_by parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111575905112831&amp;w=2">20050510 WowBB view_user.php SQL Injection Vulnerability</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/13569">13569</ref><ref source="OSVDB" url="http://www.osvdb.org/16543">16543</ref><ref source="SECUNIA" url="http://secunia.com/advisories/12843">12843</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20565">wowbb-viewuser-sql-injection(20565)</ref></refs><vuln_soft><prod name="WowBB Web Forum" vendor="WowBB"><vers num="1.6"/><vers num="1.61"/><vers num="1.62"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1555" published="2005-05-10" seq="2005-1555" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in the JRun Web Server in ColdFusion MX 7.0 allows remote attackers to inject arbitrary script or HTML via the URL, which is not properly quoted in the resulting default 404 error page.</descript></desc><loss_types><int/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CONFIRM" url="http://www.macromedia.com/devnet/security/security_zone/mpsb05-03.html">http://www.macromedia.com/devnet/security/security_zone/mpsb05-03.html</ref><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111575500403231&amp;w=2">20050510 New Macromedia Security Zone Bulletin Posted</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/20550">coldfusion-mx7-default-page-xss(20550)</ref></refs><vuln_soft><prod name="ColdFusion MX" vendor="Macromedia"><vers num="7.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1556" published="2005-05-14" seq="2005-1556" severity="Medium" type="CVE"><desc><descript source="cve">Gamespy cd-key validation system allows remote attackers to cause a denial of service (cd-key already in use) by capturing and replaying a cd-key authorization session.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2005-05/0065.html">20050504 Gamespy cd-key validation system: </ref><ref adv="1" source="Luigi Auriemma" url="http://aluigi.altervista.org/adv/gskeyinuse-adv.txt"></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/15254">15254</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/20417">gamespy-sdk-cdkey-mult-games-dos(20417)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111575820116969&amp;w=2">20050510 Gamespy cd-key validation system: &quot;Cd-key in use&quot; DoS versus many games</ref></refs><vuln_soft><prod name="GameSpy SDK CD-Key Validation Toolkit" vendor="GameSpy"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1557" published="2005-05-11" seq="2005-1557" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in WebApp Guestbook PRO 3.2.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) title or (2) content of a message.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111585232810150&amp;w=2">20050511 Guesbook Pro XSS &amp; HTML Injection</ref><ref adv="1" source="MISC" url="http://www.soulblack.com.ar/repo/papers/guesbookpro_advisory.txt">http://www.soulblack.com.ar/repo/papers/guesbookpro_advisory.txt</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/13593">13593</ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/16349">16349</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/15290/">15290</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/20544">webapp-php-guestbook-pro-xss(20544)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013940">1013940</ref></refs><vuln_soft><prod name="Guestbook Pro" vendor="PixySoft"><vers num="3.2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1558" published="2005-05-11" seq="2005-1558" severity="High" type="CVE"><desc><descript source="cve">The web module in Neteyes Nexusway allows remote attackers to bypass authentication and gain administrator privileges by setting the cyclone500_auth cookie.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111585017832066&amp;w=2">20050511 [Scan Associates Advisory] Neteyes Nexusway multiple vulnerability</ref><ref adv="1" source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2005-05/0225.html">20050510 [Scan Associates Advisory] Neteyes Nexusway multiple vulnerability</ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/16446">16446</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/15150">15150</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/20554">nexusway-configuration-modification(20554)</ref></refs><vuln_soft><prod name="Nexusway" vendor="Neteyes"><vers num="805"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1559" published="2005-05-11" seq="2005-1559" severity="High" type="CVE"><desc><descript source="cve">The web module in Neteyes Nexusway allows remote attackers to execute arbitrary commands via hex-encoded shell metacharacters in the ip parameter for (1) nslookup.cgi or (2) ping.cgi.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111585017832066&amp;w=2">20050511 [Scan Associates Advisory] Neteyes Nexusway multiple vulnerability</ref><ref adv="1" source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-May/033945.html">20050510 [Scan Associates Advisory] Neteyes Nexusway multiple vulnerability</ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/16448">16448</ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/16449">16449</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/15150">15150</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/20557">nexusway-web-command-execution(20557)</ref></refs><vuln_soft><prod name="Nexusway" vendor="Neteyes"><vers num="805"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1560" published="2005-05-11" seq="2005-1560" severity="High" type="CVE"><desc><descript source="cve">The SSH module in Neteyes Nexusway allows remote attackers to execute arbitrary commands via shell metacharacters in arguments to certain commands, as demonstrated using ping and traceroute.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111585017832066&amp;w=2">20050511 [Scan Associates Advisory] Neteyes Nexusway multiple vulnerability</ref><ref adv="1" source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-May/033945.html">20050510 [Full-disclosure] [Scan Associates Advisory] Neteyes Nexusway multiple vulnerability</ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/16447">16447</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/15150">15150</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/20555">nexusway-ssh-command-execution(20555)</ref></refs><vuln_soft><prod name="Nexusway" vendor="Neteyes"><vers num="805"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1561" published="2005-05-11" seq="2005-1561" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in post.asp in MaxWebPortal 1.3.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) mod, (2) M, or (3) type parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111584883727605&amp;w=2">20050511 [HSC Security Group] MaxWebPortal - Multiple SQL injection/XSS</ref><ref adv="1" source="MISC" url="http://www.hackerscenter.com/archive/view.asp?id=2542">http://www.hackerscenter.com/archive/view.asp?id=2542</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/13601">13601</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/15329">15329</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/20560">maxwebportal-postasp-xss(20560)</ref><ref source="OSVDB" url="http://www.osvdb.org/16501">16501</ref></refs><vuln_soft><prod name="MaxWebPortal" vendor="MaxWebPortal"><vers num="1.3.5"/><vers num="1.3.3"/><vers num="1.3.2"/><vers num="1.3.1"/><vers num="1.3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-06-15" name="CVE-2005-1562" published="2005-05-11" seq="2005-1562" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in MaxWebPortal 1.3.5 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) fpassword parameter to inc_functions.asp, (2) txtAddress, (3) message, or (4) subject parameter to post_info.asp, (5) andor parameter to search.asp, (6) verkey parameter to pop_profile.asp, or (7) Remove or (8) Delete parameter to pm_delete2.asp.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111584883727605&amp;w=2">20050511 [HSC Security Group] MaxWebPortal - Multiple SQL injection/XSS</ref><ref adv="1" source="MISC" url="http://www.hackerscenter.com/archive/view.asp?id=2542">http://www.hackerscenter.com/archive/view.asp?id=2542</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/13601">13601</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/15329">15329</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/20562">maxwebportal-postasp-sql-injection(20562)</ref><ref source="OSVDB" url="http://www.osvdb.org/16502">16502</ref><ref source="OSVDB" url="http://www.osvdb.org/16503">16503</ref><ref source="OSVDB" url="http://www.osvdb.org/16504">16504</ref><ref source="OSVDB" url="http://www.osvdb.org/16506">16506</ref><ref source="OSVDB" url="http://www.osvdb.org/16510">16510</ref></refs><vuln_soft><prod name="MaxWebPortal" vendor="MaxWebPortal"><vers num="2.0"/><vers num="1.31"/><vers num="1.30"/><vers num="1.3.5"/><vers num="1.3.3"/><vers num="1.3.2"/><vers num="1.3.1"/><vers num="1.3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1563" published="2005-05-14" seq="2005-1563" severity="Medium" type="CVE"><desc><descript source="cve">Bugzilla 2.10 through 2.18, 2.19.1, and 2.19.2 displays a different error message depending on whether a product exists or not, which allows remote attackers to determine hidden products.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111592031902962&amp;w=2">20050512 Security Advisory for Bugzilla 2.18, 2.19.2, and 2.16.8</ref><ref adv="1" patch="1" source="CONFIRM" url="http://www.bugzilla.org/security/2.16.8/">http://www.bugzilla.org/security/2.16.8/</ref><ref adv="1" patch="1" source="CONFIRM" url="https://bugzilla.mozilla.org/show_bug.cgi?id=287109">https://bugzilla.mozilla.org/show_bug.cgi?id=287109</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/0533">ADV-2005-0533</ref><ref adv="1" patch="1" source="OSVDB" url="http://www.osvdb.org/16425">16425</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/15338">15338</ref><ref source="BID" url="http://www.securityfocus.com/bid/13606">13606</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/index.php?id=a&amp;anuncio=001040">CLSA-2005:1040</ref></refs><vuln_soft><prod name="Bugzilla" vendor="Mozilla"><vers num="2.19.2"/><vers num="2.19.1"/><vers num="2.18.1"/><vers num="2.18"/><vers num="2.16.10"/><vers num="2.16.9"/><vers num="2.16.8"/><vers num="2.16.7"/><vers num="2.16.6"/><vers num="2.16.5"/><vers num="2.16.4"/><vers num="2.16.3"/><vers num="2.16.2"/><vers num="2.16.1"/><vers num="2.16"/><vers num="2.14.5"/><vers num="2.14.4"/><vers num="2.14.3"/><vers num="2.14.2"/><vers num="2.14.1"/><vers num="2.14"/><vers num="2.12"/><vers num="2.10"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2008-06-20" name="CVE-2005-1564" published="2005-05-12" seq="2005-1564" severity="High" type="CVE"><desc><descript source="cve">post_bug.cgi in Bugzilla 2.10 through 2.18, 2.19.1, and 2.19.2 allows remote authenticated users to &quot;enter bugs into products that are closed for bug entry&quot; by modifying the URL to specify the name of the product.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111592031902962&amp;w=2">20050512 Security Advisory for Bugzilla 2.18, 2.19.2, and 2.16.8</ref><ref adv="1" patch="1" source="CONFIRM" url="http://www.bugzilla.org/security/2.16.8/">http://www.bugzilla.org/security/2.16.8/</ref><ref adv="1" patch="1" source="CONFIRM" url="https://bugzilla.mozilla.org/show_bug.cgi?id=287109">https://bugzilla.mozilla.org/show_bug.cgi?id=287109</ref><ref adv="1" patch="1" source="OSVDB" url="http://www.osvdb.org/16426">16426</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/15338">15338</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/42797">bugzilla-postbug-weak-security(42797)</ref></refs><vuln_soft><prod name="Bugzilla" vendor="Mozilla"><vers num="2.19.2"/><vers num="2.19.1"/><vers num="2.18 rc2"/><vers num="2.18 rc1"/><vers num="2.17.7"/><vers num="2.17.6"/><vers num="2.17.5"/><vers num="2.17.4"/><vers num="2.17.3"/><vers num="2.17.1"/><vers num="2.17"/><vers num="2.16.5"/><vers num="2.16.4"/><vers num="2.16.3"/><vers num="2.16.2"/><vers num="2.16.1"/><vers num="2.16"/><vers num="2.14.5"/><vers num="2.14.4"/><vers num="2.14.3"/><vers num="2.14.2"/><vers num="2.14.1"/><vers num="2.14"/><vers num="2.12"/><vers num="2.10"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1565" published="2005-05-12" seq="2005-1565" severity="Medium" type="CVE"><desc><descript source="cve">Bugzilla 2.17.1 through 2.18, 2.19.1, and 2.19.2, when a user is prompted to log in while attempting to view a chart, displays the password in the URL, which may allow local users to gain sensitive information from web logs or browser history.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111592031902962&amp;w=2">20050512 Security Advisory for Bugzilla 2.18, 2.19.2, and 2.16.8</ref><ref adv="1" patch="1" source="CONFIRM" url="https://bugzilla.mozilla.org/show_bug.cgi?id=287436">https://bugzilla.mozilla.org/show_bug.cgi?id=287436</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/0533">ADV-2005-0533</ref><ref adv="1" patch="1" source="OSVDB" url="http://www.osvdb.org/16427">16427</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/15338">15338</ref><ref source="BID" url="http://www.securityfocus.com/bid/13605">13605</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/index.php?id=a&amp;anuncio=001040">CLSA-2005:1040</ref></refs><vuln_soft><prod name="Bugzilla" vendor="Mozilla"><vers num="2.19.2"/><vers num="2.19.1"/><vers num="2.18 rc2"/><vers num="2.18 rc1"/><vers num="2.17.7"/><vers num="2.17.6"/><vers num="2.17.5"/><vers num="2.17.4"/><vers num="2.17.3"/><vers num="2.17.1"/><vers num="2.17"/><vers num="2.16.5"/><vers num="2.16.4"/><vers num="2.16.3"/><vers num="2.16.2"/><vers num="2.16.1"/><vers num="2.16"/><vers num="2.14.5"/><vers num="2.14.4"/><vers num="2.14.3"/><vers num="2.14.2"/><vers num="2.14.1"/><vers num="2.14"/><vers num="2.12"/><vers num="2.10"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1566" published="2005-05-14" seq="2005-1566" severity="High" type="CVE"><desc><descript source="cve">Acrowave AAP-3100AR wireless router allows remote attackers to bypass authentication by pressing CTRL-C at the username or password prompt in a telnet session, which causes the shell to crash and restart, then leave the user in the new shell.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111592452331677&amp;w=2">20050512 Acrowave AAP-3100AR authetication bypass</ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/16445">16445</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/15343">15343</ref></refs><vuln_soft><prod name="WLAN AP + ADSL Router" vendor="Arcowave Systems"><vers num="AAP_3100AR"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1567" published="2005-05-12" seq="2005-1567" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in topic.php in DirectTopics 2.1 and 2.2 allows remote attackers to execute arbitrary SQL commands via the topic parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111592417803514&amp;w=2">20050512 Directtopics Multiple Vulnerabilities (Security Advisory)</ref></refs><vuln_soft><prod name="DirectTopics" vendor="DirectTopics"><vers num="final"/><vers num="2.1"/><vers num="2.2"/><vers num="beta"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1568" published="2005-05-12" seq="2005-1568" severity="Medium" type="CVE"><desc><descript source="cve">topic.php in DirectTopics 2.1 and 2.2 allows remote attackers to obtain sensitive information via an invalid topic parameter, which reveals the path in an error message.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111592417803514&amp;w=2">20050512 Directtopics Multiple Vulnerabilities (Security Advisory)</ref></refs><vuln_soft><prod name="DirectTopics" vendor="DirectTopics"><vers num="final"/><vers num="2.1"/><vers num="2.2"/><vers num="beta"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1569" published="2005-05-14" seq="2005-1569" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in DirectTopics 2.1 and 2.2 allows remote attackers to inject arbitrary web script via a javascript: URL in (1) a thread or (2) an IMG tag.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111592417803514&amp;w=2">20050512 Directtopics Multiple Vulnerabilities (Security Advisory)</ref></refs><vuln_soft><prod name="DirectTopics" vendor="DirectTopics"><vers num="2.1"/><vers num="2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1570" published="2005-05-14" seq="2005-1570" severity="Medium" type="CVE"><desc><descript source="cve">forum.asp in bttlxeForum 2.0 allows remote attackers to obtain full path information via a certain hex-encoded argument to the page parameter, possibly due to a SQL injection vulnerability.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="SECTRACK" url="http://securitytracker.com/id?1013934">1013934</ref></refs><vuln_soft><prod name="bttlxeForum" vendor="Battleaxe Software"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1571" published="2005-05-14" seq="2005-1571" severity="Medium" type="CVE"><desc><descript source="cve">Multiple directory traversal vulnerabilities in ShowOff! 1.5.4 allow remote attackers to read arbitrary files via &quot;..&quot; sequences in arguments to the (1) ShowAlbum, (2) ShowVideo, or (3) ShowGraphic scripts.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/><input/></vuln_types><range><network/></range><refs><ref source="OSVDB" url="http://www.osvdb.org/16332">16332</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/15300">15300</ref></refs><vuln_soft><prod name="ShowOff Digital Media Software" vendor="Wenig and Spitzer-Williams"><vers num="1.5.4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1572" published="2005-05-11" seq="2005-1572" severity="Medium" type="CVE"><desc><descript source="cve">ShowOff! 1.5.4 allows remote attackers to cause a denial of service (server crash) via a malformed request to port 8083.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="OSVDB" url="http://www.osvdb.org/16333">16333</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/15300">15300</ref></refs><vuln_soft><prod name="ShowOff Digital Media Software" vendor="Wenig and Spitzer-Williams"><vers num="1.5.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1573" published="2005-05-11" seq="2005-1573" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in admin_login.asp for ASP Virtual News Manager allows remote attackers to execute arbitrary SQL commands via the password parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://www.under9round.com/avn13.txt">http://www.under9round.com/avn13.txt</ref><ref adv="1" source="SECTRACK" url="http://securitytracker.com/id?1013933">1013933</ref></refs><vuln_soft><prod name="ASP Virtual News Manager" vendor="Darrel ONeil"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1574" published="2005-05-14" seq="2005-1574" severity="High" type="CVE"><desc><descript source="cve">Windows Media Player 9 and 10, in certain cases, allows content protected by Windows Media Digital Rights Management (WMDRM) to redirect the user to a web site to obtain a license, even when the &quot;Acquire licenses automatically for protected content&quot; setting is not enabled.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;892313">892313</ref></refs><vuln_soft><prod name="Windows Media Player" vendor="Microsoft"><vers num="9"/><vers num="10"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1575" published="2005-05-14" seq="2005-1575" severity="Medium" type="CVE"><desc><descript source="cve">The file download dialog in Mozilla Firefox 0.10.1 and 1.0 for Windows allows remote attackers to hide the real file types of downloaded files via the Content-Type HTTP header and a filename containing whitespace, dots, or ASCII byte 160.</descript></desc><loss_types><int/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://secunia.com/secunia_research/2004-11/advisory/">http://secunia.com/secunia_research/2004-11/advisory/</ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/16431">16431</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/12979">12979</ref></refs><vuln_soft><prod name="Firefox" vendor="Mozilla"><vers num="1.0"/><vers num="0.10.1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1576" published="2005-05-12" seq="2005-1576" severity="Low" type="CVE"><desc><descript source="cve">The file download dialog in Mozilla Firefox 0.10.1 and 1.0 for Windows uses the Content-Type HTTP header to determine the file type, but saves the original file extension when &quot;Save to Disk&quot; is selected, which allows remote attackers to hide the real file types of downloaded files.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="MISC" url="http://secunia.com/secunia_research/2004-11/advisory/">http://secunia.com/secunia_research/2004-11/advisory/</ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/16432">16432</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/12979">12979</ref></refs><vuln_soft><prod name="Firefox" vendor="Mozilla"><vers num="0.10.1"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1577" published="2005-05-14" seq="2005-1577" severity="High" type="CVE"><desc><descript source="cve">APG Technology ClassMaster does not properly restrict access to sensitive folders, which allows remote attackers to access folders via a network share.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://www.securiteam.com/windowsntfocus/5SP0D0AFPQ.html">http://www.securiteam.com/windowsntfocus/5SP0D0AFPQ.html</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/13604">13604</ref></refs><vuln_soft><prod name="Classmaster" vendor="APG Technology"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1578" published="2005-05-13" seq="2005-1578" severity="Low" type="CVE"><desc><descript source="cve">EnCase Forensic Edition 4.18a does not support Device Configuration Overlays (DCO), which allows attackers to hide information without detection.</descript></desc><loss_types><int/></loss_types><vuln_types><other/></vuln_types><range><local/></range><refs><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/15340">15340</ref></refs><vuln_soft><prod name="EnCase" vendor="Guidance Software"><vers num="4.18a"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1579" published="2005-05-12" seq="2005-1579" severity="Medium" type="CVE"><desc><descript source="cve">Apple QuickTime Player 7.0 on Mac OS X 10.4 allows remote attackers to obtain sensitive information via a .mov file with a Quartz Composer composition (.qtz) file that uses certain patches to read local information, then other patches to send the information to the attacker.</descript></desc><loss_types><conf/></loss_types><vuln_types><env/></vuln_types><range><network/></range><refs><ref adv="1" source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2005-05/0265.html">20050511 [DR018] Quartz Composer / QuickTime 7 information leakage</ref><ref adv="1" source="MISC" url="http://remahl.se/david/vuln/018">http://remahl.se/david/vuln/018</ref><ref adv="1" source="MLIST" url="http://lists.apple.com/archives/quartzcomposer-dev/2005/May/msg00250.html">[quartzcomposer-dev] 20050510 Quartz Quicktime embedded in remote webpages...</ref><ref adv="1" source="MLIST" url="http://lists.apple.com/archives/quartzcomposer-dev/2005/May/msg00263.html">[quartzcomposer-dev] 20050511 Re: Quartz Quicktime embedded in remote webpages...</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/13603">13603</ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/16376">16376</ref><ref adv="1" source="SECTRACK" url="http://securitytracker.com/id?1013961">1013961</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/15307">15307</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/May/msg00006.html">APPLE-SA-2005-05-31</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/0531">ADV-2005-0531</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=301714"></ref></refs><vuln_soft><prod name="Quicktime" vendor="Apple"><vers num="7.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1580" published="2005-05-11" seq="2005-1580" severity="High" type="CVE"><desc><descript source="cve">users.ini.php in BoastMachine 3.0 does not properly restrict the types of files that can be uploaded, which allows remote attackers to execute arbitrary code.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://www.kernelpanik.org/docs/kernelpanik/bmachines.txt">http://www.kernelpanik.org/docs/kernelpanik/bmachines.txt</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/13600">13600</ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/16334">16334</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/15312">15312</ref></refs><vuln_soft><prod name="BoastMachine" vendor="BoastMachine"><vers edition="platinum" num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1581" published="2005-05-14" seq="2005-1581" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Bug Report 1.0 allows remote attackers to inject arbitrary web script or HTML via various fields to bug_report.php, which are not filtered or quoted when processed by bug_list.php or admin/index.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="SECTRACK" url="http://securitytracker.com/id?1013957">1013957</ref></refs><vuln_soft><prod name="Bug Report" vendor="Eric Fichot"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1582" published="2005-05-14" seq="2005-1582" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in index.php for 1Two News 1.0 allows remote attackers to inject arbitrary web script or HTML via the (1) nom, (2) email, (3) siteweb, or (4) commentaire variables.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="SECTRACK" url="http://securitytracker.com/id?1013960">1013960</ref></refs><vuln_soft><prod name="1Two News" vendor="1Two"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1583" published="2005-05-14" seq="2005-1583" severity="Medium" type="CVE"><desc><descript source="cve">1Two News 1.0 allows remote attackers to (1) delete images for new stories via a direct request to admin/delete.php or (2) upload arbitrary images via a direct request to admin/upload.php.</descript></desc><loss_types><int/></loss_types><vuln_types><access/><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="SECTRACK" url="http://securitytracker.com/id?1013960">1013960</ref></refs><vuln_soft><prod name="1Two News" vendor="1Two"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1584" published="2005-05-14" seq="2005-1584" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in index.php for Quick.Forum 2.1.6 allows remote attackers to inject arbitrary web script or HTML via the topic field in a NewTopic action.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://lostmon.blogspot.com/2005/05/quickforum-topic-field-xss-and-page.html">http://lostmon.blogspot.com/2005/05/quickforum-topic-field-xss-and-page.html</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/13602">13602</ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/16327">16327</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/15200">15200</ref></refs><vuln_soft><prod name="Quick.Forum" vendor="Open Solution"><vers num="2.1.6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-25" name="CVE-2005-1585" published="2005-05-11" seq="2005-1585" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in Quick.Forum 2.1.6 allow remote attackers to execute arbitrary SQL commands via the (1) iCategory or (2) page parameter to index.php, or (3) iCategory parameter in the query string to the forum directory.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://lostmon.blogspot.com/2005/05/quickforum-topic-field-xss-and-page.html">http://lostmon.blogspot.com/2005/05/quickforum-topic-field-xss-and-page.html</ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/16326">16326</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/15200">15200</ref></refs><vuln_soft><prod name="Quick.Forum" vendor="Open Solution"><vers num="2.1.6"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1586" published="2005-05-14" seq="2005-1586" severity="Medium" type="CVE"><desc><descript source="cve">Quick.Forum 2.1.6 stores potentially sensitive information such as usernames, banned IP addresses, censored words, and backups under the web document root, which allows remote attackers to obtain that information via a direct request to (1) db/users.txt, (2) db/banList.txt, (3) db/censureWords.txt, or (4) backup files.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://lostmon.blogspot.com/2005/05/quickforum-topic-field-xss-and-page.html">http://lostmon.blogspot.com/2005/05/quickforum-topic-field-xss-and-page.html</ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/16328">16328</ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/16329">16329</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/15200">15200</ref></refs><vuln_soft><prod name="Quick.Forum" vendor="Open Solution"><vers num="2.1.6"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1587" published="2005-05-14" seq="2005-1587" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in index.php for Quick.cart 0.3.0 allows remote attackers to inject arbitrary web script or HTML via the sWord parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://lostmon.blogspot.com/2005/05/quickcart-sword-variable-xss-and.html">http://lostmon.blogspot.com/2005/05/quickcart-sword-variable-xss-and.html</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/13599">13599</ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/16330">16330</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/15297">15297</ref><ref source="" url="http://opensolution.org/forum/?p=readTopic&amp;nr=948"></ref></refs><vuln_soft><prod name="Quick.cart" vendor="Open Solution"><vers num="0.3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1588" published="2005-05-11" seq="2005-1588" severity="High" type="CVE"><desc><descript source="cve">** DISPUTED **  SQL injection vulnerability in index.php for Quick.cart 0.3.0 allows remote attackers to execute arbitrary SQL commands via the iCategory parameter.  NOTE: the vendor has privately disputed this issue, saying that Quick.cart does not even use SQL and therefore can not be vulnerable to SQL injection.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://lostmon.blogspot.com/2005/05/quickcart-sword-variable-xss-and.html">http://lostmon.blogspot.com/2005/05/quickcart-sword-variable-xss-and.html</ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/16331">16331</ref></refs><vuln_soft><prod name="Quick.Cart" vendor="Open Solution"><vers num="0.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-25" name="CVE-2005-1589" published="2005-05-17" seq="2005-1589" severity="High" type="CVE"><desc><descript source="cve">The pkt_ioctl function in the pktcdvd block device ioctl handler (pktcdvd.c) in Linux kernel 2.6.12-rc4 and earlier calls the wrong function before passing an ioctl to the block device, which crosses security boundaries by making kernel address space accessible from user space and allows local users to cause a denial of service and possibly execute arbitrary code, a similar vulnerability to CVE-2005-1264.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="MLIST" url="http://marc.theaimsgroup.com/?l=linux-kernel&amp;m=111630531515901&amp;w=2">[linux-kernel] 20050517 [PATCH] Fix root hole in pktcdvd</ref><ref adv="1" patch="1" source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2005-q2/0045.html">20050516 Linux kernel pktcdvd and rawdevice ioctl break user space limit vulnerability</ref><ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2005-q2/0046.html">20050517 Re: Linux kernel pktcdvd and rawdevice ioctl break user space limit vulnerability</ref><ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2005-q2/0047.html">20050517 Linux kernel pktcdvd ioctl break user space limit vulnerability [corrected]</ref><ref source="CONFIRM" url="http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.11.10">http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.11.10</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/0557">ADV-2005-0557</ref><ref source="MANDRAKE" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2005:219">MDKSA-2005:219</ref><ref source="BID" url="http://www.securityfocus.com/bid/13651">13651</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17826">17826</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:219">MDKSA-2005:219</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.6.12-rc4" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-25" name="CVE-2005-1590" published="2005-05-16" seq="2005-1590" severity="Medium" type="CVE"><desc><descript source="cve">The Altiris Client Service for Windows (ACLIENT.EXE) 6.0.88 allows local users to disable password protection and access the administrative interface by finding and showing the &quot;Altiris Client Service&quot; hidden window, disabling the password protection, disabling the &quot;Hide client tray icon box&quot; option, then opening the AClient tray icon and using the View Log File option, a different vulnerability than CVE-2004-2070.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/><design/></vuln_types><range><local/></range><refs><ref adv="1" source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2005-04/0614.html">20050427 Privilege escalation and password protection bypass in Altiris Client Service for Windows (Version 6.0.88)</ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/15897">15897</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/15159">15159</ref></refs><vuln_soft><prod name="Client Service" vendor="Altiris"><vers num="6.0.88"/></prod><prod name="Deployment Solution" vendor="Altiris"><vers edition="SP1" num="5.6"/><vers edition="SP1 Hotfix E" num="5.6"/><vers num="5.6.181"/><vers num="6"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1591" published="2005-05-16" seq="2005-1591" severity="Medium" type="CVE"><desc><descript source="cve">Unknown vulnerability in NIS+ on Solaris 7, 8, and 9 allows remote attackers to cause a denial of service (rpc.nisd disabled and NIS+ unavailable) via unknown vectors.</descript></desc><loss_types><avail/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57780-1">57780</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/0492">ADV-2005-0492</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers num="7.0"/><vers edition="x86" num="7.0"/><vers num="8.0"/><vers edition="x86" num="8.0"/><vers num="8.1"/><vers num="8.2"/><vers edition="SPARC" num="9.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1592" published="2005-05-16" seq="2005-1592" severity="High" type="CVE"><desc><descript source="cve">Multiple &quot;javascript vulerabilities in BB code&quot; in BirdBlog before 1.3.1 allow remote attackers to inject arbitrary Javascript.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="CONFIRM" url="http://sourceforge.net/project/shownotes.php?release_id=324788">http://sourceforge.net/project/shownotes.php?release_id=324788</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/15206">15206</ref></refs><vuln_soft><prod name="BirdBlog" vendor="BirdBlog"><vers num="1.3.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1593" published="2005-05-16" seq="2005-1593" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in catalog.php for CodeThat ShoppingCart 1.3.1 allows remote attackers to inject arbitrary web script or HTML via the id parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://lostmon.blogspot.com/2005/05/codethat-shoppingcart-critical.html">http://lostmon.blogspot.com/2005/05/codethat-shoppingcart-critical.html</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/13560">13560</ref><ref source="OSVDB" url="http://www.osvdb.org/16155">16155</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/15251">15251</ref><ref adv="1" source="SECTRACK" url="http://securitytracker.com/id?1013924">1013924</ref></refs><vuln_soft><prod name="ShoppingCart" vendor="CodeThat"><vers num="1.3.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1594" published="2005-05-16" seq="2005-1594" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in catalog.php for CodeThat ShoppingCart 1.3.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://lostmon.blogspot.com/2005/05/codethat-shoppingcart-critical.html">http://lostmon.blogspot.com/2005/05/codethat-shoppingcart-critical.html</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/13560">13560</ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/16156">16156</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/15251">15251</ref><ref adv="1" source="SECTRACK" url="http://securitytracker.com/id?1013924">1013924</ref></refs><vuln_soft><prod name="ShoppingCart" vendor="CodeThat"><vers num="1.3.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1595" published="2005-05-16" seq="2005-1595" severity="Medium" type="CVE"><desc><descript source="cve">CodeThat ShoppingCart 1.3.1 stores config.ini under the web root, which allows remote attackers to obtain sensitive information via a direct request.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/><config/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://lostmon.blogspot.com/2005/05/codethat-shoppingcart-critical.html">http://lostmon.blogspot.com/2005/05/codethat-shoppingcart-critical.html</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/13560">13560</ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/16157">16157</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/15251">15251</ref><ref adv="1" source="SECTRACK" url="http://securitytracker.com/id?1013924">1013924</ref></refs><vuln_soft><prod name="ShoppingCart" vendor="CodeThat"><vers num="1.3.1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1596" published="2005-05-16" seq="2005-1596" severity="High" type="CVE"><desc><descript source="cve">index.php in Fusion SBX 1.2 and earlier does not properly use the extract function, which allows remote attackers to bypass authentication by setting the is_logged parameter or execute arbitrary code via the maxname2 parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://www.securiteam.com/exploits/5OP042KFPU.html">http://www.securiteam.com/exploits/5OP042KFPU.html</ref><ref adv="1" source="MISC" url="http://www.exploits.co.in/Article1134.html">http://www.exploits.co.in/Article1134.html</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/0508">ADV-2005-0508</ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/16216">16216</ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/16217">16217</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/15257">15257</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/20531">fusion-islogged-authentication-bypass(20531)</ref></refs><vuln_soft><prod name="SBX" vendor="Fusion"><vers num="1.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1597" published="2005-05-16" seq="2005-1597" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in (1) search.php and (2) topics.php for Invision Power Board (IPB) 2.0.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the highlite parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="MISC" url="http://www.gulftech.org/?node=research&amp;article_id=00073-05052005">http://www.gulftech.org/?node=research&amp;article_id=00073-05052005</ref><ref patch="1" source="CONFIRM" url="http://forums.invisionpower.com/index.php?showtopic=168016">http://forums.invisionpower.com/index.php?showtopic=168016</ref><ref source="BID" url="http://www.securityfocus.com/bid/13534">13534</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/0487">ADV-2005-0487</ref><ref source="OSVDB" url="http://www.osvdb.org/16298">16298</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013907">1013907</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15265">15265</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20445">invision-powerboard-highlite-xss(20445)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111539908705851&amp;w=2">20050506 Multiple Vulnerabilities In Invision Power Board</ref></refs><vuln_soft><prod name="Invision Board" vendor="Invision Power Services"><vers num="1.0"/><vers num="1.0.1"/><vers num="1.1.1"/><vers num="1.1.2"/><vers num="1.2"/><vers num="1.3"/><vers num="2.0 PDR3"/><vers num="2.0 Alpha 3"/></prod><prod name="Invision Power Board" vendor="Invision Power Services"><vers num="2.0.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1598" published="2005-05-16" seq="2005-1598" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in Invision Power Board (IPB) 2.0.3 and earlier allows remote attackers to execute arbitrary SQL commands via a crafted cookie password hash (pass_hash) that modifies the internal $pid variable.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref patch="1" source="MISC" url="http://www.gulftech.org/?node=research&amp;article_id=00073-05052005">http://www.gulftech.org/?node=research&amp;article_id=00073-05052005</ref><ref patch="1" source="CONFIRM" url="http://forums.invisionpower.com/index.php?showtopic=168016">http://forums.invisionpower.com/index.php?showtopic=168016</ref><ref source="BID" url="http://www.securityfocus.com/bid/13529">13529</ref><ref source="" url="http://www.milw0rm.com/id.php?id=1013"></ref><ref source="" url="http://www.securiteam.com/exploits/5GP0E2KFQQ.html"></ref><ref source="OSVDB" url="http://www.osvdb.org/16297">16297</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013907">1013907</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014499">1014499</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15265">15265</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20446">invision-powerboard-login-sql-injection(20446)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111539908705851&amp;w=2">20050506 Multiple Vulnerabilities In Invision Power Board</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111712587206834&amp;w=2">20050526 Invision Power Board 1.* and 2.* Exploit (BID 13529)</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/1013">
1013</ref></refs><vuln_soft><prod name="Invision Board" vendor="Invision Power Services"><vers num="1.0"/><vers num="1.0.1"/><vers num="1.1.1"/><vers num="1.1.2"/><vers num="1.2"/><vers num="1.3"/><vers num="2.0 PDR3"/><vers num="2.0 Alpha 3"/></prod><prod name="Invision Power Board" vendor="Invision Power Services"><vers num="2.0.3"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1599" published="2005-05-16" seq="2005-1599" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Kryloff Technologies Subject Search Server (SSServer) 1.1 allows remote attackers to inject arbitrary web script or HTML via the &quot;Search For&quot; field.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/13574">13574</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013938">1013938</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15288">15288</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20558">ssserver-searchfor-xss(20558)</ref></refs><vuln_soft><prod name="Subject Search Server" vendor="Kryloff Technologies"><vers num="1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1600" published="2005-05-16" seq="2005-1600" severity="High" type="CVE"><desc><descript source="cve">A &quot;mathematical flaw&quot; in the implementation of the El Gamal signature algorithm for LibTomCrypt 1.0 to 1.0.2 allows attackers to generate valid signatures without having the private key.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.org/archive/1/397649">20050503 Secure Science Corporation Advisory CSA-056</ref><ref source="MISC" url="http://www.securiteam.com/unixfocus/5JP092AFPG.html">http://www.securiteam.com/unixfocus/5JP092AFPG.html</ref><ref source="BID" url="http://www.securityfocus.com/bid/13473">13473</ref><ref source="OSVDB" url="http://www.osvdb.org/16188">16188</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15233">15233</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20455">libtomcrypt-signature-security-bypass(20455)</ref></refs><vuln_soft><prod name="LibTomCrypt" vendor="LibTomCrypt"><vers num="1.0"/><vers num="1.0.1"/><vers num="1.0.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1601" published="2005-05-16" seq="2005-1601" severity="Medium" type="CVE"><desc><descript source="cve">MRO Maximo Self Service 4 and 5 stores certain information under the web document root using file extensions that are not processed by Tomcat, which allows remote attackers to obtain sensitive information via a direct request for the file, such as MXServer.properties.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/><env/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/397522">20050505 MRO Maximo v4 &amp; v5</ref><ref source="BID" url="http://www.securityfocus.com/bid/13508">13508</ref><ref source="OSVDB" url="http://www.osvdb.org/16161">16161</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15176">15176</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20452">maximo-information-disclosure(20452)</ref></refs><vuln_soft><prod name="Maximo Self Service" vendor="MRO Software"><vers num="4.0"/><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1602" published="2005-05-16" seq="2005-1602" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in login.asp for Net56 Browser Based File Manager 1.0 allows remote attackers to execute arbitrary SQL commands and bypass authentication via the password field.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2005-05/0134.html">20050508 Browser Based File Manager Administration Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/13547">13547</ref><ref source="OSVDB" url="http://www.osvdb.org/16544">16544</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20504">browser-based-file-mgr-sql-injection(20504)</ref></refs><vuln_soft><prod name="File Manager" vendor="Net56"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1603" published="2005-05-16" seq="2005-1603" severity="Medium" type="CVE"><desc><descript source="cve">NiteEnterprises Remote File Manager 1.0 allows remote attackers to cause a denial of service (crash) via a crafted string to TCP port 7080.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2005-05/0129.html">20050508 Server Remote File Manager DOS Exploit</ref><ref source="BID" url="http://www.securityfocus.com/bid/13550">13550</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/0501">ADV-2005-0501</ref><ref source="OSVDB" url="http://www.osvdb.org/16158">16158</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15299">15299</ref></refs><vuln_soft><prod name="Remote File Manager" vendor="NiteEnterprises"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-07" name="CVE-2005-1604" published="2005-05-16" seq="2005-1604" severity="High" type="CVE"><desc><descript source="cve">PHP Advanced Transfer Manager (phpATM) 1.21 allows remote attackers to upload arbitrary files via filenames containing multiple file extensions, as demonstrated using a filename ending in &quot;php.ns&quot;, which allows execution of arbitrary PHP code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://seclists.org/lists/bugtraq/2005/May/0075.html">20050506 PHP Advanced Transfer Manager v1.21</ref><ref source="BID" url="http://www.securityfocus.com/bid/13542">13542</ref><ref source="OSVDB" url="http://www.osvdb.org/16160">16160</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15279">15279</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/415172">20051029 uplod phpshell in PHP Advanced Transfer Manager</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/415300/30/0/threaded">20051030 Re: uplod phpshell in PHP Advanced Transfer Manager</ref></refs><vuln_soft><prod name="PHP Advanced Transfer Manager" vendor="Bugada Andrea"><vers num="1.21"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1605" published="2005-05-16" seq="2005-1605" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in the guestbook for SiteStudio 1.6 allows remote attackers to inject arbitrary web script or HTML via the name field to (1) psoft.guestbook.GuestBookServ in Standalone Site Studio or (2) E-Guest_sign.pl in Integrated Site Studio with H-Sphere.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="FULLDISC" url="http://www.derkeiler.com/Mailing-Lists/Full-Disclosure/2005-05/0154.html">20050509 SiteStudio</ref><ref patch="1" source="MISC" url="http://exploitlabs.com/files/advisories/EXPL-A-2005-008-sitestudio.txt">http://exploitlabs.com/files/advisories/EXPL-A-2005-008-sitestudio.txt</ref><ref patch="1" source="CONFIRM" url="http://www.psoft.net/SS/ss_16_security_update_guestbook.html">http://www.psoft.net/SS/ss_16_security_update_guestbook.html</ref><ref patch="1" source="CONFIRM" url="http://www.psoft.net/misc/hsphere_winbox_security_update_guestbook.html">http://www.psoft.net/misc/hsphere_winbox_security_update_guestbook.html</ref><ref source="BID" url="http://www.securityfocus.com/bid/13554">13554</ref><ref source="OSVDB" url="http://www.osvdb.org/16240">16240</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/15286">15286</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/20496">sitestudio-guestbook-xss(20496)</ref></refs><vuln_soft><prod name="SiteStudio" vendor="Positive Software"><vers num="1.6 Final"/><vers num="1.6 Patch 1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1606" published="2005-05-16" seq="2005-1606" severity="Medium" type="CVE"><desc><descript source="cve">H-Sphere Winbox 2.4.2 and 2.4.3 RC1 stores sensitive information such as username and password in plaintext in world-readable log files, which allows local users to gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref patch="1" source="MISC" url="http://exploitlabs.com/files/advisories/EXPL-A-2005-007-hsphere.txt">http://exploitlabs.com/files/advisories/EXPL-A-2005-007-hsphere.txt</ref><ref patch="1" source="CONFIRM" url="http://www.psoft.net/misc/hsphere_winbox_security_update_passwd.html">http://www.psoft.net/misc/hsphere_winbox_security_update_passwd.html</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/13559">13559</ref><ref source="OSVDB" url="http://www.osvdb.org/16239">16239</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/15287">15287</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/20522">hsphere-information-disclosure(20522)</ref></refs><vuln_soft><prod name="H-Sphere Winbox" vendor="Positive Software"><vers num="2.4.2 Patch 4"/><vers num="2.4.3 RC1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1607" published="2005-05-16" seq="2005-1607" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in shop.cgi in Remote Cart allows remote attackers to inject arbitrary web script or HTML via the (1) merchant or (2) demo parameters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://www.governmentsecurity.org/forum/lofiversion/index.php/t14715.html">http://www.governmentsecurity.org/forum/lofiversion/index.php/t14715.html</ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/16454">16454</ref><ref adv="1" source="SECTRACK" url="http://securitytracker.com/id?1013903">1013903</ref></refs><vuln_soft><prod name="Remote Cart" vendor="Remote Cart"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1608" published="2005-05-16" seq="2005-1608" severity="Medium" type="CVE"><desc><descript source="cve">Multiple unknown vulnerabilities in the Blocks module in Spidean AutoTheme 1.7 and AT-Lite for PostNuke have unknown impact.</descript></desc><loss_types><int/></loss_types><range><network/></range><refs><ref patch="1" source="MISC" url="http://news.postnuke.com/Article2687.html">http://news.postnuke.com/Article2687.html</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/13539">13539</ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/16346">16346</ref><ref adv="1" patch="1" source="SECTRACK" url="http://securitytracker.com/id?1013908">1013908</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/15289">15289</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/20490">autotheme-pnadminphp-gain-access(20490)</ref></refs><vuln_soft><prod name="AutoTheme" vendor="Spidean"><vers num="1.7"/></prod><prod name="AT-Lite" vendor="Spidean"><vers num="0.8"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1609" published="2005-05-16" seq="2005-1609" severity="High" type="CVE"><desc><descript source="cve">Unknown vulnerability in Sun StorEdge 6130 Arrays (SE6130) with serial numbers between 0451AWF00G and 0513AWF00J allows local users and remote attackers to delete data.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57771-1">57771</ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/812438">VU#812438</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/13566">13566</ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/16325">16325</ref><ref adv="1" source="SECTRACK" url="http://securitytracker.com/id?1013921">1013921</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/15306">15306</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/20542">storedge-6130-array-bypass-security(20542)</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/0491">ADV-2005-0491</ref></refs><vuln_soft><prod name="StorEdge" vendor="Sun"><vers num="6130 Arrays"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1610" published="2005-05-16" seq="2005-1610" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in security.php for Tru-Zone NukeET 3.0 and 3.1 allows remote attackers to inject arbitrary web script or HTML via a base64 encoded Codigo parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="MISC" url="http://lostmon.blogspot.com/2005/05/nukeet-codigo-variable-cross-site.html">http://lostmon.blogspot.com/2005/05/nukeet-codigo-variable-cross-site.html</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/13570">13570</ref><ref adv="1" patch="1" source="OSVDB" url="http://www.osvdb.org/16214">16214</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/15332">15332</ref><ref adv="1" patch="1" source="SECTRACK" url="http://securitytracker.com/id?1013936">1013936</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/20540">nukeet-securityphp-xss(20540)</ref></refs><vuln_soft><prod name="NukeET" vendor="Tru-Zone"><vers num="3.0"/><vers num="3.1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1611" published="2005-05-16" seq="2005-1611" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in WebX in Web Crossing 5.x allows remote attackers to inject arbitrary web script or HTML via a URL with an &quot;@&quot; followed by the desired script.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://osvdb.org/ref/16/16070-webcrossing.txt">http://osvdb.org/ref/16/16070-webcrossing.txt</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/13482">13482</ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/16070">16070</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/15218">15218</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/20381">web-crossing-webx-xss(20381)</ref></refs><vuln_soft><prod name="Web Crossing" vendor="Web Crossing Inc"><vers num="5.x"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1612" published="2005-05-16" seq="2005-1612" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in read.php in Open Bulletin Board (OpenBB) 1.0.8 allows remote attackers to execute arbitrary SQL commands via the TID parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111601780332632&amp;w=2">20050513 OpenBB SQL Injection &amp; Cross-site Scripting Vulnerability</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/13624">13624</ref></refs><vuln_soft><prod name="OpenBB" vendor="OpenBB"><vers num="1.0.8"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1613" published="2005-05-16" seq="2005-1613" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in member.php in Open Bulletin Board (OpenBB) 1.0.8 allows remote attackers to inject arbitrary web script or HTML via the reverse parameter in a list action.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111601780332632&amp;w=2">20050513 OpenBB SQL Injection &amp; Cross-site Scripting Vulnerability</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/13625">13625</ref></refs><vuln_soft><prod name="OpenBB" vendor="OpenBB"><vers num="1.0.8"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1614" published="2005-05-16" seq="2005-1614" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in viewforum.php in Ultimate PHP Board (UPB) 1.8 through 1.9.6 allows remote attackers to inject arbitrary web script or HTML via the postorder parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111600262424876&amp;w=2">20050513 Ultimate PHP Board (UPB) Security Advisory</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/13621">13621</ref></refs><vuln_soft><prod name="Ultimate PHP Board" vendor="Ultimate PHP Board"><vers num="1.8"/><vers num="1.8.2"/><vers num="1.9"/><vers num="1.9.6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1615" published="2005-05-16" seq="2005-1615" severity="High" type="CVE"><desc><descript source="cve">viewforum.php in Ultimate PHP Board (UPB) 1.8 through 1.9.6 may allow remote attackers to read sensitive data via the postorder parameter, which is not properly handled by textdb.inc.php, possibly due to a SQL injection vulnerability.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111600262424876&amp;w=2">20050513 Ultimate PHP Board (UPB) Security Advisory</ref><ref source="BID" url="http://www.securityfocus.com/bid/13622">13622</ref></refs><vuln_soft><prod name="Ultimate PHP Board" vendor="Ultimate PHP Board"><vers num="1.8"/><vers num="1.8.2"/><vers num="1.9"/><vers num="1.9.6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1616" published="2005-05-16" seq="2005-1616" severity="High" type="CVE"><desc><descript source="cve">viewforum.php in Ultimate PHP Board (UPB) 1.8 through 1.9.6 allows remote attackers to obtain sensitive information via an invalid (1) id or possibly (2) postorder parameter, which reveals the path in an error message when a file can not be opened.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111600262424876&amp;w=2">20050513 Ultimate PHP Board (UPB) Security Advisory</ref></refs><vuln_soft><prod name="Ultimate PHP Board" vendor="Ultimate PHP Board"><vers num="1.8"/><vers num="1.8.2"/><vers num="1.9"/><vers num="1.9.6"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1617" published="2005-05-16" seq="2005-1617" severity="Low" type="CVE"><desc><descript source="cve">Willings WebCam and WebCam Lite 2.8 and earlier stores the password in memory in plaintext, which allows local users to gain sensitive information.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111601481221137&amp;w=2">20050513 Willings WebCam - Password Disclosure Issue</ref></refs><vuln_soft><prod name="WebCam Lite" vendor="Willings"><vers num="2.8" prev="1"/></prod><prod name="WebCam" vendor="Willings"><vers num="2.8" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-04-07" name="CVE-2005-1618" published="2005-05-16" seq="2005-1618" severity="Medium" type="CVE"><desc><descript source="cve">The YMSGR URL handler in Yahoo! Messenger 5.x through 6.0 allows remote attackers to cause a denial of service (disconnect) via a room login or a room join request packet with a third : (colon) and an &amp; (ampersand), which causes Messenger to send a corrupted packet to the server, which triggers a disconnect from the server.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111601904204055&amp;w=2">20050513 Yahoo! Messenger URL Handler Remote DoS Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/13626">13626</ref><ref source="OSVDB" url="http://www.osvdb.org/16816">16816</ref></refs><vuln_soft><prod name="Messenger" vendor="Yahoo"><vers num="5.6"/><vers num="5.5"/><vers num="6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2008-01-03" name="CVE-2005-1619" published="2005-05-16" seq="2005-1619" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in (1) start_page.css.php3 (aka start-page.css.php3) or (2) style.css.php3 in PHPMyChat 0.14.5 allow remote attackers to inject arbitrary web script or HTML commands via the FontName parameter.  NOTE: it was later reported that 0.14.5 is also affected.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111602076500031&amp;w=2">20050513 PHPHeaven PHPMyChat Cross-site Scripting Vulnerablitiy</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/484575/100/0/threaded">20071204 RFI and Multiple XSS in PhpMyChat</ref><ref source="BID" url="http://www.securityfocus.com/bid/13627">13627</ref><ref source="BID" url="http://www.securityfocus.com/bid/13628">13628</ref></refs><vuln_soft><prod name="PHPMyChat" vendor="phpHeaven"><vers num="0.14.5"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1620" published="2005-05-16" seq="2005-1620" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Skull-Splitter Guestbook 1.0, 2.0 and 2.2 allows remote attackers to inject arbitrary web script or HTML via the (1) title or (2) content of a message.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111609838307070&amp;w=2">20050514 Skull-Splitters Guestbook Multiple XXS/HTML injection</ref><ref adv="1" patch="1" source="Skull-Splitter" url="http://www.skull-splitter.net/main/news/news.php">Skull-Splitter critical update</ref></refs><vuln_soft><prod name="Skull-Splitter Guestbook" vendor="Soren Boysen"><vers num="2.2"/><vers num="2.0"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-04-07" name="CVE-2005-1621" published="2005-05-16" seq="2005-1621" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in the pnModFunc function in pnMod.php for PostNuke 0.750 through 0.760rc4 allows remote attackers to read arbitrary files via a .. (dot dot) in the func parameter to index.php.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111627124301526&amp;w=2">20050516 Postnuke 0.750 - 0.760rc4 local file inclusion</ref><ref patch="1" source="CONFIRM" url="http://cvs.postnuke.com/viewcvs.cgi/Historic_PostNuke_Library/postnuke-devel/html/includes/pnMod.php.diff?r1=1.47&amp;r2=1.48">http://cvs.postnuke.com/viewcvs.cgi/Historic_PostNuke_Library/postnuke-devel/html/includes/pnMod.php.diff?r1=1.47&amp;r2=1.48</ref><ref source="CONFIRM" url="http://news.postnuke.com/Article2690.html">http://news.postnuke.com/Article2690.html</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/0553">ADV-2005-0553</ref><ref source="" url="http://news.postnuke.com/modules.php?op=modload&amp;name=News&amp;file=article&amp;sid=2691"></ref></refs><vuln_soft><prod name="PostNuke" vendor="PostNuke Software Foundation"><vers num="0.760 RC4"/><vers num="0.760 RC3"/><vers num="0.760 RC2"/><vers num="0.750"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1622" published="2005-05-16" seq="2005-1622" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in productsByCategory.asp in MetaCart e-Shop allows remote attackers to inject arbitrary web script or HTML via the strCatalog_NAME parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111627073203176&amp;w=2">20050516 Multiple Vulnerabilities in MetaCart e-Shop</ref><ref patch="1" source="MISC" url="http://echo.or.id/adv/adv13-theday-2005.txt">http://echo.or.id/adv/adv13-theday-2005.txt</ref><ref patch="1" source="SecuriTeam" url="http://www.securiteam.com/windowsntfocus/5DP0D20FPG.html">MetaCart e-Shop Multiple Vulnerabilities</ref></refs><vuln_soft><prod name="MetaCart e-Shop" vendor="Metalinks"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1625" published="2005-07-05" seq="2005-1625" severity="Medium" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in the UnixAppOpenFilePerform function in Adobe Reader 5.0.9 and 5.0.10 for Unix allows remote attackers to execute arbitrary code via a PDF document with a long /Filespec tag.</descript></desc><loss_types><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=279&amp;type=vulnerabilities">20050705 iDEFENSE Security Advisory 07.05.05: Adobe Acrobat Reader UnixAppOpenFilePerform() Buffer Overflow Vulnerability</ref><ref adv="1" patch="1" source="" url="http://www.adobe.com/support/techdocs/329083.html">http://www.adobe.com/support/techdocs/329083.html</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-575.html">RHSA-2005:575</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_42_acroread.html">SUSE-SA:2005:042</ref></refs><vuln_soft><prod name="Acrobat Reader" vendor="Adobe"><vers num="5.0.9"/><vers num="5.0.10"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1626" published="2005-05-17" seq="2005-1626" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in handlers.c for Pico Server (pServ) before 3.3 may allow attackers to execute arbitrary code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/13648">13648</ref><ref source="CONFIRM" url="http://sourceforge.net/project/shownotes.php?release_id=327708">http://sourceforge.net/project/shownotes.php?release_id=327708</ref></refs><vuln_soft><prod name="Pico Server" vendor="Pico Server"><vers num="3.2"/><vers num="3.1"/><vers num="3.0 beta 3"/><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1627" published="2005-05-17" seq="2005-1627" severity="Low" type="CVE"><desc><descript source="cve">Unknown vulnerability in Viewglob before 2.0.1, related to &quot;a potential security issue with the Viewglob display and ssh X forwarding,&quot; has unknown impact.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref patch="1" source="CONFIRM" url="http://sourceforge.net/project/shownotes.php?release_id=325574">http://sourceforge.net/project/shownotes.php?release_id=325574</ref><ref source="OSVDB" url="http://www.osvdb.org/16170">16170</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1013937">1013937</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/15293">15293</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/20559">viewglob-connection-information-disclosure(20559)</ref></refs><vuln_soft><prod name="Viewglob" vendor="Viewglob"><vers num="2.0"/><vers num="1.1.1"/><vers num="1.1.0"/><vers num="1.0.3"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0.0"/><vers num="0.9.1"/><vers num="0.9.0"/><vers num="0.8.4"/><vers num="0.8.3"/><vers num="0.8.2"/><vers num="0.8.1"/><vers num="0.8.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-11-30" name="CVE-2005-1628" published="2005-05-17" seq="2005-1628" severity="High" type="CVE"><desc><descript source="cve">apage.cgi in WebAPP 0.9.9.2.1, and possibly earlier versions, allows remote attackers to execute arbitrary commands via shell metacharacters in the f parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/13637">13637</ref><ref source="frsirt" url="http://www.frsirt.com/english/advisories/2005/0554">WebAPP apage.cgi Remote Command Execution Vulnerability</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/449517/100/200/threaded">20061023 Application orders Linux in WebAPP v0.9.9.2.1</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/449573/100/200/threaded">20061024 Re: Application orders Linux in WebAPP v0.9.9.2.1</ref><ref source="" url="http://www.soulblack.com.ar/repo/tools/sbwebapp.txt"></ref><ref source="" url="http://www.defacers.com.mx/advisories/3.txt"></ref></refs><vuln_soft><prod name="WebAPP" vendor="Web-APP.org"><vers num="0.9.9.2.1"/><vers num="0.9.9.2"/><vers num="0.9.9"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-27" name="CVE-2005-1629" published="2005-05-17" seq="2005-1629" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in member.php for Photopost PHP Pro allows remote attackers to execute arbitrary SQL commands via the verifykey parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="FULLDISC" url="http://seclists.org/lists/fulldisclosure/2005/May/0311.html">20050513 PhotoPost Arbitrary Data Exploit</ref><ref source="BID" url="http://www.securityfocus.com/bid/13620">13620</ref></refs><vuln_soft><prod name="PhotoPost PHP Pro" vendor="PhotoPost"><vers num="3.1"/><vers num="3.2"/><vers num="3.3"/><vers num="4.0"/><vers num="4.1"/><vers num="4.6"/><vers num="4.8.1"/><vers num="5.0 RC3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-08-23" name="CVE-2005-1630" published="2005-05-17" seq="2005-1630" severity="High" type="CVE"><desc><descript source="cve">Unknown vulnerability in Attachment Mod before 2.3.13, related to a &quot;serious issue with realnames,&quot; has unknown impact and attack vectors.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref patch="1" source="CONFIRM" url="http://sourceforge.net/project/shownotes.php?release_id=326408">http://sourceforge.net/project/shownotes.php?release_id=326408</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/15327">15327</ref><ref patch="1" source="" url="http://archives.neohapsis.com/archives/secunia/2005-q2/0563.html"></ref></refs><vuln_soft><prod name="Attachment Mod" vendor="Opentools"><vers num="2.3.12"/><vers num="2.3.11"/><vers num="2.3.10"/><vers num="2.3.9"/><vers num="2.3.8"/><vers num="2.3.7"/><vers num="2.3.6"/><vers num="2.3.5"/><vers num="2.3.4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1631" published="2005-05-17" seq="2005-1631" severity="Medium" type="CVE"><desc><descript source="cve">booby.php in Booby 1.0.0 and earlier allows remote attackers to view private bookmarks by guessing item IDs.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref patch="1" source="CONFIRM" url="http://sourceforge.net/project/shownotes.php?release_id=326826">http://sourceforge.net/project/shownotes.php?release_id=326826</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/13623">13623</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/15305">15305</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/20605">booby-bookmarks-information-disclosure(20605)</ref></refs><vuln_soft><prod name="Booby" vendor="Booby"><vers num="0.3"/><vers num="0.1"/><vers num="0.1.1"/><vers num="0.1.2"/><vers num="0.1.3"/><vers num="0.2"/><vers num="0.2.1"/><vers num="0.2.2"/><vers num="0.2.3"/><vers num="0.2.4"/><vers num="1.0.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1632" published="2005-05-17" seq="2005-1632" severity="High" type="CVE"><desc><descript source="cve">Cheetah 0.9.15 and 0.9.16 searches the /tmp directory for modules before using the paths in the PYTHONPATH variable, which allows local users to execute arbitrary code via a malicious module in /tmp/.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref patch="1" source="CONFIRM" url="http://sourceforge.net/mailarchive/forum.php?thread_id=7070332&amp;forum_id=1542">http://sourceforge.net/mailarchive/forum.php?thread_id=7070332&amp;forum_id=1542</ref><ref source="OSVDB" url="http://www.osvdb.org/16622">16622</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/15386">15386</ref></refs><vuln_soft><prod name="Cheetah" vendor="Tavis Rudd"><vers num="0.9.15"/><vers num="0.9.16"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1633" published="2005-05-17" seq="2005-1633" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in JGS-XA JGS-Portal 3.0.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) anzahl_beitraege parameter to jgs_portal.php, 2) year parameter to (jgs_portal_statistik.php, 3) year parameter to (jgs_portal_beitraggraf.php, 4) tag parameter to (jgs_portal_viewsgraf.php, 5) year parameter to (jgs_portal_themengraf.php, 6) year parameter to (jgs_portal_mitgraf.php, 7) id parameter to jgs_portal_sponsor.php, or (8) the Accept-Language header to jgs_portal_log.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111627681218415&amp;w=2">20050516 [SePro Bugtraq] WBB Portal - JGS-Portal &lt;= 3.0.2 - Multiple Vulnerabilities (09.05.05)</ref></refs><vuln_soft><prod name="JGS-Portal" vendor="JGS-XA"><vers num="3.0.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-06-15" name="CVE-2005-1634" published="2005-05-17" seq="2005-1634" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in JGS-XA JGS-Portal 3.0.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) anzahl_beitraege parameter to jgs_portal.php, (2) year parameter to jgs_portal_statistik.php, (3) year parameter to jgs_portal_beitraggraf.php, (4) tag parameter to jgs_portal_viewsgraf.php, (5) year parameter to jgs_portal_themengraf.php, (6) year parameter to jgs_portal_mitgraf.php, (7) id parameter to jgs_portal_sponsor.php, or (8) the Accept-Language header to jgs_portal_log.php.  NOTE: this issue may stem from the same core problem as CVE-2005-1633.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111627681218415&amp;w=2">20050516 [SePro Bugtraq] WBB Portal - JGS-Portal &lt;= 3.0.2 - Multiple Vulnerabilities (09.05.05)</ref></refs><vuln_soft><prod name="JGS-Portal" vendor="JGS-XA"><vers num="3.0.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-06-15" name="CVE-2005-1635" published="2005-05-17" seq="2005-1635" severity="Medium" type="CVE"><desc><descript source="cve">JGS-XA JGS-Portal 3.0.2 and earlier allows remote attackers to obtain the full server path via direct requests to (1) jgs_portal_ref.php, (2) jgs_portal_land.php, (3) jgs_portal_log.php, (4) jgs_portal_global_sponsor.php, (5) jgs_portal_global.php, (6) jgs_portal_system.php, (7) jgs_portal_views.php; or multiple files in the jgs_portal_include directory, including (8) jgs_portal_boardmenue.php, (9) jgs_portal_forenliste.php, (10) jgs_portal_geburtstag.php, (11) jgs_portal_guckloch.php, (12) jgs_portal_kalender.php, (13) jgs_portal_letztethemen.php, (14) jgs_portal_links.php, (15) jgs_portal_neustemember.php, (16) jgs_portal_newsboard.php, (17) jgs_portal_online.php, (18) jgs_portal_pn.php, (19) jgs_portal_portalmenue.php, (20) jgs_portal_styles.php, (21) jgs_portal_suchen.php, (22) jgs_portal_team.php, (23) jgs_portal_topforen.php, (24) jgs_portal_topposter.php, (25) jgs_portal_umfrage.php, (26) jgs_portal_useravatar.php, (27) jgs_portal_waronline.php, (28) jgs_portal_woonline.php, or (29) jgs_portal_zufallsavatar.php.</descript></desc><loss_types><conf/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111627681218415&amp;w=2">20050516 [SePro Bugtraq] WBB Portal - JGS-Portal &lt;= 3.0.2 - Multiple Vulnerabilities (09.05.05)</ref></refs><vuln_soft><prod name="JGS-Portal" vendor="JGS-XA"><vers num="3.0.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-03-28" name="CVE-2005-1636" published="2005-05-17" seq="2005-1636" severity="Medium" type="CVE"><desc><descript source="cve">mysql_install_db in MySQL 4.1.x before 4.1.12 and 5.x up to 5.0.4 creates the mysql_install_db.X file with a predictable filename and insecure permissions, which allows local users to execute arbitrary SQL commands by modifying the file&apos;s contents.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=111632686805498&amp;w=2">20050517 MySQL &lt; 4.0.12 &amp;&amp; MySQL &lt;= 5.0.4 : Insecure tmp</ref><ref source="MISC" url="http://www.zataz.net/adviso/mysql-05172005.txt">http://www.zataz.net/adviso/mysql-05172005.txt</ref><ref source="BID" url="http://www.securityfocus.com/bid/13660">13660</ref><ref source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=111632686805498&amp;w=2">20050517 MySQL &lt; 4.0.12 &amp;&amp; MySQL &lt;= 5.0.4 : Insecure tmp</ref><ref source="CONFIRM" url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=158688">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=158688</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15369">15369</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-685.html">RHSA-2005:685</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17080">17080</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:045">MDKSA-2006:045</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:045">MDKSA-2006:045</ref></refs><vuln_soft><prod name="MySQL" vendor="MySQL"><vers num="4.0.0"/><vers num="4.0.1"/><vers num="4.0.2"/><vers num="4.0.3"/><vers num="4.0.4"/><vers num="4.0.5a"/><vers num="4.0.5"/><vers num="4.0.6"/><vers num="4.0.7 gamma"/><vers num="4.0.7"/><vers num="4.0.8 gamma"/><vers num="4.0.8"/><vers num="4.0.9 gamma"/><vers num="4.0.9"/><vers num="4.0.10"/><vers num="4.0.11 gamma"/><vers num="4.0.11"/><vers num="5.0.0 alpha"/><vers num="5.0.0.0"/><vers num="5.0.1"/><vers num="5.0.2"/><vers num="5.0.3"/><vers num="5.0.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1637" published="2005-05-17" seq="2005-1637" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in NPDS 4.8 and 5.0 allow remote attackers to execute arbitrary SQL commands via the thold parameter to (1) comments.php or (2) pollcomments.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="CONFIRM" url="http://www.npds.org/article.php?sid=1258">http://www.npds.org/article.php?sid=1258</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1013973">1013973</ref></refs><vuln_soft><prod name="NPDS" vendor="NPDS"><vers num="4.8"/><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-08-23" name="CVE-2005-1638" published="2005-05-17" seq="2005-1638" severity="Medium" type="CVE"><desc><descript source="cve">The _writeAttrs function in SafeHTML before 1.3.2 does not properly handle quotes in attribute values, which could allow remote attackers to exploit cross-site scripting (XSS) vulnerabilities in applications that rely on SafeHTML for protection.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="CONFIRM" url="http://pixel-apes.com/safehtml/feed">http://pixel-apes.com/safehtml/feed</ref><ref source="OSVDB" url="http://www.osvdb.org/16612">16612</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15371">15371</ref></refs><vuln_soft><prod name="SafeHTML" vendor="Pixel-Apes Group"><vers num="1.3.1"/><vers num="1.3.0"/><vers num="1.2.1"/><vers num="1.2.0"/><vers num="1.1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1639" published="2005-05-17" seq="2005-1639" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in Sigmaweb.DLL in Sigma ISP Manager 6.6 allows remote attackers to execute arbitrary SQL commands via the (1) username, (2) password, or (3) domain fields.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://www.under9round.com/sigma.txt">http://www.under9round.com/sigma.txt</ref><ref source="OSVDB" url="http://www.osvdb.org/16620">16620</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15379">15379</ref></refs><vuln_soft><prod name="Sigma ISP Manager" vendor="Atinegar"><vers num="6.6" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1640" published="2005-05-17" seq="2005-1640" severity="High" type="CVE"><desc><descript source="cve">mod_channel.bas in The Ignition Project ignitionServer 0.3.0 to 0.3.6, and possibly earlier versions, does not properly verify whether a host has the owner privileges required to delete IRC channel access entries, which allows remote attackers to bypass intended restrictions.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CONFIRM" url="http://www.ignition-project.com/security/20050414-hosts-delete-owner-access-entries">http://www.ignition-project.com/security/20050414-hosts-delete-owner-access-entries</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/15388">15388</ref></refs><vuln_soft><prod name="ignitionServer" vendor="The Ignition Project"><vers num="0.3.0"/><vers num="0.3.1"/><vers num="0.3.2"/><vers num="0.3.3"/><vers num="0.3.4"/><vers num="0.3.5"/><vers num="0.3.6"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1641" published="2005-05-17" seq="2005-1641" severity="Low" type="CVE"><desc><descript source="cve">mod_channel in The Ignition Project ignitionServer 0.3.0 to 0.3.6, and possibly earlier versions, does not allow protected operators to access channels that have been locked out by a key, which allows IRC users to cause a denial of service.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref patch="1" source="CONFIRM" url="http://www.ignition-project.com/security/20050515-protected-opers-cannot-join-channel-with-key">http://www.ignition-project.com/security/20050515-protected-opers-cannot-join-channel-with-key</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/15388">15388</ref></refs><vuln_soft><prod name="ignitionServer" vendor="The Ignition Project"><vers num="0.3.0"/><vers num="0.3.1"/><vers num="0.3.2"/><vers num="0.3.3"/><vers num="0.3.4"/><vers num="0.3.5"/><vers num="0.3.6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1642" published="2005-05-17" seq="2005-1642" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in the verify_email function in Woltlab Burning Board 2.x and earlier allows remote attackers to execute arbitrary SQL commands via the $email variable.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2005-05/0199.html">20050516 Woltlab Burning Board SQL Injection Vulnerability</ref><ref source="MLIST" url="http://www.attrition.org/pipermail/vim/2005-May/000047.html">20050516 Re: Woltlab Burning Board SQL Injection Vulnerability (fwd)</ref><ref source="OSVDB" url="http://www.osvdb.org/16575">16575</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/15395">15395</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/0558">ADV-2005-0558</ref></refs><vuln_soft><prod name="Burning Board" vendor="Woltlab"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1643" published="2005-05-17" seq="2005-1643" severity="Medium" type="CVE"><desc><descript source="cve">The ZCom_BitStream::Deserialize function in Zoidcom 1.0 beta 4 and earlier allows remote attackers to cause a denial of service via a crafted UDP packet with a large size value, which causes a memory allocation error or an out-of-bounds read.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2005-05/0107.html">20050510 Crash in Zoidcom 1.0 beta 4</ref><ref patch="1" source="CONFIRM" url="http://www.zoidcom.com/download/changelog.txt">http://www.zoidcom.com/download/changelog.txt</ref><ref source="OSVDB" url="http://www.osvdb.org/16495">16495</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1013939">1013939</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/20511">zoidcom-deserialize-dos(20511)</ref></refs><vuln_soft><prod name="Zoidcom" vendor="Jorg Ruppel"><vers num="1.0 Beta 4"/><vers num="1.0 Beta 3"/><vers num="1.0 Beta 2"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1644" published="2005-05-18" seq="2005-1644" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in guestbook.php for 1Two Livre d&apos;Or 1.0 allows remote attackers to inject arbitrary web script or HTML via the (1) livreornom, (2) livreoremail, or (3) livreormessage parameters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/13631">13631</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1013971">1013971</ref><ref source="OSVDB" url="http://www.osvdb.org/16717">16717</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20589">1two-livere-dor-guestbook-xss(20589)</ref></refs><vuln_soft><prod name="Livre D&apos;Or" vendor="1Two"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1645" published="2005-05-18" seq="2005-1645" severity="Medium" type="CVE"><desc><descript source="cve">Keyvan1 ImageGallery stores the image.mdb database under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/13630">13630</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013970">1013970</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/15362">15362</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20592">imagegallery-information-disclosure(20592)</ref></refs><vuln_soft><prod name="ImageGallery" vendor="Keyvan1"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1646" published="2005-05-18" seq="2005-1646" severity="High" type="CVE"><desc><descript source="cve">The default installation of Fastream NETFile FTP/Web Server 7.4.6, which supports FXP, does not require that the IP address in a PORT command be the same as the IP of the logged in user, which allows remote attackers to conduct FTP Bounce attacks to bypass firewall rules or cause a denial of service.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref patch="1" source="MISC" url="http://www.security.org.sg/vuln/netfileftp746port.html">http://www.security.org.sg/vuln/netfileftp746port.html</ref><ref patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/0556">ADV-2005-0556</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/15394">15394</ref></refs><vuln_soft><prod name="NetFILE FTP_Web Server" vendor="Fastream"><vers num="7.4.6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1647" published="2005-05-18" seq="2005-1647" severity="High" type="CVE"><desc><descript source="cve">Gurgens (GASoft) Guest Book 2.1 stores the db/Genid.dat database file under the web document root with insufficient access control, which allows remote attackers to obtain and decrypt usernames and passwords.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2005-05/0351.html">20050515 Gurgens Guest Book Password Database Vulnerability</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013976">1013976</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/15373">15373</ref></refs><vuln_soft><prod name="Gurgens Guest Book" vendor="Gurgens"><vers num="2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1648" published="2005-05-18" seq="2005-1648" severity="High" type="CVE"><desc><descript source="cve">Gurgens (GASoft) Ultimate Forum 1.0 stores the db/Genid.dat database file under the web document root with insufficient access control, which allows remote attackers to obtain and decrypt usernames and passwords.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref patch="1" source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2005-05/0350.html">20050515 Ultimate Forum Password Database Vulnerability</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013974">1013974</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/15374">15374</ref></refs><vuln_soft><prod name="Gurgens Ultimate Forum" vendor="Gurgens"><vers num="2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-25" name="CVE-2005-1649" published="2005-05-18" seq="2005-1649" severity="Medium" type="CVE"><desc><descript source="cve">The IpV6 support in Windows XP SP2, 2003 Server SP1, and Longhorn, with Windows Firewall turned off, allows remote attackers to cause a denial of service (CPU consumption) via a TCP packet with the SYN flag set and the same destination and source address and port, a variant of CVE-2005-0688 and a reoccurrence of the &quot;Land&quot; vulnerability (CVE-1999-0016).</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="NTBUGTRAQ" url="http://www.ntbugtraq.com/default.aspx?pid=36&amp;sid=1&amp;A2=ind0505&amp;L=NTBUGTRAQ&amp;P=R409&amp;D=0&amp;F=N&amp;H=0&amp;O=D&amp;T=0">20050516 Windows (XP, 2k3, Longhorn) is vulnerable to IpV6 Land attack.</ref><ref source="BID" url="http://www.securityfocus.com/bid/13658">13658</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/0559">ADV-2005-0559</ref></refs><vuln_soft><prod name="Windows XP" vendor="Microsoft"><vers edition="SP1" num="64-bit"/><vers num="64-bit"/><vers edition="SP1" num="64-bit Version 2003"/><vers num="64-bit Version 2003"/><vers edition="SP1" num="Embedded"/><vers num="Embedded"/><vers edition="SP2" num="Home"/><vers edition="SP1" num="Home"/><vers num="Home"/><vers edition="Gold" num="Professional"/><vers edition="Gold" num="Professional"/><vers edition="Gold" num="Professional"/><vers edition="64-bit" num="Professional"/><vers edition="SP2" num="Media Center"/><vers edition="SP1" num="Media Center"/><vers num="Media Center"/><vers edition="SP2" num="Tablet PC"/><vers edition="SP2" num="Tablet PC"/><vers edition="SP2" num="Tablet PC"/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers edition="SP1" num="R2"/><vers edition="64-bit" num="R2"/><vers edition="SP1" num="Datacenter 64-bit"/><vers edition="Datacenter 64-bit" num="R2"/><vers edition="SP1" num="Enterprise"/><vers edition="64-bit" num="Enterprise"/><vers edition="SP1" num="Enterprise 64-bit"/><vers num="Enterprise 64-bit"/><vers edition="SP1" num="Standard"/><vers edition="64-bit" num="Standard"/><vers edition="SP1" num="Web"/><vers num="Web"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1650" published="2005-05-18" seq="2005-1650" severity="High" type="CVE"><desc><descript source="cve">The web mail service in Woppoware PostMaster 4.2.2 (build 3.2.5) generates different error messages depending on whether a user exists or not, which allows remote attackers to determine valid usernames.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/13597">13597</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15268">15268</ref></refs><vuln_soft><prod name="PostMaster" vendor="Woppoware"><vers num="4.2.2 build3.2.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1651" published="2005-05-18" seq="2005-1651" severity="High" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in message.htm for Woppoware PostMaster 4.2.2 (build 3.2.5) allows remote attackers to determine the existence of arbitrary files via a .. (dot dot) in the wmm parameter.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/13597">13597</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15268">15268</ref></refs><vuln_soft><prod name="PostMaster" vendor="Woppoware"><vers num="4.2.2 build3.2.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1652" published="2005-05-18" seq="2005-1652" severity="High" type="CVE"><desc><descript source="cve">message.htm for Woppoware PostMaster 4.2.2 (build 3.2.5) allows remote attackers to bypass authentication by modifying the email parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/13597">13597</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15268">15268</ref></refs><vuln_soft><prod name="PostMaster" vendor="Woppoware"><vers num="4.2.2 build3.2.5"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1653" published="2005-05-18" seq="2005-1653" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in message.htm for Woppoware PostMaster 4.2.2 (build 3.2.5) allows remote attackers to inject arbitrary web script or HTML via the email parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/13597">13597</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15268">15268</ref></refs><vuln_soft><prod name="PostMaster" vendor="Woppoware"><vers num="4.2.2 build3.2.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1654" published="2005-05-18" seq="2005-1654" severity="High" type="CVE"><desc><descript source="cve">Hosting Controller 6.1 Hotfix 1.9 and earlier allows remote attackers to register arbitrary users via a direct request to addsubsite.asp with the loginname and password parameters set.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="MISC" url="http://isun.shabgard.org/hc3.txt">http://isun.shabgard.org/hc3.txt</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15271">15271</ref></refs><vuln_soft><prod name="Hosting Controller" vendor="Hosting Controller"><vers num="6.1 Hotfix 1.9"/><vers num="6.1 Hotfix 1.4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1655" published="2005-05-18" seq="2005-1655" severity="Medium" type="CVE"><desc><descript source="cve">AOL Instant Messenger 5.5.x and earlier allows remote attackers to cause a denial of service (client crash) via an invalid smiley icon location in the sml parameter of a font tag.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/13553">13553</ref></refs><vuln_soft><prod name="Instant Messenger" vendor="AOL"><vers num="1.2"/><vers num="2.0 N"/><vers num="2.0.912"/><vers num="2.0.996"/><vers num="2.1.1236"/><vers num="2.5.1366"/><vers num="2.5.1598"/><vers num="3.0.1470"/><vers num="3.0 N"/><vers num="3.0.1415"/><vers num="3.5.1635"/><vers num="3.5.1670"/><vers num="3.5.1808"/><vers num="3.5.1856"/><vers num="4.0"/><vers num="4.1"/><vers num="4.1.2010"/><vers num="4.2"/><vers num="4.2.1193"/><vers num="4.3"/><vers num="4.3.2229"/><vers num="4.4"/><vers num="4.5"/><vers num="4.6"/><vers num="4.7"/><vers num="4.7.2480"/><vers num="4.8.2646"/><vers num="4.8.2616"/><vers num="4.8.2790"/><vers num="5.0.2938"/><vers num="5.1.3036"/><vers num="5.2.3292"/><vers num="5.5"/><vers num="5.5.3415 Beta"/><vers num="5.5.3595"/><vers num="5.9.3702"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1656" published="2005-05-18" seq="2005-1656" severity="Medium" type="CVE"><desc><descript source="cve">Mercur Messaging 2005 SP2 allows remote attackers to read the source code of .ctml files via a URL with a trailing hex-encoded space (&quot;%20&quot;).</descript></desc><loss_types><conf/></loss_types><vuln_types><access/><input/></vuln_types><range><network/></range><refs><ref source="OSVDB" url="http://www.osvdb.org/16218">16218</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15234">15234</ref></refs><vuln_soft><prod name="Mercur Messaging" vendor="Mercur"><vers num="2005 SP2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1657" published="2005-05-18" seq="2005-1657" severity="High" type="CVE"><desc><descript source="cve">Multiple directory traversal vulnerabilities in Mercur Messaging 2005 SP2 allow remote attackers to perform unauthorized file operations via the Folder.Id parameter to (1) deletefolder.ctml, (2) deletemessage.ctml, (3) origmessage.ctml, or (4) readmessage.ctml, the Message.Id parameter to editmessage.ctml, or the (5) Message.Command parameter to messages.ctml.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="OSVDB" url="http://www.osvdb.org/16220">16220</ref><ref source="OSVDB" url="http://www.osvdb.org/16221">16221</ref><ref source="OSVDB" url="http://www.osvdb.org/16222">16222</ref><ref source="OSVDB" url="http://www.osvdb.org/16223">16223</ref><ref source="OSVDB" url="http://www.osvdb.org/16224">16224</ref><ref source="OSVDB" url="http://www.osvdb.org/16225">16225</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15234">15234</ref></refs><vuln_soft><prod name="Mercur Messaging" vendor="Mercur"><vers num="2005 SP2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1658" published="2005-05-18" seq="2005-1658" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in filemanager.cpp in MyServer 0.8 allows remote attackers to list the parent directory of the web root via a URL with a &quot;...&quot;  (triple dot).</descript></desc><loss_types><conf/></loss_types><vuln_types><access/><input/></vuln_types><range><network/></range><refs><ref source="SECUNIA" url="http://secunia.com/advisories/15274">15274</ref><ref source="CONFIRM" url="http://cvs.sourceforge.net/viewcvs.py/myserverweb/myserverweb/source/filemanager.cpp?rev=1.116&amp;view=log">http://cvs.sourceforge.net/viewcvs.py/myserverweb/myserverweb/source/filemanager.cpp?rev=1.116&amp;view=log</ref></refs><vuln_soft><prod name="MyServer" vendor="MyServer"><vers num="0.8"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1659" published="2005-05-18" seq="2005-1659" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in filemanager.cpp in MyServer 0.8 allows remote attackers to inject arbitrary Javascript via a URL with a &quot;...&quot;  (triple dot) followed by an onmouseover event.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/15274">15274</ref><ref patch="1" source="CONFIRM" url="http://cvs.sourceforge.net/viewcvs.py/myserverweb/myserverweb/source/filemanager.cpp?rev=1.116&amp;view=log">http://cvs.sourceforge.net/viewcvs.py/myserverweb/myserverweb/source/filemanager.cpp?rev=1.116&amp;view=log</ref></refs><vuln_soft><prod name="MyServer" vendor="MyServer"><vers num="0.8"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1660" published="2005-05-18" seq="2005-1660" severity="High" type="CVE"><desc><descript source="cve">HTMLJunction EZGuestbook stores the guestbook.mdb file under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information such as the administrative password.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref source="OSVDB" url="http://www.osvdb.org/16444">16444</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013912">1013912</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20487">htmljunction-database-disclosure(20487)</ref></refs><vuln_soft><prod name="EZGuestbook" vendor="HTMLJunction"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1661" published="2005-05-18" seq="2005-1661" severity="Medium" type="CVE"><desc><descript source="cve">Jeuce Personal Webserver 2.13 allows remote attackers to cause a denial of service (server crash) via a long GET request, possibly triggering a buffer overflow.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="MISC" url="http://users.pandora.be/bratax/advisories/b005.html">http://users.pandora.be/bratax/advisories/b005.html</ref><ref source="OSVDB" url="http://www.osvdb.org/16453">16453</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013902">1013902</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/13732">13732</ref></refs><vuln_soft><prod name="Jeuce Personal Web Server" vendor="Jeuce"><vers num="2.13"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1662" published="2005-05-18" seq="2005-1662" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in Jeuce Personal Web Server 2.13 allows remote attackers to read arbitrary files via a .. (dot dot) in the URL.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MISC" url="http://www.securiteam.com/windowsntfocus/5JP011PEKY.html">http://www.securiteam.com/windowsntfocus/5JP011PEKY.html</ref><ref source="BID" url="http://www.securityfocus.com/bid/12183">12183</ref><ref source="OSVDB" url="http://www.osvdb.org/12718">12718</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13732">13732</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1012791">1012791</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18787">jeuce-dotdot-directory-traversal(18787)</ref></refs><vuln_soft><prod name="Jeuce Personal Web Server" vendor="Jeuce"><vers num="2.13"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1663" published="2005-05-18" seq="2005-1663" severity="Medium" type="CVE"><desc><descript source="cve">Jeuce Personal Web Server 2.13 allows remote attackers to cause a denial of service (server crash) via a GET request beginning with &quot;://&quot;.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MISC" url="http://www.securiteam.com/windowsntfocus/5JP011PEKY.html">http://www.securiteam.com/windowsntfocus/5JP011PEKY.html</ref><ref source="BID" url="http://www.securityfocus.com/bid/12183">12183</ref><ref source="OSVDB" url="http://www.osvdb.org/12719">12719</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13732">13732</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1012791">1012791</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18791">jeuce-url-dos(18791)</ref></refs><vuln_soft><prod name="Jeuce Personal Web Server" vendor="Jeuce"><vers num="2.13"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1664" published="2005-05-18" seq="2005-1664" severity="Medium" type="CVE"><desc><descript source="cve">The __VIEWSTATE functionality in Microsoft ASP.NET 1.x allows remote attackers to conduct replay attacks to (1) apply a ViewState generated from one view to a different view, (2) reuse ViewState information after the application&apos;s state has changed, or (3) use the ViewState to conduct attacks or expose content to third parties.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><access/><design/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111513127704270&amp;w=2">20050503 ASP.NET __VIEWSTATE crypto validation prone to replay attacks</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111532887612517&amp;w=2">20050505 Re: ASP.NET __VIEWSTATE crypto validation prone to replay attacks</ref><ref source="MISC" url="http://scottonwriting.net/sowblog/posts/3747.aspx">http://scottonwriting.net/sowblog/posts/3747.aspx</ref><ref source="OSVDB" url="http://www.osvdb.org/16196">16196</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/15241">15241</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20409">ms-aspnet-viewstate-replay(20409)</ref></refs><vuln_soft><prod name="ASP.NET" vendor="Microsoft"><vers num="1.0"/><vers num="1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1665" published="2005-05-18" seq="2005-1665" severity="Medium" type="CVE"><desc><descript source="cve">The __VIEWSTATE functionality in Microsoft ASP.NET 1.x, when not cryptographically signed, allows remote attackers to cause a denial of service (CPU consumption) via deeply nested markup.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/><config/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111513127704270&amp;w=2">20050503 ASP.NET __VIEWSTATE crypto validation prone to replay attacks</ref><ref adv="1" source="MISC" url="http://scottonwriting.net/sowblog/posts/3747.aspx">http://scottonwriting.net/sowblog/posts/3747.aspx</ref><ref source="OSVDB" url="http://www.osvdb.org/16195">16195</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/15241">15241</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20408">ms-aspnet-viewstate-dos(20408)</ref></refs><vuln_soft><prod name="ASP.NET" vendor="Microsoft"><vers num="1.0"/><vers num="1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1666" published="2005-05-18" seq="2005-1666" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in Orenosv HTTP/FTP Server 0.8.1 allow remote authenticated users to cause a denial of service (server crash) and possibly execute arbitrary code via long arguments to FTP commands such as MKD, RMD, or DELE, which are processed by the (1) ftp_xlate_path, (2) ftp_is_canonical, or (3) os_fn_nativize functions, or (4) a long SSI command that is processed by the parse_cmd function in cgissi.exe.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://www.security.org.sg/vuln/orenosv081.html">http://www.security.org.sg/vuln/orenosv081.html</ref><ref adv="1" source="MISC" url="http://www.securiteam.com/windowsntfocus/5FP0H00FPS.html">http://www.securiteam.com/windowsntfocus/5FP0H00FPS.html</ref><ref patch="1" source="CONFIRM" url="http://hp.vector.co.jp/authors/VA027031/orenosv/index_en.html">http://hp.vector.co.jp/authors/VA027031/orenosv/index_en.html</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/13546">13546</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/13549">13549</ref><ref patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/0499">ADV-2005-0499</ref><ref source="OSVDB" url="http://www.osvdb.org/16165">16165</ref><ref source="OSVDB" url="http://www.osvdb.org/16166">16166</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1013923">1013923</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/15302">15302</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/20510">orenosv-http-ftp-commands-bo(20510)</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/20512">orenosv-http-ftp-cgissi-bo(20512)</ref></refs><vuln_soft><prod name="Orenosv HTTP FTP Server" vendor="Orenosv"><vers num="0.8.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1667" published="2005-05-18" seq="2005-1667" severity="Medium" type="CVE"><desc><descript source="cve">DataTrac Activity Console 1.1 allows remote attackers to cause a denial of service via a long HTTP GET request.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref source="MISC" url="http://www.milw0rm.com/id.php?id=983">http://www.milw0rm.com/id.php?id=983</ref><ref source="MISC" url="http://www.securiteam.com/windowsntfocus/5FP052AFPA.html">http://www.securiteam.com/windowsntfocus/5FP052AFPA.html</ref><ref source="BID" url="http://www.securityfocus.com/bid/13558">13558</ref><ref source="OSVDB" url="http://www.osvdb.org/16168">16168</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15291">15291</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/983">

983</ref></refs><vuln_soft><prod name="Activity Console" vendor="DataTrac"><vers num="1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1668" published="2005-05-18" seq="2005-1668" severity="High" type="CVE"><desc><descript source="cve">YusASP Web Asset Manager 1.0 allows remote attackers to gain privileges via a direct request to assetmanager.asp.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref patch="1" source="MISC" url="http://www.securiteam.com/windowsntfocus/5OP0115FPQ.html">http://www.securiteam.com/windowsntfocus/5OP0115FPQ.html</ref><ref source="BID" url="http://www.securityfocus.com/bid/13501">13501</ref><ref source="OSVDB" url="http://www.osvdb.org/16198">16198</ref></refs><vuln_soft><prod name="Web Asset Manager" vendor="YusASP"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1669" published="2005-06-16" seq="2005-1669" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Opera 8.0 Final Build 1095 allows remote attackers to inject arbitrary web script or HTML via &quot;javascript:&quot; URLs when a new window or frame is opened, which allows remote attackers to bypass access restrictions and perform unauthorized actions on other domains.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="MISC" url="http://secunia.com/secunia_research/2005-5/advisory/">http://secunia.com/secunia_research/2005-5/advisory/</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/15411">15411</ref></refs><vuln_soft><prod name="Opera Web Browser" vendor="Opera Software"><vers num="8.0 Final Build 1095"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1670" published="2005-05-19" seq="2005-1670" severity="Medium" type="CVE"><desc><descript source="cve">Unknown vulnerability in Extreme BlackDiamond 10808 and 8800 switches running ExtremeWare XOS 11.1 before 11.1.3.3, 11.0 before 11.0.2.4, and 10.x allows remote authenticated users to execute arbitrary commands.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref patch="1" source="CONFIRM" url="http://www.extremenetworks.com/services/documentation/FieldNotices_FN0215-Security_Alert_EXOS.asp">http://www.extremenetworks.com/services/documentation/FieldNotices_FN0215-Security_Alert_EXOS.asp</ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/937838">VU#937838</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/0572">ADV-2005-0572</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/15438">15438</ref></refs><vuln_soft><prod name="BlackDiamond 8800" vendor="Extreme Networks"><vers num=""/></prod><prod name="ExtremeWare XOS" vendor="Extreme Networks"><vers num="11.1.3.2" prev="1"/><vers num="11.1"/><vers num="11.0.2.3" prev="1"/><vers num="10.0"/></prod><prod name="BlackDiamond 10808" vendor="Extreme Networks"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1671" published="2005-05-19" seq="2005-1671" severity="Low" type="CVE"><desc><descript source="cve">The Logfile feature in Yahoo! Messenger 5.x through 6.0 can be activated by a YMSGR: URL and writes all output to a single ypager.log file, even when there are multiple users, and does not properly warn later users that the feature has been enabled, which allows local users to obtain sensitive information from other users.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111643475210982&amp;w=2">20050518 Yahoo Messenger may be storing all session data Unencoded on the local machine</ref></refs><vuln_soft><prod name="Messenger" vendor="Yahoo"><vers num="6.0"/><vers num="5.6.0.1351"/><vers num="5.6"/><vers num="5.5"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1672" published="2005-05-19" seq="2005-1672" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Help Center Live allow remote attackers to inject arbitrary web script or HTML via the (1) find parameter to index.php, (2) name or (3) message field of a chat request, or (4) the message body when opening a trouble ticket.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/398457">20050517 Help Center Live Vulnerabilities</ref></refs><vuln_soft><prod name="Help Center Live" vendor="UberTec"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1673" published="2005-05-19" seq="2005-1673" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in Help Center Live allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to index.php, (2) tid parameter to view.php, fid parameter to (3) download.php or (4) chat_download.php, (5) status parameter to icon.php, TICKET_tid parameter to (6) index.php or (7) view.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/398457/2005-05-15/2005-05-21/0">20050517 Help Center Live Vulnerabilities</ref></refs><vuln_soft><prod name="Help Center Live" vendor="UberTec"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1674" published="2005-05-19" seq="2005-1674" severity="High" type="CVE"><desc><descript source="cve">Cross-Site Request Forgery (CSRF) vulnerability in Help Center Live allows remote attackers to perform actions as the administrator via a link or IMG tag to view.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/398457/2005-05-15/2005-05-21/0">20050517 Help Center Live Vulnerabilities</ref></refs><vuln_soft><prod name="Help Center Live" vendor="UberTec"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1675" published="2005-05-20" seq="2005-1675" severity="Medium" type="CVE"><desc><descript source="cve">Groove Virtual Office before 3.1 build 2338, before 3.1a build 2364, and Groove Workspace before 2.5n build 1871 installs the client installation directories with insecure EVERYBODY permissions, which allows local users to gain sensitive information.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><config/></vuln_types><range><local/></range><refs><ref adv="1" source="CONFIRM" url="http://www.kb.cert.org/vuls/id/JGEI-6BCRBX">http://www.kb.cert.org/vuls/id/JGEI-6BCRBX</ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/443370">VU#443370</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/15421">15421</ref></refs><vuln_soft><prod name="Groove Workspace" vendor="Groove"><vers num="2.5n build 1871" prev="1"/></prod><prod name="Virtual Office" vendor="Groove"><vers num="3.1 build 2338" prev="1"/><vers num="3.1a build 2364" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1676" published="2005-05-20" seq="2005-1676" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Groove Mobile Workspace in Groove Virtual Office before 3.1 build 2338, before 3.1a build 2364, and Groove Workspace before 2.5n build 1871 allow remote attackers to inject arbitrary web script or HTML via the (1) picture columns embedded within SharePoint lists or (2) drop-down menus in a SharePoint list.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="CONFIRM" url="http://www.kb.cert.org/vuls/id/JGEI-6BCRCC">http://www.kb.cert.org/vuls/id/JGEI-6BCRCC</ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/372618">VU#372618</ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/514386">VU#514386</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/15421">15421</ref></refs><vuln_soft><prod name="Groove Workspace" vendor="Groove"><vers num="2.5n build 1871" prev="1"/></prod><prod name="Virtual Office" vendor="Groove"><vers num="3.1 build 2338" prev="1"/><vers num="3.1a build 2364" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1677" published="2005-05-20" seq="2005-1677" severity="High" type="CVE"><desc><descript source="cve">Unknown vulnerability in Groove Virtual Office before 3.1 build 2338, before 3.1a build 2364, and Groove Workspace before 2.5n build 1871 allows remote attackers to bypass restrictions on COM objects.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="CONFIRM" url="http://www.kb.cert.org/vuls/id/JGEI-6BCRCM">http://www.kb.cert.org/vuls/id/JGEI-6BCRCM</ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/155610">VU#155610</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/15421">15421</ref></refs><vuln_soft><prod name="Groove Workspace" vendor="Groove"><vers num="2.5n build 1871" prev="1"/></prod><prod name="Virtual Office" vendor="Groove"><vers num="3.1 build 2338" prev="1"/><vers num="3.1a build 2364" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1678" published="2005-05-20" seq="2005-1678" severity="Low" type="CVE"><desc><descript source="cve">Groove Virtual Office before 3.1 build 2338, before 3.1a build 2364, and Groove Workspace before 2.5n build 1871 does not properly display file extensions on attached or embedded files in a compound document, which may allow remote attackers to trick users into executing malicious code.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="CONFIRM" url="http://www.kb.cert.org/vuls/id/JGEI-6BCRD6">http://www.kb.cert.org/vuls/id/JGEI-6BCRD6</ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/232232">VU#232232</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/15421">15421</ref></refs><vuln_soft><prod name="Groove Workspace" vendor="Groove"><vers num="2.5n build 1871" prev="1"/></prod><prod name="Virtual Office" vendor="Groove"><vers num="3.1 build 2338" prev="1"/><vers num="3.1a build 2364" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1679" published="2005-05-20" seq="2005-1679" severity="Medium" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in the error directive in picasm 1.12b and earlier allows attackers to execute arbitrary code via a long error message.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111661253517089&amp;w=2">20050520 picasm error handling stack overflow vulnerability</ref><ref patch="1" source="CONFIRM" url="http://www.co.jyu.fi/~trossi/pic/">http://www.co.jyu.fi/~trossi/pic/</ref><ref source="BID" url="http://www.securityfocus.com/bid/13698">13698</ref></refs><vuln_soft><prod name="picasm" vendor="Timo Rossi"><vers num="1.12b" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1680" published="2005-05-20" seq="2005-1680" severity="High" type="CVE"><desc><descript source="cve">D-Link DSL-502T, DSL-504T, DSL-562T, and DSL-G604T, when /cgi-bin/firmwarecfg is executed, allows remote attackers to bypass authentication (1) if their IP address already exists in /var/tmp/fw_ip or (2) if their request is the first, which causes /var/tmp/fw_ip to be created and contain their IP address.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111652806030943&amp;w=2">20050519 D-Link DSL routers authentication bypass</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/0573">ADV-2005-0573</ref></refs><vuln_soft><prod name="DSL-504T" vendor="D-Link"><vers num=""/></prod><prod name="DSL-G604T" vendor="D-Link"><vers num=""/></prod><prod name="DSL-562T" vendor="D-Link"><vers num=""/></prod><prod name="DSL-502T" vendor="D-Link"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-07" name="CVE-2005-1681" published="2005-05-20" seq="2005-1681" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in common.php in phpATM 1.21, and possibly earlier versions, allows remote attackers to execute arbitrary PHP code via a URL in the include_location parameter to index.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111653168810937&amp;w=2">20050519 phpATM arbitrary PHP code inclusion</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15420">15420</ref><ref source="OSVDB" url="http://www.osvdb.org/16692">16692</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014008">1014008</ref></refs><vuln_soft><prod name="PHP Advanced Transfer Manager" vendor="Bugada Andrea"><vers num="1.21"/><vers num="1.20"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2008-01-14" name="CVE-2005-1682" published="2005-05-20" seq="2005-1682" severity="Low" type="CVE"><desc><descript source="cve">** DISPUTED **  JavaMail API, as used by Solstice Internet Mail Server POP3 2.0, does not properly validate the message number in the MimeMessage constructor in javax.mail.internet.InternetHeaders, which allows remote authenticated users to read other users&apos; e-mail messages by modifying the msgno parameter.  NOTE: Sun disputes this issue, stating &quot;The report makes references to source code and files that do not exist in the mentioned products.&quot;</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111653029605189&amp;w=2">20050519 JavaMail Information Disclosure (msgno)</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/0574">ADV-2005-0574</ref></refs><vuln_soft><prod name="Solstice Internet Mail Server" vendor="Solstice"><vers num="POP3 2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1683" published="2005-05-20" seq="2005-1683" severity="Low" type="CVE"><desc><descript source="cve">Buffer overflow in winword.exe 10.2627.6714 and earlier in Microsoft Word for the Macintosh, before SP3 for Word 2002, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted mcw file.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/><exception/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111653088303057&amp;w=2">20050519 UNICODE BUFFER OVERFLOW IN MS-WORD</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/398649">20050521 [UPDATE] UNICODE BUFFER OVERFLOW IN MS-WORD</ref><ref source="BID" url="http://www.securityfocus.com/bid/13687">13687</ref></refs><vuln_soft><prod name="Word" vendor="Microsoft"><vers num="Gold"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1684" published="2005-05-20" seq="2005-1684" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in default.asp for episodex guestbook allows remote attackers to inject arbitrary web script or HTML via the Name field and other fields.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111661380018313&amp;w=2">20050520 episodex guestbook security bypass &amp; html injection</ref></refs><vuln_soft><prod name="episodex guestbook" vendor="episodex"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1685" published="2005-05-20" seq="2005-1685" severity="High" type="CVE"><desc><descript source="cve">episodex guestbook allows remote attackers to bypass authentication and edit scripts via a direct request to admin.asp.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111661380018313&amp;w=2">20050520 episodex guestbook security bypass &amp; html injection</ref></refs><vuln_soft><prod name="episodex guestbook" vendor="episodex"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1686" published="2005-05-20" seq="2005-1686" severity="Low" type="CVE"><desc><descript source="cve">Format string vulnerability in gedit 2.10.2 may allow attackers to cause a denial of service (application crash) via a bin file with format string specifiers in the filename.  NOTE: while this issue is triggered on the command line by the gedit user, it has been reported that web browsers and email clients could be configured to provide a file name as an argument to gedit, so there is a valid attack that crosses security boundaries.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111661117701398&amp;w=2">20050520 pst.advisory: gedit fun. opensource is god .lol windows</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200506-09.xml">GLSA-200506-09</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-499.html">RHSA-2005:499</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-138-1">USN-138-1</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-753">DSA-753</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1245.html">OVAL1245</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_36_sudo.html">SUSE-SA:2005:036</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1245">oval:org.mitre.oval:def:1245</ref></refs><vuln_soft><prod name="gedit" vendor="Gnome"><vers num="2.10.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1687" published="2005-05-20" seq="2005-1687" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in wp-trackback.php in Wordpress 1.5 and earlier allows remote attackers to execute arbitrary SQL commands via the tb_id parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111661517716733&amp;w=2">20050520 [BuHa Security] Wordpress SQL-Injection</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200506-04.xml">GLSA-200506-04</ref><ref source="CONFIRM" url="http://bugs.gentoo.org/show_bug.cgi?id=88926">http://bugs.gentoo.org/show_bug.cgi?id=88926</ref></refs><vuln_soft><prod name="Wordpress" vendor="Wordpress"><vers num="1.5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1688" published="2005-05-20" seq="2005-1688" severity="Medium" type="CVE"><desc><descript source="cve">Wordpress 1.5 and earlier allows remote attackers to obtain sensitive information via a direct request to files in (1) wp-content/themes/, (2) wp-includes/, or (3) wp-admin/, which reveal the path in an error message.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111661517716733&amp;w=2">20050520 [BuHa Security] Wordpress SQL-Injection</ref></refs><vuln_soft><prod name="Wordpress" vendor="Wordpress"><vers num="1.5" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-02-26" name="CVE-2005-1689" published="2005-07-18" seq="2005-1689" severity="High" type="CVE"><desc><descript source="cve">Double free vulnerability in the krb5_recvauth function in MIT Kerberos 5 (krb5) 1.4.1 and earlier allows remote attackers to execute arbitrary code via certain error conditions.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-757">DSA-757</ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200507-11.xml">GLSA-200507-11</ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/623332">VU#623332</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/Aug/msg00000.html">APPLE-SA-2005-08-15</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2005//Aug/msg00001.html">APPLE-SA-2005-08-17</ref><ref source="" url="http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2005-003-recvauth.txt"></ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20050703-01-U.asc">20050703-01-U</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_17_sr.html">SuSE-SR:2005:017</ref><ref source="TURBO" url="http://www.turbolinux.com/security/2005/TLSA-2005-78.txt">TLSA-2005-78</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2005/0036">2005-0036</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-224-1">USN-224-1</ref><ref source="BID" url="http://www.securityfocus.com/bid/14239">14239</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/1066">ADV-2005-1066</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/16041">16041</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/21055">kerberos-kdc-krb5recvauth-execute-code(21055)</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/17899">17899</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014461">1014461</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-562.html">RHSA-2005:562</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-567.html">RHSA-2005:567</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/17135">17135</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112119974704542&amp;w=2">20050712 MITKRB5-SA-2005-003: double-free in krb5_recvauth</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000993">CLA-2005:993</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101810-1">101810</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/446940/100/0/threaded">HPSBUX02152</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/3776">ADV-2006-3776</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/22090">22090</ref></refs><vuln_soft><prod name="Kerberos 5" vendor="MIT"><vers num="1.3"/><vers num="1.3.1"/><vers num="1.3.2"/><vers num="1.3.3"/><vers num="1.3.4"/><vers num="1.3.5"/><vers num="1.3.6"/><vers num="1.4"/><vers num="1.4.1"/></prod></vuln_soft></entry><entry modified="2005-10-25" name="CVE-2005-1690" published="2005-06-30" reject="1" seq="2005-1690" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2005-1250.  Reason: This candidate is a duplicate of CVE-2005-1250.  Notes: this duplicate occurred as a result of multiple independent discoveries and insufficient coordination by the vendor and CNA.  All CVE users should reference CVE-2005-1250 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript></desc><refs/></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1691" published="2005-07-26" seq="2005-1691" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in Internet Graphics Server in SAP before 6.40 Patch 11 allows remote attackers to read arbitrary files via &quot;..&quot; sequences in an HTTP GET request.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://www.corsaire.com/advisories/c050503-001.txt">http://www.corsaire.com/advisories/c050503-001.txt</ref></refs><vuln_soft><prod name="SAP R/3" vendor="SAP"><vers num="6.30" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1692" published="2005-05-24" seq="2005-1692" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in gxine 0.4.1 through 0.4.4, and other versions down to 0.3, allows remote attackers to execute arbitrary code via a ram file with a URL whose hostname contains format string specifiers.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111670637812128&amp;w=2">20050521 pst.advisory 2005-21: gxine remote exploitable . opensource is god .lol windows</ref><ref source="BID" url="http://www.securityfocus.com/bid/13707">13707</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15451">15451</ref><ref source="MISC" url="http://www.0xbadexworm.org/adv/gxinefmt.txt">http://www.0xbadexworm.org/adv/gxinefmt.txt</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200505-19.xml">GLSA-200505-19</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/0626">ADV-2005-0626</ref><ref source="OSVDB" url="http://www.osvdb.org/16747">16747</ref><ref source="" url="http://cvs.sourceforge.net/viewcvs.py/xine/gnome-xine/ChangeLog?rev=HEAD&amp;content-type=text/vnd.viewcvs-markup"></ref></refs><vuln_soft><prod name="gxine" vendor="xine"><vers num="0.41"/><vers num="0.42"/><vers num="0.43"/><vers num="0.44"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1693" published="2005-05-24" seq="2005-1693" severity="High" type="CVE"><desc><descript source="cve">Integer overflow in Computer Associates Vet Antivirus library, as used by CA InoculateIT 6.0, eTrust Antivirus r6.0 through 7.1, eTrust Antivirus for the Gateway r7.0 and r7.1, eTrust Secure Content Manager, eTrust Intrusion Detection, BrightStor ARCserve Backup (BAB) r11.1, Vet Antivirus, Zonelabs ZoneAlarm Security Suite, and ZoneAlarm Antivirus, allows remote attackers to gain privileges via a compressed VBA directory with a project name length of -1, which leads to a heap-based buffer overflow.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111686576416450&amp;w=2">20050523 Computer Associates Vet Antivirus Library Remote Heap Overflow</ref><ref patch="1" source="CONFIRM" url="http://crm.my-etrust.com/login.asp?username=guest&amp;target=DOCUMENT&amp;openparameter=1588">http://crm.my-etrust.com/login.asp?username=guest&amp;target=DOCUMENT&amp;openparameter=1588</ref><ref adv="1" patch="1" source="MISC" url="http://www3.ca.com/securityadvisor/vulninfo/vuln.aspx?id=32896">http://www3.ca.com/securityadvisor/vulninfo/vuln.aspx?id=32896</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/13710">13710</ref><ref source="MISC" url="http://www.rem0te.com/public/images/vet.pdf">http://www.rem0te.com/public/images/vet.pdf</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014050">1014050</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15470">15470</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15479">15479</ref></refs><vuln_soft><prod name="BrightStor ARCserve Backup" vendor="Computer Associates"><vers edition="Windows" num="11.1"/></prod><prod name="eTrust Secure Content Manager" vendor="Computer Associates"><vers num="1.0 SP1"/><vers num="1.0"/><vers num="1.1"/></prod><prod name="eTrust Antivirus" vendor="Computer Associates"><vers num="6.0"/><vers num="7.0 SP2"/><vers num="7.0"/><vers num="7.1"/><vers num="EE 6.0"/><vers num="EE 7.0"/><vers edition="Gateway" num="7.0"/><vers edition="Gateway" num="7.1"/></prod><prod name="InoculateIT" vendor="Computer Associates"><vers num="6.0"/></prod><prod name="eTrust EZ Armor" vendor="Computer Associates"><vers num="1.0"/><vers num="2.0"/><vers num="2.3"/><vers num="2.4"/><vers num="2.4.4"/><vers num="LE 2.0"/><vers num="LE 3.0.0.1.4"/></prod><prod name="ZoneAlarm" vendor="Zone Labs"><vers num="Antivirus"/><vers num="Security Suite"/></prod><prod name="Vet Antivirus" vendor="Computer Associates"><vers num="10.66"/></prod><prod name="eTrust Intrusion Detection" vendor="Computer Associates"><vers num="1.4.1.13"/><vers num="1.4.5"/><vers num="1.5"/><vers num="3.0 SP1"/><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-04-07" name="CVE-2005-1694" published="2005-05-24" seq="2005-1694" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in Xanthia.php in the Xanthia module in PostNuke 0.750 allow remote attackers to execute arbitrary SQL commands via the (1) name or (2) module parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111670823128472&amp;w=2">20050521 [SECURITYREASON.COM] PostNuke SQL Injection 0.750=&gt;x</ref><ref adv="1" patch="1" source="CONFIRM" url="http://news.postnuke.com/modules.php?op=modload&amp;name=News&amp;file=article&amp;sid=2691">http://news.postnuke.com/modules.php?op=modload&amp;name=News&amp;file=article&amp;sid=2691</ref></refs><vuln_soft><prod name="PostNuke" vendor="PostNuke Software Foundation"><vers num="0.750"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-04-07" name="CVE-2005-1695" published="2005-05-24" seq="2005-1695" severity="Low" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in the RSS module in PostNuke 0.750 and 0.760RC2 and RC3 allow remote attackers to inject arbitrary web script or HTML via the (1) rss_url parameter to magpie_slashbox.php, or the url parameter to (2) magpie_simple.php or (3) magpie_debug.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111670482500552&amp;w=2">20050521 [SECURITYREASON.COM] PostNuke XSS 0.760{RC2,RC3}</ref><ref patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111670506926649&amp;w=2">20050521 [SECURITYREASON.COM] PostNuke XSS and Full path disclosure</ref><ref adv="1" patch="1" source="CONFIRM" url="http://news.postnuke.com/modules.php?op=modload&amp;name=News&amp;file=article&amp;sid=2691">http://news.postnuke.com/modules.php?op=modload&amp;name=News&amp;file=article&amp;sid=2691</ref></refs><vuln_soft><prod name="PostNuke" vendor="PostNuke Software Foundation"><vers num="0.750"/><vers num="0.760 RC2"/><vers num="0.760 RC3"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-04-07" name="CVE-2005-1696" published="2005-05-24" seq="2005-1696" severity="Low" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in PostNuke 0.750 and 0.760RC3 allow remote attackers to inject arbitrary web script or HTML via the (1) skin or (2) paletteid parameter to demo.php in the Xanthia module, or (3) the serverName parameter to config.php in the Multisites (aka NS-Multisites) module.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111670506926649&amp;w=2">20050521 [SECURITYREASON.COM] PostNuke XSS and Full path disclosure</ref><ref adv="1" patch="1" source="CONFIRM" url="http://news.postnuke.com/modules.php?op=modload&amp;name=News&amp;file=article&amp;sid=2691">http://news.postnuke.com/modules.php?op=modload&amp;name=News&amp;file=article&amp;sid=2691</ref></refs><vuln_soft><prod name="PostNuke" vendor="PostNuke Software Foundation"><vers num="0.750"/><vers num="0.760 RC3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-04-07" name="CVE-2005-1697" published="2005-05-24" seq="2005-1697" severity="Medium" type="CVE"><desc><descript source="cve">The RSS module in PostNuke 0.750 and 0.760RC2 and RC3 allows remote attackers to obtain sensitive information via a direct request to simple_smarty.php, which reveals the path in an error message.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111670482500552&amp;w=2">20050521 [SECURITYREASON.COM] PostNuke XSS 0.760{RC2,RC3}</ref></refs><vuln_soft><prod name="PostNuke" vendor="PostNuke Software Foundation"><vers num="0.750"/><vers num="0.760 RC2"/><vers num="0.760 RC3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-04-07" name="CVE-2005-1698" published="2005-05-24" seq="2005-1698" severity="Medium" type="CVE"><desc><descript source="cve">PostNuke 0.750 and 0.760RC3 allows remote attackers to obtain sensitive information via a direct request to (1) theme.php or (2) Xanthia.php in the Xanthia module, (3) user.php, (4) thelang.php, (5) text.php, (6) html.php, (7) menu.php, (8) finclude.php, or (9) button.php in the pnblocks directory in the Blocks module, (10) config.php in the NS-Multisites (aka Multisites) module, or (11) xmlrpc.php, which reveals the path in an error message.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111670506926649&amp;w=2">20050521 [SECURITYREASON.COM] PostNuke XSS and Full path disclosure</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111670506926649&amp;w=2">20050521 [SECURITYREASON.COM] PostNuke XSS and Full path disclosure</ref></refs><vuln_soft><prod name="PostNuke" vendor="PostNuke Software Foundation"><vers num="0.750"/><vers num="0.760 RC3"/></prod></vuln_soft></entry><entry CVSS_base_score="4.0" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="2.9" CVSS_score="4.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-04-07" name="CVE-2005-1699" published="2005-05-24" seq="2005-1699" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in pnadminapi.php in the Xanthia module in PostNuke 0.760-RC3 allows remote administrators to read arbitrary files via a .. (dot dot) in the skin parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111670586322172&amp;w=2">20050521 [SECURITYREASON.COM] PostNuke Non Critical SQL Injection and Include 0.760-RC3=&gt;x cXIb8O3.10</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111670586322172&amp;w=2">20050521 [SECURITYREASON.COM] PostNuke Non Critical SQL Injection and Include 0.760-RC3=&gt;x cXIb8O3.10</ref></refs><vuln_soft><prod name="PostNuke" vendor="PostNuke Software Foundation"><vers num="0.760 RC3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-04-07" name="CVE-2005-1700" published="2005-05-24" seq="2005-1700" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in pnadmin.php in the Xanthia module in PostNuke 0.760-RC3 allows remote administrators to execute arbitrary SQL commands via the riga[0] parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111670586322172&amp;w=2">20050521 [SECURITYREASON.COM] PostNuke Non Critical SQL Injection and Include 0.760-RC3=&gt;x cXIb8O3.10</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111670586322172&amp;w=2">20050521 [SECURITYREASON.COM] PostNuke Non Critical SQL Injection and Include 0.760-RC3=&gt;x cXIb8O3.10</ref></refs><vuln_soft><prod name="PostNuke" vendor="PostNuke Software Foundation"><vers num="0.760 RC3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1701" published="2005-05-24" seq="2005-1701" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in PortailPHP 1.3 allows remote attackers to execute arbitrary SQL commands via the id parameter to the (1) News, (2) File, (3) Liens, or (4) Faq modules.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111686643823025&amp;w=2">20050521 SQL injections in PortailPHP</ref><ref source="BID" url="http://www.securityfocus.com/bid/13708">13708</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014036">1014036</ref></refs><vuln_soft><prod name="PortailPHP" vendor="PortailPHP"><vers num="1.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1702" published="2005-05-24" seq="2005-1702" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in Warrior Kings: Battles 1.23 and earlier and Warrior Kings 1.3 and earlier allows remote attackers to execute arbitrary code via format string specifiers in a nickname.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="Luigi Auriemma" url="http://aluigi.altervista.org/adv/warkings-adv.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/13711">13711</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014040">1014040</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014041">1014041</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15482">15482</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111686776303832&amp;w=2">20050523 Format string and crash in Warrior Kings 1.3 and Battles 1.23</ref></refs><vuln_soft><prod name="Warrior Kings Battles" vendor="Black Cactus"><vers num="1.23" prev="1"/></prod><prod name="Warrior Kings" vendor="Black Cactus"><vers num="1.3" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1703" published="2005-05-24" seq="2005-1703" severity="Medium" type="CVE"><desc><descript source="cve">Warrior Kings: Battles 1.23 and earlier allows remote attackers to cause a denial of service (server crash) via a partial join packet that triggers a NULL pointer dereference.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref source="Luigi Auriemma" url="http://aluigi.altervista.org/adv/warkings-adv.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/13712">13712</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014040">1014040</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014041">1014041</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15482">15482</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111686776303832&amp;w=2">20050523 Format string and crash in Warrior Kings 1.3 and Battles 1.23</ref></refs><vuln_soft><prod name="Warrior Kings Battles" vendor="Black Cactus"><vers num="1.23"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2007-02-08" name="CVE-2005-1704" published="2005-05-24" seq="2005-1704" severity="Medium" type="CVE"><desc><descript source="cve">Integer overflow in the Binary File Descriptor (BFD) library for gdb before 6.3, binutils, elfutils, and possibly other packages, allows user-assisted attackers to execute arbitrary code via a crafted object file that specifies a large number of section headers, leading to a heap-based buffer overflow.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref source="CONFIRM" url="http://bugs.gentoo.org/show_bug.cgi?id=91398">http://bugs.gentoo.org/show_bug.cgi?id=91398</ref><ref adv="1" source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200505-15.xml">GLSA-200505-15</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200506-01.xml">GLSA-200506-01</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:095">MDKSA-2005:095</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2005/0025/">2005-0025</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-136-1">USN-136-1</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-763.html">RHSA-2005:763</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-801.html">RHSA-2005:801</ref><ref source="MANDRAKE" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2005:215">MDKSA-2005:215</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15527">15527</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17718">17718</ref><ref source="OSVDB" url="http://www.osvdb.org/16757">16757</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-659.html">RHSA-2005:659</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-673.html">RHSA-2005:673</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-709.html">RHSA-2005:709</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2005-222.pdf"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/17072">17072</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17135">17135</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17257">17257</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17356">17356</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17001">17001</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=001060">CLA-2006:1060</ref><ref source="BID" url="http://www.securityfocus.com/bid/13697">13697</ref><ref source="SECUNIA" url="http://support.avaya.com/elmodocs2/security/ASA-2006-015.htm">18506</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0368.html">RHSA-2006:0368</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1016544">1016544</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21122">21122</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0354.html">RHSA-2006:0354</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20060703-01-U.asc">20060703-01-P</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21262">21262</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-178.htm"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/21717">21717</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/464745/100/0/threaded">

20070404 VMSA-2007-0003 VMware ESX 3.0.1 and 3.0.0 server security updates</ref><ref source="" url="http://www.vmware.com/support/vi3/doc/esx-55052-patch.html"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1267">
ADV-2007-1267</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24788">
24788</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:215">MDKSA-2005:215</ref></refs><vuln_soft><prod name="GNU Debugger GDB" vendor="GNU"><vers num="6.3 r2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2007-02-08" name="CVE-2005-1705" published="2005-05-24" seq="2005-1705" severity="High" type="CVE"><desc><descript source="cve">gdb before 6.3 searches the current working directory to load the .gdbinit configuration file, which allows local users to execute arbitrary commands as the user running gdb.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="CONFIRM" url="http://bugs.gentoo.org/show_bug.cgi?id=88398">http://bugs.gentoo.org/show_bug.cgi?id=88398</ref><ref adv="1" source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200505-15.xml">GLSA-200505-15</ref><ref adv="1" patch="1" source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:095">MDKSA-2005:095</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-801.html">RHSA-2005:801</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-709.html">RHSA-2005:709</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/17072">17072</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17356">17356</ref><ref source="SECUNIA" url="http://support.avaya.com/elmodocs2/security/ASA-2006-015.htm">18506</ref></refs><vuln_soft><prod name="GNU Debugger GDB" vendor="GNU"><vers num="6.3 r2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-20" name="CVE-2005-1706" published="2005-05-24" seq="2005-1706" severity="High" type="CVE"><desc><descript source="cve">Unknown vulnerability in MailScanner 4.41.3 and earlier, related to &quot;incomplete reporting of viruses in zip files,&quot; allows remote attackers to bypass virus detection.</descript></desc><sols><sol source="nvd">The vendor has released a fixed version (4.42.2)</sol></sols><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="CONFIRM" url="http://www.sng.ecs.soton.ac.uk/mailscanner/ChangeLog">http://www.sng.ecs.soton.ac.uk/mailscanner/ChangeLog</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014024">1014024</ref></refs><vuln_soft><prod name="MailScanner" vendor="MailScanner"><vers num="4.41.3" prev="1"/><vers num="4.41.2"/><vers num="4.41.1"/><vers num="4.40.11"/><vers num="4.40.8"/><vers num="4.40.7"/><vers num="4.40.6"/><vers num="4.40.4"/><vers num="4.40.2"/><vers num="4.40.1"/><vers num="4.39.6"/><vers num="4.39.4"/><vers num="4.39.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1707" published="2005-05-24" seq="2005-1707" severity="Medium" type="CVE"><desc><descript source="cve">The fn_show_postinst function in Gentoo webapp-config before 1.10-r14 allows local users to overwrite arbitrary files via a symlink attack on the postinst.txt temporary file.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/><env/></vuln_types><range><local/></range><refs><ref adv="1" source="MISC" url="http://www.zataz.net/adviso/webapp-config-05182005.txt">http://www.zataz.net/adviso/webapp-config-05182005.txt</ref><ref source="OSVDB" url="http://www.osvdb.org/16746">16746</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1014027">1014027</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/15445">15445</ref><ref source="MISC" url="http://bugs.gentoo.org/show_bug.cgi?id=91785">http://bugs.gentoo.org/show_bug.cgi?id=91785</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200506-13.xml">GLSA-200506-13</ref><ref source="BID" url="http://www.securityfocus.com/bid/13780">13780</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/0809">ADV-2005-0809</ref></refs><vuln_soft><prod name="Gentoo Linux webapp-config" vendor="Gentoo"><vers num="1.10 r14"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1708" published="2005-05-24" seq="2005-1708" severity="Medium" type="CVE"><desc><descript source="cve">templates.admin.users.user_form_processing in Blue Coat Reporter before 7.1.2 allows authenticated users to gain administrator privileges via an HTTP POST that sets volatile.user.administrator to true.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref patch="1" source="CONFIRM" url="http://www.bluecoat.com/support/knowledge/advisory_reporter_711_vulnerabilities.html">http://www.bluecoat.com/support/knowledge/advisory_reporter_711_vulnerabilities.html</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/0589">ADV-2005-0589</ref><ref source="OSVDB" url="http://www.osvdb.org/16763">16763</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/15452">15452</ref><ref source="BID" url="http://www.securityfocus.com/bid/13723">13723</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111695726810435&amp;w=2">20050524 Blue Coat Reporter multiple remote vulnerabilities</ref></refs><vuln_soft><prod name="Reporter" vendor="Blue Coat Systems"><vers num="7.1.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1709" published="2005-05-24" seq="2005-1709" severity="High" type="CVE"><desc><descript source="cve">Unknown vulnerability in Blue Coat Reporter before 7.1.2 allows remote unauthenticated attackers to add a license.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref patch="1" source="CONFIRM" url="http://www.bluecoat.com/support/knowledge/advisory_reporter_711_vulnerabilities.html">http://www.bluecoat.com/support/knowledge/advisory_reporter_711_vulnerabilities.html</ref><ref patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/0589">ADV-2005-0589</ref><ref source="OSVDB" url="http://www.osvdb.org/16764">16764</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/15452">15452</ref><ref source="BID" url="http://www.securityfocus.com/bid/13725">13725</ref></refs><vuln_soft><prod name="Reporter" vendor="Blue Coat Systems"><vers num="7.1.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1710" published="2005-05-24" seq="2005-1710" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Blue Coat Reporter before 7.1.2 allow remote attackers to inject arbitrary web script or HTML via (1) the username in an Add User window or (2) the license key (volatile.license_to_add parameter) in the Licensing page.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="CONFIRM" url="http://www.bluecoat.com/support/knowledge/advisory_reporter_711_vulnerabilities.html">http://www.bluecoat.com/support/knowledge/advisory_reporter_711_vulnerabilities.html</ref><ref patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/0589">ADV-2005-0589</ref><ref source="OSVDB" url="http://www.osvdb.org/16765">16765</ref><ref source="OSVDB" url="http://www.osvdb.org/16766">16766</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/15452">15452</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111695726810435&amp;w=2">20050524 Blue Coat Reporter multiple remote vulnerabilities</ref></refs><vuln_soft><prod name="Reporter" vendor="Blue Coat Systems"><vers num="7.1.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1711" published="2005-05-24" seq="2005-1711" severity="High" type="CVE"><desc><descript source="cve">Gibraltar Firewall 2.2 and earlier, when using the ClamAV update to 0.81 for Squid, uses a defunct ClamAV method to scan memory for viruses, which does not return an error code and prevents viruses from being detected.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><env/></vuln_types><range><network/></range><refs><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1014030">1014030</ref></refs><vuln_soft><prod name="Gibraltar Firewall" vendor="Gibraltar"><vers num="2.2"/></prod><prod name="ClamAV" vendor="Clam Anti-Virus"><vers num=""/></prod><prod name="Squid" vendor="Squid"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-08-24" name="CVE-2005-1712" published="2005-05-24" seq="2005-1712" severity="High" type="CVE"><desc><descript source="cve">Unknown vulnerability in Serendipity 0.8, when used with multiple authors, allows unprivileged authors to upload arbitrary media files.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref patch="1" source="CONFIRM" url="http://sourceforge.net/project/shownotes.php?release_id=328092">http://sourceforge.net/project/shownotes.php?release_id=328092</ref><ref source="OSVDB" url="http://www.osvdb.org/16659">16659</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/15405">15405</ref></refs><vuln_soft><prod name="Serendipity" vendor="SY9"><vers num="0.8"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1713" published="2005-05-24" seq="2005-1713" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Serendipity 0.8 allow remote attackers to inject arbitrary web script or HTML via the (1) templatedropdown and (2) shoutbox plugins.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="CONFIRM" url="http://sourceforge.net/project/shownotes.php?release_id=328092">http://sourceforge.net/project/shownotes.php?release_id=328092</ref><ref patch="1" source="OSVDB" url="http://www.osvdb.org/16660">16660</ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/16661">16661</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/15405">15405</ref></refs><vuln_soft><prod name="Serendipity" vendor="S9Y"><vers num="0.8"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1714" published="2005-05-24" seq="2005-1714" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in NetWin SurgeMail 3.0c2 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/0576">ADV-2005-0576</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/15425">15425</ref></refs><vuln_soft><prod name="SurgeMail" vendor="NetWin"><vers num="3.0c2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1715" published="2005-05-24" seq="2005-1715" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in index.php for TOPo 2.2 (2.2.178) allows remote attackers to inject arbitrary web script or HTML via the (1) m, (2) s, (3) ID, or (4) t parameters, or the (5) field name, (6) Your Web field, or (7) email field in the comments section.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="MISC" url="http://lostmon.blogspot.com/2005/05/topo-22-multiple-variable-fields-xss.html">http://lostmon.blogspot.com/2005/05/topo-22-multiple-variable-fields-xss.html</ref><ref source="BID" url="http://www.securityfocus.com/bid/13700">13700</ref><ref source="BID" url="http://www.securityfocus.com/bid/13701">13701</ref><ref source="OSVDB" url="http://www.osvdb.org/16699">16699</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014016">1014016</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15325">15325</ref></refs><vuln_soft><prod name="TOPo" vendor="EJ3"><vers num="2.2"/><vers num="2.2.178"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1716" published="2005-05-24" seq="2005-1716" severity="Medium" type="CVE"><desc><descript source="cve">TOPo 2.2 (2.2.178) stores data files in the data directory under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information such as client IP addresses.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref source="MISC" url="http://lostmon.blogspot.com/2005/05/topo-22-multiple-variable-fields-xss.html">http://lostmon.blogspot.com/2005/05/topo-22-multiple-variable-fields-xss.html</ref><ref source="OSVDB" url="http://www.osvdb.org/16700">16700</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014016">1014016</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15325">15325</ref></refs><vuln_soft><prod name="TOPo" vendor="EJ3"><vers num="2.2"/><vers num="2.2.178"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1717" published="2005-05-24" seq="2005-1717" severity="Medium" type="CVE"><desc><descript source="cve">ZyXEL Prestige 650R-31 router running ZyNOS FW v3.40(KO.1) allows remote attackers to cause a denial of service (CPU consumption and network loss) via crafted fragmented IP packets.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://www.infobyte.com.ar/adv/ISR-10.html">http://www.infobyte.com.ar/adv/ISR-10.html</ref><ref source="BID" url="http://www.securityfocus.com/bid/13703">13703</ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/16779">16779</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/15463">15463</ref></refs><vuln_soft><prod name="Prestige 650R-31" vendor="ZyXEL"><vers num="3.40 KO.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1718" published="2005-05-24" seq="2005-1718" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in LS Games War Times 1.03 and earlier allows remote attackers to cause a denial of service (server crash) via a long nickname.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="Luigi Auriemma" url="http://aluigi.altervista.org/adv/wartimesboom-adv.txt"></ref><ref source="OSVDB" url="http://www.osvdb.org/16619">16619</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013981">1013981</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15363">15363</ref></refs><vuln_soft><prod name="War Times" vendor="LS Games"><vers num="1.03"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1719" published="2005-05-24" seq="2005-1719" severity="High" type="CVE"><desc><descript source="cve">Unknown vulnerability in ALWIL avast! antivirus 4 (4.6.6230) and earlier, when running on Windows NT 4.0, does not properly detect certain viruses.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><env/><other/></vuln_types><range><network/></range><refs><ref patch="1" source="MISC" url="http://www.avast.com/eng/av4_revision_history.html">http://www.avast.com/eng/av4_revision_history.html</ref><ref adv="1" source="SECTRACK" url="http://securitytracker.com/id?1013991">1013991</ref></refs><vuln_soft><prod name="Avast Antivirus" vendor="ALWIL"><vers num="4.6.623"/><vers num="4.6.603"/><vers num="4.5.561"/><vers num="4.5.549"/><vers num="4.5.518"/><vers num="4.1.501"/><vers num="4.1.418"/><vers num="4.1.412"/><vers num="4.1.396"/><vers num="4.1.389"/><vers num="4.1.357"/><vers num="4.1.342"/><vers num="4.1.335"/><vers num="4.1.319"/><vers num="4.1.304"/><vers num="4.1.289"/><vers num="4.1.287"/><vers num="4.1.278"/><vers num="4.1.268"/><vers num="4.1.260"/><vers num="4.0.235"/><vers num="4.0.229"/><vers num="4.0.211"/><vers num="4.0.202"/><vers num="4.0.183"/><vers num="4.0.172"/><vers num="4.0.168"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1720" published="2005-06-16" seq="2005-1720" severity="Low" type="CVE"><desc><descript source="cve">AFP Server for Mac OS X 10.4.1, when using an ACL enabled volume, does not properly remove an ACL when a file is copied to a directory that does not use ACLs, which will override the POSIX file permissions for that ACL.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/Jun/msg00000.html">APPLE-SA-2005-06-08</ref></refs><vuln_soft><prod name="AFP Server" vendor="Apple"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1721" published="2005-06-16" seq="2005-1721" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the legacy client support for AFP Server for Mac OS X 10.4.1 allows attackers to execute arbitrary code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/Jun/msg00000.html">APPLE-SA-2005-06-08</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014138">1014138</ref></refs><vuln_soft><prod name="AFP Server" vendor="Apple"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1722" published="2005-06-16" seq="2005-1722" severity="High" type="CVE"><desc><descript source="cve">Unknown vulnerability in the CoreGraphics Window Server for Mac OS X 10.4.x up to 10.4.1 allows local users to inject arbitrary commands into root sessions.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><other/></vuln_types><range><local/></range><refs><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/Jun/msg00000.html">APPLE-SA-2005-06-08</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.4.1"/><vers num="10.4"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.4.1"/><vers num="10.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1723" published="2005-06-08" seq="2005-1723" severity="High" type="CVE"><desc><descript source="cve">LaunchServices in Apple Mac OS X 10.4.x up to 10.4.1 does not properly mark file extensions and MIME types as unsafe if an Apple Uniform Type Identifier (UTI) is not created when the type is added to the database of unsafe types, which could allow attackers to bypass intended restrictions.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/Jun/msg00000.html">APPLE-SA-2005-06-08</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014141">1014141</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.4.1"/><vers num="10.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1724" published="2005-06-08" seq="2005-1724" severity="High" type="CVE"><desc><descript source="cve">NFS on Apple Mac OS X 10.4.x up to 10.4.1 does not properly obey the -network or -mask flags for a filesystem and exports it to everyone, which allows remote attackers to bypass intended access restrictions.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/Jun/msg00000.html">APPLE-SA-2005-06-08</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014142">1014142</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.4.1"/><vers num="10.4"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1725" published="2005-06-08" seq="2005-1725" severity="Low" type="CVE"><desc><descript source="cve">launchd 106 in Apple Mac OS X 10.4.x up to 10.4.1 allows local users to overwrite arbitrary files via a symlink attack on the socket file in an insecure temporary directory.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111833509424379&amp;w=2">20050608 [ Suresec Advisories ] - Mac OS X 10.4 - launchd local root vulnerability</ref><ref adv="1" source="MISC" url="http://www.suresec.org/advisories/adv3.pdf">http://www.suresec.org/advisories/adv3.pdf</ref><ref adv="1" patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/Jun/msg00000.html">APPLE-SA-2005-06-08</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.4.1"/><vers num="10.4"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-08-08" name="CVE-2005-1726" published="2005-12-31" seq="2005-1726" severity="Medium" type="CVE"><desc><descript source="cve">The CoreGraphics Window Server in Mac OS X 10.4.1 allows local users with console access to gain privileges by &quot;launching commands into root sessions.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><other/></vuln_types><range><local/></range><refs><ref source="" url="http://docs.info.apple.com/article.html?artnum=301742"></ref><ref source="APPLE" url="http://lists.apple.com/archives/Security-announce/2005/Jun/msg00000.html">APPLE-SA-2005-06-08</ref></refs><vuln_soft><prod name="Mac OS X" vendor="Apple"><vers num="10.4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="3.7" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="6.4" CVSS_score="3.7" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1727" published="2005-06-08" seq="2005-1727" severity="Low" type="CVE"><desc><descript source="cve">Apple Mac OS X 10.4.x up to 10.4.1 sets insecure world- and group-writable permissions for the (1) system cache folder and (2) Dashboard system widgets, which allows local users to conduct unauthorized file operations via &quot;file race conditions.&quot;</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><race/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/Jun/msg00000.html">APPLE-SA-2005-06-08</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.4.1"/><vers num="10.4"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1728" published="2005-06-08" seq="2005-1728" severity="Medium" type="CVE"><desc><descript source="cve">MCX Client for Apple Mac OS X 10.4.x up to 10.4.1 insecurely logs Portable Home Directory credentials, which allows local users to obtain the credentials.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/Jun/msg00000.html">APPLE-SA-2005-06-08</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014148">1014148</ref></refs><vuln_soft><prod name="Mac OS X" vendor="Apple"><vers num="10.4.1"/><vers num="10.4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1729" published="2005-06-12" seq="2005-1729" severity="Medium" type="CVE"><desc><descript source="cve">Novell eDirectory 8.7.3 allows remote attackers to cause a denial of service (application crash) via a URL containing an MS-DOS device name such as AUX, CON, PRN, COM1, or LPT1.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-June/034536.html">20050612 [CIRT.DK - Advisory] Novell eDirectory 8.7.3 DOS Device name Denial of Service</ref><ref adv="1" source="MISC" url="http://www.cirt.dk/advisories/cirt-33-advisory.pdf">http://www.cirt.dk/advisories/cirt-33-advisory.pdf</ref><ref source="" url="http://support.novell.com/cgi-bin/search/searchtid.cgi?/10097766.htm"></ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014177">1014177</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15676">15676</ref></refs><vuln_soft><prod name="eDirectory" vendor="Novell"><vers num="8.7.3"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-03-08" name="CVE-2005-1730" published="2005-12-31" seq="2005-1730" severity="High" type="CVE"><desc><descript source="cve">Multiple vulnerabilities in the OpenSSL ASN.1 parser, as used in Novell iManager 2.0.2, allows remote attackers to cause a denial of service (NULL pointer dereference) via crafted packets, as demonstrated by &quot;OpenSSL ASN.1 brute forcer.&quot;  NOTE: this issue might overlap CVE-2004-0079, CVE-2004-0081, or CVE-2004-0112.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://www.cirt.dk/advisories/cirt-32-advisory.pdf"></ref><ref source="" url="http://www.securityfocus.com/data/vulnerabilities/exploits/ASN.1-Brute.c"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/0744">ADV-2005-0744</ref><ref source="BID" url="http://www.securityfocus.com/bid/8732">
8732</ref></refs><vuln_soft><prod name="iManager" vendor="Novell"><vers num="2.0.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1732" published="2005-05-24" seq="2005-1732" severity="Medium" type="CVE"><desc><descript source="cve">Cookie Cart allows remote attackers to read the Order Notification list via the testmycgi and path parameters to testmy.cgi.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111686721022831&amp;w=2">20050521 Cookie Cart Default Installation Multiple Vulnerabilities</ref><ref adv="1" source="MISC" url="http://www.soulblack.com.ar/repo/papers/cookiec_advisory.txt">http://www.soulblack.com.ar/repo/papers/cookiec_advisory.txt</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014026">1014026</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15448">15448</ref></refs><vuln_soft><prod name="Cookie Cart" vendor="Metro Marketing"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1733" published="2005-05-24" seq="2005-1733" severity="Medium" type="CVE"><desc><descript source="cve">Cookie Cart stores the password file under the web document root with insufficient access control, which allows remote attackers to obtain usernames and encrypted passwords via a direct request to passwd.txt.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref source="MISC" url="http://www.soulblack.com.ar/repo/papers/cookiec_advisory.txt">http://www.soulblack.com.ar/repo/papers/cookiec_advisory.txt</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014026">1014026</ref></refs><vuln_soft><prod name="Cookie Cart" vendor="Metro Marketing"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1734" published="2005-05-24" seq="2005-1734" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in PROMS before 0.11 allow remote attackers to execute arbitrary SQL commands via unknown vectors.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="CONFIRM" url="http://projects.electricmonk.nl/proms.php?action=ReleaseOverview&amp;project_id=2&amp;release_id=91">http://projects.electricmonk.nl/proms.php?action=ReleaseOverview&amp;project_id=2&amp;release_id=91</ref><ref source="CONFIRM" url="http://projects.electricmonk.nl//files/PROMS/proms-0.11.tar.gz">http://projects.electricmonk.nl//files/PROMS/proms-0.11.tar.gz</ref><ref adv="1" source="SECTRACK" url="http://securitytracker.com/id?1013992">1013992</ref></refs><vuln_soft><prod name="PROMS" vendor="electricmonk"><vers num="0.10" prev="1"/><vers num="0.9"/><vers num="0.8"/><vers num="0.7"/><vers num="0.6.1"/><vers num="0.6"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1735" published="2005-05-24" seq="2005-1735" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in PROMS before 0.11 allow remote attackers to inject arbitrary web script or HTML via unknown vectors.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="CONFIRM" url="http://projects.electricmonk.nl/proms.php?action=ReleaseOverview&amp;project_id=2&amp;release_id=91">http://projects.electricmonk.nl/proms.php?action=ReleaseOverview&amp;project_id=2&amp;release_id=91</ref><ref source="CONFIRM" url="http://projects.electricmonk.nl//files/PROMS/proms-0.11.tar.gz">http://projects.electricmonk.nl//files/PROMS/proms-0.11.tar.gz</ref><ref adv="1" source="SECTRACK" url="http://securitytracker.com/id?1013992">1013992</ref></refs><vuln_soft><prod name="PROMS" vendor="electricmonk"><vers num="0.10" prev="1"/><vers num="0.9"/><vers num="0.8"/><vers num="0.7"/><vers num="0.6.1"/><vers num="0.6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1736" published="2005-05-24" seq="2005-1736" severity="High" type="CVE"><desc><descript source="cve">PROMS 0.11 does not properly handle &quot;certain combinations of rights,&quot; which gives more rights to users than intended.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref source="CONFIRM" url="http://projects.electricmonk.nl/proms.php?action=ReleaseOverview&amp;project_id=2&amp;release_id=91">http://projects.electricmonk.nl/proms.php?action=ReleaseOverview&amp;project_id=2&amp;release_id=91</ref><ref source="CONFIRM" url="http://projects.electricmonk.nl//files/PROMS/proms-0.11.tar.gz">http://projects.electricmonk.nl//files/PROMS/proms-0.11.tar.gz</ref></refs><vuln_soft><prod name="PROMS" vendor="electricmonk"><vers num="0.11" prev="1"/><vers num="0.10"/><vers num="0.9"/><vers num="0.8"/><vers num="0.7"/><vers num="0.6.1"/><vers num="0.6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1737" published="2005-05-24" seq="2005-1737" severity="High" type="CVE"><desc><descript source="cve">Multiple unknown vulnerabilities in PROMS 0.11 allow &quot;non-authorized users&quot; to (1) view or modify the project member list or (2) modify the todos list.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="SECTRACK" url="http://securitytracker.com/id?1013992">1013992</ref><ref source="USCERT" url="http://www.us-cert.gov/cas/bulletins/SB05-145.html#proms">Summary of Security Items from May 18 through May 24, 2005</ref></refs><vuln_soft><prod name="PROMS" vendor="electricmonk"><vers num="0.11"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1738" published="2005-05-24" seq="2005-1738" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in the logPrintBadfile function in delbadfiles.c Iron Bars SHell (ibsh) before 0.3d allows users to &quot;access files outside the home directory&quot; and possibly execute arbitrary code via certain inputs that are not properly handled in a syslog call.</descript></desc><sols><sol source="nvd">Fixed in version 0.3 d</sol></sols><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="CONFIRM" url="http://sourceforge.net/project/shownotes.php?release_id=329340">http://sourceforge.net/project/shownotes.php?release_id=329340</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/13720">13720</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/15473">15473</ref></refs><vuln_soft><prod name="Iron Bars SHell" vendor="Iron Bars SHell"><vers num="0.3c"/><vers num="0.3b"/><vers num="0.3a"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1739" published="2005-05-24" seq="2005-1739" severity="Medium" type="CVE"><desc><descript source="cve">The XWD Decoder in ImageMagick before 6.2.2.3, and GraphicsMagick before 1.1.6-r1, allows remote attackers to cause a denial of service (infinite loop) via an image with a zero color mask.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200505-16.xml">GLSA-200505-16</ref><ref source="MISC" url="http://bugs.gentoo.org/show_bug.cgi?id=90423">http://bugs.gentoo.org/show_bug.cgi?id=90423</ref><ref patch="1" source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-132-1">USN-132-1</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/13705">13705</ref><ref source="OSVDB" url="http://www.osvdb.org/16774">16774</ref><ref source="OSVDB" url="http://www.osvdb.org/16775">16775</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/15429">15429</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15446">15446</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:107">MDKSA-2005:107</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval960.html">OVAL960</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15453">15453</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-480.html">RHSA-2005:480</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:960">oval:org.mitre.oval:def:960</ref></refs><vuln_soft><prod name="ImageMagick" vendor="ImageMagick"><vers num="5.3.3"/><vers num="5.3.8"/><vers num="5.4.3"/><vers num="5.4.4.5"/><vers num="5.4.7"/><vers num="5.4.8.2.1.1.0"/><vers num="5.4.8"/><vers num="5.5.3.2.1.2.0"/><vers num="5.5.4"/><vers num="5.5.6.0 2003-04-09"/><vers num="5.5.6"/><vers num="5.5.7"/><vers num="6.0"/><vers num="6.0.1"/><vers num="6.0.2.5"/><vers num="6.0.2"/><vers num="6.0.3"/><vers num="6.0.4"/><vers num="6.0.5"/><vers num="6.0.6"/><vers num="6.0.7"/><vers num="6.0.8"/><vers num="6.1"/><vers num="6.1.1.6"/><vers num="6.1.2"/><vers num="6.1.3"/><vers num="6.1.4"/><vers num="6.1.5"/><vers num="6.1.6"/><vers num="6.1.7"/><vers num="6.1.8"/><vers num="6.2.0.7"/><vers num="6.2.0.4"/><vers num="6.2"/><vers num="6.2.1"/><vers num="6.2.2"/></prod><prod name="GraphicsMagick" vendor="GraphicsMagick"><vers num="1.0"/><vers num="1.0.6"/><vers num="1.1"/><vers num="1.1.3"/><vers num="1.1.4"/><vers num="1.1.5"/><vers num="1.1.6"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1740" published="2005-05-24" seq="2005-1740" severity="High" type="CVE"><desc><descript source="cve">fixproc in Net-snmp 5.x before 5.2.1-r1 creates temporary files insecurely, which allows local users to modify the contents of those files to execute arbitrary commands, or overwrite arbitrary files via a symlink attack.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="MISC" url="http://www.zataz.net/adviso/net-snmp-05182005.txt">http://www.zataz.net/adviso/net-snmp-05182005.txt</ref><ref adv="1" source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200505-18.xml">GLSA-200505-18</ref><ref patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/0598">ADV-2005-0598</ref><ref source="OSVDB" url="http://www.osvdb.org/16778">16778</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15471">15471</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014039">1014039</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:025">MDKSA-2006:025</ref><ref source="BID" url="http://www.securityfocus.com/bid/13715">13715</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18635">18635</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-373.html">RHSA-2005:373</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-395.html">RHSA-2005:395</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17135">17135</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16999">16999</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:025">MDKSA-2006:025</ref></refs><vuln_soft><prod name="Net-SNMP" vendor="Net-SNMP"><vers num="5.1.2"/><vers num="5.0.9"/><vers num="5.0.8"/><vers num="5.0.7"/><vers num="5.0.6"/><vers num="5.0.5"/><vers num="5.0.4 pre2"/><vers num="5.0.3"/><vers num="5.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1741" published="2005-05-24" seq="2005-1741" severity="Medium" type="CVE"><desc><descript source="cve">Gearbox Software Halo: Combat Evolved 1.6 allows remote attackers to cause a denial of service (infinite loop) via malformed data.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="Luigi Auriemma" url="http://aluigi.altervista.org/adv/haloloop-adv.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/13728">13728</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/0616">ADV-2005-0616</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014067">1014067</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15501">15501</ref></refs><vuln_soft><prod name="Halo Combat Evolved" vendor="Gearbox Software"><vers num="1.6"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1742" published="2005-05-24" seq="2005-1742" severity="Medium" type="CVE"><desc><descript source="cve">BEA WebLogic Server and WebLogic Express 8.1 SP2 and SP3 allows users with the Monitor security role to &quot;shrink or reset JDBC connection pools.&quot;</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="CONFIRM" url="http://dev2dev.bea.com/pub/advisory/125">http://dev2dev.bea.com/pub/advisory/125</ref><ref source="BID" url="http://www.securityfocus.com/bid/13717">13717</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/0602">ADV-2005-0602</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/15486">15486</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014049">1014049</ref></refs><vuln_soft><prod name="WebLogic Server" vendor="BEA Systems"><vers num="6.0"/><vers num="6.0 SP1"/><vers num="6.0 SP2"/><vers num="6.1"/><vers num="6.1 SP1"/><vers num="6.1 SP2"/><vers num="6.1 SP3"/><vers num="6.1 SP4"/><vers num="6.1 SP5"/><vers num="6.1 SP6"/><vers num="7.0"/><vers num="7.0.0.1"/><vers num="7.0.0.1 SP1"/><vers num="7.0.0.1 SP2"/><vers num="7.0.0.1 SP3"/><vers num="7.0.0.1 SP4"/><vers num="7.0 SP1"/><vers num="7.0 SP2"/><vers num="7.0 SP3"/><vers num="7.0 SP4"/><vers num="7.0 SP5"/><vers num="8.1"/><vers num="8.1 SP1"/><vers num="8.1 SP2"/><vers num="8.1 SP3"/><vers num="8.1 SP4"/><vers edition="Win32" num="6.0"/><vers edition="Win32" num="6.0 SP1"/><vers edition="Win32" num="6.0 SP2"/><vers edition="Win32" num="6.1"/><vers edition="Win32" num="6.1 SP1"/><vers edition="Win32" num="6.1 SP2"/><vers edition="Win32" num="6.1 SP4"/><vers edition="Win32" num="6.1 SP5"/><vers edition="Win32" num="6.1 SP6"/><vers edition="Win32" num="7.0"/><vers edition="Win32" num="7.0.0.1 SP1"/><vers edition="Win32" num="7.0.0.1 SP2"/><vers edition="Win32" num="7.0 SP1"/><vers edition="Win32" num="7.0 SP4"/><vers edition="Win32" num="7.0 SP3"/><vers edition="Win32" num="7.0 SP5"/><vers edition="Win32" num="8.1"/><vers edition="Win32" num="8.1 SP1"/><vers edition="Win32" num="8.1 SP2"/><vers edition="Win32" num="8.1 SP3"/><vers edition="Win32" num="8.1 SP4"/></prod><prod name="WebLogic Portal" vendor="BEA Systems"><vers num="8.0"/></prod><prod name="WebLogic Express" vendor="BEA Systems"><vers num="6.0"/><vers num="6.0 SP1"/><vers num="6.0 SP2"/><vers num="6.1"/><vers num="6.1 SP1"/><vers num="6.1 SP2"/><vers num="6.1 SP3"/><vers num="6.1 SP4"/><vers num="6.1 SP5"/><vers num="7.0"/><vers num="7.0.0.1"/><vers num="7.0.0.1 SP1"/><vers num="7.0.0.1 SP2"/><vers num="7.0.0.1 SP3"/><vers num="7.0.0.1 SP4"/><vers num="7.0 SP1"/><vers num="7.0 SP2"/><vers num="7.0 SP3"/><vers num="7.0 SP4"/><vers num="7.0 SP5"/><vers num="8.1"/><vers num="8.1 SP1"/><vers num="8.1 SP2"/><vers num="8.1 SP3"/><vers num="8.1 SP4"/><vers edition="Win32" num="6.0"/><vers edition="Win32" num="6.0 SP1"/><vers edition="Win32" num="6.0 SP2"/><vers edition="Win32" num="6.1"/><vers edition="Win32" num="6.1 SP1"/><vers edition="Win32" num="6.1 SP2"/><vers edition="Win32" num="6.1 SP3"/><vers edition="Win32" num="6.1 SP4"/><vers edition="Win32" num="6.1 SP5"/><vers edition="Win32" num="7.0"/><vers edition="Win32" num="7.0.0.1"/><vers edition="Win32" num="7.0.0.1 SP1"/><vers edition="Win32" num="7.0.0.1 SP2"/><vers edition="Win32" num="7.0 SP1"/><vers edition="Win32" num="7.0 SP2"/><vers edition="Win32" num="7.0 SP3"/><vers edition="Win32" num="7.0 SP4"/><vers edition="Win32" num="7.0 SP5"/><vers edition="Win32" num="8.1"/><vers edition="Win32" num="8.1 SP1"/><vers edition="Win32" num="8.1 SP2"/><vers edition="Win32" num="8.1 SP3"/><vers edition="Win32" num="8.1 SP4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1743" published="2005-05-24" seq="2005-1743" severity="High" type="CVE"><desc><descript source="cve">BEA WebLogic Server and WebLogic Express 8.1 through Service Pack 3 and 7.0 through Service Pack 5 does not properly handle when a security provider throws an exception, which may cause WebLogic to use incorrect identity for the thread, or to fail to audit security exceptions.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="CONFIRM" url="http://dev2dev.bea.com/pub/advisory/126">http://dev2dev.bea.com/pub/advisory/126</ref><ref source="BID" url="http://www.securityfocus.com/bid/13717">13717</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/0603">ADV-2005-0603</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/15486">15486</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014049">1014049</ref></refs><vuln_soft><prod name="WebLogic Server" vendor="BEA Systems"><vers num="6.0"/><vers num="6.0 SP1"/><vers num="6.0 SP2"/><vers num="6.1"/><vers num="6.1 SP1"/><vers num="6.1 SP2"/><vers num="6.1 SP3"/><vers num="6.1 SP4"/><vers num="6.1 SP5"/><vers num="6.1 SP6"/><vers num="7.0"/><vers num="7.0.0.1"/><vers num="7.0.0.1 SP1"/><vers num="7.0.0.1 SP2"/><vers num="7.0.0.1 SP3"/><vers num="7.0.0.1 SP4"/><vers num="7.0 SP1"/><vers num="7.0 SP2"/><vers num="7.0 SP3"/><vers num="7.0 SP4"/><vers num="7.0 SP5"/><vers num="8.1"/><vers num="8.1 SP1"/><vers num="8.1 SP2"/><vers num="8.1 SP3"/><vers num="8.1 SP4"/><vers edition="Win32" num="6.0"/><vers edition="Win32" num="6.0 SP1"/><vers edition="Win32" num="6.0 SP2"/><vers edition="Win32" num="6.1"/><vers edition="Win32" num="6.1 SP1"/><vers edition="Win32" num="6.1 SP2"/><vers edition="Win32" num="6.1 SP4"/><vers edition="Win32" num="6.1 SP5"/><vers edition="Win32" num="6.1 SP6"/><vers edition="Win32" num="7.0"/><vers edition="Win32" num="7.0.0.1 SP1"/><vers edition="Win32" num="7.0.0.1 SP2"/><vers edition="Win32" num="7.0 SP1"/><vers edition="Win32" num="7.0 SP4"/><vers edition="Win32" num="7.0 SP3"/><vers edition="Win32" num="7.0 SP5"/><vers edition="Win32" num="8.1"/><vers edition="Win32" num="8.1 SP1"/><vers edition="Win32" num="8.1 SP2"/><vers edition="Win32" num="8.1 SP3"/><vers edition="Win32" num="8.1 SP4"/></prod><prod name="WebLogic Portal" vendor="BEA Systems"><vers num="8.0"/></prod><prod name="WebLogic Express" vendor="BEA Systems"><vers num="6.0"/><vers num="6.0 SP1"/><vers num="6.0 SP2"/><vers num="6.1"/><vers num="6.1 SP1"/><vers num="6.1 SP2"/><vers num="6.1 SP3"/><vers num="6.1 SP4"/><vers num="6.1 SP5"/><vers num="7.0"/><vers num="7.0.0.1"/><vers num="7.0.0.1 SP1"/><vers num="7.0.0.1 SP2"/><vers num="7.0.0.1 SP3"/><vers num="7.0.0.1 SP4"/><vers num="7.0 SP1"/><vers num="7.0 SP2"/><vers num="7.0 SP3"/><vers num="7.0 SP4"/><vers num="7.0 SP5"/><vers num="8.1"/><vers num="8.1 SP1"/><vers num="8.1 SP2"/><vers num="8.1 SP3"/><vers num="8.1 SP4"/><vers edition="Win32" num="6.0"/><vers edition="Win32" num="6.0 SP1"/><vers edition="Win32" num="6.0 SP2"/><vers edition="Win32" num="6.1"/><vers edition="Win32" num="6.1 SP1"/><vers edition="Win32" num="6.1 SP2"/><vers edition="Win32" num="6.1 SP3"/><vers edition="Win32" num="6.1 SP4"/><vers edition="Win32" num="6.1 SP5"/><vers edition="Win32" num="7.0"/><vers edition="Win32" num="7.0.0.1"/><vers edition="Win32" num="7.0.0.1 SP1"/><vers edition="Win32" num="7.0.0.1 SP2"/><vers edition="Win32" num="7.0 SP1"/><vers edition="Win32" num="7.0 SP2"/><vers edition="Win32" num="7.0 SP3"/><vers edition="Win32" num="7.0 SP4"/><vers edition="Win32" num="7.0 SP5"/><vers edition="Win32" num="8.1"/><vers edition="Win32" num="8.1 SP1"/><vers edition="Win32" num="8.1 SP2"/><vers edition="Win32" num="8.1 SP3"/><vers edition="Win32" num="8.1 SP4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1744" published="2005-05-24" seq="2005-1744" severity="High" type="CVE"><desc><descript source="cve">BEA WebLogic Server and WebLogic Express 7.0 through Service Pack 5 does not log out users when an application is redeployed, which allows those users to continue to access the application without having to log in again, which may be in violation of newly changed security constraints or role mappings.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/><design/></vuln_types><range><network/></range><refs><ref adv="1" source="CONFIRM" url="http://dev2dev.bea.com/pub/advisory/127">http://dev2dev.bea.com/pub/advisory/127</ref><ref source="BID" url="http://www.securityfocus.com/bid/13717">13717</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/0604">ADV-2005-0604</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/15486">15486</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014049">1014049</ref></refs><vuln_soft><prod name="WebLogic Server" vendor="BEA Systems"><vers num="6.0"/><vers num="6.0 SP1"/><vers num="6.0 SP2"/><vers num="6.1"/><vers num="6.1 SP1"/><vers num="6.1 SP2"/><vers num="6.1 SP3"/><vers num="6.1 SP4"/><vers num="6.1 SP5"/><vers num="6.1 SP6"/><vers num="7.0"/><vers num="7.0.0.1"/><vers num="7.0.0.1 SP1"/><vers num="7.0.0.1 SP2"/><vers num="7.0.0.1 SP3"/><vers num="7.0.0.1 SP4"/><vers num="7.0 SP1"/><vers num="7.0 SP2"/><vers num="7.0 SP3"/><vers num="7.0 SP4"/><vers num="7.0 SP5"/><vers num="8.1"/><vers num="8.1 SP1"/><vers num="8.1 SP2"/><vers num="8.1 SP3"/><vers num="8.1 SP4"/><vers edition="Win32" num="6.0"/><vers edition="Win32" num="6.0 SP1"/><vers edition="Win32" num="6.0 SP2"/><vers edition="Win32" num="6.1"/><vers edition="Win32" num="6.1 SP1"/><vers edition="Win32" num="6.1 SP2"/><vers edition="Win32" num="6.1 SP4"/><vers edition="Win32" num="6.1 SP5"/><vers edition="Win32" num="6.1 SP6"/><vers edition="Win32" num="7.0"/><vers edition="Win32" num="7.0.0.1 SP1"/><vers edition="Win32" num="7.0.0.1 SP2"/><vers edition="Win32" num="7.0 SP1"/><vers edition="Win32" num="7.0 SP4"/><vers edition="Win32" num="7.0 SP3"/><vers edition="Win32" num="7.0 SP5"/><vers edition="Win32" num="8.1"/><vers edition="Win32" num="8.1 SP1"/><vers edition="Win32" num="8.1 SP2"/><vers edition="Win32" num="8.1 SP3"/><vers edition="Win32" num="8.1 SP4"/></prod><prod name="WebLogic Portal" vendor="BEA Systems"><vers num="8.0"/></prod><prod name="WebLogic Express" vendor="BEA Systems"><vers num="6.0"/><vers num="6.0 SP1"/><vers num="6.0 SP2"/><vers num="6.1"/><vers num="6.1 SP1"/><vers num="6.1 SP2"/><vers num="6.1 SP3"/><vers num="6.1 SP4"/><vers num="6.1 SP5"/><vers num="7.0"/><vers num="7.0.0.1"/><vers num="7.0.0.1 SP1"/><vers num="7.0.0.1 SP2"/><vers num="7.0.0.1 SP3"/><vers num="7.0.0.1 SP4"/><vers num="7.0 SP1"/><vers num="7.0 SP2"/><vers num="7.0 SP3"/><vers num="7.0 SP4"/><vers num="7.0 SP5"/><vers num="8.1"/><vers num="8.1 SP1"/><vers num="8.1 SP2"/><vers num="8.1 SP3"/><vers num="8.1 SP4"/><vers edition="Win32" num="6.0"/><vers edition="Win32" num="6.0 SP1"/><vers edition="Win32" num="6.0 SP2"/><vers edition="Win32" num="6.1"/><vers edition="Win32" num="6.1 SP1"/><vers edition="Win32" num="6.1 SP2"/><vers edition="Win32" num="6.1 SP3"/><vers edition="Win32" num="6.1 SP4"/><vers edition="Win32" num="6.1 SP5"/><vers edition="Win32" num="7.0"/><vers edition="Win32" num="7.0.0.1"/><vers edition="Win32" num="7.0.0.1 SP1"/><vers edition="Win32" num="7.0.0.1 SP2"/><vers edition="Win32" num="7.0 SP1"/><vers edition="Win32" num="7.0 SP2"/><vers edition="Win32" num="7.0 SP3"/><vers edition="Win32" num="7.0 SP4"/><vers edition="Win32" num="7.0 SP5"/><vers edition="Win32" num="8.1"/><vers edition="Win32" num="8.1 SP1"/><vers edition="Win32" num="8.1 SP2"/><vers edition="Win32" num="8.1 SP3"/><vers edition="Win32" num="8.1 SP4"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1745" published="2005-05-24" seq="2005-1745" severity="Medium" type="CVE"><desc><descript source="cve">The UserLogin control in BEA WebLogic Portal 8.1 through Service Pack 3 prints the password to standard output when an incorrect login attempt is made, which could make it easier for attackers to guess the correct password.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/><exception/></vuln_types><range><local/></range><refs><ref adv="1" source="CONFIRM" url="http://dev2dev.bea.com/pub/advisory/128">http://dev2dev.bea.com/pub/advisory/128</ref><ref source="BID" url="http://www.securityfocus.com/bid/13717">13717</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/0605">ADV-2005-0605</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/15486">15486</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014049">1014049</ref></refs><vuln_soft><prod name="WebLogic Server" vendor="BEA Systems"><vers num="6.0"/><vers num="6.0 SP1"/><vers num="6.0 SP2"/><vers num="6.1"/><vers num="6.1 SP1"/><vers num="6.1 SP2"/><vers num="6.1 SP3"/><vers num="6.1 SP4"/><vers num="6.1 SP5"/><vers num="6.1 SP6"/><vers num="7.0"/><vers num="7.0.0.1"/><vers num="7.0.0.1 SP1"/><vers num="7.0.0.1 SP2"/><vers num="7.0.0.1 SP3"/><vers num="7.0.0.1 SP4"/><vers num="7.0 SP1"/><vers num="7.0 SP2"/><vers num="7.0 SP3"/><vers num="7.0 SP4"/><vers num="7.0 SP5"/><vers num="8.1"/><vers num="8.1 SP1"/><vers num="8.1 SP2"/><vers num="8.1 SP3"/><vers num="8.1 SP4"/><vers edition="Win32" num="6.0"/><vers edition="Win32" num="6.0 SP1"/><vers edition="Win32" num="6.0 SP2"/><vers edition="Win32" num="6.1"/><vers edition="Win32" num="6.1 SP1"/><vers edition="Win32" num="6.1 SP2"/><vers edition="Win32" num="6.1 SP4"/><vers edition="Win32" num="6.1 SP5"/><vers edition="Win32" num="6.1 SP6"/><vers edition="Win32" num="7.0"/><vers edition="Win32" num="7.0.0.1 SP1"/><vers edition="Win32" num="7.0.0.1 SP2"/><vers edition="Win32" num="7.0 SP1"/><vers edition="Win32" num="7.0 SP4"/><vers edition="Win32" num="7.0 SP3"/><vers edition="Win32" num="7.0 SP5"/><vers edition="Win32" num="8.1"/><vers edition="Win32" num="8.1 SP1"/><vers edition="Win32" num="8.1 SP2"/><vers edition="Win32" num="8.1 SP3"/><vers edition="Win32" num="8.1 SP4"/></prod><prod name="WebLogic Portal" vendor="BEA Systems"><vers num="8.0"/></prod><prod name="WebLogic Express" vendor="BEA Systems"><vers num="6.0"/><vers num="6.0 SP1"/><vers num="6.0 SP2"/><vers num="6.1"/><vers num="6.1 SP1"/><vers num="6.1 SP2"/><vers num="6.1 SP3"/><vers num="6.1 SP4"/><vers num="6.1 SP5"/><vers num="7.0"/><vers num="7.0.0.1"/><vers num="7.0.0.1 SP1"/><vers num="7.0.0.1 SP2"/><vers num="7.0.0.1 SP3"/><vers num="7.0.0.1 SP4"/><vers num="7.0 SP1"/><vers num="7.0 SP2"/><vers num="7.0 SP3"/><vers num="7.0 SP4"/><vers num="7.0 SP5"/><vers num="8.1"/><vers num="8.1 SP1"/><vers num="8.1 SP2"/><vers num="8.1 SP3"/><vers num="8.1 SP4"/><vers edition="Win32" num="6.0"/><vers edition="Win32" num="6.0 SP1"/><vers edition="Win32" num="6.0 SP2"/><vers edition="Win32" num="6.1"/><vers edition="Win32" num="6.1 SP1"/><vers edition="Win32" num="6.1 SP2"/><vers edition="Win32" num="6.1 SP3"/><vers edition="Win32" num="6.1 SP4"/><vers edition="Win32" num="6.1 SP5"/><vers edition="Win32" num="7.0"/><vers edition="Win32" num="7.0.0.1"/><vers edition="Win32" num="7.0.0.1 SP1"/><vers edition="Win32" num="7.0.0.1 SP2"/><vers edition="Win32" num="7.0 SP1"/><vers edition="Win32" num="7.0 SP2"/><vers edition="Win32" num="7.0 SP3"/><vers edition="Win32" num="7.0 SP4"/><vers edition="Win32" num="7.0 SP5"/><vers edition="Win32" num="8.1"/><vers edition="Win32" num="8.1 SP1"/><vers edition="Win32" num="8.1 SP2"/><vers edition="Win32" num="8.1 SP3"/><vers edition="Win32" num="8.1 SP4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1746" published="2005-05-24" seq="2005-1746" severity="Medium" type="CVE"><desc><descript source="cve">The cluster cookie parsing code in BEA WebLogic Server 7.0 through Service Pack 5 attempts to contact any host or port specified in a cookie, even when it is not in the cluster, which allows remote attackers to cause a denial of service (cluster slowdown) via modified cookies.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="CONFIRM" url="http://dev2dev.bea.com/pub/advisory/129">http://dev2dev.bea.com/pub/advisory/129</ref><ref source="BID" url="http://www.securityfocus.com/bid/13717">13717</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/0606">ADV-2005-0606</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/15486">15486</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014049">1014049</ref></refs><vuln_soft><prod name="WebLogic Server" vendor="BEA Systems"><vers num="6.0"/><vers num="6.0 SP1"/><vers num="6.0 SP2"/><vers num="6.1"/><vers num="6.1 SP1"/><vers num="6.1 SP2"/><vers num="6.1 SP3"/><vers num="6.1 SP4"/><vers num="6.1 SP5"/><vers num="6.1 SP6"/><vers num="7.0"/><vers num="7.0.0.1"/><vers num="7.0.0.1 SP1"/><vers num="7.0.0.1 SP2"/><vers num="7.0.0.1 SP3"/><vers num="7.0.0.1 SP4"/><vers num="7.0 SP1"/><vers num="7.0 SP2"/><vers num="7.0 SP3"/><vers num="7.0 SP4"/><vers num="7.0 SP5"/><vers num="8.1"/><vers num="8.1 SP1"/><vers num="8.1 SP2"/><vers num="8.1 SP3"/><vers num="8.1 SP4"/><vers edition="Win32" num="6.0"/><vers edition="Win32" num="6.0 SP1"/><vers edition="Win32" num="6.0 SP2"/><vers edition="Win32" num="6.1"/><vers edition="Win32" num="6.1 SP1"/><vers edition="Win32" num="6.1 SP2"/><vers edition="Win32" num="6.1 SP4"/><vers edition="Win32" num="6.1 SP5"/><vers edition="Win32" num="6.1 SP6"/><vers edition="Win32" num="7.0"/><vers edition="Win32" num="7.0.0.1 SP1"/><vers edition="Win32" num="7.0.0.1 SP2"/><vers edition="Win32" num="7.0 SP1"/><vers edition="Win32" num="7.0 SP4"/><vers edition="Win32" num="7.0 SP3"/><vers edition="Win32" num="7.0 SP5"/><vers edition="Win32" num="8.1"/><vers edition="Win32" num="8.1 SP1"/><vers edition="Win32" num="8.1 SP2"/><vers edition="Win32" num="8.1 SP3"/><vers edition="Win32" num="8.1 SP4"/></prod><prod name="WebLogic Portal" vendor="BEA Systems"><vers num="8.0"/></prod><prod name="WebLogic Express" vendor="BEA Systems"><vers num="6.0"/><vers num="6.0 SP1"/><vers num="6.0 SP2"/><vers num="6.1"/><vers num="6.1 SP1"/><vers num="6.1 SP2"/><vers num="6.1 SP3"/><vers num="6.1 SP4"/><vers num="6.1 SP5"/><vers num="7.0"/><vers num="7.0.0.1"/><vers num="7.0.0.1 SP1"/><vers num="7.0.0.1 SP2"/><vers num="7.0.0.1 SP3"/><vers num="7.0.0.1 SP4"/><vers num="7.0 SP1"/><vers num="7.0 SP2"/><vers num="7.0 SP3"/><vers num="7.0 SP4"/><vers num="7.0 SP5"/><vers num="8.1"/><vers num="8.1 SP1"/><vers num="8.1 SP2"/><vers num="8.1 SP3"/><vers num="8.1 SP4"/><vers edition="Win32" num="6.0"/><vers edition="Win32" num="6.0 SP1"/><vers edition="Win32" num="6.0 SP2"/><vers edition="Win32" num="6.1"/><vers edition="Win32" num="6.1 SP1"/><vers edition="Win32" num="6.1 SP2"/><vers edition="Win32" num="6.1 SP3"/><vers edition="Win32" num="6.1 SP4"/><vers edition="Win32" num="6.1 SP5"/><vers edition="Win32" num="7.0"/><vers edition="Win32" num="7.0.0.1"/><vers edition="Win32" num="7.0.0.1 SP1"/><vers edition="Win32" num="7.0.0.1 SP2"/><vers edition="Win32" num="7.0 SP1"/><vers edition="Win32" num="7.0 SP2"/><vers edition="Win32" num="7.0 SP3"/><vers edition="Win32" num="7.0 SP4"/><vers edition="Win32" num="7.0 SP5"/><vers edition="Win32" num="8.1"/><vers edition="Win32" num="8.1 SP1"/><vers edition="Win32" num="8.1 SP2"/><vers edition="Win32" num="8.1 SP3"/><vers edition="Win32" num="8.1 SP4"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1747" published="2005-05-24" seq="2005-1747" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in BEA WebLogic Server and Express 8.1 through Service Pack 4, and 7.0 through Service Pack 6, allow remote attackers to inject arbitrary web script or HTML, and possibly gain administrative privileges, via the (1) j_username or (2) j_password parameters in the login page (LoginForm.jsp), (3) parameters to the error page in the Administration Console, (4) unknown vectors in the Server Console while the administrator has an active session to obtain the ADMINCONSOLESESSION cookie, or (5) an alternate vector in the Server Console that does not require an active session but also leaks the username and password.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="CONFIRM" url="http://dev2dev.bea.com/pub/advisory/130">http://dev2dev.bea.com/pub/advisory/130</ref><ref source="BID" url="http://www.securityfocus.com/bid/13717">13717</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/0607">ADV-2005-0607</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/15486">15486</ref><ref source="MISC" url="http://www.acrossecurity.com/aspr/ASPR-2005-05-24-1-PUB.txt">http://www.acrossecurity.com/aspr/ASPR-2005-05-24-1-PUB.txt</ref><ref source="MISC" url="http://www.acrossecurity.com/aspr/ASPR-2005-05-24-2-PUB.txt">http://www.acrossecurity.com/aspr/ASPR-2005-05-24-2-PUB.txt</ref><ref source="MISC" url="http://www.appsecinc.com/resources/alerts/general/BEA-001.html">http://www.appsecinc.com/resources/alerts/general/BEA-001.html</ref><ref source="MISC" url="http://www.appsecinc.com/resources/alerts/general/BEA-002.html">http://www.appsecinc.com/resources/alerts/general/BEA-002.html</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014049">1014049</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111695921212456&amp;w=2">20050524 ACROS Security: HTML Injection in BEA WebLogic Server Console (1)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111695844803328&amp;w=2">20050524 ACROS Security: HTML Injection in BEA WebLogic Server Console (2)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111722298705561&amp;w=2">20050527 [AppSecInc Advisory BEA05-V0100] BEA WebLogic Administration Console error page cross-site scripting vulnerability</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111722380313416&amp;w=2">20050527 [AppSecInc Advisory BEA05-V0101] BEA WebLogic Administration Console login page cross-site scripting vulnerability</ref></refs><vuln_soft><prod name="WebLogic Server" vendor="BEA Systems"><vers num="6.0"/><vers num="6.0 SP1"/><vers num="6.0 SP2"/><vers num="6.1"/><vers num="6.1 SP1"/><vers num="6.1 SP2"/><vers num="6.1 SP3"/><vers num="6.1 SP4"/><vers num="6.1 SP5"/><vers num="6.1 SP6"/><vers num="7.0"/><vers num="7.0.0.1"/><vers num="7.0.0.1 SP1"/><vers num="7.0.0.1 SP2"/><vers num="7.0.0.1 SP3"/><vers num="7.0.0.1 SP4"/><vers num="7.0 SP1"/><vers num="7.0 SP2"/><vers num="7.0 SP3"/><vers num="7.0 SP4"/><vers num="7.0 SP5"/><vers num="8.1"/><vers num="8.1 SP1"/><vers num="8.1 SP2"/><vers num="8.1 SP3"/><vers num="8.1 SP4"/><vers edition="Win32" num="6.0"/><vers edition="Win32" num="6.0 SP1"/><vers edition="Win32" num="6.0 SP2"/><vers edition="Win32" num="6.1"/><vers edition="Win32" num="6.1 SP1"/><vers edition="Win32" num="6.1 SP2"/><vers edition="Win32" num="6.1 SP4"/><vers edition="Win32" num="6.1 SP5"/><vers edition="Win32" num="6.1 SP6"/><vers edition="Win32" num="7.0"/><vers edition="Win32" num="7.0.0.1 SP1"/><vers edition="Win32" num="7.0.0.1 SP2"/><vers edition="Win32" num="7.0 SP1"/><vers edition="Win32" num="7.0 SP4"/><vers edition="Win32" num="7.0 SP3"/><vers edition="Win32" num="7.0 SP5"/><vers edition="Win32" num="8.1"/><vers edition="Win32" num="8.1 SP1"/><vers edition="Win32" num="8.1 SP2"/><vers edition="Win32" num="8.1 SP3"/><vers edition="Win32" num="8.1 SP4"/></prod><prod name="WebLogic Portal" vendor="BEA Systems"><vers num="8.0"/></prod><prod name="WebLogic Express" vendor="BEA Systems"><vers num="6.0"/><vers num="6.0 SP1"/><vers num="6.0 SP2"/><vers num="6.1"/><vers num="6.1 SP1"/><vers num="6.1 SP2"/><vers num="6.1 SP3"/><vers num="6.1 SP4"/><vers num="6.1 SP5"/><vers num="7.0"/><vers num="7.0.0.1"/><vers num="7.0.0.1 SP1"/><vers num="7.0.0.1 SP2"/><vers num="7.0.0.1 SP3"/><vers num="7.0.0.1 SP4"/><vers num="7.0 SP1"/><vers num="7.0 SP2"/><vers num="7.0 SP3"/><vers num="7.0 SP4"/><vers num="7.0 SP5"/><vers num="8.1"/><vers num="8.1 SP1"/><vers num="8.1 SP2"/><vers num="8.1 SP3"/><vers num="8.1 SP4"/><vers edition="Win32" num="6.0"/><vers edition="Win32" num="6.0 SP1"/><vers edition="Win32" num="6.0 SP2"/><vers edition="Win32" num="6.1"/><vers edition="Win32" num="6.1 SP1"/><vers edition="Win32" num="6.1 SP2"/><vers edition="Win32" num="6.1 SP3"/><vers edition="Win32" num="6.1 SP4"/><vers edition="Win32" num="6.1 SP5"/><vers edition="Win32" num="7.0"/><vers edition="Win32" num="7.0.0.1"/><vers edition="Win32" num="7.0.0.1 SP1"/><vers edition="Win32" num="7.0.0.1 SP2"/><vers edition="Win32" num="7.0 SP1"/><vers edition="Win32" num="7.0 SP2"/><vers edition="Win32" num="7.0 SP3"/><vers edition="Win32" num="7.0 SP4"/><vers edition="Win32" num="7.0 SP5"/><vers edition="Win32" num="8.1"/><vers edition="Win32" num="8.1 SP1"/><vers edition="Win32" num="8.1 SP2"/><vers edition="Win32" num="8.1 SP3"/><vers edition="Win32" num="8.1 SP4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1748" published="2005-05-24" seq="2005-1748" severity="Medium" type="CVE"><desc><descript source="cve">The embedded LDAP server in BEA WebLogic Server and Express 8.1 through Service Pack 4, and 7.0 through Service Pack 5, allows remote anonymous binds, which may allow remote attackers to view user entries or cause a denial of service.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="CONFIRM" url="http://dev2dev.bea.com/pub/advisory/131">http://dev2dev.bea.com/pub/advisory/131</ref><ref source="BID" url="http://www.securityfocus.com/bid/13717">13717</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/0608">ADV-2005-0608</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/15486">15486</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014049">1014049</ref></refs><vuln_soft><prod name="WebLogic Server" vendor="BEA Systems"><vers num="6.0"/><vers num="6.0 SP1"/><vers num="6.0 SP2"/><vers num="6.1"/><vers num="6.1 SP1"/><vers num="6.1 SP2"/><vers num="6.1 SP3"/><vers num="6.1 SP4"/><vers num="6.1 SP5"/><vers num="6.1 SP6"/><vers num="7.0"/><vers num="7.0.0.1"/><vers num="7.0.0.1 SP1"/><vers num="7.0.0.1 SP2"/><vers num="7.0.0.1 SP3"/><vers num="7.0.0.1 SP4"/><vers num="7.0 SP1"/><vers num="7.0 SP2"/><vers num="7.0 SP3"/><vers num="7.0 SP4"/><vers num="7.0 SP5"/><vers num="8.1"/><vers num="8.1 SP1"/><vers num="8.1 SP2"/><vers num="8.1 SP3"/><vers num="8.1 SP4"/><vers edition="Win32" num="6.0"/><vers edition="Win32" num="6.0 SP1"/><vers edition="Win32" num="6.0 SP2"/><vers edition="Win32" num="6.1"/><vers edition="Win32" num="6.1 SP1"/><vers edition="Win32" num="6.1 SP2"/><vers edition="Win32" num="6.1 SP4"/><vers edition="Win32" num="6.1 SP5"/><vers edition="Win32" num="6.1 SP6"/><vers edition="Win32" num="7.0"/><vers edition="Win32" num="7.0.0.1 SP1"/><vers edition="Win32" num="7.0.0.1 SP2"/><vers edition="Win32" num="7.0 SP1"/><vers edition="Win32" num="7.0 SP4"/><vers edition="Win32" num="7.0 SP3"/><vers edition="Win32" num="7.0 SP5"/><vers edition="Win32" num="8.1"/><vers edition="Win32" num="8.1 SP1"/><vers edition="Win32" num="8.1 SP2"/><vers edition="Win32" num="8.1 SP3"/><vers edition="Win32" num="8.1 SP4"/></prod><prod name="WebLogic Portal" vendor="BEA Systems"><vers num="8.0"/></prod><prod name="WebLogic Express" vendor="BEA Systems"><vers num="6.0"/><vers num="6.0 SP1"/><vers num="6.0 SP2"/><vers num="6.1"/><vers num="6.1 SP1"/><vers num="6.1 SP2"/><vers num="6.1 SP3"/><vers num="6.1 SP4"/><vers num="6.1 SP5"/><vers num="7.0"/><vers num="7.0.0.1"/><vers num="7.0.0.1 SP1"/><vers num="7.0.0.1 SP2"/><vers num="7.0.0.1 SP3"/><vers num="7.0.0.1 SP4"/><vers num="7.0 SP1"/><vers num="7.0 SP2"/><vers num="7.0 SP3"/><vers num="7.0 SP4"/><vers num="7.0 SP5"/><vers num="8.1"/><vers num="8.1 SP1"/><vers num="8.1 SP2"/><vers num="8.1 SP3"/><vers num="8.1 SP4"/><vers edition="Win32" num="6.0"/><vers edition="Win32" num="6.0 SP1"/><vers edition="Win32" num="6.0 SP2"/><vers edition="Win32" num="6.1"/><vers edition="Win32" num="6.1 SP1"/><vers edition="Win32" num="6.1 SP2"/><vers edition="Win32" num="6.1 SP3"/><vers edition="Win32" num="6.1 SP4"/><vers edition="Win32" num="6.1 SP5"/><vers edition="Win32" num="7.0"/><vers edition="Win32" num="7.0.0.1"/><vers edition="Win32" num="7.0.0.1 SP1"/><vers edition="Win32" num="7.0.0.1 SP2"/><vers edition="Win32" num="7.0 SP1"/><vers edition="Win32" num="7.0 SP2"/><vers edition="Win32" num="7.0 SP3"/><vers edition="Win32" num="7.0 SP4"/><vers edition="Win32" num="7.0 SP5"/><vers edition="Win32" num="8.1"/><vers edition="Win32" num="8.1 SP1"/><vers edition="Win32" num="8.1 SP2"/><vers edition="Win32" num="8.1 SP3"/><vers edition="Win32" num="8.1 SP4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1749" published="2005-05-24" seq="2005-1749" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in BEA WebLogic Server and WebLogic Express 6.1 Service Pack 4 allows remote attackers to cause a denial of service (CPU consumption from thread looping).</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="CONFIRM" url="http://dev2dev.bea.com/pub/advisory/132">http://dev2dev.bea.com/pub/advisory/132</ref><ref source="BID" url="http://www.securityfocus.com/bid/13717">13717</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/0609">ADV-2005-0609</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/15486">15486</ref></refs><vuln_soft><prod name="WebLogic Server" vendor="BEA Systems"><vers num="6.0"/><vers num="6.0 SP1"/><vers num="6.0 SP2"/><vers num="6.1"/><vers num="6.1 SP1"/><vers num="6.1 SP2"/><vers num="6.1 SP3"/><vers num="6.1 SP4"/><vers num="6.1 SP5"/><vers num="6.1 SP6"/><vers num="7.0"/><vers num="7.0.0.1"/><vers num="7.0.0.1 SP1"/><vers num="7.0.0.1 SP2"/><vers num="7.0.0.1 SP3"/><vers num="7.0.0.1 SP4"/><vers num="7.0 SP1"/><vers num="7.0 SP2"/><vers num="7.0 SP3"/><vers num="7.0 SP4"/><vers num="7.0 SP5"/><vers num="8.1"/><vers num="8.1 SP1"/><vers num="8.1 SP2"/><vers num="8.1 SP3"/><vers num="8.1 SP4"/><vers edition="Win32" num="6.0"/><vers edition="Win32" num="6.0 SP1"/><vers edition="Win32" num="6.0 SP2"/><vers edition="Win32" num="6.1"/><vers edition="Win32" num="6.1 SP1"/><vers edition="Win32" num="6.1 SP2"/><vers edition="Win32" num="6.1 SP4"/><vers edition="Win32" num="6.1 SP5"/><vers edition="Win32" num="6.1 SP6"/><vers edition="Win32" num="7.0"/><vers edition="Win32" num="7.0.0.1 SP1"/><vers edition="Win32" num="7.0.0.1 SP2"/><vers edition="Win32" num="7.0 SP1"/><vers edition="Win32" num="7.0 SP4"/><vers edition="Win32" num="7.0 SP3"/><vers edition="Win32" num="7.0 SP5"/><vers edition="Win32" num="8.1"/><vers edition="Win32" num="8.1 SP1"/><vers edition="Win32" num="8.1 SP2"/><vers edition="Win32" num="8.1 SP3"/><vers edition="Win32" num="8.1 SP4"/></prod><prod name="WebLogic Portal" vendor="BEA Systems"><vers num="8.0"/></prod><prod name="WebLogic Express" vendor="BEA Systems"><vers num="6.0"/><vers num="6.0 SP1"/><vers num="6.0 SP2"/><vers num="6.1"/><vers num="6.1 SP1"/><vers num="6.1 SP2"/><vers num="6.1 SP3"/><vers num="6.1 SP4"/><vers num="6.1 SP5"/><vers num="7.0"/><vers num="7.0.0.1"/><vers num="7.0.0.1 SP1"/><vers num="7.0.0.1 SP2"/><vers num="7.0.0.1 SP3"/><vers num="7.0.0.1 SP4"/><vers num="7.0 SP1"/><vers num="7.0 SP2"/><vers num="7.0 SP3"/><vers num="7.0 SP4"/><vers num="7.0 SP5"/><vers num="8.1"/><vers num="8.1 SP1"/><vers num="8.1 SP2"/><vers num="8.1 SP3"/><vers num="8.1 SP4"/><vers edition="Win32" num="6.0"/><vers edition="Win32" num="6.0 SP1"/><vers edition="Win32" num="6.0 SP2"/><vers edition="Win32" num="6.1"/><vers edition="Win32" num="6.1 SP1"/><vers edition="Win32" num="6.1 SP2"/><vers edition="Win32" num="6.1 SP3"/><vers edition="Win32" num="6.1 SP4"/><vers edition="Win32" num="6.1 SP5"/><vers edition="Win32" num="7.0"/><vers edition="Win32" num="7.0.0.1"/><vers edition="Win32" num="7.0.0.1 SP1"/><vers edition="Win32" num="7.0.0.1 SP2"/><vers edition="Win32" num="7.0 SP1"/><vers edition="Win32" num="7.0 SP2"/><vers edition="Win32" num="7.0 SP3"/><vers edition="Win32" num="7.0 SP4"/><vers edition="Win32" num="7.0 SP5"/><vers edition="Win32" num="8.1"/><vers edition="Win32" num="8.1 SP1"/><vers edition="Win32" num="8.1 SP2"/><vers edition="Win32" num="8.1 SP3"/><vers edition="Win32" num="8.1 SP4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1750" published="2005-05-25" seq="2005-1750" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in login.asp in ezdwc NewsletterEz 3.0 allows remote attackers to execute arbitrary SQL commands via the password parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://www.under9round.com/nez.txt">http://www.under9round.com/nez.txt</ref><ref source="BID" url="http://www.securityfocus.com/bid/13730">13730</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15469">15469</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014038">1014038</ref></refs><vuln_soft><prod name="NewsletterEz" vendor="Distinct Web Creations"><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="3.7" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="6.4" CVSS_score="3.7" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-25" name="CVE-2005-1751" published="2005-05-25" seq="2005-1751" severity="Low" type="CVE"><desc><descript source="cve">Race condition in shtool 2.0.1 and earlier allows local users to create or modify arbitrary files via a symlink attack on the .shtool.$$ temporary file, a different vulnerability than CVE-2005-1759.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><race/></vuln_types><range><local/></range><refs><ref adv="1" source="MISC" url="http://www.zataz.net/adviso/shtool-05252005.txt">http://www.zataz.net/adviso/shtool-05252005.txt</ref><ref source="MISC" url="http://bugs.gentoo.org/show_bug.cgi?id=93782">http://bugs.gentoo.org/show_bug.cgi?id=93782</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014059">1014059</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15496">15496</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200506-08.xml">GLSA-200506-08</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval345.html">OVAL345</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-789">DSA-789</ref><ref source="BID" url="http://www.securityfocus.com/bid/13767">13767</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15668">15668</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-564.html">RHSA-2005:564</ref><ref source="OPENPKG" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111955937622637&amp;w=2">OpenPKG-SA-2005.011</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:345">oval:org.mitre.oval:def:345</ref></refs><vuln_soft><prod name="shtool" vendor="shtool"><vers num="2.0.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2005-05-24" modified="2006-05-22" name="CVE-2005-1752" published="2005-12-31" seq="2005-1752" severity="Medium" type="CVE"><desc><descript source="cve">viewFile.php in the scm component of Gforge before 4.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the file_name parameter.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111695779919830&amp;w=2">20050524 Gforge - viewFile.php security flaw</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/13716">13716</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/13845">13845</ref></refs><vuln_soft><prod name="GForge" vendor="GForge"><vers num="3.3"/><vers num="3.21"/><vers num="3.2"/><vers num="3.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" discovered="2005-05-24" modified="2008-01-14" name="CVE-2005-1753" published="2005-12-31" seq="2005-1753" severity="Medium" type="CVE"><desc><descript source="cve">** DISPUTED **  ReadMessage.jsp in JavaMail API 1.1.3 through 1.3, as used by Apache Tomcat 5.0.16, allows remote attackers to view other users&apos; e-mail attachments via a direct request to /mailboxesdir/username@domainname. NOTE: Sun and Apache dispute this issue.  Sun states: &quot;The report makes references to source code and files that do not exist in the mentioned products.&quot;</descript></desc><loss_types><conf/></loss_types><vuln_types><input/><design/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111697083812367&amp;w=2">20050524 Javamail Multiple Information Disclosure Vulnerabilities</ref><ref source="" url="http://tomcat.apache.org/security-5.html"></ref></refs><vuln_soft><prod name="JavaMail" vendor="Sun"><vers num="1.1.3"/><vers num="1.2"/><vers num="1.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" discovered="2005-05-24" modified="2008-01-14" name="CVE-2005-1754" published="2005-12-31" seq="2005-1754" severity="Medium" type="CVE"><desc><descript source="cve">** DISPUTED **  JavaMail API 1.1.3 through 1.3, as used by Apache Tomcat 5.0.16, allows remote attackers to read arbitrary files via a full pathname in the argument to the Download parameter.  NOTE: Sun and Apache dispute this issue.  Sun states: &quot;The report makes references to source code and files that do not exist in the mentioned products.&quot;</descript></desc><loss_types><conf/></loss_types><vuln_types><input/><design/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111697083812367&amp;w=2">20050524 Javamail Multiple Information Disclosure Vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/13753">13753</ref><ref source="" url="http://tomcat.apache.org/security-5.html"></ref></refs><vuln_soft><prod name="JavaMail" vendor="Sun"><vers num="1.3.2"/><vers num="1.3"/><vers num="1.2"/><vers num="1.1.3"/></prod><prod name="Apache Tomcat" vendor="Apache Tomcat"><vers num="5.0.16"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2005-05-24" modified="2006-09-27" name="CVE-2005-1755" published="2005-12-31" seq="2005-1755" severity="Medium" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in poll_vote.php in PHP Poll Creator 1.01 allows remote attackers to execute arbitrary PHP code via the relativer_pfad parameter.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111704581329860&amp;w=2">20050525 PHP Injection in PHP Poll Creator</ref><ref patch="1" source="OSVDB" url="http://www.osvdb.org/16846">16846</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014061">1014061</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/15510">15510</ref></refs><vuln_soft><prod name="PHP Poll Creator" vendor="PHP Poll Creator"><vers num="1.01"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1756" published="2005-06-08" seq="2005-1756" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in the ModWeb agent for Novell NetMail 3.52 before 3.52C allows remote attackers to inject arbitrary web script or HTML via calendar display fields.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CONFIRM" url="http://support.novell.com/cgi-bin/search/searchtid.cgi?/2971588.htm">http://support.novell.com/cgi-bin/search/searchtid.cgi?/2971588.htm</ref><ref adv="1" patch="1" source="CONFIRM" url="http://support.novell.com/cgi-bin/search/searchtid.cgi?/2971590.htm">http://support.novell.com/cgi-bin/search/searchtid.cgi?/2971590.htm</ref><ref adv="1" patch="1" source="CONFIRM" url="http://support.novell.com/cgi-bin/search/searchtid.cgi?/2971591.htm">http://support.novell.com/cgi-bin/search/searchtid.cgi?/2971591.htm</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/15644">15644</ref><ref source="" url="http://support.novell.com/cgi-bin/search/searchtid.cgi?/10097957.htm"></ref><ref source="BID" url="http://www.securityfocus.com/bid/13926">13926</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/0727">ADV-2005-0727</ref><ref source="OSVDB" url="http://www.osvdb.org/17240">17240</ref></refs><vuln_soft><prod name="NetMail" vendor="Novell"><vers edition="b" num="3.5.2"/><vers edition="a" num="3.5.2"/><vers edition="e-ftfl" num="3.5.2"/><vers edition="h" num="3.10"/><vers edition="g" num="3.10"/><vers edition="f" num="3.10"/><vers edition="e" num="3.10"/><vers edition="d" num="3.10"/><vers edition="c" num="3.10"/><vers edition="b" num="3.10"/><vers edition="a" num="3.10"/><vers num="3.10"/><vers edition="f" num="3.1"/><vers num="3.1"/><vers edition="b" num="3.0.3a"/><vers edition="a" num="3.0.3a"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1757" published="2005-06-08" seq="2005-1757" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the Modweb agent for Novell NetMail 3.52 before 3.52C, when renaming folders, may allow attackers to execute arbitrary code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CONFIRM" url="http://support.novell.com/cgi-bin/search/searchtid.cgi?/2971588.htm">http://support.novell.com/cgi-bin/search/searchtid.cgi?/2971588.htm</ref><ref adv="1" patch="1" source="CONFIRM" url="http://support.novell.com/cgi-bin/search/searchtid.cgi?/2971590.htm">http://support.novell.com/cgi-bin/search/searchtid.cgi?/2971590.htm</ref><ref adv="1" patch="1" source="CONFIRM" url="http://support.novell.com/cgi-bin/search/searchtid.cgi?/2971591.htm">http://support.novell.com/cgi-bin/search/searchtid.cgi?/2971591.htm</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/15644">15644</ref><ref source="" url="http://support.novell.com/cgi-bin/search/searchtid.cgi?/10097957.htm"></ref><ref source="BID" url="http://www.securityfocus.com/bid/13926">13926</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/0727">ADV-2005-0727</ref><ref source="OSVDB" url="http://www.osvdb.org/17241">17241</ref></refs><vuln_soft><prod name="NetMail" vendor="Novell"><vers edition="b" num="3.5.2"/><vers edition="a" num="3.5.2"/><vers edition="e-ftfl" num="3.5.2"/><vers edition="h" num="3.10"/><vers edition="g" num="3.10"/><vers edition="f" num="3.10"/><vers edition="e" num="3.10"/><vers edition="d" num="3.10"/><vers edition="c" num="3.10"/><vers edition="b" num="3.10"/><vers edition="a" num="3.10"/><vers num="3.10"/><vers edition="f" num="3.1"/><vers num="3.1"/><vers edition="b" num="3.0.3a"/><vers edition="a" num="3.0.3a"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1758" published="2005-06-08" seq="2005-1758" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the IMAP command continuation function in Novell NetMail 3.52 before 3.52C may allow remote attackers to execute arbitrary code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CONFIRM" url="http://support.novell.com/cgi-bin/search/searchtid.cgi?/2971588.htm">http://support.novell.com/cgi-bin/search/searchtid.cgi?/2971588.htm</ref><ref adv="1" patch="1" source="CONFIRM" url="http://support.novell.com/cgi-bin/search/searchtid.cgi?/2971590.htm">http://support.novell.com/cgi-bin/search/searchtid.cgi?/2971590.htm</ref><ref adv="1" patch="1" source="CONFIRM" url="http://support.novell.com/cgi-bin/search/searchtid.cgi?/2971591.htm">http://support.novell.com/cgi-bin/search/searchtid.cgi?/2971591.htm</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/15644">15644</ref><ref source="" url="http://support.novell.com/cgi-bin/search/searchtid.cgi?/10097957.htm"></ref><ref source="BID" url="http://www.securityfocus.com/bid/13926">13926</ref><ref source="BID" url="http://www.securityfocus.com/bid/14718">14718</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/0727">ADV-2005-0727</ref><ref source="OSVDB" url="http://www.osvdb.org/17239">17239</ref></refs><vuln_soft><prod name="NetMail" vendor="Novell"><vers edition="b" num="3.5.2"/><vers edition="a" num="3.5.2"/><vers edition="e-ftfl" num="3.5.2"/><vers edition="h" num="3.10"/><vers edition="g" num="3.10"/><vers edition="f" num="3.10"/><vers edition="e" num="3.10"/><vers edition="d" num="3.10"/><vers edition="c" num="3.10"/><vers edition="b" num="3.10"/><vers edition="a" num="3.10"/><vers num="3.10"/><vers edition="f" num="3.1"/><vers num="3.1"/><vers edition="b" num="3.0.3a"/><vers edition="a" num="3.0.3a"/></prod></vuln_soft></entry><entry CVSS_base_score="1.2" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="2.9" CVSS_score="1.2" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-25" name="CVE-2005-1759" published="2005-06-28" seq="2005-1759" severity="Low" type="CVE"><desc><descript source="cve">Race condition in shtool 2.0.1 and earlier allows local users to modify or create arbitrary files via a symlink attack on temporary files after they have been created, a different vulnerability than CVE-2005-1751.</descript></desc><loss_types><int/></loss_types><vuln_types><race/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111955937622637&amp;w=2">20050623 [OpenPKG-SA-2005.011] OpenPKG Security Advisory (shtool)</ref><ref patch="1" source="MISC" url="http://bugs.gentoo.org/show_bug.cgi?id=93782">http://bugs.gentoo.org/show_bug.cgi?id=93782</ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200506-08.xml">GLSA-200506-08</ref><ref source="BID" url="http://www.securityfocus.com/bid/13767">13767</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15668">15668</ref></refs><vuln_soft><prod name="shtool" vendor="shtool"><vers num="2.0.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1760" published="2005-06-13" seq="2005-1760" severity="High" type="CVE"><desc><descript source="cve">sysreport 1.3.15 and earlier includes contents of the up2date file in a report, which leaks the password for a proxy server in plaintext and allows local users to gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-502.html">RHSA-2005:502</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval623.html">OVAL623</ref><ref source="BID" url="http://www.securityfocus.com/bid/13936">13936</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014181">1014181</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15675">15675</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:623">oval:org.mitre.oval:def:623</ref></refs><vuln_soft><prod name="Desktop" vendor="Red Hat"><vers num="4.0"/><vers num="3.0"/></prod><prod name="Advanced Workstation Itanium Processor" vendor="Red Hat"><vers edition="IA64" num="2.1"/><vers num="2.1"/></prod><prod name="sysreport" vendor="Red Hat"><vers num="1.3"/><vers num="1.2"/><vers num="1.1"/></prod><prod name="Enterprise Linux" vendor="Red Hat"><vers edition="Workstation" num="4.0"/><vers edition="Workstation Server" num="3.0"/><vers edition="Workstation" num="2.1"/><vers edition="Workstation" num="2.1"/><vers edition="Enterprise Server" num="4.0"/><vers edition="Enterprise Server" num="3.0"/><vers edition="Enterprise Server" num="2.1"/><vers edition="Enterprise Server" num="2.1"/><vers edition="Advanced Server" num="4.0"/><vers edition="Advanced Server" num="3.0"/><vers edition="Advanced Server" num="2.1"/><vers edition="Advanced Server" num="2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2008-04-04" name="CVE-2005-1761" published="2005-08-05" seq="2005-1761" severity="Low" type="CVE"><desc><descript source="cve">Linux kernel 2.6 and 2.4 on the IA64 architecture allows local users to cause a denial of service (kernel crash) via ptrace and the restore_sigcontext function.</descript></desc><loss_types><avail/></loss_types><range><local/></range><refs><ref adv="1" patch="1" source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_44_kernel.html">SuSE-SA:2005:044</ref><ref source="" url="http://kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=4ea78729b8dbfc400fe165a57b90a394a7275a54"></ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-922">DSA-922</ref><ref source="BID" url="http://www.securityfocus.com/bid/14051">14051</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18056">18056</ref><ref source="" url="http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.12.1"></ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014275">1014275</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-514.html">RHSA-2005:514</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-551.html">RHSA-2005:551</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-663.html">RHSA-2005:663</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/427980/100/0/threaded">FLSA:157459-3</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17073">17073</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1018">DSA-1018</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19369">19369</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17002">17002</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/1878">ADV-2005-1878</ref></refs><vuln_soft><prod name="SuSE Linux" vendor="SuSE"><vers num="9.0"/><vers num="9.1"/><vers num="9.2"/><vers num="9.3"/></prod><prod name="SuSE Linux Enterprise Server" vendor="SuSE"><vers num="8"/><vers num="9"/></prod><prod name="Open Enterprise Server" vendor="Novell"><vers num="9"/></prod><prod name="Linux Desktop" vendor="Novell"><vers num="9"/></prod><prod name="SuSE Linux Desktop" vendor="SuSE"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1762" published="2005-08-02" seq="2005-1762" severity="Low" type="CVE"><desc><descript source="cve">The ptrace call in the Linux kernel 2.6.8.1 and 2.6.10 for the AMD64 platform allows local users to cause a denial of service (kernel crash) via a &quot;non-canonical&quot; address.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_29_kernel.html">SuSE-SA:2005:029</ref><ref adv="1" source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-143-1">USN-143-1</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/15786">15786</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-922">DSA-922</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-921">DSA-921</ref><ref source="BID" url="http://www.securityfocus.com/bid/13904">13904</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18056">18056</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18059">18059</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-514.html">RHSA-2005:514</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-663.html">RHSA-2005:663</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/428058/100/0/threaded">FLSA:157459-2</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/427980/100/0/threaded">FLSA:157459-3</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17073">17073</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17002">17002</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/1878">ADV-2005-1878</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.6.8.1"/><vers num="2.6.10"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1763" published="2005-06-09" seq="2005-1763" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in ptrace in the Linux Kernel for 64-bit architectures allows local users to write bytes into kernel memory.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_29_kernel.html">SuSE-SA:2005:029</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-922">DSA-922</ref><ref source="BID" url="http://www.securityfocus.com/bid/13903">13903</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18056">18056</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-514.html">RHSA-2005:514</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/427980/100/0/threaded">FLSA:157459-3</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17073">17073</ref></refs><vuln_soft><prod name="SuSE Linux Enterprise Server" vendor="SuSE"><vers num="9"/><vers num="8"/></prod><prod name="Linux Desktop" vendor="Novell"><vers num="9"/></prod><prod name="SuSE Linux Desktop" vendor="SuSE"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1764" published="2005-10-07" seq="2005-1764" severity="Low" type="CVE"><desc><descript source="cve">Linux 2.6.11 on 64-bit x86 (x86_64) platforms does not use a guard page for the 47-bit address page to protect against an AMD K8 bug, which allows local users to cause a denial of service.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="" url="http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=637716a3825e186555361574aa1fa3c0ebf8018b"></ref><ref source="" url="http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=637716a3825e186555361574aa1fa3c0ebf8018b"></ref><ref adv="1" patch="1" source="SUSE" url="http://freshmeat.net/articles/view/1678/">SUSE-SA:2005:029</ref><ref source="MANDRAKE" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2005:220">MDKSA-2005:220</ref><ref source="BID" url="http://www.securityfocus.com/bid/13904">13904</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:220">MDKSA-2005:220</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/43324">linux-kernel-guardpage-dos(43324)</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.6.11 for 64-bit x86"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1765" published="2005-05-31" seq="2005-1765" severity="Low" type="CVE"><desc><descript source="cve">syscall in the Linux kernel 2.6.8.1 and 2.6.10 for the AMD64 platform, when running in 32-bit compatibility mode, allows local users to cause a denial of service (kernel hang) via crafted arguments.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_29_kernel.html">SuSE-SA:2005:029</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-143-1">USN-143-1</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-922">DSA-922</ref><ref source="BID" url="http://www.securityfocus.com/bid/13904">13904</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18056">18056</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.6.8.1"/><vers num="2.6.10"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-01-05" name="CVE-2005-1766" published="2005-06-28" seq="2005-1766" severity="Medium" type="CVE"><desc><descript source="cve">Heap-based buffer overflow in rtffplin.cpp in RealPlayer 10.5 6.0.12.1056 on Windows, and 10, 10.0.1.436, and other versions before 10.0.5 on Linux, allows remote attackers to execute arbitrary code via a RealMedia file with a long RealText string, such as an SMIL file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-523.html">RHSA-2005:523</ref><ref source="RedHat" url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=159871">Bugzilla Bug 159871 - CAN-2005-1766 HelixPlayer heap overflow</ref><ref adv="1" patch="1" source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=250&amp;type=vulnerabilities&amp;flashstatus=true">20050623 RealNetworks RealPlayer RealText Parsing Heap Overflow Vulnerability</ref><ref patch="1" source="" url="http://service.real.com/help/faq/security/050623_player/EN/">http://service.real.com/help/faq/security/050623_player/EN/</ref><ref adv="1" source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=250&amp;type=vulnerabilities&amp;flashstatus=true">20050623 RealNetworks RealPlayer RealText Parsing Heap Overflow Vulnerability</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_37_real_player.html">SUSE-SA:2005:037</ref><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-826">DSA-826</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16981">16981</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-517.html">RHSA-2005:517</ref></refs><vuln_soft><prod name="RealPlayer" vendor="RealNetworks"><vers num="10.0.5" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1767" published="2005-08-05" seq="2005-1767" severity="Low" type="CVE"><desc><descript source="cve">traps.c in the Linux kernel 2.6.x and 2.4.x executes stack segment faults on an exception stack, which allows local users to cause a denial of service (oops and stack fault exception).</descript></desc><loss_types><avail/></loss_types><range><local/></range><refs><ref adv="1" patch="1" source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_44_kernel.html">SuSE-SA:2005:044</ref><ref source="" url="http://kernel.org/git/?p=linux/kernel/git/marcelo/linux-2.4.git;a=commit;h=51e31546a2fc46cb978da2ee0330a6a68f07541e"></ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-187-1">USN-187-1</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-922">DSA-922</ref><ref source="BID" url="http://www.securityfocus.com/bid/14467">14467</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-921">DSA-921</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18056">18056</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18059">18059</ref><ref source="MANDRIVA" url="http://wwwnew.mandriva.com/security/advisories?name=MDKSA-2006:044">MDKSA-2006:044</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18977">18977</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-663.html">RHSA-2005:663</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17002">17002</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/1878">ADV-2005-1878</ref></refs><vuln_soft><prod name="SuSE Linux" vendor="SuSE"><vers num="9.0"/><vers num="9.1"/><vers num="9.2"/><vers num="9.3"/></prod><prod name="SuSE Linux Enterprise Server" vendor="SuSE"><vers num="8"/><vers num="9"/></prod><prod name="Open Enterprise Server" vendor="Novell"><vers num="9"/></prod><prod name="Linux Desktop" vendor="Novell"><vers num="9"/></prod><prod name="SuSE Linux Desktop" vendor="SuSE"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="3.7" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="6.4" CVSS_score="3.7" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1768" published="2005-07-11" seq="2005-1768" severity="Low" type="CVE"><desc><descript source="cve">Race condition in the ia32 compatibility code for the execve system call in Linux kernel 2.4 before 2.4.31 and 2.6 before 2.6.6 allows local users to cause a denial of service (kernel panic) and possibly execute arbitrary code via a concurrent thread that increments a pointer count after the nargs function has counted the pointers, but before the count is copied from user space to kernel space, which leads to a buffer overflow.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/><race/></vuln_types><range><local/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112110120216116&amp;w=2">20050711 [ Suresec Advisories ] - Linux kernel ia32 compatibility (ia64/x86-64)</ref><ref source="MISC" url="http://www.suresec.org/advisories/adv4.pdf">http://www.suresec.org/advisories/adv4.pdf</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_44_kernel.html">SUSE-SA:2005:044</ref><ref source="BID" url="http://www.securityfocus.com/bid/14205">14205</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-921">DSA-921</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18059">18059</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014442">1014442</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15980">15980</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-551.html">RHSA-2005:551</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-663.html">RHSA-2005:663</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17002">17002</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19185">19185</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/1878">ADV-2005-1878</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20060402-01-U">
20060402-01-U</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19607">
19607</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.6.6-rc1"/><vers num="2.6.6"/><vers num="2.6.5"/><vers num="2.6.4"/><vers num="2.6.3"/><vers num="2.6.2"/><vers num="2.6.1 -rc2"/><vers num="2.6.1 -rc1"/><vers num="2.6.1"/><vers num="2.6.0"/><vers num="2.6 -test9-CVS"/><vers num="2.6 -test9"/><vers num="2.6 -test8"/><vers num="2.6 -test7"/><vers num="2.6 -test6"/><vers num="2.6 -test5"/><vers num="2.6 -test4"/><vers num="2.6 -test3"/><vers num="2.6 -test2"/><vers num="2.6 -test11"/><vers num="2.6 -test10"/><vers num="2.6 -test1"/><vers num="2.6 .10"/><vers num="2.6"/><vers num="2.4.31-pre1"/><vers num="2.4.31 -pre1"/><vers num="2.4.30-rc3"/><vers num="2.4.30-rc2"/><vers num="2.4.30 rc3"/><vers num="2.4.30 rc2"/><vers num="2.4.30"/><vers num="2.4.3"/><vers num="2.4.29-rc2"/><vers num="2.4.29-rc1"/><vers num="2.4.29 -rc2"/><vers num="2.4.29 -rc1"/><vers num="2.4.29"/><vers num="2.4.28"/><vers num="2.4.27-pre5"/><vers num="2.4.27-pre4"/><vers num="2.4.27-pre3"/><vers num="2.4.27-pre2"/><vers num="2.4.27-pre1"/><vers num="2.4.27 -pre5"/><vers num="2.4.27 -pre4"/><vers num="2.4.27 -pre3"/><vers num="2.4.27 -pre2"/><vers num="2.4.27 -pre1"/><vers num="2.4.27"/><vers num="2.4.26"/><vers num="2.4.25"/><vers num="2.4.24-ow1"/><vers num="2.4.24 ow1"/><vers num="2.4.24"/><vers num="2.4.23-pre9"/><vers num="2.4.23-ow2"/><vers num="2.4.23 -pre9"/><vers num="2.4.23 -ow2"/><vers num="2.4.23"/><vers num="2.4.22-pre10"/><vers num="2.4.22 -pre10"/><vers num="2.4.22"/><vers num="2.4.21-pre7"/><vers num="2.4.21-pre4"/><vers num="2.4.21-pre1"/><vers num="2.4.21 pre7"/><vers num="2.4.21 pre4"/><vers num="2.4.21 pre1"/><vers num="2.4.21"/><vers num="2.4.20"/><vers num="2.4.2"/><vers num="2.4.19-pre6"/><vers num="2.4.19-pre5"/><vers num="2.4.19-pre4"/><vers num="2.4.19-pre3"/><vers num="2.4.19-pre2"/><vers num="2.4.19-pre1"/><vers num="2.4.19 -pre6"/><vers num="2.4.19 -pre5"/><vers num="2.4.19 -pre4"/><vers num="2.4.19 -pre3"/><vers num="2.4.19 -pre2"/><vers num="2.4.19 -pre1"/><vers num="2.4.19"/><vers num="2.4.18-x86"/><vers num="2.4.18-pre-8"/><vers num="2.4.18-pre-7"/><vers num="2.4.18-pre-6"/><vers num="2.4.18-pre-5"/><vers num="2.4.18-pre-4"/><vers num="2.4.18-pre-3"/><vers num="2.4.18-pre-2"/><vers num="2.4.18-pre-1"/><vers edition="x86" num="2.4.18"/><vers num="2.4.18 pre-8"/><vers num="2.4.18 pre-7"/><vers num="2.4.18 pre-6"/><vers num="2.4.18 pre5"/><vers num="2.4.18 pre4"/><vers num="2.4.18 pre3"/><vers num="2.4.18 pre2"/><vers num="2.4.18 pre1"/><vers num="2.4.18"/><vers num="2.4.17"/><vers num="2.4.16"/><vers num="2.4.15"/><vers num="2.4.14"/><vers num="2.4.13"/><vers num="2.4.12"/><vers num="2.4.11"/><vers num="2.4.10"/><vers num="2.4.1"/><vers num="2.4.0 test9"/><vers num="2.4.0 test8"/><vers num="2.4.0 test7"/><vers num="2.4.0 test6"/><vers num="2.4.0 test5"/><vers num="2.4.0 test4"/><vers num="2.4.0 test3"/><vers num="2.4.0 test2"/><vers num="2.4.0 test12"/><vers num="2.4.0 test11"/><vers num="2.4.0 test10"/><vers num="2.4.0 test1"/><vers num="2.4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1769" published="2005-06-16" seq="2005-1769" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in SquirrelMail 1.4.0 through 1.4.4 allow remote attackers to inject arbitrary web script or HTML via unknown attack vectors in (1) the URL or (2) an e-mail message.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111893827711390&amp;w=2">20050616 [SM-ANNOUNCE] Patch fixes SquirrelMail cross site scripting vulnerabilities [CAN-2005-1769]</ref><ref adv="1" patch="1" source="CONFIRM" url="http://www.squirrelmail.org/security/issue/2005-06-15">http://www.squirrelmail.org/security/issue/2005-06-15</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-756">DSA-756</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:108">MDKSA-2005:108</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/Aug/msg00000.html">APPLE-SA-2005-08-15</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2005//Aug/msg00001.html">APPLE-SA-2005-08-17</ref><ref source="FEDORA" url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=163047">FLSA:163047</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-595.html">RHSA-2005:595</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_18_sr.html">SUSE-SR:2005:018</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:108">MDKSA-2005:108</ref></refs><vuln_soft><prod name="SquirrelMail" vendor="SquirrelMail"><vers num="1.44"/><vers num="1.4.3 RC1"/><vers num="1.4.3a"/><vers num="1.4.3"/><vers num="1.4.2"/><vers num="1.4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1770" published="2005-05-31" seq="2005-1770" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the Aavmker4 device driver in Avast! Antivirus 4.6 and possibly other versions allows local users to cause a denial of service (system crash) and possibly execute arbitrary code via certain signals combined with crafted input.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111712494620031&amp;w=2">20050526 Alwil Software Avast Antivirus Device Driver Memory Overwrite Vulnerability</ref><ref adv="1" source="MISC" url="http://pb.specialised.info/all/adv/avast-adv.txt">http://pb.specialised.info/all/adv/avast-adv.txt</ref></refs><vuln_soft><prod name="Avast Antivirus" vendor="ALWIL"><vers num="4.6.623"/><vers num="4.6.603"/><vers num="4.5.561"/><vers num="4.5.549"/><vers num="4.5.518"/><vers num="4.1.501"/><vers num="4.1.418"/><vers num="4.1.412"/><vers num="4.1.396"/><vers num="4.1.389"/><vers num="4.1.357"/><vers num="4.1.342"/><vers num="4.1.335"/><vers num="4.1.319"/><vers num="4.1.304"/><vers num="4.1.289"/><vers num="4.1.287"/><vers num="4.1.278"/><vers num="4.1.268"/><vers num="4.1.260"/><vers num="4.0.235"/><vers num="4.0.229"/><vers num="4.0.211"/><vers num="4.0.202"/><vers num="4.0.183"/><vers num="4.0.172"/><vers num="4.0.168"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1771" published="2005-05-31" seq="2005-1771" severity="High" type="CVE"><desc><descript source="cve">Unknown vulnerability in HP-UX trusted systems B.11.00 through B.11.23 allows remote attackers to gain unauthorized access, possibly involving remshd and/or telnet -t.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref patch="1" source="HP" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111713178014478&amp;w=2">HPSBUX01165</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014060">1014060</ref></refs><vuln_soft><prod name="HP-UX" vendor="HP"><vers num="B.11.00"/><vers num="B.11.11"/><vers num="B.11.22"/><vers edition="IA64 64-bit" num="B.11.23"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-25" name="CVE-2005-1772" published="2005-05-31" seq="2005-1772" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in the client cd-key hash in Terminator 3: War of the Machines 1.16 and earlier allows remote attackers to cause a denial of service (application crash) via a long client cd-key hash value, a different vulnerability than CVE-2005-1556.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="Luigi Auriemma" url="http://aluigi.altervista.org/adv/t3wmbof-adv.txt"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/15520">15520</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111713248227479&amp;w=2">20050526 Buffer-overflow and crash in Terminator 3: War of the Machines 1.16</ref></refs><vuln_soft><prod name="Terminator 3 War of the Machines" vendor="Atari"><vers num="1.16" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1773" published="2005-05-31" seq="2005-1773" severity="High" type="CVE"><desc><descript source="cve">Multiple unknown vulnerabilities in L-Soft LISTSERV 14.3, 1.8e, and 1.8d allow remote attackers to execute arbitrary code or cause a denial of service.  NOTE: this candidate may be SPLIT in the future when more precise technical details become available.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111705329308546&amp;w=2">20050525 High Risk Vulnerability in L-Soft&apos;s LISTSERV Server</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/13768">13768</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15498">15498</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014051">1014051</ref></refs><vuln_soft><prod name="Listserv" vendor="L-Soft"><vers num="14.3"/><vers num="1.8e"/><vers num="1.8d"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1774" published="2005-05-31" seq="2005-1774" severity="Low" type="CVE"><desc><descript source="cve">WEB-DAV Linux File System (davfs2) 0.2.3 does not properly enforce Unix permissions, which allows local users to write arbitrary files on a davfs2 mounted filesystem.</descript></desc><loss_types><int/></loss_types><vuln_types><access/><design/></vuln_types><range><local/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111705524308096&amp;w=2">20050525 davfs2 does not honour Unix permissions</ref><ref source="CONFIRM" url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=310757">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=310757</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15497">15497</ref></refs><vuln_soft><prod name="davfs2" vendor="davfs2"><vers num="0.2.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1775" published="2005-05-31" seq="2005-1775" severity="Medium" type="CVE"><desc><descript source="cve">Terminator 3: War of the Machines 1.16 and earlier allows remote attackers to cause a denial of service (application crash) via a large nickname.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111713248227479&amp;w=2">20050526 Buffer-overflow and crash in Terminator 3: War of the Machines 1.16</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15520">15520</ref></refs><vuln_soft><prod name="Terminator 3 War of the Machines" vendor="Atari"><vers num="1.16"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1776" published="2005-05-31" seq="2005-1776" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the READ_TCP_STRING function in game_message_functions.cpp in the network plugin for C&apos;Nedra 0.4.0 and earlier allows remote attackers to execute arbitrary code via a long text string.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="Luigi Auriemma" url="http://aluigi.altervista.org/adv/cnedrabof-adv.txt"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/15519">15519</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111713300212601&amp;w=2">20050526 Buffer-overflow in C&apos;Nedra 0.4.0</ref></refs><vuln_soft><prod name="CNedra" vendor="CNedra"><vers num="0.4.0"/><vers num="0.3.0"/><vers num="0.1.5"/><vers num="0.1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-04-07" name="CVE-2005-1777" published="2005-05-31" seq="2005-1777" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in readpmsg.php in PostNuke 0.750 allows remote attackers to execute arbitrary SQL commands via the start parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111721364707520&amp;w=2">20050527 PostNuke Critical SQL Injection and XSS 0.750=&gt;x</ref><ref adv="1" patch="1" source="CONFIRM" url="http://news.postnuke.com/Article2691.html">http://news.postnuke.com/Article2691.html</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111721364707520&amp;w=2">20050527 PostNuke Critical SQL Injection and XSS 0.750=&gt;x</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014066">1014066</ref></refs><vuln_soft><prod name="PostNuke" vendor="PostNuke Software Foundation"><vers num="0.750"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-04-07" name="CVE-2005-1778" published="2005-05-31" seq="2005-1778" severity="Low" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in readpmsg.php in PostNuke 0.750 allows remote attackers to inject arbitrary web script or HTML via the start parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111721364707520&amp;w=2">20050527 PostNuke Critical SQL Injection and XSS 0.750=&gt;x</ref><ref adv="1" patch="1" source="CONFIRM" url="http://news.postnuke.com/Article2691.html">http://news.postnuke.com/Article2691.html</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111721364707520&amp;w=2">20050527 PostNuke Critical SQL Injection and XSS 0.750=&gt;x</ref></refs><vuln_soft><prod name="PostNuke" vendor="PostNuke Software Foundation"><vers num="0.750"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1779" published="2005-05-31" seq="2005-1779" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in password.asp in MaxWebPortal 1.35, 1.36, 2.0, and 20050418 Next allows remote attackers to execute arbitrary SQL commands via the memKey parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="SECTRACK" url="http://securitytracker.com/id?1014048">1014048</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/15511">15511</ref></refs><vuln_soft><prod name="MaxWebPortal" vendor="MaxWebPortal"><vers num="1.35"/><vers num="1.36"/><vers num="2.0"/><vers num="2005-04-18"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1780" published="2005-05-31" seq="2005-1780" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in admin/login.asp in Active News Manager allows remote attackers to execute arbitrary SQL commands via the password.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://www.under9round.com/anm.txt">http://www.under9round.com/anm.txt</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/15493">15493</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014057">1014057</ref></refs><vuln_soft><prod name="Active News Manager" vendor="Dotnetindex"><vers num="2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2007-07-24" name="CVE-2005-1781" published="2005-05-31" seq="2005-1781" severity="Medium" type="CVE"><desc><descript source="cve">Unknown vulnerability in SMTP authentication for MailEnable allows remote attackers to cause a denial of service (crash).</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/15487">15487</ref></refs><vuln_soft><prod name="MailEnable Professional" vendor="MailEnable"><vers num="1.5"/><vers num="1.51"/><vers num="1.52"/><vers num="1.53"/><vers num="1.54"/></prod><prod name="MailEnable Enterprise" vendor="MailEnable"><vers num="1.00"/><vers num="1.01"/><vers num="1.02"/><vers num="1.03"/><vers num="1.04"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-08-23" name="CVE-2005-1782" published="2005-05-26" seq="2005-1782" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in BookReview beta 1.0 allow remote attackers to inject arbitrary web script or HTML via the node parameter to (1) add_review.htm, (2) suggest_review.htm, (3) suggest_category.htm, (4) add_booklist.htm, or (5) add_url.htm, the isbn parameter to (6) add_review.htm, (7) add_contents.htm, (8) add_classification.htm, the (9) chapters parameter to the add_contents page in index.php (aka add_contents.htm), (10) the user parameter to contact.htm, or (11) the submit[string] parameter to search.htm. NOTE: it is not clear whether BookReview is available to the public. If not, then it should not be included in CVE.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://lostmon.blogspot.com/2005/05/bookreview-10-multiple-variable-xss.html">http://lostmon.blogspot.com/2005/05/bookreview-10-multiple-variable-xss.html</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/13783">13783</ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/16871">16871</ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/16872">16872</ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/16873">16873</ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/16874">16874</ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/16875">16875</ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/16876">16876</ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/16877">16877</ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/16878">16878</ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/16879">16879</ref><ref adv="1" source="SECTRACK" url="http://securitytracker.com/id?1014058">1014058</ref></refs><vuln_soft><prod name="BookReview" vendor="W.M.R. Simpson"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1783" published="2005-05-31" seq="2005-1783" severity="Medium" type="CVE"><desc><descript source="cve">BookReview beta 1.0 allows remote attackers to obtain the path of the web server via certain parameters to search.htm, possibly due to a search[string] parameter with a missing value or an incorrect submit[type] value, which reveals the path in the resulting error message.  NOTE: it is not clear whether BookReview is available to the public.  If not, then it should not be included in CVE.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://lostmon.blogspot.com/2005/05/bookreview-10-multiple-variable-xss.html">http://lostmon.blogspot.com/2005/05/bookreview-10-multiple-variable-xss.html</ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/16881">16881</ref><ref adv="1" source="" url="http://securitytracker.com/alerts/2005/May/1014058.html"></ref><ref source="OSVDB" url="http://www.osvdb.org/16880">16880</ref></refs><vuln_soft><prod name="BookReview" vendor="W.M.R. Simpson"><vers num="beta 1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1784" published="2005-05-27" seq="2005-1784" severity="High" type="CVE"><desc><descript source="cve">Hosting Controller 6.1 HotFix 2.0 and earlier allows remote attackers to steal passwords and gain privileges via a modified emailaddress parameter in an updateprofile action for UserProfile.asp.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="SECTRACK" url="http://securitytracker.com/id?1014062">1014062</ref></refs><vuln_soft><prod name="Hosting Controller" vendor="Hosting Controller"><vers num="6.1 HotFix 2.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1785" published="2005-05-31" seq="2005-1785" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in ad/login.asp in ZonGG 1.2 allows remote attackers to execute arbitrary SQL commands via the password parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://www.under9round.com/zongg.txt">http://www.under9round.com/zongg.txt</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/13787">13787</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/0636">ADV-2005-0636</ref><ref adv="1" source="SECTRACK" url="http://securitytracker.com/id?1014063">1014063</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15515">15515</ref></refs><vuln_soft><prod name="ZonGG" vendor="ZonGG"><vers num="V1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1786" published="2005-05-25" seq="2005-1786" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in admin.asp in FunkyASP AD System 1.1 allows remote attackers to execute arbitrary SQL commands and gain privileges via the password parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://www.under9round.com/funky-asp.txt">http://www.under9round.com/funky-asp.txt</ref><ref adv="1" patch="1" source="CONFIRM" url="http://www.funkyasp.co.uk/product.asp?prod=1&amp;currency=USD">http://www.funkyasp.co.uk/product.asp?prod=1&amp;currency=USD</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/15494">15494</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014056">1014056</ref></refs><vuln_soft><prod name="FunkyASP AD System" vendor="FunkyASP"><vers num="1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1787" published="2005-05-27" seq="2005-1787" severity="High" type="CVE"><desc><descript source="cve">setup.php in phpStat 1.5 allows remote attackers to bypass authentication and gain administrator privileges by setting the $check variable.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111721290726958&amp;w=2">20050527 PHP Stat Administrative User Authentication Bypass</ref><ref adv="1" source="MISC" url="http://www.soulblack.com.ar/repo/tools/sbphpstatpoc.txt">http://www.soulblack.com.ar/repo/tools/sbphpstatpoc.txt</ref><ref source="MISC" url="http://www.soulblack.com.ar/repo/papers/advisory/PhpStat_advisory.txt">http://www.soulblack.com.ar/repo/papers/advisory/PhpStat_advisory.txt</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014064">1014064</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15516">15516</ref></refs><vuln_soft><prod name="PHPStat" vendor="PHPStat"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1788" published="2005-06-01" seq="2005-1788" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in resellerresources.asp in Hosting Controller 6.1 Hotfix 2.0 allows remote attackers to execute arbitrary SQL commands via the jresourceid parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="SECTRACK" url="http://securitytracker.com/id?1014071">1014071</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15540">15540</ref></refs><vuln_soft><prod name="Hosting Controller" vendor="Hosting Controller"><vers num="6.1 HotFix 2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1789" published="2005-05-29" seq="2005-1789" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in SignIn.asp in India Software Solution shopping cart allows remote attackers to execute arbitrary SQL commands via the password.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://ir-hackers.com/indsc.txt">http://ir-hackers.com/indsc.txt</ref><ref adv="1" source="SECTRACK" url="http://securitytracker.com/id?1014074">1014074</ref></refs><vuln_soft><prod name="Shopping Cart" vendor="India Software Solution"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-06-15" name="CVE-2005-1790" published="2005-06-01" seq="2005-1790" severity="Low" type="CVE"><desc><descript source="cve">Microsoft Internet Explorer 6 SP2 6.0.2900.2180 and 6.0.2800.1106, and earlier versions, allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a Javascript BODY onload event that calls the window function, aka &quot;Mismatched Document Object Model Objects Memory Corruption Vulnerability.&quot;</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111746394106172&amp;w=2">20050528 Microsoft Internet Explorer - Crash on JavaScript </ref><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111755552306013&amp;w=2">20050530 Re: Microsoft Internet Explorer - Crash on JavaScript </ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/15546">15546</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/417326/30/0/threaded">20051121 Computer Terrorism Security Advisory (Reclassification) - Microsoft Internet Explorer JavaScript Window() Vulnerability</ref><ref source="" url="http://www.computerterrorism.com/research/ie/ct21-11-2005"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/2509">ADV-2005-2509</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015251">1015251</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms05-054.mspx">MS05-054</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA05-347A.html">TA05-347A</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/887861">VU#887861</ref><ref source="BID" url="http://www.securityfocus.com/bid/13799">13799</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/2867">ADV-2005-2867</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15368">15368</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2005-234.pdf"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/2909">ADV-2005-2909</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18064">18064</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1091.html">OVAL1091</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1299.html">OVAL1299</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1303.html">OVAL1303</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1489.html">OVAL1489</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1508.html">OVAL1508</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval722.html">OVAL722</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18311">18311</ref><ref source="" url="http://www130.nortelnetworks.com/cgi-bin/eserv/cs/main.jsp?cscat=BLTNDETAIL&amp;DocumentOID=375420"></ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1091">oval:org.mitre.oval:def:1091</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1299">oval:org.mitre.oval:def:1299</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1303">oval:org.mitre.oval:def:1303</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1489">oval:org.mitre.oval:def:1489</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1508">oval:org.mitre.oval:def:1508</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:722">oval:org.mitre.oval:def:722</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers edition="for Microsoft Windows Server 2003 SP1.0.2900.2180" num="6"/><vers edition="for Microsoft Windows Server 2003 SP1.0.2800.1106" num="6"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1791" published="2005-05-28" seq="2005-1791" severity="Low" type="CVE"><desc><descript source="cve">Microsoft Internet Explorer 6 SP2 (6.0.2900.2180) crashes when the user attempts to add a URI to the restricted zone, in which the full domain name of the URI begins with numeric sequences similar to an IP address.  NOTE: if there is not an exploit scenario in which an attacker can trigger this behavior, then perhaps this issue should not be included in CVE.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111746303509720&amp;w=2">20050531 Microsoft Internet Explorer - Crash on adding sites to restricted zone (05/28/2005)</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/13798">13798</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers edition="for Microsoft Windows Server 2003 SP1.0 SP2" num="6"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1792" published="2005-06-01" seq="2005-1792" severity="Medium" type="CVE"><desc><descript source="cve">Memory leak in Windows Management Instrumentation (WMI) service allows attackers to cause a denial of service (memory consumption and crash) by creating security contexts more quickly than they can be cleared from the RPC cache.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="MISC" url="http://www.networksecurity.fi/advisories/windows-wmi-rpc.html">http://www.networksecurity.fi/advisories/windows-wmi-rpc.html</ref><ref adv="1" patch="1" source="MSKB" url="http://support.microsoft.com/kb/890196">890196</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/13801">13801</ref><ref source="OSVDB" url="http://www.osvdb.org/13020">13020</ref></refs><vuln_soft><prod name="Windows XP" vendor="Microsoft"><vers edition="Gold" num="Professional"/><vers edition="Gold" num="Professional"/><vers edition="Gold" num="Professional"/><vers edition="SP2" num="Home"/><vers edition="SP1" num="Home"/><vers num="Home"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1793" published="2005-06-01" seq="2005-1793" severity="Low" type="CVE"><desc><descript source="cve">User32.DLL in Microsoft Windows 98SE, and possibly other operating systems, allows local and remote attackers to cause a denial of service (crash) via an icon (.ico) bitmap file with large width and height values.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/><user_init/></range><refs><ref source="RUS-CERT" url="http://cert.uni-stuttgart.de/archive/bugtraq/2005/05/msg00318.html">User32.dll Icon Size Crash</ref></refs><vuln_soft><prod name="Windows 98" vendor="Microsoft"><vers num="SE"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1794" published="2005-06-01" seq="2005-1794" severity="Medium" type="CVE"><desc><descript source="cve">Microsoft Terminal Server using Remote Desktop Protocol (RDP) 5.2 stores an RSA private key in mstlsapi.dll and uses it to sign a certificate, which allows remote attackers to spoof public keys of legitimate servers and conduct man-in-the-middle attacks.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://www.oxid.it/downloads/rdp-gbu.pdf">http://www.oxid.it/downloads/rdp-gbu.pdf</ref><ref source="BID" url="http://www.securityfocus.com/bid/13818">13818</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15605/">15605</ref></refs><vuln_soft><prod name="Windows Terminal Services using RDP" vendor="Microsoft"><vers num="5.2"/></prod><prod name="Remote Desktop" vendor="Microsoft"><vers edition="Windows XP" num="5.1.2600.2180"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1795" published="2005-05-27" seq="2005-1795" severity="High" type="CVE"><desc><descript source="cve">The filecopy function in misc.c in Clam AntiVirus (ClamAV) before 0.85, on Mac OS, allows remote attackers to execute arbitrary code via a virus in a a filename that contains shell metacharacters, which are not properly handled when HFS permissions prevent the file from being deleted and ditto is invoked.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><exception/><env/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://www.sentinelchicken.com/advisories/clamav">http://www.sentinelchicken.com/advisories/clamav</ref><ref adv="1" patch="1" source="SECTRACK" url="http://securitytracker.com/id?1014070">1014070</ref></refs><vuln_soft><prod name="ClamAV" vendor="Clam Anti-Virus"><vers num="0.84" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1796" published="2005-05-31" seq="2005-1796" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in the curses_msg function in the Ncurses interface (ec_curses.c) for Ettercap before 0.7.3 allows remote attackers to execute arbitrary code.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CONFIRM" url="http://ettercap.sourceforge.net/history.php">http://ettercap.sourceforge.net/history.php</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/15535">15535</ref><ref source="BID" url="http://www.securityfocus.com/bid/13820">13820</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/0670">ADV-2005-0670</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014084">1014084</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-749">DSA-749</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200506-07.xml">GLSA-200506-07</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15664">15664</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16000">16000</ref></refs><vuln_soft><prod name="Ettercap" vendor="Ettercap"><vers num="0.7.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1797" published="2005-05-26" seq="2005-1797" severity="Medium" type="CVE"><desc><descript source="cve">The design of Advanced Encryption Standard (AES), aka Rijndael, allows remote attackers to recover AES keys via timing attacks on S-box lookups, which are difficult to perform in constant time in AES implementations.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/><race/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://cr.yp.to/antiforgery/cachetiming-20050414.pdf">http://cr.yp.to/antiforgery/cachetiming-20050414.pdf</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/13785">13785</ref></refs><vuln_soft><prod name="OpenSSL" vendor="OpenSSL Project"><vers num="0.9.7d"/><vers num="0.9.7c"/><vers num="0.9.7 beta3"/><vers num="0.9.7 beta2"/><vers num="0.9.7 beta1"/><vers num="0.9.7b"/><vers num="0.9.7a"/><vers num="0.9.7"/><vers num="0.9.6m"/><vers num="0.9.6l"/><vers num="0.9.6k"/><vers num="0.9.6j"/><vers num="0.9.6i"/><vers num="0.9.6h"/><vers num="0.9.6g"/><vers num="0.9.6f"/><vers num="0.9.6e"/><vers num="0.9.6d"/><vers num="0.9.6c"/><vers num="0.9.6b"/><vers num="0.9.6a"/><vers num="0.9.6"/><vers num="0.9.5a"/><vers num="0.9.5"/><vers num="0.9.4"/><vers num="0.9.3"/><vers num="0.9.2b"/><vers num="0.9.1c"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1798" published="2005-05-29" seq="2005-1798" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in ServersCheck Monitoring Software 5.9.0 to 5.10.0 allows remote attackers to read arbitrary files via .. (dot dot) sequences in an HTTP request.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://www.rgod.altervista.org/hacking/news/serverscheck.html">http://www.rgod.altervista.org/hacking/news/serverscheck.html</ref><ref adv="1" source="SECTRACK" url="http://securitytracker.com/id?1014075">1014075</ref></refs><vuln_soft><prod name="Monitoring Software" vendor="ServersCheck"><vers num="5.9.0"/><vers num="5.10.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1799" published="2005-05-31" seq="2005-1799" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in FreeStyle Wiki 3.5.7 and WikiLite (FSWikiLite) .10 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/15538">15538</ref><ref source="BID" url="http://www.securityfocus.com/bid/13824">13824</ref></refs><vuln_soft><prod name="Wiki" vendor="FreeStyle"><vers num="3.5.7"/></prod><prod name="WikiLite" vendor="FreeStyle"><vers num=".10"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1800" published="2005-05-28" seq="2005-1800" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Jaws Glossary gadget 0.4 to 0.5.1 allows remote attackers to inject arbitrary web script or HTML via the term parameter in a view or ViewTerm action to index.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-May/034354.html">20050529 XSS Bug in Jaws Glossary Action: ViewTerm ( v 0.4 - 0.5.1 (latest version))</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/13795">13795</ref><ref source="BID" url="http://www.securityfocus.com/bid/13796">13796</ref></refs><vuln_soft><prod name="ClamAV" vendor="Clam Anti-Virus"><vers num="0.84 rc2"/><vers num="0.84 rc1"/><vers num="0.83"/><vers num="0.82"/><vers num="0.81"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1801" published="2005-05-26" seq="2005-1801" severity="Low" type="CVE"><desc><descript source="cve">The vCard viewer in Nokia 9500 allows attackers to cause a denial of service (crash) via a vCard with a long Name field, which causes the crash when the user views it.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/><exception/></vuln_types><range><network/><user_init/></range><refs><ref source="MISC" url="http://www.securityfocus.com/infocus/1834">http://www.securityfocus.com/infocus/1834</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/13784">13784</ref><ref source="MISC" url="http://www.securityfocus.com/infocus/1836">http://www.securityfocus.com/infocus/1836</ref></refs><vuln_soft><prod name="Nokia" vendor="Nokia"><vers num="9500"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1802" published="2005-05-27" seq="2005-1802" severity="Medium" type="CVE"><desc><descript source="cve">Nortel VPN Router (aka Contivity) allows remote attackers to cause a denial of service (crash) via an IPsec IKE packet with a malformed ISAKMP header.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/399423">20050531 Nortel VPN Router Malformed Packet DoS Vulnerability</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/13792">13792</ref><ref source="MISC" url="http://www.nta-monitor.com/news/vpn-flaws/nortel/vpn-router-dos/">http://www.nta-monitor.com/news/vpn-flaws/nortel/vpn-router-dos/</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014068">1014068</ref></refs><vuln_soft><prod name="VPN Router" vendor="Nortel Networks"><vers num="600"/><vers num="5000"/><vers num="2700"/><vers num="1740"/><vers num="1700"/><vers num="1100"/><vers num="1050"/><vers num="1010"/></prod><prod name="Contivity" vendor="Nortel Networks"><vers num="4600 Secure IP Services Gateway"/><vers num="4500 Secure IP Services Gateway"/><vers num="4000 VPN Switch"/><vers num="2600 Secure IP Services Gateway"/><vers num="2500 VPN Switch"/><vers num="2000 VPN Switch"/><vers num="1600 Secure IP Services Gateway"/><vers num="1500 VPN Switch"/><vers num="1000 VPN Switch"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1803" published="2005-05-29" seq="2005-1803" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Net Portal Dynamic System (NPDS) 5.0 allow remote attackers to inject arbitrary web script or HTML via the language parameter to (1) admin.php, or (2) powerpack_f.php, (3) the sitename parameter to sdv_infos.php, (4) the categories parameter to faq.php, (5) the lettre parameter to the glossaire module, (6) the title parameter to reviews.php, or (7) the image_subject parameter to reply.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="CONFIRM" url="http://www.npds.org/download.php?op=geninfo&amp;did=115">http://www.npds.org/download.php?op=geninfo&amp;did=115</ref><ref adv="1" patch="1" source="SECTRACK" url="http://securitytracker.com/id?1014073">1014073</ref><ref source="OSVDB" url="http://www.osvdb.org/16464">16464</ref><ref source="OSVDB" url="http://www.osvdb.org/16922">16922</ref></refs><vuln_soft><prod name="Net Portal Dynamic System" vendor="Net Portal Dynamic System"><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1804" published="2005-05-29" seq="2005-1804" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in Net Portal Dynamic System (NPDS) 5.0 allow remote attackers to execute arbitrary SQL commands via the (1) terme parameter in the glossaire module (glossaire.php) or (2) query parameter to links.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CONFIRM" url="http://www.npds.org/download.php?op=geninfo&amp;did=115">http://www.npds.org/download.php?op=geninfo&amp;did=115</ref><ref adv="1" patch="1" source="SECTRACK" url="http://securitytracker.com/id?1014073">1014073</ref></refs><vuln_soft><prod name="Net Portal Dynamic System" vendor="Net Portal Dynamic System"><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1805" published="2005-05-28" seq="2005-1805" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in login.asp in an unknown product by Online Solutions for Educators (OS4E) allows remote attackers to execute arbitrary SQL commands via the password.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://www.under9round.com/os4e.txt">http://www.under9round.com/os4e.txt</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/13804">13804</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/0645">ADV-2005-0645</ref><ref adv="1" source="SECTRACK" url="http://securitytracker.com/id?1014072">1014072</ref></refs><vuln_soft><prod name="Online Solutions for Educators" vendor="Online Solutions for Educators"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1806" published="2005-05-28" seq="2005-1806" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in PeerCast 0.1211 and earlier allows remote attackers to execute arbitrary code via format strings in the URL.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111746603629979&amp;w=2">20050528 Format String Vulnerability In Peercast 0.1211 And Earlier</ref><ref adv="1" patch="1" source="MISC" url="http://www.gulftech.org/?node=research&amp;article_id=00077-05282005">http://www.gulftech.org/?node=research&amp;article_id=00077-05282005</ref><ref adv="1" patch="1" source="CONFIRM" url="http://www.peercast.org/forum/viewtopic.php?p=11596">http://www.peercast.org/forum/viewtopic.php?p=11596</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/0651">ADV-2005-0651</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/15536">15536</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200506-15.xml">GLSA-200506-15</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15753">15753</ref></refs><vuln_soft><prod name="PeerCast" vendor="PeerCast"><vers num="0.1211" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1807" published="2005-05-28" seq="2005-1807" severity="Medium" type="CVE"><desc><descript source="cve">The Data function in class.smtp.php in PHPMailer 1.7.2 and earlier allows remote attackers to cause a denial of service (infinite loop leading to memory and CPU consumption) via a long header field.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://www.cybsec.com/vuln/PHPMailer-DOS.pdf">http://www.cybsec.com/vuln/PHPMailer-DOS.pdf</ref><ref adv="1" source="SECTRACK" url="http://securitytracker.com/id?1014069">1014069</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15543">15543</ref><ref source="BID" url="http://www.securityfocus.com/bid/13805">13805</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0448">ADV-2006-0448</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18732">18732</ref><ref source="" url="http://sourceforge.net/project/shownotes.php?release_id=341210&amp;group_id=26031"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/2242">ADV-2007-2242</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25726">25726</ref></refs><vuln_soft><prod name="PHPMailer" vendor="PHPMailer"><vers num="1.72" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-07-31" name="CVE-2005-1808" published="2005-05-30" seq="2005-1808" severity="Medium" type="CVE"><desc><descript source="cve">Firefly Studios Stronghold 2 1.2 and earlier allows remote attackers to cause a denial of service (crash) via a packet with a large size value for the nickname, which causes a memory allocation failure and generates an exception.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="Luigi Auriemma" url="http://aluigi.altervista.org/adv/strong2boom-adv.txt"></ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111747562806999&amp;w=2">20050530 Crash in Stronghold 2 1.2</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15556">15556</ref></refs><vuln_soft><prod name="Stronghold 2" vendor="Firefly Studios"><vers num="1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1809" published="2005-06-01" seq="2005-1809" severity="Medium" type="CVE"><desc><descript source="cve">Sony Ericsson P900 Beamer allows remote attackers to cause a denial of service (panic) via an obexftp session with a long filename in an OBEX File Transfer or OBEX Object Push.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref source="MISC" url="http://www.securityfocus.com/infocus/1834">http://www.securityfocus.com/infocus/1834</ref><ref source="BID" url="http://www.securityfocus.com/bid/13872">13872</ref><ref source="MISC" url="http://www.securityfocus.com/infocus/1836">http://www.securityfocus.com/infocus/1836</ref></refs></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1810" published="2005-06-01" seq="2005-1810" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in template-functions-category.php in WordPress 1.5.1 allows remote attackers to execute arbitrary SQL commands via the $cat_ID variable, as demonstrated using the cat parameter to index.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="CONFIRM" url="http://wordpress.org/development/2005/05/security-update/">http://wordpress.org/development/2005/05/security-update/</ref><ref source="OSVDB" url="http://www.osvdb.org/16905">16905</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/15517">15517</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200506-04.xml">GLSA-200506-04</ref><ref source="CONFIRM" url="http://bugs.gentoo.org/show_bug.cgi?id=94512">http://bugs.gentoo.org/show_bug.cgi?id=94512</ref><ref source="BID" url="http://www.securityfocus.com/bid/13809">13809</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111817436619067&amp;w=2">20050607 SQL Injection Exploit for WordPress &lt;= 1.5.1.1</ref></refs><vuln_soft><prod name="WordPress" vendor="WordPress"><vers num="1.5.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1811" published="2005-06-01" seq="2005-1811" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in usercp.php for MyBulletinBoard (MyBB) allows remote attackers to inject arbitrary web script or HTML via the website field in a user profile.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://seclists.org/lists/bugtraq/2005/May/0338.html">20050530 MyBB 1.0 RC4 XSS Bug</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/15552">15552</ref><ref source="BID" url="http://www.securityfocus.com/bid/13819">13819</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014081">1014081</ref></refs><vuln_soft><prod name="MyBulletinBoard" vendor="MyBulletinBoard"><vers num="1.0 RC4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1812" published="2005-06-01" seq="2005-1812" severity="High" type="CVE"><desc><descript source="cve">Multiple stack-based buffer overflows in FutureSoft TFTP Server Evaluation Version 1.0.0.1 allow remote attackers to execute arbitrary code via a long (1) filename or (2) transfer mode string in a Read Request (RRQ) or Write Request (WRQ) packet.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="MISC" url="http://www.security.org.sg/vuln/tftp2000-1001.html">http://www.security.org.sg/vuln/tftp2000-1001.html</ref><ref source="BID" url="http://www.securityfocus.com/bid/13821">13821</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014079">1014079</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15539">15539</ref></refs><vuln_soft><prod name="TFTP Server 2000" vendor="FutureSoft"><vers num="1.0.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1813" published="2005-06-01" seq="2005-1813" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in FutureSoft TFTP Server Evaluation Version 1.0.0.1 allows remote attackers to read arbitrary files via a TFTP GET request containing (1) &quot;../&quot; (dot dot slash) or (2) &quot;..\&quot; (dot dot backslash) sequences.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/><input/></vuln_types><range><network/></range><refs><ref source="MISC" url="http://www.security.org.sg/vuln/tftp2000-1001.html">http://www.security.org.sg/vuln/tftp2000-1001.html</ref><ref source="BID" url="http://www.securityfocus.com/bid/13821">13821</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014079">1014079</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15539">15539</ref></refs><vuln_soft><prod name="TFTP Server 2000" vendor="FutureSoft"><vers num="1.0.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1814" published="2005-06-01" seq="2005-1814" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in PicoWebServer 1.0 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long URL.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111746551802380&amp;w=2">20050528 PicoWebServer Remote Unicode Stack Overflow</ref><ref source="BID" url="http://www.securityfocus.com/bid/13807">13807</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15541">15541</ref></refs><vuln_soft><prod name="PicoWebServer" vendor="Newmad Technologies"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1815" published="2005-06-01" seq="2005-1815" severity="Medium" type="CVE"><desc><descript source="cve">Multiple buffer overflows in Hummingbird Connectivity inetD 10.0.0.1 and 9.0.0.4 allows attackers to cause a denial of service and possibly execute arbitrary code via (1) an FTP command with a long argument to FTPD (ftpdw.exe) or (2) a large amount of data to LPD (Lpdw.exe).</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref patch="1" source="CONFIRM" url="http://connectivity.hummingbird.com/support/nc/exceed/ftpd_advisory.html?cks=y">http://connectivity.hummingbird.com/support/nc/exceed/ftpd_advisory.html?cks=y</ref><ref patch="1" source="CONFIRM" url="http://connectivity.hummingbird.com/support/nc/exceed/lpdw_advisory.html">http://connectivity.hummingbird.com/support/nc/exceed/lpdw_advisory.html</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/13788">13788</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/13790">13790</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/15557">15557</ref></refs><vuln_soft><prod name="Connectivity" vendor="Hummingbird"><vers num="10.0"/><vers num="9.0"/><vers num="7.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1816" published="2005-06-01" seq="2005-1816" severity="Medium" type="CVE"><desc><descript source="cve">Invision Power Board (IPB) 1.0 through 2.0.4 allows non-root admins to add themselves or other users to the root admin group via the &quot;Move users in this group to&quot; screen.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2005-05/0635.html">20050528 Invision Power Board 1.x and 2.x Privilege Escalation Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/13797">13797</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15545">15545</ref></refs><vuln_soft><prod name="Invision Board" vendor="Invision Power Services"><vers num="2.0.4"/><vers num="2.0.3"/><vers num="2.0.2"/><vers num="2.0.1"/><vers num="2.0 PF2"/><vers num="2.0 PF1"/><vers num="2.0 PDR3"/><vers num="2.0 Alpha 3"/><vers num="2.0"/><vers num="1.3.1 Final"/><vers num="1.3 Final"/><vers num="1.3"/><vers num="1.2"/><vers num="1.1.2"/><vers num="1.1.1"/><vers num="1.0.1"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1817" published="2005-06-01" seq="2005-1817" severity="Medium" type="CVE"><desc><descript source="cve">Invision Power Board (IPB) 1.0 through 1.3 allows remote attackers to edit arbitrary forum posts via a direct request to index.php with modified parameters.</descript></desc><loss_types><int/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/13802">13802</ref></refs><vuln_soft><prod name="Invision Board" vendor="Invision Power Services"><vers num="1.3 Final"/><vers num="1.3"/><vers num="1.2"/><vers num="1.1.2"/><vers num="1.1.1"/><vers num="1.0.1"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1818" published="2005-06-01" seq="2005-1818" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in NewLife Blogger before 3.3.1 allow remote attackers to execute arbitrary SQL commands via unknown attack vectors.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="CONFIRM" url="http://www.sevengraff.com/index.php">http://www.sevengraff.com/index.php</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/13815">13815</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/15523">15523</ref></refs><vuln_soft><prod name="NewLife Blogger" vendor="NewLife Blogger"><vers num="3.3"/><vers num="3.2.3"/><vers num="3.2"/><vers num="3.1"/><vers num="3.0.1"/><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1819" published="2005-06-01" seq="2005-1819" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in NikoSoft WebMail before 0.11.0 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="CONFIRM" url="http://www.nikosoft.net/nswm/">http://www.nikosoft.net/nswm/</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/15518">15518</ref></refs><vuln_soft><prod name="WebMail" vendor="NikoSoft"><vers num="0.10.4"/><vers num="0.10.3"/><vers num="0.10.2"/><vers num="0.10.1"/><vers num="0.10.0"/><vers num="0.9.10"/><vers num="0.9.9"/><vers num="0.9.8"/><vers num="0.9.7"/><vers num="0.9.6"/><vers num="0.9.5"/><vers num="0.9.4"/><vers num="0.9.3"/><vers num="0.9.2"/><vers num="0.9.1"/><vers num="0.9.0"/><vers num="0.8.3"/><vers num="0.8.2"/><vers num="0.8.1"/><vers num="0.8.0"/><vers num="0.7.9"/><vers num="0.7.7"/><vers num="0.7.6"/><vers num="0.7.5"/><vers num="0.7"/><vers num="O.6"/><vers num="0.5"/><vers num="0.4"/><vers num="0.3"/><vers num="0.2"/><vers num="0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1820" published="2005-06-01" seq="2005-1820" severity="High" type="CVE"><desc><descript source="cve">zboard.php in Zeroboard version 4.1pl2 to 4.1pl5 allows remote attackers to execute arbitrary PHP code via improper quoting when using the preg_replace function.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/><design/></vuln_types><range><network/></range><refs><ref source="MISC" url="http://pandora.sapzil.info/text/notify/20050123.zb41advisory.php">http://pandora.sapzil.info/text/notify/20050123.zb41advisory.php</ref><ref source="MISC" url="http://www.securiteam.com/exploits/5KP0V0AFPA.html">http://www.securiteam.com/exploits/5KP0V0AFPA.html</ref><ref source="BID" url="http://www.securityfocus.com/bid/13823">13823</ref></refs><vuln_soft><prod name="Zeroboard" vendor="Zeroboard"><vers num="4.1 pl5"/><vers num="4.1 pl4"/><vers num="4.1 pl3"/><vers num="4.1 pl2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-28" name="CVE-2005-1821" published="2005-06-01" seq="2005-1821" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in pdl_header.inc.php in PowerDownload 3.0.2 and 3.0.3 allows remote attackers to execute arbitrary PHP code via the incdir parameter to downloads.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://www.soulblack.com.ar/repo/papers/advisory/powerdownload_advisory.txt">http://www.soulblack.com.ar/repo/papers/advisory/powerdownload_advisory.txt</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/13822">13822</ref><ref adv="1" source="SECTRACK" url="http://securitytracker.com/id?1014078">1014078</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/15537">15537</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111755754126095&amp;w=2">20050531 PowerDownload Remote File Inclusion</ref></refs><vuln_soft><prod name="PowerDownload" vendor="PowerScripts.org"><vers num="3.0.3"/><vers num="3.0.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1822" published="2005-06-01" seq="2005-1822" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in Qualiteam X-Cart 4.0.8 allow remote attackers to execute arbitrary SQL commands via the (1) cat or (2) printable parameter to home.php, (3) productid or (4) mode parameter to product.php, (5) id parameter to error_message.php, (6) section parameter to help.php, (7) mode parameter to orders.php, (8) mode parameter to register.php, (9) mode parameter to search.php, or the (10) gcid or (11) gcindex parameter to giftcert.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111748583101076&amp;w=2">20050530 Multiple vulnerabilities in x-cart Gold</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014077">1014077</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15555">15555</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20773">xcart-multiple-parameters-sql-injection(20773)</ref><ref source="BID" url="http://www.securityfocus.com/bid/13817">13817</ref></refs><vuln_soft><prod name="X-Cart" vendor="Qualiteam"><vers num="4.0.8"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1823" published="2005-06-01" seq="2005-1823" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Qualiteam X-Cart 4.0.8 allow remote attackers to inject arbitrary web script or HTML via the (1) cat or (2) printable parameter to home.php, (3) productid or (4) mode parameter to product.php, (5) id parameter to error_message.php, (6) section parameter to help.php, (7) mode parameter to orders.php, (8) mode parameter to register.php, (9) mode parameter to search.php, or the (10) gcid or (11) gcindex parameter to giftcert.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111748583101076&amp;w=2">20050530 Multiple vulnerabilities in x-cart Gold</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014077">1014077</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15555">15555</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20774">xcart-multiple-scripts-xss(20774)</ref><ref source="BID" url="http://www.securityfocus.com/bid/13817">13817</ref></refs><vuln_soft><prod name="X-Cart" vendor="Qualiteam"><vers num="4.0.8"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-21" name="CVE-2005-1824" published="2005-06-02" seq="2005-1824" severity="High" type="CVE"><desc><descript source="cve">The sql_escape_string function in auth/sql.c for the mailutils SQL authentication module does not properly quote the &quot;\&quot; (backslash) character, which is used as an escape character and makes the module vulnerable to SQL injection attacks.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CONFIRM" url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=308031">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=308031</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200506-02.xml">GLSA-200506-02</ref></refs><vuln_soft><prod name="Mailutils" vendor="GNU"><vers num="1.0.6.1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1825" published="2005-05-03" seq="2005-1825" severity="High" type="CVE"><desc><descript source="cve">Multiple stack-based buffer overflows in the nvd_exec function in HP Radia Notify Daemon 3.1.2.0 (formerly by Novadigm), and other versions including 2.x, 3.x, and 4.x, allows remote attackers to execute arbitrary code via a command with crafted parameters to a RADEXECD process.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-June/034387.html">20050601 HP Radia Notify Daemon: Multiple Buffer Overflow Vulnerabilities</ref><ref adv="1" source="MISC" url="http://www.grok.org.uk/advisories/radexecd.html">http://www.grok.org.uk/advisories/radexecd.html</ref><ref adv="1" source="HP" url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-June/034394.html">HPSBMA01143</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/0681">ADV-2005-0681</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014089">1014089</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15567">15567</ref></refs><vuln_soft><prod name="Radia Notify Daemon" vendor="HP"><vers num="3.1.2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1826" published="2005-05-03" seq="2005-1826" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in HP Radia Notify Daemon 3.1.0.0 (formerly by Novadigm), and other versions including 2.x, 3.x, and 4.x, allows remote attackers to execute arbitrary code via a long file extension.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-June/034387.html">20050601 HP Radia Notify Daemon: Multiple Buffer Overflow Vulnerabilities</ref><ref source="MISC" url="http://www.grok.org.uk/advisories/radexecd.html">http://www.grok.org.uk/advisories/radexecd.html</ref><ref adv="1" source="HP" url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-June/034394.html">HPSBMA01143</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/0681">ADV-2005-0681</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014089">1014089</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15567">15567</ref></refs><vuln_soft><prod name="Radia Notify Daemon" vendor="HP"><vers num="3.1.0.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1827" published="2005-05-26" seq="2005-1827" severity="High" type="CVE"><desc><descript source="cve">D-Link DSL-504T allows remote attackers to bypass authentication and gain privileges, such as upgrade firmware, restart the router or restore a saved configuration, via a direct request to firmwarecfg.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111722515805478&amp;w=2">20050526 DSL-504T (and maybe many other) remote access without password bug</ref><ref source="BID" url="http://www.securityfocus.com/bid/13679">13679</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15422">15422</ref></refs><vuln_soft><prod name="DSL-504T" vendor="D-Link"><vers num="V1.00B01T16.EU.2004-02-17"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1828" published="2005-05-26" seq="2005-1828" severity="High" type="CVE"><desc><descript source="cve">D-Link DSL-504T stores usernames and passwords in cleartext in the router configuration file, which allows remote attackers to obtain sensitive information.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111722515805478&amp;w=2">20050526 DSL-504T (and maybe many other) remote access without password bug</ref></refs><vuln_soft><prod name="DSL-504T" vendor="D-Link"><vers num="V1.00B01T16.EU.2004-02-17"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1829" published="2005-05-28" seq="2005-1829" severity="Medium" type="CVE"><desc><descript source="cve">Microsoft Internet Explorer 6 SP2 allows remote attackers to cause a denial of service (infinite loop and application crash) via two embedded files that call each other.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111746441220149&amp;w=2">20050528 Microsoft Internet Explorer - Crash on processing embedded files with endless loop (05/28/2005)</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="SP2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1830" published="2005-05-29" seq="2005-1830" severity="Medium" type="CVE"><desc><descript source="cve">The DbgMsg.sys driver in Compuware SoftICE DriverStudio 3.1 and 3.2 allows remote attackers to cause a denial of service (application crash) via an invalid Debug Message pointer.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111746654827861&amp;w=2">20050529 Compuware Softice (DbgMsg driver) Local Denial Of Service</ref><ref adv="1" source="MISC" url="http://pb.specialised.info/all/adv/sice-adv.txt">http://pb.specialised.info/all/adv/sice-adv.txt</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/15522">15522</ref></refs><vuln_soft><prod name="SoftICE DriverStudio" vendor="Compuware"><vers num="3.1"/><vers num="3.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-10-05" name="CVE-2005-1831" published="2005-05-31" seq="2005-1831" severity="High" type="CVE"><desc><descript source="cve">** DISPUTED **  Sudo 1.6.8p7 on SuSE Linux 9.3, and possibly other Linux distributions, allows local users to gain privileges by using sudo to call su, then entering a blank password and hitting CTRL-C. NOTE: SuSE and multiple third-party researchers have not been able to replicate this issue, stating &quot;Sudo catches SIGINT and returns an empty string for the password so I don&apos;t see how this could happen unless the user&apos;s actual password was empty.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111755694008928&amp;w=2">20050531 [XNUXER-SECURITY] Root Privilige Escalation in Sudo version 1.6.8p7 without Password, SuSE 9.3</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2005-05/0359.html">20050531 RE: [securitysuse.de] [XNUXER-SECURITY] Root Privilige Escalation in Sudo version 1.6.8p7 without Password, SuSE 9.3</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2005-05/0349.html">20050531 Re: [securitysuse.de] [XNUXER-SECURITY] Root Privilige Escalation in Sudo version 1.6.8p7 without Password, SuSE 9.3</ref><ref source="OSVDB" url="http://www.osvdb.org/20417">20417</ref></refs><vuln_soft><prod name="Sudo" vendor="Todd Miller"><vers num="1.6.8p7"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1832" published="2005-05-31" seq="2005-1832" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in MyBulletinBoard (MyBB) 1.00 RC4 and earlier allow remote attackers to execute arbitrary web script or HTML via the (1) forums, (2) version, or (3) limit parameter to misc.php, (4) page or (5) datecut parameter to forumdisplay.php, (6) username, (7) email, or (8) email2 parameter to member.php, (9) page or (10) usersearch parameter to memberlist.php, (11) pid or (12) tid parameter to showthread.php, or (13) tid parameter to printthread.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111757191118050&amp;w=2">20050531 Multiple vulnerabilities in MyBulletinBoard (MyBB) 1.00 RC4</ref><ref adv="1" patch="1" source="CONFIRM" url="http://www.mybboard.com/community/showthread.php?tid=2559">http://www.mybboard.com/community/showthread.php?tid=2559</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/15552">15552</ref></refs><vuln_soft><prod name="MyBulletinBoard" vendor="MyBulletinBoard"><vers num="1.00 RC4" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1833" published="2005-05-31" seq="2005-1833" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in MyBulletinBoard (MyBB) 1.00 RC4 allow remote attackers to execute arbitrary SQL commands via the (1) eid parameter to calendar.php, (2) idsql parameter to online.php, (3) usersearch parameter to memberlist.php, (4) pid parameter to editpost.php, (5) fid parameter to forumdisplay.php, (6) tid parameter to newreply.php, (7) sid parameter to search.php, (8) tid or (9) pid parameter to showthread.php, (10) tid parameter to usercp2.php, (11) tid parameter to printthread.php, or (12) pid parameter to reputation.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111757191118050&amp;w=2">20050531 Multiple vulnerabilities in MyBulletinBoard (MyBB) 1.00 RC4</ref><ref adv="1" patch="1" source="CONFIRM" url="http://www.mybboard.com/community/showthread.php?tid=2559">http://www.mybboard.com/community/showthread.php?tid=2559</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/15552">15552</ref><ref source="OSVDB" url="http://www.osvdb.org/17024">17024</ref></refs><vuln_soft><prod name="MyBulletinBoard" vendor="MyBulletinBoard"><vers num="1.00 RC4" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1834" published="2005-06-01" seq="2005-1834" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in login.asp in NEXTWEB (i)Site allows remote attackers to execute arbitrary SQL commands and bypass authentication via the password field.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111764682925083&amp;w=2">20050601 [ZH2005-13SA] NEXTWEB (i)Site website management multiple</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/15560">15560</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014085">1014085</ref></refs><vuln_soft><prod name="NEXTWEB (i)Site" vendor="NEXTWEB"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1835" published="2005-06-01" seq="2005-1835" severity="Medium" type="CVE"><desc><descript source="cve">NEXTWEB (i)Site stores databases under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request to databases/Users.mdb.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/><design/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111764682925083&amp;w=2">20050601 [ZH2005-13SA] NEXTWEB (i)Site website management multiple</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/15560">15560</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014085">1014085</ref></refs><vuln_soft><prod name="NEXTWEB (i)Site" vendor="NEXTWEB"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1836" published="2005-06-01" seq="2005-1836" severity="Medium" type="CVE"><desc><descript source="cve">NEXTWEB (i)Site allows remote attackers to cause a denial of service (error 500) via a crafted HTTP request, possibly involving wildcard requests for .jsp files.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111764682925083&amp;w=2">20050601 [ZH2005-13SA] NEXTWEB (i)Site website management multiple</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/15560">15560</ref></refs><vuln_soft><prod name="NEXTWEB (i)Site" vendor="NEXTWEB"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1837" published="2005-06-01" seq="2005-1837" severity="High" type="CVE"><desc><descript source="cve">Fortinet firewall running FortiOS 2.x contains a hardcoded uername with the password set to the serial number, which allows local users with console access to gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/><config/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111773657526375&amp;w=2">20050601 Backdoor in =?ISO-8859-1?Q?Fortinet=B4s_firewall_Fortigate?=</ref></refs><vuln_soft><prod name="Fortinet firewall" vendor="Fortinet"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1838" published="2005-06-02" seq="2005-1838" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting vulnerabilities in castnewPost.asp in Liberum Help Desk 0.97.3 allow remote attackers to inject arbitrary web script or HTML via the (1) Email, (2) Title, or (3) Description fields.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111773586701991&amp;w=2">20050602 [ECHO_ADV_14$2005] Multiple Vulnerabilities in Liberum Help Desk</ref><ref adv="1" source="MISC" url="http://echo.or.id/adv/adv14-theday-2005.txt">http://echo.or.id/adv/adv14-theday-2005.txt</ref></refs><vuln_soft><prod name="Liberum Help Desk" vendor="Liberum"><vers num="0.97.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1839" published="2005-06-02" seq="2005-1839" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in Doug Luxem Liberum Help Desk 0.97.3 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) view.asp or (2) print.asp or (3) edit parameter to register.asp.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111773586701991&amp;w=2">20050602 [ECHO_ADV_14$2005] Multiple Vulnerabilities in Liberum Help Desk</ref><ref adv="1" source="MISC" url="http://echo.or.id/adv/adv14-theday-2005.txt">http://echo.or.id/adv/adv14-theday-2005.txt</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15593">15593</ref></refs><vuln_soft><prod name="Liberum Help Desk" vendor="Liberum"><vers num="0.97.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1840" published="2005-06-02" seq="2005-1840" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in class.layout_phpcms.php in phpCMS 1.2.x before 1.2.1pl2 allows remote attackers to read or include arbitrary files, as demonstrated using a .. (dot dot) in the language parameter to parser.php.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111773774916907&amp;w=2">20050602 SEC-CONSULT SA20050602-1 :: Arbitrary File Inclusion in phpCMS 1.2.x</ref><ref adv="1" patch="1" source="CONFIRM" url="http://www.phpcms.de/download/index.en.html">http://www.phpcms.de/download/index.en.html</ref><ref adv="1" patch="1" source="MISC" url="http://cvs.sourceforge.net/viewcvs.py/phpcms/phpcms/parser/include/class.layout_phpcms.php?rev=1.12.2.37&amp;view=markup">http://cvs.sourceforge.net/viewcvs.py/phpcms/phpcms/parser/include/class.layout_phpcms.php?rev=1.12.2.37&amp;view=markup</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15586">15586</ref></refs><vuln_soft><prod name="phpCMS" vendor="phpCMS"><vers num="1.2.1 p12"/><vers num="1.2.0"/><vers num="1.2.1"/><vers num="1.2.1 pl1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1841" published="2005-07-07" seq="2005-1841" severity="Low" type="CVE"><desc><descript source="cve">The control for Adobe Reader 5.0.9 and 5.0.10 on Linux, Solaris, HP-UX, and AIX creates temporary files with the permissions as specified in a user&apos;s umask, which could allow local users to read PDF documents of that user if the umask allows it.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="MISC" url="http://secunia.com/secunia_research/2005-6/advisory/">http://secunia.com/secunia_research/2005-6/advisory/</ref><ref adv="1" patch="1" source="" url="http://www.adobe.com/support/techdocs/329121.html">http://www.adobe.com/support/techdocs/329121.html</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/14457">14457</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-575.html">RHSA-2005:575</ref></refs><vuln_soft><prod name="Acrobat Reader" vendor="Adobe"><vers num="5.0.9"/><vers num="5.0.10"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1842" published="2005-08-24" seq="2005-1842" severity="Low" type="CVE"><desc><descript source="cve">VCNative for Adobe Version Cue 1.0 and 1.0.1, as used in Creative Suite 1.0 and 1.3, and when running on Mac OS X with Version Cue Workspace, creates temporary log files with predictable names, which allows local users to modify arbitrary files via a symlink attack.</descript></desc><loss_types><int/></loss_types><range><local/></range><refs><ref adv="1" patch="1" source="" url="http://www.adobe.com/support/techdocs/327129.html"></ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/16541">16541</ref><ref source="BID" url="http://www.securityfocus.com/bid/14638">14638</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014776">1014776</ref><ref source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=297&amp;type=vulnerabilities">20050829 Adobe Version Cue VCNative Arbitrary File Overwrite Vulnerability</ref></refs><vuln_soft><prod name="Version Cue" vendor="Adobe"><vers num="1.0"/><vers num="1.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1843" published="2005-08-24" seq="2005-1843" severity="Medium" type="CVE"><desc><descript source="cve">VCNative for Adobe Version Cue 1.0 and 1.0.1, as used in Creative Suite 1.0 and 1.3, and when running on Mac OS X with Version Cue Workspace, allows local users to load arbitrary libraries and execute arbitrary code via the -lib command line argument.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><range><local/></range><refs><ref adv="1" patch="1" source="" url="http://www.adobe.com/support/techdocs/327129.html"></ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/16541">16541</ref><ref source="BID" url="http://www.securityfocus.com/bid/14638">14638</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014776">1014776</ref><ref source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=296&amp;type=vulnerabilities">20050829 Adobe Version Cue VCNative Arbitrary Library Loading Vulnerability</ref></refs><vuln_soft><prod name="Version Cue" vendor="Adobe"><vers num="1.0"/><vers num="1.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1846" published="2005-01-20" seq="2005-1846" severity="Medium" type="CVE"><desc><descript source="cve">Multiple directory traversal vulnerabilities in YaMT before 0.5_2 allow attackers to overwrite arbitrary files via the (1) rename or (2) sort options.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CONFIRM" url="http://rpmfind.net/linux/RPM/suse/updates/8.2/i386/rpm/i586/yamt-0.5-1277.i586.html">http://rpmfind.net/linux/RPM/suse/updates/8.2/i386/rpm/i586/yamt-0.5-1277.i586.html</ref><ref adv="1" patch="1" source="CONFIRM" url="http://www.vuxml.org/freebsd/99b5cfa5-d3d2-11d9-8ffb-00061bc2ad93.html">http://www.vuxml.org/freebsd/99b5cfa5-d3d2-11d9-8ffb-00061bc2ad93.html</ref></refs><vuln_soft><prod name="yamt" vendor="yamt"><vers num="0.5.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1847" published="2005-01-20" seq="2005-1847" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in YaMT before 0.5_2 allow attackers to execute arbitrary code via the (1) rename or (2) sort options.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CONFIRM" url="http://rpmfind.net/linux/RPM/suse/updates/8.2/i386/rpm/i586/yamt-0.5-1277.i586.html">http://rpmfind.net/linux/RPM/suse/updates/8.2/i386/rpm/i586/yamt-0.5-1277.i586.html</ref><ref adv="1" patch="1" source="CONFIRM" url="http://www.vuxml.org/freebsd/99b5cfa5-d3d2-11d9-8ffb-00061bc2ad93.html">http://www.vuxml.org/freebsd/99b5cfa5-d3d2-11d9-8ffb-00061bc2ad93.html</ref></refs><vuln_soft><prod name="yamt" vendor="yamt"><vers num="0.5.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1848" published="2005-07-11" seq="2005-1848" severity="Medium" type="CVE"><desc><descript source="cve">The dhcpcd DHCP client before 1.3.22 allows remote attackers to cause a denial of service (daemon crash) via unknown vectors that cause an out-of-bounds memory read.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-750">DSA-750</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-603.html">RHSA-2005:603</ref></refs><vuln_soft><prod name="dhcpcd" vendor="Phystech"><vers num="1.3.17 pl2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1849" published="2005-07-26" seq="2005-1849" severity="Medium" type="CVE"><desc><descript source="cve">inftrees.h in zlib 1.2.2 allows remote attackers to cause a denial of service (application crash) via an invalid file that causes a large dynamic tree to be produced.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-763">DSA-763</ref><ref source="MISC" url="http://security.debian.org/pool/updates/main/z/zlib/zlib_1.2.2-4.sarge.2.diff.gz">http://security.debian.org/pool/updates/main/z/zlib/zlib_1.2.2-4.sarge.2.diff.gz</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/Aug/msg00000.html">APPLE-SA-2005-08-15</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2005//Aug/msg00001.html">APPLE-SA-2005-08-17</ref><ref source="FEDORA" url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=162680">FLSA:162680</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200509-18.xml">GLSA-200509-18</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-797">DSA-797</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/usn/usn-151-3">USN-151-3</ref><ref source="BID" url="http://www.securityfocus.com/bid/14340">14340</ref><ref source="OSVDB" url="http://www.osvdb.org/18141">18141</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014540">1014540</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16137">16137</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/21456">zlib-codetable-dos(21456)</ref><ref source="SCO" url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2006.6/SCOSA-2006.6.txt">SCOSA-2006.6</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18377">18377</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-584.html">RHSA-2005:584</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2005:196">MDKSA-2005:196</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17326">17326</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17516">17516</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1026">DSA-1026</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19550">19550</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200603-18.xml">GLSA-200603-18</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19334">19334</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:070">MDKSA-2006:070</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_43_zlib.html">SUSE-SA:2005:043</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19597">
19597</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/464745/100/0/threaded">

20070404 VMSA-2007-0003 VMware ESX 3.0.1 and 3.0.0 server security updates</ref><ref source="" url="http://www.vmware.com/support/vi3/doc/esx-3616065-patch.html"></ref><ref source="" url="http://www.vmware.com/support/vi3/doc/esx-9916286-patch.html"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1267">
ADV-2007-1267</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24788">
24788</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:196">MDKSA-2005:196</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:070">MDKSA-2006:070</ref></refs><vuln_soft><prod name="zlib" vendor="Gnu"><vers num="1.2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-09-05" name="CVE-2005-1850" published="2005-07-19" seq="2005-1850" severity="High" type="CVE"><desc><descript source="cve">Certain contributed scripts for ekg Gadu Gadu client 1.5 and earlier create temporary files insecurely, with unknown impact and attack vectors, a different vulnerability than CVE-2005-1916.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-760">DSA-760</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112198499417250&amp;w=2">20050721 Multiple vulnerabilities in libgadu and ekg package</ref></refs><vuln_soft><prod name="ekg" vendor="ekg"><vers num="1.5"/><vers num="1.5 rc2"/><vers num="1.5 rc1"/><vers num="1.4"/><vers num="1.3"/><vers num="1.1"/><vers num="1.1 rc2"/><vers num="1.1 rc1"/><vers num="1.0"/><vers num="1.0 rc3"/><vers num="1.0 rc2"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-09-05" name="CVE-2005-1851" published="2005-07-19" seq="2005-1851" severity="High" type="CVE"><desc><descript source="cve">A certain contributed script for ekg Gadu Gadu client 1.5 and earlier allows attackers to execute shell commands via unknown attack vectors.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-760">DSA-760</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112198499417250&amp;w=2">20050721 Multiple vulnerabilities in libgadu and ekg package</ref></refs><vuln_soft><prod name="ekg" vendor="ekg"><vers num="1.5"/><vers num="1.5 rc2"/><vers num="1.5 rc1"/><vers num="1.4"/><vers num="1.3"/><vers num="1.1"/><vers num="1.1 rc2"/><vers num="1.1 rc1"/><vers num="1.0"/><vers num="1.0 rc3"/><vers num="1.0 rc2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-05" name="CVE-2005-1852" published="2005-07-26" seq="2005-1852" severity="High" type="CVE"><desc><descript source="cve">Multiple integer overflows in libgadu, as used in Kopete in KDE 3.2.3 to 3.4.1, ekg before 1.6rc3, GNU Gadu, CenterICQ, Kadu, and other packages, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an incoming message.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112198499417250&amp;w=2">20050721 Multiple vulnerabilities in libgadu and ekg package</ref><ref adv="1" patch="1" source="" url="http://www.kde.org/info/security/advisory-20050721-1.txt">http://www.kde.org/info/security/advisory-20050721-1.txt</ref><ref adv="1" patch="1" source="FEDORA" url="http://lwn.net/Articles/144724/">FEDORA-2005-624</ref><ref adv="1" patch="1" source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200507-23.xml">GLSA-200507-23</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/14345">14345 </ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200507-26.xml">GLSA-200507-26</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16140">16140</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16155">16155</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16211">16211</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16242">16242</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-639.html">RHSA-2005:639</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_19_sr.html">SUSE-SR:2005:019</ref></refs><vuln_soft><prod name="KDE" vendor="KDE"><vers num="3.4.1"/><vers num="3.4.0"/><vers num="3.4"/><vers num="3.3.2"/><vers num="3.3.1"/><vers num="3.3"/><vers num="3.2.3"/></prod><prod name="ekg" vendor="ekg"><vers num="1.5 rc2"/><vers num="1.5 rc1"/><vers num="1.5"/><vers num="1.4"/><vers num="1.3"/><vers num="1.1 rc2"/><vers num="1.1 rc1"/><vers num="1.1"/><vers num="1.0 rc3"/><vers num="1.0 rc2"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1853" published="2005-08-03" seq="2005-1853" severity="High" type="CVE"><desc><descript source="cve">gopher.c in the Gopher client 3.0.5 does not properly create temporary files, which allows local users to gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-770">DSA-770</ref><ref source="SECTRACK" url="http://www.securitytracker.com/alerts/2005/Jul/1014599.html">1014599</ref></refs><vuln_soft><prod name="gopher" vendor="University of Minnesota"><vers num="3.0.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1854" published="2005-08-05" seq="2005-1854" severity="High" type="CVE"><desc><descript source="cve">Unknown vulnerability in apt-cacher in Debian 3.1, related to &quot;missing input sanitising,&quot; allows remote attackers to execute arbitrary commands on the caching server.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-772">DSA-772</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/14459">14459</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/16327">16327</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/21664">aptcacher-command-execution(21664)</ref></refs><vuln_soft><prod name="apt-cacher" vendor="Debian"><vers num="0.9.9"/><vers num="0.9.4"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-08-23" name="CVE-2005-1855" published="2005-08-30" seq="2005-1855" severity="Low" type="CVE"><desc><descript source="cve">Backup Manager (backup-manager) before 0.5.8 creates backup files with world-readable default permissions, which allows local users to obtain sensitive information.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="" url="http://www.usenetlinux.com/archive/index.php/t-411815.html"></ref><ref patch="1" source="" url="http://www.sukria.net/packages/backup-manager/"></ref><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-787">DSA-787</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/13892">13892</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1014124">1014124</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/15615">15615</ref></refs><vuln_soft><prod name="Backup Manager" vendor="Sukria"><vers num="0.5.7"/><vers num="0.5.6"/></prod><prod name="Debian Linux" vendor="Debian"><vers num="3.1 sparc"/><vers num="3.1 s_390"/><vers num="3.1 ppc"/><vers num="3.1 mipsel"/><vers num="3.1 mips"/><vers num="3.1 m68k"/><vers num="3.1 ia-64"/><vers num="3.1 ia-32"/><vers num="3.1 hppa"/><vers num="3.1 arm"/><vers num="3.1 amd64"/><vers num="3.1 alpha"/><vers num="3.1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-08-23" name="CVE-2005-1856" published="2005-08-30" seq="2005-1856" severity="Low" type="CVE"><desc><descript source="cve">The CD-burning feature in backup-manager 0.5.8 and earlier uses a fixed filename in a world-writable directory for logging, which allows local users to overwrite files via a symlink attack.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-787">DSA-787</ref></refs><vuln_soft><prod name="Backup Manager" vendor="Sukria"><vers num="0.5.7"/><vers num="0.5.6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-01-30" name="CVE-2005-1857" published="2005-09-02" seq="2005-1857" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in simpleproxy before 3.4 allows remote malicious HTTP proxies to execute arbitrary code via format string specifiers in a reply.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://sourceforge.net/project/shownotes.php?group_id=604&amp;release_id=351847"></ref><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-786">DSA-786</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/14666">14666</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/16567/">16567</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/22016">simpleproxy-reply-format-string(22016)</ref><ref source="" url="http://sourceforge.net/project/shownotes.php?group_id=604&amp;release_id=351847"></ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/139421">VU#139421</ref></refs><vuln_soft><prod name="Simpleproxy" vendor="Simpleproxy"><vers num="3.2"/><vers num="3.1"/><vers num="3.0"/><vers num="2.2b"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1858" published="2005-06-03" seq="2005-1858" severity="Low" type="CVE"><desc><descript source="cve">FUSE 2.x before 2.3.0 does not properly clear previously used memory from unfilled pages when the filesystem returns a short byte count to a read request, which may allow local users to obtain sensitive information.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="MISC" url="http://www.sven-tantau.de/public_files/fuse/fuse_20050603.txt">http://www.sven-tantau.de/public_files/fuse/fuse_20050603.txt</ref><ref adv="1" source="CONFIRM" url="http://sourceforge.net/project/shownotes.php?release_id=331884">http://sourceforge.net/project/shownotes.php?release_id=331884</ref><ref adv="1" source="CONFIRM" url="http://bugs.debian.org/311634">http://bugs.debian.org/311634</ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/17042">17042</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/15561/">15561</ref><ref source="BID" url="http://www.securityfocus.com/bid/13857">13857</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-744">DSA-744</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014107">1014107</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16024">16024</ref></refs><vuln_soft><prod name="Fuse" vendor="Fuse"><vers num="2.3 rc1"/><vers num="2.3 pre"/><vers num="2.2.1"/><vers num="2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1859" published="2005-07-12" seq="2005-1859" severity="High" type="CVE"><desc><descript source="cve">Unknown vulnerability in arshell in the Array Service (arrayd) for SGI ProPack 3 with SP 5 and 6, and SGI ProPack 4, allows local users to execute arbitrary shells as root on other hosts in the cluster or array.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><other/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20050701-01-P.asc">20050701-01-P</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1014454">1014454</ref></refs><vuln_soft><prod name="ProPack" vendor="SGI"><vers num="3.0 SP5"/><vers num="3.0 SP6"/><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-27" name="CVE-2005-1864" published="2005-06-09" seq="2005-1864" severity="Medium" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in cal_admintop.php in Calendarix Advanced 1.5 allows remote attackers to execute arbitrary PHP code via the calpath parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2005-05/0356.html">20050531 multiple vulnerability Calendarix Advanced</ref><ref adv="1" source="SECTRACK" url="http://securitytracker.com/alerts/2005/May/1014083.html">1014083</ref></refs><vuln_soft><prod name="Calendarix Advanced" vendor="Vincent Hor"><vers num="1.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1865" published="2005-06-09" seq="2005-1865" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in Calendarix Advanced 1.5 allow remote attackers to execute arbitrary SQL commands via the catview parameter to (1) cal_week.php, (2) cal_cat.php, or (3) cal_day.php, or (4) id parameter to cal_pophols.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2005-05/0356.html">20050531 multiple vulnerability Calendarix Advanced</ref><ref source="OSVDB" url="http://www.osvdb.org/16971">16971</ref><ref source="OSVDB" url="http://www.osvdb.org/16972">16972</ref><ref source="OSVDB" url="http://www.osvdb.org/16974">16974</ref><ref source="OSVDB" url="http://www.osvdb.org/16975">16975</ref><ref source="SECTRACK" url="http://securitytracker.com/alerts/2005/May/1014083.html">1014083</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15569">15569</ref><ref source="" url="http://www.calendarix.com/download_advanced.php"></ref><ref source="" url="http://www.calendarix.com/download_basic.php"></ref></refs><vuln_soft><prod name="Calendarix Advanced" vendor="Vincent Hor"><vers num="1.5"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-08-17" name="CVE-2005-1866" published="2005-05-31" seq="2005-1866" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in calendar.php in Calendarix Advanced 1.5 allows remote attackers to inject arbitrary web script or HTML via the year parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2005-05/0356.html">20050531 multiple vulnerability Calendarix Advanced</ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/16973">16973</ref><ref adv="1" source="SECTRACK" url="http://securitytracker.com/alerts/2005/May/1014083.html">1014083</ref></refs><vuln_soft><prod name="Calendarix Advanced" vendor="Vincent Hor"><vers num="1.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1867" published="2005-06-09" seq="2005-1867" severity="High" type="CVE"><desc><descript source="cve">Symantec Brightmail AntiSpam before 6.0.2 has a hard-coded database administrator password, which allows remote attackers to gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CONFIRM" url="http://securityresponse.symantec.com/avcenter/security/Content/2005.05.31a.html">http://securityresponse.symantec.com/avcenter/security/Content/2005.05.31a.html</ref><ref patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/0671">ADV-2005-0671</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/15562">15562</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20804">brightmail-static-database-security-bypass(20804)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014088">1014088</ref></refs><vuln_soft><prod name="Brightmail AntiSpam" vendor="Symantec"><vers num="6.0.1"/><vers num="6.0"/><vers num="5.5"/><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1868" published="2005-06-09" seq="2005-1868" severity="High" type="CVE"><desc><descript source="cve">I-Man 0.9, and possibly earlier versions, allows remote attackers to execute arbitrary PHP code by uploading a file attachment with a .php extension.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="CONFIRM" url="http://sourceforge.net/project/shownotes.php?release_id=331422">http://sourceforge.net/project/shownotes.php?release_id=331422</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/15558/">15558</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20857">iman-file-upload(20857)</ref></refs><vuln_soft><prod name="I-Man" vendor="I-Man"><vers num="0.9"/><vers num="0.8"/><vers num="0.7"/><vers num="0.6"/><vers num="0.5"/><vers num="0.4"/><vers num="0.3"/><vers num="0.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-28" name="CVE-2005-1869" published="2005-06-07" seq="2005-1869" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in start_lobby.php in MWChat 6.x allows remote attackers to execute arbitrary PHP code via the CONFIG[MWCHAT_Libs] parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://www.defacers.com.mx/advisories/4.txt">http://www.defacers.com.mx/advisories/4.txt</ref><ref adv="1" patch="1" source="CONFIRM" url="http://www.appindex.net">http://www.appindex.net</ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/17087">17087</ref><ref adv="1" patch="1" source="SECTRACK" url="http://www.securitytracker.com/alerts/2005/Jun/1014090.html">1014090</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15596">15596</ref></refs><vuln_soft><prod name="MWChat" vendor="Appindex"><vers num="6.7" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-27" name="CVE-2005-1870" published="2005-06-09" seq="2005-1870" severity="Medium" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in childwindow.inc.php in Popper 1.41-r2 and earlier allows remote attackers to execute arbitrary PHP code via the form parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MISC" url="http://security.lss.hr/en/index.php?page=details&amp;ID=LSS-2005-06-07">http://security.lss.hr/en/index.php?page=details&amp;ID=LSS-2005-06-07</ref><ref source="OSVDB" url="http://www.osvdb.org/17085">17085</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/15584">15584</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-June/034408.html">20050604 LSS.hr false positives.</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-June/034425.html">20050606 Popper webmail remote code execution vulnerability - advisory fix</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014116">1014116</ref><ref source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=111801389729155&amp;w=2">20050605 Re: LSS.hr false positives. (correction)</ref></refs><vuln_soft><prod name="Popper" vendor="Popper"><vers num="1.41 r2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1871" published="2005-06-09" seq="2005-1871" severity="High" type="CVE"><desc><descript source="cve">Unknown vulnerability in the privilege system in Drupal 4.4.0 through 4.6.0, when public registration is enabled, allows remote attackers to gain privileges, due to an &quot;input check&quot; that &quot;is not implemented properly.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111782257601422&amp;w=2">20050603 [DRUPAL-SA-2005-001] New Drupal release fixes critical security issue</ref><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2005-06/0010.html">20050603 [DRUPAL-SA-2005-001] New Drupal release fixes critical security issue</ref><ref source="OSVDB" url="http://www.osvdb.org/17028">17028</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15372">15372</ref></refs><vuln_soft><prod name="Drupal" vendor="Drupal"><vers num="4.4.0"/><vers num="4.4.1"/><vers num="4.4.2"/><vers num="4.5.0"/><vers num="4.5.1"/><vers num="4.5.2"/><vers num="4.6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1872" published="2005-06-03" seq="2005-1872" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the administrative console in IBM WebSphere Application Server 5.x, when the global security option is enabled, allows remote attackers to execute arbitrary code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111817727120752&amp;w=2">20050607 [AppSecInc Advisory WEBSP05-V0098] Remote Buffer overflow in WebSphere Application Server Administrative Console</ref><ref adv="1" source="MISC" url="http://www.appsecinc.com/resources/alerts/general/WEBSPHERE-001.html">http://www.appsecinc.com/resources/alerts/general/WEBSPHERE-001.html</ref><ref adv="1" patch="1" source="MISC" url="http://www-1.ibm.com/support/docview.wss?rs=180&amp;uid=swg24009775">http://www-1.ibm.com/support/docview.wss?rs=180&amp;uid=swg24009775</ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/17041">17041</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/15598/">15598</ref></refs><vuln_soft><prod name="Websphere Application Server" vendor="IBM"><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1873" published="2005-06-09" seq="2005-1873" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in Crob FTP 3.6.1, and possibly earlier versions, allow remote attackers to execute arbitrary code via (1) an FTP command with a large string followed by the RMD command with a long string or (2) a globbing (&quot;*&quot;) character followed by a long string.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-June/034426.html">20050606 Crob FTP Server remote buffer overflows</ref><ref source="Secunia" url="http://secunia.com/advisories/15585/">Crob FTP Server Buffer Overflow Vulnerabilities </ref><ref source="SECUNIA" url="http://secunia.com/advisories/15585">15585</ref><ref source="" url="http://security.lss.hr/index.php?page=details&amp;ID=LSS-2005-06-06"></ref></refs><vuln_soft><prod name="Crob FTP" vendor="Crob"><vers num="3.6.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1874" published="2005-06-09" seq="2005-1874" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in Dzip before 2.9 allows remote attackers to create arbitrary files via a filename containing a .. (dot dot) in a .dz archive.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="MISC" url="http://bugs.gentoo.org/show_bug.cgi?id=93079">http://bugs.gentoo.org/show_bug.cgi?id=93079</ref><ref adv="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200506-03.xml">GLSA-200506-03</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/0692">ADV-2005-0692</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15599">15599</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15614">15614</ref></refs><vuln_soft><prod name="Dzip" vendor="Evan Wagner"><vers num="2.84"/><vers num="2.83"/><vers num="2.82"/><vers num="2.81"/><vers num="2.8"/><vers num="2.6"/><vers num="2.55"/><vers num="2.51"/><vers num="2.5"/><vers num="2.4"/><vers num="2.3"/><vers num="2.21"/><vers num="2.2"/><vers num="2.1"/><vers num="2.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1875" published="2005-06-02" seq="2005-1875" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in list.php in Exhibit Engine (EE) 1.22 allow remote attackers to execute arbitrary SQL commands via the (1) search_row, (2) sort_row, (3) order or (4) perpage parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111773894525119&amp;w=2">20050602 SEC-CONSULT SA20050602-2 :: Exhibit Engine Blind SQL Injection</ref><ref adv="1" source="CONFIRM" url="http://photography-on-the.net/forum/showthread.php?p=579692">http://photography-on-the.net/forum/showthread.php?p=579692</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/13844">13844</ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/17006">17006</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/15583">15583</ref></refs><vuln_soft><prod name="Exhibit Engine" vendor="Exhibit Engine"><vers num="1.54 RC4"/><vers num="1.22"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1876" published="2005-06-09" seq="2005-1876" severity="Medium" type="CVE"><desc><descript source="cve">Direct code injection vulnerability in CuteNews 1.3.6 and earlier allows remote attackers with administrative privileges to execute arbitrary PHP code via certain inputs that are injected into a template (.tpl) file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111773528322711&amp;w=2">20050602 PHP Execution Vulnerability in CuteNews</ref><ref source="OSVDB" url="http://www.osvdb.org/17030">17030</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15594">15594</ref></refs><vuln_soft><prod name="CuteNews" vendor="CutePHP"><vers num="1.3.6"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1877" published="2005-06-06" seq="2005-1877" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in view_ticket.php in Lpanel 1.59 and earlier allows remote attackers to inject arbitrary web script or HTML and obtain sensitive information via the pid parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-June/034413.html">20050606 Lpanel.NET&apos;s Lpanel (all versions up to and including 1.59) is vulnerable to plain-text session credential leakage via script injection.</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/13869">13869</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15589/">15589</ref></refs><vuln_soft><prod name="LPanel" vendor="LPanel"><vers num="1.59"/></prod></vuln_soft></entry><entry CVSS_base_score="1.2" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="2.9" CVSS_score="1.2" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1878" published="2005-06-09" seq="2005-1878" severity="Low" type="CVE"><desc><descript source="cve">GIPTables Firewall 1.1 and earlier allows local users to overwrite arbitrary files via a symlink attack on the temp.ip.addresses temporary file.</descript></desc><loss_types><int/></loss_types><vuln_types><design/><race/></vuln_types><range><local/></range><refs><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-June/034423.html">20050606 GIPTables Firewall &lt;= v1.1 insecure temporary file creation</ref><ref source="MISC" url="http://www.zataz.net/adviso/giptables-05222005.txt">http://www.zataz.net/adviso/giptables-05222005.txt</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15604">15604</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014109">1014109</ref></refs><vuln_soft><prod name="GIPTables Firewall" vendor="GIPTables"><vers num="1.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1879" published="2005-06-09" seq="2005-1879" severity="Low" type="CVE"><desc><descript source="cve">LutelWall 0.97 and earlier allows local users to overwrite arbitrary files via a symlink attack on a temporary file created by a system call to wget.</descript></desc><loss_types><int/></loss_types><vuln_types><design/><exception/></vuln_types><range><local/></range><refs><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-June/034424.html">20050606 LutelWall &lt;= 0.97 insecure temporary file creation</ref><ref source="MISC" url="http://www.zataz.net/adviso/lutelwall-05222005.txt">http://www.zataz.net/adviso/lutelwall-05222005.txt</ref><ref source="BID" url="http://www.securityfocus.com/bid/13863">13863</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014112">1014112</ref><ref source="CONFIRM" url="http://firewall.lutel.pl/download/0.98/ChangeLog">http://firewall.lutel.pl/download/0.98/ChangeLog</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200506-10.xml">GLSA-200506-10</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15647">15647</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15665">15665</ref></refs><vuln_soft><prod name="LutelWall" vendor="Tomasz Lutelmowski"><vers num="0.97"/><vers num="0.96"/><vers num="0.95"/><vers num="0.94"/><vers num="0.93"/><vers num="0.92"/><vers num="0.91"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1880" published="2005-06-06" seq="2005-1880" severity="Low" type="CVE"><desc><descript source="cve">everybuddy 0.4.3 and earlier allows local users to overwrite arbitrary files via a symlink attack on a temporary file created by a system call to wget.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-June/034422.html">20050606 everybuddy &lt;= 0.4.3 insecure temporary file creation</ref><ref adv="1" source="MISC" url="http://www.zataz.net/adviso/everybuddy-06062005.txt">http://www.zataz.net/adviso/everybuddy-06062005.txt</ref><ref adv="1" source="MISC" url="http://bugs.gentoo.org/show_bug.cgi?id=94473">http://bugs.gentoo.org/show_bug.cgi?id=94473</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/13865">13865</ref><ref adv="1" source="SECTRACK" url="http://securitytracker.com/id?1014110">1014110</ref></refs><vuln_soft><prod name="EveryBuddy" vendor="EveryBuddy"><vers num="0.4.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1881" published="2005-06-06" seq="2005-1881" severity="High" type="CVE"><desc><descript source="cve">upload.php in YaPiG 0.92b, 0.93u and 0.94u does not properly restrict the file extension for uploaded image files, which allows remote attackers to upload arbitrary files and execute arbitrary PHP code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://secwatch.org/advisories/secwatch/20050530_yapig.txt">http://secwatch.org/advisories/secwatch/20050530_yapig.txt</ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/17115">17115</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/15600/">15600</ref><ref adv="1" source="SECTRACK" url="http://securitytracker.com/id?1014103">1014103</ref></refs><vuln_soft><prod name="YaPiG" vendor="YaPiG"><vers num="0.94u"/><vers num="0.93u"/><vers num="0.92b"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-28" name="CVE-2005-1882" published="2005-06-09" seq="2005-1882" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in last_gallery.php in YaPiG 0.93u and 0.94u allows remote attackers to execute arbitrary PHP code via the YAPIG_PATH parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://secwatch.org/advisories/secwatch/20050530_yapig.txt">http://secwatch.org/advisories/secwatch/20050530_yapig.txt</ref><ref source="OSVDB" url="http://www.osvdb.org/17117">17117</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/15600/">15600</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014103">1014103</ref></refs><vuln_soft><prod name="YaPiG" vendor="YaPiG"><vers num="0.93u"/><vers num="0.94u"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1883" published="2005-06-09" seq="2005-1883" severity="Medium" type="CVE"><desc><descript source="cve">global.php in YaPiG 0.92b allows remote attackers to include arbitrary local files via the BASE_DIR parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://secwatch.org/advisories/secwatch/20050530_yapig.txt">http://secwatch.org/advisories/secwatch/20050530_yapig.txt</ref><ref source="OSVDB" url="http://www.osvdb.org/17116">17116</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/15600/">15600</ref><ref adv="1" source="SECTRACK" url="http://securitytracker.com/id?1014103">1014103</ref></refs><vuln_soft><prod name="YaPiG" vendor="YaPiG"><vers num="0.92b"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1884" published="2005-06-09" seq="2005-1884" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in the (1) rmdir or (2) mkdir commands in upload.php in YaPiG 0.92b, 0.93u and 0.94u allows remote attackers to create or delete arbitrary directories via a .. (dot dot) in the dir parameter.</descript></desc><loss_types><avail/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://secwatch.org/advisories/secwatch/20050530_yapig.txt">http://secwatch.org/advisories/secwatch/20050530_yapig.txt</ref><ref source="BID" url="http://www.securityfocus.com/bid/13877">13877</ref><ref source="OSVDB" url="http://www.osvdb.org/17120">17120</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15600/">15600</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014103">1014103</ref></refs><vuln_soft><prod name="YaPiG" vendor="YaPiG"><vers num="0.92b"/><vers num="0.93u"/><vers num="0.94u"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1885" published="2005-06-06" seq="2005-1885" severity="Medium" type="CVE"><desc><descript source="cve">view.php in YaPiG 0.92b, 0.93u and 0.94u allows remote attackers to obtain sensitive information via a phid parameter that is not an integer, which reveals the path in an error message.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://secwatch.org/advisories/secwatch/20050530_yapig.txt">http://secwatch.org/advisories/secwatch/20050530_yapig.txt</ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/17119">17119</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/15600/">15600</ref><ref adv="1" source="SECTRACK" url="http://securitytracker.com/id?1014103">1014103</ref></refs><vuln_soft><prod name="YaPiG" vendor="YaPiG"><vers num="0.94u"/><vers num="0.93u"/><vers num="0.92b"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1886" published="2005-06-09" seq="2005-1886" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in view.php in YaPiG 0.92b, 0.93u and 0.94u allows remote attackers to inject arbitrary web script or HTML via (1) the phid parameter or (2) unknown parameters when posting a new comment.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://secwatch.org/advisories/secwatch/20050530_yapig.txt">http://secwatch.org/advisories/secwatch/20050530_yapig.txt</ref><ref source="BID" url="http://www.securityfocus.com/bid/13875">13875</ref><ref source="BID" url="http://www.securityfocus.com/bid/13876">13876</ref><ref source="OSVDB" url="http://www.osvdb.org/17118">17118</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/15600/">15600</ref><ref adv="1" source="SECTRACK" url="http://securitytracker.com/id?1014103">1014103</ref></refs><vuln_soft><prod name="YaPiG" vendor="YaPiG"><vers num="0.92b"/><vers num="0.93u"/><vers num="0.94u"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1887" published="2005-06-09" seq="2005-1887" severity="Medium" type="CVE"><desc><descript source="cve">Unknown vulnerability in the Sun Solaris C library (libc and libproject) in Solaris 10 allows local users to gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><other/></vuln_types><range><local/></range><refs><ref adv="1" source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101740-1">101740</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/0690">ADV-2005-0690</ref><ref source="OSVDB" url="http://www.osvdb.org/17099">17099</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15613">15613</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20874">solaris-clibrary-libproject-gain-privileges(20874)</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers edition="SPARC" num="10.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1888" published="2005-06-06" seq="2005-1888" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in MediaWiki before 1.4.5 allows remote attackers to inject arbitrary web script via HTML attributes in page templates.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CONFIRM" url="http://sourceforge.net/project/shownotes.php?release_id=332231">http://sourceforge.net/project/shownotes.php?release_id=332231</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/13861">13861</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_19_sr.html">SUSE-SR:2005:019</ref></refs><vuln_soft><prod name="MediaWiki" vendor="MediaWiki"><vers num="stable 2003-11-17"/><vers num="stable 2003-11-07"/><vers num="stable 2003-08-29"/><vers num="1.4 beta5"/><vers num="1.4 beta4"/><vers num="1.4 beta3"/><vers num="1.4 beta2"/><vers num="1.4 beta1"/><vers num="1.3.11"/><vers num="1.3.10"/><vers num="1.3.9"/><vers num="1.3.8"/><vers num="1.3.7"/><vers num="1.3.6"/><vers num="1.3.5"/><vers num="1.3.4"/><vers num="1.3.3"/><vers num="1.3.2"/><vers num="1.3.1"/><vers num="1.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1889" published="2005-06-07" seq="2005-1889" severity="Medium" type="CVE"><desc><descript source="cve">Unknown vulnerability in Sun ONE Application Server 6.5 SP1 Maintenance Update 6 and earlier allows attackers to read files.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101690-1">101690</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/0695">ADV-2005-0695</ref></refs><vuln_soft><prod name="Java System Web Server" vendor="Sun"><vers num="6.1 SP1"/><vers num="6.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1890" published="2005-06-07" seq="2005-1890" severity="Medium" type="CVE"><desc><descript source="cve">Unknown vulnerability in Mortiforo before 0.9.1 allows users to access private forums via unknown attack vectors.</descript></desc><loss_types><conf/></loss_types><range><network/></range><refs><ref adv="1" source="CONFIRM" url="http://sourceforge.net/project/shownotes.php?release_id=332807">http://sourceforge.net/project/shownotes.php?release_id=332807</ref><ref adv="1" patch="1" source="SECTRACK" url="http://securitytracker.com/id?1014120">1014120</ref></refs><vuln_soft><prod name="Mortiforo" vendor="Mortiforo"><vers num="0.9.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1891" published="2005-06-09" seq="2005-1891" severity="Medium" type="CVE"><desc><descript source="cve">The GIF parser in ateimg32.dll in AOL Instant Messenger (AIM) 5.9.3797 and earlier allows remote attackers to cause a denial of service (crash) via a malformed buddy icon that causes an integer underflow in a loop counter variable.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111816939928640&amp;w=2">20050607 AOL AIM Instant Messenger Buddy Icon </ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111817881214343&amp;w=2">20050607 Re: AOL AIM Instant Messenger Buddy Icon </ref><ref source="BID" url="http://www.securityfocus.com/bid/13880">13880</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014145">1014145</ref></refs><vuln_soft><prod name="Instant Messenger" vendor="AOL"><vers num="5.9.3797"/><vers num="5.5.3595"/><vers num="5.5.3415 Beta"/><vers num="5.5"/><vers num="5.2.3292"/><vers num="5.1.3036"/><vers num="5.0.2938"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1892" published="2005-06-09" seq="2005-1892" severity="Medium" type="CVE"><desc><descript source="cve">FlatNuke 2.5.3 allows remote attackers to cause a denial of service or obtain sensitive information via (1) a direct request to foot_news.php, which triggers an infinite loop, or (2) direct requests to unknown scripts, which reveals the web document root in an error message.</descript></desc><loss_types><avail/><conf/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="MISC" url="http://secwatch.org/advisories/secwatch/20050604_flatnuke.txt">http://secwatch.org/advisories/secwatch/20050604_flatnuke.txt</ref><ref source="CONFIRM" url="http://flatnuke.sourceforge.net/index.php?mod=read&amp;id=1117979256">http://flatnuke.sourceforge.net/index.php?mod=read&amp;id=1117979256</ref><ref patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/0697">ADV-2005-0697</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15603">15603</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014114">1014114</ref></refs><vuln_soft><prod name="FlatNuke" vendor="FlatNuke"><vers num="2.5.3" prev="1"/><vers num="2.0"/><vers num="1.8"/><vers num="1.7"/><vers num="1.6"/><vers num="1.5"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1893" published="2005-06-09" seq="2005-1893" severity="Medium" type="CVE"><desc><descript source="cve">FlatNuke 2.5.3 allows remote attackers to obtain sensitive information via invalid parameters to certain scripts, which leaks the web document root in an error message.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="MISC" url="http://secwatch.org/advisories/secwatch/20050604_flatnuke.txt">http://secwatch.org/advisories/secwatch/20050604_flatnuke.txt</ref><ref source="CONFIRM" url="http://flatnuke.sourceforge.net/index.php?mod=read&amp;id=1117979256">http://flatnuke.sourceforge.net/index.php?mod=read&amp;id=1117979256</ref><ref patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/0697">ADV-2005-0697</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/15603">15603</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1014114">1014114</ref></refs><vuln_soft><prod name="FlatNuke" vendor="FlatNuke"><vers num="2.5.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1894" published="2005-06-09" seq="2005-1894" severity="High" type="CVE"><desc><descript source="cve">Direct code injection vulnerability in FlatNuke 2.5.3 allows remote attackers to execute arbitrary PHP code by placing the code into the Referer header of an HTTP request, which causes the code to be injected into referer.php, which can then be accessed by the attacker.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1014114">1014114</ref><ref adv="1" patch="1" source="MISC" url="http://secwatch.org/advisories/secwatch/20050604_flatnuke.txt">http://secwatch.org/advisories/secwatch/20050604_flatnuke.txt</ref><ref patch="1" source="CONFIRM" url="http://flatnuke.sourceforge.net/index.php?mod=read&amp;id=1117979256">http://flatnuke.sourceforge.net/index.php?mod=read&amp;id=1117979256</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/0697">ADV-2005-0697</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/15603">15603</ref></refs><vuln_soft><prod name="FlatNuke" vendor="FlatNuke"><vers num="2.5.3"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1895" published="2005-06-09" seq="2005-1895" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in FlatNuke 2.5.3 allows remote attackers to inject arbitrary web script or HTML via the border or back parameters to (1) help.php or (2) footer.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://secwatch.org/advisories/secwatch/20050604_flatnuke.txt">http://secwatch.org/advisories/secwatch/20050604_flatnuke.txt</ref><ref source="CONFIRM" url="http://flatnuke.sourceforge.net/index.php?mod=read&amp;id=1117979256">http://flatnuke.sourceforge.net/index.php?mod=read&amp;id=1117979256</ref><ref patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/0697">ADV-2005-0697</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/15603">15603</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1014114">1014114</ref></refs><vuln_soft><prod name="FlatNuke" vendor="FlatNuke"><vers num="2.5.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1896" published="2005-06-09" seq="2005-1896" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in thumb.php in FlatNuke 2.5.3 allows remote attackers to read arbitrary images or obtain the installation path via the image parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="MISC" url="http://secwatch.org/advisories/secwatch/20050604_flatnuke.txt">http://secwatch.org/advisories/secwatch/20050604_flatnuke.txt</ref><ref patch="1" source="CONFIRM" url="http://flatnuke.sourceforge.net/index.php?mod=read&amp;id=1117979256">http://flatnuke.sourceforge.net/index.php?mod=read&amp;id=1117979256</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/0697">ADV-2005-0697</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/15603">15603</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1014114">1014114</ref></refs><vuln_soft><prod name="FlatNuke" vendor="FlatNuke"><vers num="2.5.3"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1897" published="2005-06-09" seq="2005-1897" severity="High" type="CVE"><desc><descript source="cve">Unknown vulnerability in FlexCast Audio Video Streaming Server before 2.0 has unknown impact and attack vectors.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref source="SECUNIA" url="http://secunia.com/advisories/15441">15441</ref></refs><vuln_soft><prod name="FlexCast Audio Video Streaming Server" vendor="FlexCast"><vers num="0.51"/><vers num="0.5"/><vers num="0.4"/><vers num="0.3"/><vers num="0.2"/><vers num="0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1898" published="2005-06-09" seq="2005-1898" severity="Medium" type="CVE"><desc><descript source="cve">The passthrough functionality in phpThumb.php in phpThumb() before 1.5.4 allows remote attackers to read files that are not images.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="CONFIRM" url="http://sourceforge.net/project/shownotes.php?release_id=330469">http://sourceforge.net/project/shownotes.php?release_id=330469</ref><ref source="BID" url="http://www.securityfocus.com/bid/13842">13842</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/15534">15534</ref></refs><vuln_soft><prod name="phpThumb" vendor="phpThumb"><vers num="1.5.3"/><vers num="1.5.2"/><vers num="1.5.1"/><vers num="1.5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1899" published="2005-06-09" seq="2005-1899" severity="Medium" type="CVE"><desc><descript source="cve">Rakkarsoft RakNet network library 2.33 and earlier, when released before 30 May 2005, and as used in multiple products including nFusion Elite Warriors: Vietnam, allows remote attackers to cause a denial of service (infinite loop) via a zero-byte UDP packet.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref source="Luigi Auriemma" url="http://aluigi.altervista.org/adv/rakzero-adv.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/13862">13862</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014111">1014111</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15597">15597</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111809312423958&amp;w=2">20050605 Server termination in Raknet 2.33 (before 30 May 2005)</ref></refs><vuln_soft><prod name="Raknet" vendor="Rakkarsoft"><vers num="2.33" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1900" published="2005-06-09" seq="2005-1900" severity="High" type="CVE"><desc><descript source="cve">Sawmill before 7.1.6 allows remote attackers to bypass authentication and (1) gain administrative privileges or (2) add a license.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref source="CONFIRM" url="http://www.sawmill.net/version_history7.html">http://www.sawmill.net/version_history7.html</ref><ref source="OSVDB" url="http://www.osvdb.org/17100">17100</ref><ref source="OSVDB" url="http://www.osvdb.org/17101">17101</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/15499">15499</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20879">sawmill-unknown-gain-access(20879)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20880">sawmill-unknown-add-license(20880)</ref><ref source="MISC" url="http://www.networksecurity.fi/advisories/sawmill-admin.html">http://www.networksecurity.fi/advisories/sawmill-admin.html</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014106">1014106</ref></refs><vuln_soft><prod name="Sawmill" vendor="Sawmill"><vers num="7.1.5"/><vers num="7.1.4"/><vers num="7.1.3"/><vers num="7.1.2"/><vers num="7.1.1b"/><vers num="7.1.1"/><vers num="7.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1901" published="2005-06-09" seq="2005-1901" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Sawmill before 7.1.6 allow remote attackers to inject arbitrary web script or HTML via (1) the username in the Add User window or (2) the license key in the Licensing page.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="CONFIRM" url="http://www.sawmill.net/version_history7.html">http://www.sawmill.net/version_history7.html</ref><ref source="OSVDB" url="http://www.osvdb.org/17102">17102</ref><ref source="OSVDB" url="http://www.osvdb.org/17103">17103</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/15499">15499</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20881">sawmill-add-user-xss(20881)</ref><ref source="MISC" url="http://www.networksecurity.fi/advisories/sawmill-admin.html">http://www.networksecurity.fi/advisories/sawmill-admin.html</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014106">1014106</ref></refs><vuln_soft><prod name="Sawmill" vendor="Sawmill"><vers num="7.1.5"/><vers num="7.1.4"/><vers num="7.1.3"/><vers num="7.1.2"/><vers num="7.1.1b"/><vers num="7.1.1"/><vers num="7.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="3.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="4.9" CVSS_score="3.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1902" published="2005-06-09" seq="2005-1902" severity="Low" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in the IMAP service for SPA-PRO Mail @Solomon 4.00 allows remote authenticated users to read other users&apos; mail and perform operations on arbitrary directories via .. sequences in the (1) SELECT, (2) CREATE, (3) DELETE, and (4) RENAME commands.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="MISC" url="http://www.security.org.sg/vuln/spa-promail4.html">http://www.security.org.sg/vuln/spa-promail4.html</ref><ref patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/0680">ADV-2005-0680</ref><ref source="OSVDB" url="http://www.osvdb.org/16989">16989</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/15573">15573</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/20860">spa-pro-imap-diectory-traversal(20860)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014095">1014095</ref></refs><vuln_soft><prod name="SPA-PRO Mail @Solomon" vendor="E-POST Corporation"><vers num="4.00"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1903" published="2005-06-02" seq="2005-1903" severity="Low" type="CVE"><desc><descript source="cve">Buffer overflow in the IMAP service for SPA-PRO Mail @Solomon 4.00 allows remote authenticated users to execute arbitrary code via a long CREATE command.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="MISC" url="http://www.security.org.sg/vuln/spa-promail4.html">http://www.security.org.sg/vuln/spa-promail4.html</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/0680">ADV-2005-0680</ref><ref adv="1" patch="1" source="OSVDB" url="http://www.osvdb.org/16990">16990</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/15573">15573</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/20862">spa-pro-create-bo(20862)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014095">1014095</ref></refs><vuln_soft><prod name="SPA-PRO Mail @Solomon" vendor="E-POST Corporation"><vers num="4.00"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1904" published="2005-06-09" seq="2005-1904" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in login.asp in JiRo&apos;s Upload System (JUS) 1 allows remote attackers to execute arbitrary SQL commands via the password parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://www.under9round.com/jus.txt">http://www.under9round.com/jus.txt</ref><ref source="OSVDB" url="http://www.osvdb.org/16969">16969</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15564">15564</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014086">1014086</ref></refs><vuln_soft><prod name="JiRO Upload System" vendor="JiRO"><vers num="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-08-16" name="CVE-2005-1905" published="2005-06-09" seq="2005-1905" severity="High" type="CVE"><desc><descript source="cve">The klif.sys driver in Kaspersky Labs Anti-Virus 5.0.227, 5.0.228, and 5.0.335 on Windows 2000 allows local users to gain privileges by modifying certain critical code addresses that are later accessed by privileged programs.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><exception/></vuln_types><range><local/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111817777430401&amp;w=2">20050607 Kaspersky AntiVirus </ref><ref source="BID" url="http://www.securityfocus.com/bid/13878">13878</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111817777430401&amp;w=2">20050607 Kaspersky AntiVirus &apos;klif.sys&apos; Privilege Escalation Vulnerability</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111817777430401&amp;w=2">20050607 Kaspersky AntiVirus &apos;klif.sys&apos; Privilege Escalation Vulnerability</ref></refs><vuln_soft><prod name="Kaspersky Anti-Virus Personal" vendor="Kaspersky Lab"><vers num="5.0.227"/><vers num="5.0.325"/><vers num="5.0.228"/></prod><prod name="Kaspersky Anti-Virus" vendor="Kaspersky Lab"><vers edition="Windows File Servers" num="5.0.335"/><vers edition="Windows File Servers" num="5.0.228"/><vers edition="Windows File Servers" num="5.0.227"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1906" published="2005-06-02" seq="2005-1906" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in login.asp in livingmailing 1.3 allows remote attackers to execute arbitrary SQL commands via the password. NOTE: there is little public information about this product and its vendor, and the original researcher announcement is no longer available.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/0678">ADV-2005-0678</ref><ref adv="1" source="SECTRACK" url="http://securitytracker.com/id?1014087">1014087</ref></refs><vuln_soft><prod name="livingmailing" vendor="livingmailing"><vers num="1.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1907" published="2005-05-31" seq="2005-1907" severity="Medium" type="CVE"><desc><descript source="cve">The ISA Firewall service in Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to cause a denial of service (Wspsrv.exe crash) via a large amount of SecureNAT network traffic.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;894864">894864</ref><ref source="MISC" url="http://www.networksecurity.fi/advisories/windows-isa-firewall.html">http://www.networksecurity.fi/advisories/windows-isa-firewall.html</ref><ref source="MISC" url="http://www.niscc.gov.uk/niscc/docs/br-20050602-00456.html?lang=en">http://www.niscc.gov.uk/niscc/docs/br-20050602-00456.html?lang=en</ref><ref source="BID" url="http://www.securityfocus.com/bid/13846">13846</ref><ref source="OSVDB" url="http://www.osvdb.org/17031">17031</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014113">1014113</ref></refs><vuln_soft><prod name="ISA Server" vendor="Microsoft"><vers num="2000"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1908" published="2005-06-09" seq="2005-1908" severity="High" type="CVE"><desc><descript source="cve">Perception LiteWeb allows remote attackers to bypass access controls for files via an extra leading / (slash) or leading \ (backslash) in the URL.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/><input/></vuln_types><range><network/></range><refs><ref source="OSVDB" url="http://www.osvdb.org/17084">17084</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014096">1014096</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15592">15592</ref></refs><vuln_soft><prod name="LiteWeb" vendor="Perception"><vers num="2.5"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-04-07" name="CVE-2005-1909" published="2005-06-09" seq="2005-1909" severity="Medium" type="CVE"><desc><descript source="cve">The web server control panel in 602LAN SUITE 2004 allows remote attackers to make it more difficult for the administrator to read portions of log files via a &quot;&lt;/pre&gt;&lt;!-&quot; sequence in an HTTP GET request in the logon, possibly due to a cross-site scripting (XSS) vulnerability.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MISC" url="http://rgod.altervista.org/602_en.html">http://rgod.altervista.org/602_en.html</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014105">1014105</ref></refs><vuln_soft><prod name="602LAN Suite" vendor="Software602"><vers num="2004"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1910" published="2005-06-05" seq="2005-1910" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in login.asp for WWWeb Concepts Events System 1.0 allows remote attackers to execute arbitrary SQL commands via the password.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://www.under9round.com/wecs.txt">http://www.under9round.com/wecs.txt</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014104">1014104</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15595">15595</ref></refs><vuln_soft><prod name="Events System" vendor="WWWeb Concepts"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1911" published="2005-06-09" seq="2005-1911" severity="Medium" type="CVE"><desc><descript source="cve">The fetchnews NNTP client in leafnode 1.11.2 and earlier can hang while waiting for input that never arrives, which allows remote NNTP servers to cause a denial of service (news loss).</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="CONFIRM" url="http://leafnode.sourceforge.net/leafnode-SA-2005-02.txt">http://leafnode.sourceforge.net/leafnode-SA-2005-02.txt</ref></refs><vuln_soft><prod name="Leafnode" vendor="Leafnode"><vers num="1.9.53"/><vers num="1.9.52"/><vers num="1.9.48"/><vers num="1.9.47"/><vers num="1.9.46"/><vers num="1.9.45"/><vers num="1.9.44"/><vers num="1.9.43"/><vers num="1.9.42"/><vers num="1.9.41"/><vers num="1.9.40"/><vers num="1.9.39"/><vers num="1.9.38"/><vers num="1.9.37"/><vers num="1.9.36"/><vers num="1.9.35"/><vers num="1.9.34"/><vers num="1.9.33"/><vers num="1.9.32"/><vers num="1.9.31"/><vers num="1.9.30"/><vers num="1.9.29"/><vers num="1.9.28"/><vers num="1.9.27"/><vers num="1.9.26"/><vers num="1.9.25"/><vers num="1.9.24"/><vers num="1.9.23"/><vers num="1.9.22"/><vers num="1.9.21"/><vers num="1.9.20"/><vers num="1.9.19"/><vers num="1.11.1"/><vers num="1.10.0"/></prod></vuln_soft></entry><entry modified="2005-10-25" name="CVE-2005-1912" published="2005-07-07" reject="1" seq="2005-1912" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2005-1841.  Reason: This candidate is a duplicate of CVE-2005-1841.  Notes: this duplicate occurred as a result of separate assignments by multiple CNAs, one to the researcher and one to the vendor.  All CVE users should reference CVE-2005-1841 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript></desc><refs/></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1913" published="2005-09-14" seq="2005-1913" severity="Low" type="CVE"><desc><descript source="cve">The Linux kernel 2.6 before 2.6.12.1 allows local users to cause a denial of service (kernel panic) via a non group-leader thread executing a different program than was pending in itimer, which causes the signal to be delivered to the old group-leader task, which does not exist.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><local/></range><refs><ref source="" url="http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.12.1"></ref><ref adv="1" source="UBUNTU" url="http://www.ubuntu.com/usn/usn-178-1">USN-178-1</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/14054">14054</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/15786/">15786</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/21138">kernel-subthread-dos(21138)</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.6.12-rc4"/><vers num="2.6.12-rc1"/><vers num="2.6.11.8"/><vers num="2.6.11.7"/><vers num="2.6.11.6"/><vers num="2.6.11.5"/><vers num="2.6.11.11"/><vers num="2.6.11-rc4"/><vers num="2.6.11-rc3"/><vers num="2.6.11-rc2"/><vers num="2.6.11"/><vers num="2.6.10-rc2"/><vers edition="2.6.20" num="2.6.9"/><vers num="2.6.8-rc3"/><vers num="2.6.8-rc2"/><vers num="2.6.8-rc1"/><vers num="2.6.8"/><vers num="2.6.7 rc1"/><vers num="2.6.7"/><vers num="2.6.6-rc1"/><vers num="2.6.6"/><vers num="2.6.5"/><vers num="2.6.4"/><vers num="2.6.3"/><vers num="2.6.2"/><vers num="2.6.1-rc2"/><vers num="2.6.1-rc1"/><vers num="2.6.1"/><vers num="2.6.10"/><vers num="2.6 test 9 CVS"/><vers num="2.6-test9"/><vers num="2.6-test8"/><vers num="2.6-test7"/><vers num="2.6-test6"/><vers num="2.6-test5"/><vers num="2.6-test4"/><vers num="2.6-test3"/><vers num="2.6-test2"/><vers num="2.6-test11"/><vers num="2.6-test10"/><vers num="2.6-test1"/><vers num="2.6"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1914" published="2005-07-18" seq="2005-1914" severity="Low" type="CVE"><desc><descript source="cve">CenterICQ 4.20.0 and earlier creates temporary files with predictable file names, which allows local users to overwrite arbitrary files via a symlink attack on the gg.token.PID temporary file.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="MISC" url="http://www.zataz.net/adviso/centericq-06152005.txt">http://www.zataz.net/adviso/centericq-06152005.txt</ref><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-754">DSA-754</ref><ref source="BID" url="http://www.securityfocus.com/bid/14144">14144</ref></refs><vuln_soft><prod name="CenterICQ" vendor="CenterICQ"><vers num="4.20"/><vers num="4.14"/><vers num="4.13"/><vers num="4.12"/><vers num="4.9.12"/><vers num="4.9.11"/><vers num="4.9.10"/><vers num="4.9.9"/><vers num="4.9.8"/><vers num="4.9.7"/><vers num="4.9.6"/><vers num="4.9.5"/><vers num="4.9.4"/><vers num="4.9.3"/><vers num="4.9.2"/><vers num="4.9.1"/><vers num="4.9.0"/><vers num="4.8.9"/><vers num="4.8.8"/><vers num="4.8.7"/><vers num="4.8.6"/><vers num="4.8.5"/><vers num="4.8.4"/><vers num="4.8.3"/><vers num="4.8.2"/><vers num="4.8.0"/><vers num="4.7.8"/><vers num="4.7.7"/><vers num="4.7.2"/><vers num="4.7.1"/><vers num="4.6.9"/><vers num="4.6.5"/><vers num="4.6.0"/><vers num="4.5.1"/><vers num="4.20.0.1"/><vers num="4.14.0.1"/><vers num="4.13.0.1"/><vers num="4.12.0.1"/><vers num="4.11.0.1"/><vers num="4.10.0.1"/><vers num="4.9.9.1"/><vers num="4.9.7.1"/><vers num="4.9.6.1"/><vers num="4.9.5.1"/><vers num="4.9.4.1"/><vers num="4.9.3.1"/><vers num="4.9.2.1"/><vers num="4.9.12.1"/><vers num="4.9.11.1"/><vers num="4.9.1.1"/><vers num="4.9.10.1"/><vers num="4.9.0.1"/><vers num="4.8.8.1"/><vers num="4.8.7.1"/><vers num="4.8.6.1"/><vers num="4.8.5.1"/><vers num="4.8.4.1"/><vers num="4.8.3.1"/><vers num="4.8.2.1"/><vers num="4.8.0.1"/><vers num="4.7.8.3"/><vers num="4.7.7.3"/><vers num="4.7.2.3"/><vers num="4.7.1.3"/><vers num="4.6.9.3"/><vers num="4.6.5.3"/><vers num="4.6.0.3"/><vers num="4.5.1.3"/><vers num="4.5.0.3"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1915" published="2005-09-02" seq="2005-1915" severity="Low" type="CVE"><desc><descript source="cve">The log4sh_readProperties function in log4sh 1.2.5 and earlier allows local users to overwrite arbitrary files via a symlink attack on predictable log4sh.$$ filenames.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="" url="http://www.zataz.net/adviso/log4sh-06092005.txt"></ref><ref source="" url="http://bugs.gentoo.org/show_bug.cgi?id=94069"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/14140">14140</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/0957">ADV-2005-0957</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/15899">15899</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-July/034873.html">20050704 log4sh insecure temporary file creation</ref><ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2005-q3/0001.html">20050705 log4sh insecure temporary file creation</ref></refs><vuln_soft><prod name="Log4sh" vendor="Log4sh"><vers num="1.2.5"/><vers num="1.2.4"/><vers num="1.2.3"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1916" published="2005-07-06" seq="2005-1916" severity="Low" type="CVE"><desc><descript source="cve">linki.py in ekg 2005-06-05 and earlier allows local users to overwrite or create arbitrary files via a symlink attack on temporary files.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112060146011122&amp;w=2">20050705 ekg insecure temporary file creation and arbitrary code execution</ref><ref adv="1" source="MISC" url="http://www.zataz.net/adviso/ekg-06062005.txt">http://www.zataz.net/adviso/ekg-06062005.txt</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-760">DSA-760</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112198499417250&amp;w=2">20050721 Multiple vulnerabilities in libgadu and ekg package</ref></refs><vuln_soft><prod name="ekg" vendor="ekg"><vers num="2005-06-05"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1917" published="2005-07-05" seq="2005-1917" severity="Low" type="CVE"><desc><descript source="cve">kpopper 1.0 and earlier allows local users to create and overwrite arbitrary files via a symlink attack on the .popper-new temporary file.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" source="MISC" url="http://www.zataz.net/adviso/kpopper-06152005.txt">http://www.zataz.net/adviso/kpopper-06152005.txt</ref></refs><vuln_soft><prod name="kpopper" vendor="kpopper"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-08-28" name="CVE-2005-1918" published="2005-12-31" seq="2005-1918" severity="Low" type="CVE"><desc><descript source="cve">The original patch for a GNU tar directory traversal vulnerability (CVE-2002-0399) in Red Hat Enterprise Linux 3 and 2.1 uses an &quot;incorrect optimization&quot; that allows user-assisted attackers to overwrite arbitrary files via a crafted tar file, probably involving &quot;/../&quot; sequences with a leading &quot;/&quot;.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0195.html">RHSA-2006:0195</ref><ref source="" url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=140589"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/5834">5834</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015655">1015655</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18988">18988</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20060301-01.U.asc">20060301-01-U</ref><ref adv="1" source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_05_sr.html">SUSE-SR:2006:005</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19130">19130</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19183">19183</ref><ref adv="1" patch="1" source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/430297/100/0/threaded">FLSA:183571-1</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-110.htm"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/20397">20397</ref></refs><vuln_soft><prod name="Desktop" vendor="Red Hat"><vers num="3.0"/></prod><prod name="Enterprise Linux WS" vendor="Red Hat"><vers edition="Workstation" num="3.0"/><vers edition="Workstation" num="2.1"/><vers edition="Workstation" num="2.1"/></prod><prod name="Enterprise Linux ES" vendor="Red Hat"><vers edition="Enterprise Server" num="3.0"/><vers edition="Enterprise Server" num="2.1"/><vers edition="Enterprise Server" num="2.1"/></prod><prod name="Advanced Workstation" vendor="Red Hat"><vers edition="IA64" num="2.1"/><vers edition="Itanium" num="2.1"/></prod><prod name="Tar" vendor="Gnu"><vers num="1.13.25"/></prod><prod name="Enterprise Linux AS" vendor="Red Hat"><vers edition="Advanced Servers" num="3.0"/><vers edition="Advanced Server" num="2.1"/><vers edition="Advanced Server" num="2.1"/></prod></vuln_soft></entry><entry modified="2006-02-28" name="CVE-2005-1919" published="2005-12-31" reject="1" seq="2005-1919" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: none.  Reason: This candidate was withdrawn by its CNA.  Further investigation showed that it was not a security issue.  Notes: none.</descript></desc><refs/></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1920" published="2005-07-26" seq="2005-1920" severity="Medium" type="CVE"><desc><descript source="cve">The (1) Kate and (2) Kwrite applications in KDE KDE 3.2.x through 3.4.0 do not properly set the same permissions on the backup file as were set on the original file, which could allow local users and possibly remote attackers to obtain sensitive information.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112171434023679&amp;w=2">20050718 [KDE Security Advisory]: Kate backup file permission leak</ref><ref adv="1" patch="1" source="" url="http://www.kde.org/info/security/advisory-20050718-1.txt">http://www.kde.org/info/security/advisory-20050718-1.txt</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-804">DSA-804</ref><ref source="BID" url="http://www.securityfocus.com/bid/14297">14297</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014512">1014512</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16099">16099</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-612.html">RHSA-2005:612</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/427976/100/0/threaded">FLSA:178606</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_18_sr.html">SUSE-SR:2005:018</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200611-21.xml">GLSA-200611-21</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23099">23099</ref></refs><vuln_soft><prod name="KDE" vendor="KDE"><vers num="3.4.0"/><vers num="3.4"/><vers num="3.3.2"/><vers num="3.3.1"/><vers num="3.3"/><vers num="3.2.3"/><vers num="3.2.2"/><vers num="3.2.1"/><vers num="3.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1921" published="2005-07-05" seq="2005-1921" severity="High" type="CVE"><desc><descript source="cve">Eval injection vulnerability in PEAR XML_RPC 1.3.0 and earlier (aka XML-RPC or xmlrpc) and PHPXMLRPC (aka XML-RPC For PHP or php-xmlrpc) 1.1 and earlier, as used in products such as (1) WordPress, (2) Serendipity, (3) Drupal, (4) egroupware, (5) MailWatch, (6) TikiWiki, (7) phpWebSite, (8) Ampache, and others, allows remote attackers to execute arbitrary PHP code via an XML file, which is not properly sanitized before being used in an eval statement.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112008638320145&amp;w=2">20050629 Advisory 02/2005: Remote code execution in Serendipity</ref><ref patch="1" source="MISC" url="http://pear.php.net/package/XML_RPC/download/1.3.1">http://pear.php.net/package/XML_RPC/download/1.3.1</ref><ref adv="1" patch="1" source="MISC" url="http://www.gulftech.org/?node=research&amp;article_id=00087-07012005">http://www.gulftech.org/?node=research&amp;article_id=00087-07012005</ref><ref adv="1" source="MISC" url="http://www.hardened-php.net/advisory-022005.php">http://www.hardened-php.net/advisory-022005.php</ref><ref adv="1" patch="1" source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:109">MDKSA-2005:109</ref><ref source="" url="http://sourceforge.net/project/shownotes.php?release_id=338803">http://sourceforge.net/project/shownotes.php?release_id=338803</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-745">DSA-745</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-747">DSA-747</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200507-01.xml">GLSA-200507-01</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200507-06.xml">GLSA-200507-06</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200507-07.xml">GLSA-200507-07</ref><ref source="" url="http://www.drupal.org/security/drupal-sa-2005-003/advisory.txt">http://www.drupal.org/security/drupal-sa-2005-003/advisory.txt</ref><ref source="" url="http://sourceforge.net/project/showfiles.php?group_id=87163">http://sourceforge.net/project/showfiles.php?group_id=87163</ref><ref source="" url="http://www.ampache.org/announce/3_3_1_2.php">http://www.ampache.org/announce/3_3_1_2.php</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15852">15852</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15872">15872</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15944">15944</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15947">15947</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15957">15957</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16001">16001</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval350.html">OVAL350</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-789">DSA-789</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/419064/100/0/threaded">HPSBTU02083</ref><ref source="BID" url="http://www.securityfocus.com/bid/14088">14088</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015336">1015336</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18003">18003</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15810">15810</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15855">15855</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15861">15861</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15883">15883</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15884">15884</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15895">15895</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15903">15903</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15904">15904</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15916">15916</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15917">15917</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15922">15922</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16339">16339</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16693">16693</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17440">17440</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17674">17674</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/2827">ADV-2005-2827</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-746">DSA-746</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-564.html">RHSA-2005:564</ref><ref source="SUSE" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112605112027335&amp;w=2">SUSE-SA:2005:051</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112015336720867&amp;w=2">20050629 [DRUPAL-SA-2005-003] Drupal 4.6.2 / 4.5.4 fixes critical XML-RPC issue</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_41_php_pear.html">SUSE-SA:2005:041</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_49_php.html">SUSE-SA:2005:049</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_18_sr.html">SUSE-SR:2005:018</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:350">oval:org.mitre.oval:def:350</ref></refs><vuln_soft><prod name="XML_RPC" vendor="PEAR"><vers num="1.3.0RC3"/><vers num="1.3.0RC2"/><vers num="1.3.0RC1"/><vers num="1.2.2"/><vers num="1.2.1"/><vers num="1.2.0"/><vers num="1.2.0RC7"/><vers num="1.2.0RC6"/><vers num="1.2.0RC5"/><vers num="1.2.0RC4"/><vers num="1.2.0RC3"/><vers num="1.2.0RC2"/><vers num="1.2.0RC1"/><vers num="1.1.0"/><vers num="1.0.4"/><vers num="1.0.3"/><vers num="1.0.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1922" published="2005-07-05" seq="2005-1922" severity="Medium" type="CVE"><desc><descript source="cve">The MS-Expand file handling in Clam AntiVirus (ClamAV) before 0.86 allows remote attackers to cause a denial of service (file descriptor and memory consumption) via a crafted file that causes repeated errors in the cli_msexpand function.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=276&amp;type=vulnerabilities&amp;flashstatus=true">20050629 Clam AntiVirus ClamAV MS-Expand File Handling DoS Vulnerability</ref><ref patch="1" source="" url="http://sourceforge.net/project/shownotes.php?release_id=336462">http://sourceforge.net/project/shownotes.php?release_id=336462</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-737">DSA-737</ref></refs><vuln_soft><prod name="ClamAV" vendor="Clam Anti-Virus"><vers num="0.85.1"/><vers num="0.85"/><vers num="0.84 rc2"/><vers num="0.84 rc1"/><vers num="0.83"/><vers num="0.82"/><vers num="0.81"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1923" published="2005-07-05" seq="2005-1923" severity="Low" type="CVE"><desc><descript source="cve">The ENSURE_BITS macro in mszipd.c for Clam AntiVirus (ClamAV) 0.83, and other versions vefore 0.86, allows remote attackers to cause a denial of service (CPU consumption by infinite loop) via a cabinet (CAB) file with the cffile_FolderOffset field set to 0xff, which causes a zero-length read.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=275&amp;type=vulnerabilities">20050629 Clam AntiVirus ClamAV Cabinet File Handling DoS Vulnerability</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-737">DSA-737</ref></refs><vuln_soft><prod name="ClamAV" vendor="Clam Anti-Virus"><vers num="0.85.1"/><vers num="0.85"/><vers num="0.84 rc2"/><vers num="0.84 rc1"/><vers num="0.83"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-07-24" name="CVE-2005-1924" published="2005-12-31" seq="2005-1924" severity="High" type="CVE"><desc><descript source="cve">The G/PGP (GPG) Plugin 2.1 and earlier for Squirrelmail allow remote authenticated users to execute arbitrary commands via shell metacharacters in (1) the fpr parameter to the deleteKey function in gpg_keyring.php, as called by (a) import_key_file.php, (b) import_key_text.php, and (c) keyring_main.php; and (2) the keyserver parameter to the gpg_recv_key function in gpg_key_functions.php, as called by gpg_options.php.  NOTE: this issue may overlap CVE-2007-3636.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref source="IDEFENSE" url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=329">20070711 SquirrelMail G/PGP Plugin deleteKey() Command Injection Vulnerability</ref><ref source="IDEFENSE" url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=331">20070711 SquirrelMail G/PGP Plugin gpg_recv_key() Command Injection Vulnerability</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/473370/100/0/threaded">20070711 SquirrelMail G/PGP Encryption Plug-in Remote Command Execution Vulnerability</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/4173">4173</ref><ref source="VIM" url="http://www.attrition.org/pipermail/vim/2007-July/001710.html">20070711 True: SquirrelMail G/PGP Encryption Plug-in 2.0 Command Execution Vuln</ref><ref source="BID" url="http://www.securityfocus.com/bid/24874">24874</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/2513">ADV-2007-2513</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/26035">26035</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200708-08.xml">GLSA-200708-08</ref><ref source="SECUNIA" url="http://secunia.com/advisories/26424">26424</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/35355">squirrelmail-gpgp-keyring-command-execution(35355)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/35364">squirrelmail-gpgp-keyfunc-command-execution(35364)</ref></refs><vuln_soft><prod name="GPG Plugin" vendor="SquirrelMail"><vers num="2.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2005-11-21" name="CVE-2005-1925" published="2005-11-18" seq="2005-1925" severity="Medium" type="CVE"><desc><descript source="cve">Multiple directory traversal vulnerabilities in Tikiwiki before 1.9.1 allow remote attackers to read arbitrary files and execute commands via (1) the suck_url parameter to tiki-editpage.php or (2) language parameter to tiki-user_preferences.php.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=337&amp;type=vulnerabilities">20051110 Tikiwiki tiki-editpage Arbitrary File Exposure Vulnerability</ref><ref adv="1" patch="1" source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=335&amp;type=vulnerabilities">20051110 Tikiwiki tiki-user_preferences Command Injection Vulnerability</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015190">1015190</ref><ref source="BID" url="http://www.securityfocus.com/bid/15390">15390</ref><ref source="BID" url="http://www.securityfocus.com/bid/15392">15392</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/23095">tikiwiki-tikieditpage-directory-traversal(23095)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/23099">tikiwiki-tikiuserpreferences-dir-traversal(23099)</ref></refs><vuln_soft><prod name="Tikiwiki" vendor="Tikiwiki Project"><vers num="1.9"/><vers num="1.8.6"/><vers num="1.8.5"/><vers num="1.8.4"/><vers num="1.8.3"/><vers num="1.8.2"/><vers num="1.8.1"/><vers num="1.8"/><vers num="1.7.1.1"/><vers num="1.7.1"/><vers num="1.7"/><vers num="1.6"/><vers num="1.5"/><vers num="1.4.2"/><vers num="1.4.1"/><vers num="1.4"/><vers num="1.3"/><vers num="1.2"/><vers num="1.1"/><vers num="0.95"/><vers num="0.9"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-06-09" name="CVE-2005-1928" published="2005-12-14" seq="2005-1928" severity="High" type="CVE"><desc><descript source="cve">Trend Micro ServerProtect EarthAgent for Windows Management Console 5.58 and possibly earlier versions, when running with Trend Micro Control Manager 2.5 and 3.0, and Damage Cleanup Server 1.1, allows remote attackers to cause a denial of service (CPU consumption) via a flood of crafted packets with a certain &quot;magic value&quot; to port 5005, which also leads to a memory leak.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><env/></vuln_types><range><network/></range><refs><ref adv="1" source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=356&amp;type=vulnerabilities">20051214 Trend Micro ServerProtect EarthAgent Remote DoS Vulnerability</ref><ref source="" url="http://kb.trendmicro.com/solutions/search/main/search/solutionDetail.asp?solutionID=25254"></ref><ref source="" url="http://solutionfile.trendmicro.com/SolutionFile/25254/en/Hotfix_Readme_SPNT5_58_B1137.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/15868">15868</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/2907">ADV-2005-2907</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015358">1015358</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18038">18038</ref><ref source="OSVDB" url="http://www.osvdb.org/21773">21773</ref><ref source="SREASON" url="http://securityreason.com/securityalert/259">259</ref></refs><vuln_soft><prod name="ServerProtect EarthAgent" vendor="Trend Micro"><vers num="5.58"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-06-09" name="CVE-2005-1929" published="2005-12-14" seq="2005-1929" severity="High" type="CVE"><desc><descript source="cve">Multiple heap-based buffer overflows in (1) isaNVWRequest.dll and (2) relay.dll in Trend Micro ServerProtect Management Console 5.58 and earlier, as used in Control Manager 2.5 and 3.0 and Damage Cleanup Server 1.1, allow remote attackers to execute arbitrary code via &quot;wrapped&quot; length values in Chunked transfer requests.  NOTE: the original report suggests that the relay.dll issue is related to a problem in which a Microsoft Foundation Classes (MFC) static library returns invalid values under heavy load.  As such, this might not be a vulnerability in Trend Micro&apos;s product.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=353&amp;type=vulnerabilities">20051214 Trend Micro ServerProtect isaNVWRequest.dll Chunked Overflow</ref><ref source="BID" url="http://www.securityfocus.com/bid/15865">15865</ref><ref source="BID" url="http://www.securityfocus.com/bid/15866">15866</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-December/039972.html">20051214 Re: iDefense Security Advisory 12.14.05: Trend Micro ServerProtect relay.dll Chunked Overflow Vulnerability</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-December/039978.html">20051214 Re: iDefense Security Advisory 12.14.05: Trend Micro ServerProtect relay.dll Chunked Overflow Vulnerability</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/2907">ADV-2005-2907</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015358">1015358</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18038">18038</ref><ref source="OSVDB" url="http://www.osvdb.org/21771">21771</ref><ref source="OSVDB" url="http://www.osvdb.org/21772">21772</ref><ref source="SREASON" url="http://securityreason.com/securityalert/256">256</ref><ref source="SREASON" url="http://securityreason.com/securityalert/257">257</ref></refs><vuln_soft><prod name="ServerProtect" vendor="Trend Micro"><vers num="5.58" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2005-12-14" name="CVE-2005-1930" published="2005-12-14" seq="2005-1930" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in the Crystal Report component (rptserver.asp) in Trend Micro ServerProtect Management Console 5.58, as used in Control Manager 2.5 and 3.0 and Damage Cleanup Server 1.1, and possibly earlier versions, allows remote attackers to read arbitrary files via the IMAGE parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=352&amp;type=vulnerabilities">20051214 Trend Micro ServerProtect Crystal Reports ReportServer File Disclosure</ref><ref source="BID" url="http://www.securityfocus.com/bid/15867">15867</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/2907">ADV-2005-2907</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015358">1015358</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18038">18038</ref><ref source="OSVDB" url="http://www.osvdb.org/21770">21770</ref><ref source="SREASON" url="http://securityreason.com/securityalert/258">258</ref></refs><vuln_soft><prod name="ServerProtect" vendor="Trend Micro"><vers num="5.58"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1931" published="2005-07-05" seq="2005-1931" severity="Medium" type="CVE"><desc><descript source="cve">GoodTech SMTP Server 5.14 allows remote attackers to cause a denial of service (application crash) via a RCPT TO command with an invalid argument, as demonstrated using an &quot;A&quot; character.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111817606013776&amp;w=2">20050607 Denial of Service vulnerability in GoodTech SMTP Server for Windows NT/2000/XP version 5.14</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/15623">15623</ref></refs><vuln_soft><prod name="GoodTech SMTP Server" vendor="GoodTech Systems"><vers num="5.14"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1932" published="2005-07-05" seq="2005-1932" severity="Low" type="CVE"><desc><descript source="cve">Lpanel 1.59 and earlier, and other versions before 1.597, allows remote authenticated users to modify certain critical variables and (1) modify DNS settings for arbitrary domains via the domain parameter to diagnose.php, (2) close, open, or respond to arbitrary support tickets via the close, open, or pid parameter to view_ticket.php, (3) obtain sensitive information on arbitrary invoices via the inv parameter to viewreceipt.php, or (4) modify domain information for arbitrary domains via the editdomain parameter to domains.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-June/034414.html">20050606 Lpanel.NET&apos;s Lpanel (all versions up to and including 1.59) is vulnerable in that it allows an attacker to close any support ticket within the system.</ref><ref adv="1" source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-June/034415.html">20050606 Lpanel.NET&apos;s Lpanel (all versions up to and including 1.59) is vulnerable in that it allows an attacker to open any support ticket within the system.</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-June/034419.html">20050606 Lpanel.NET&apos;s Lpanel (all versions up to and including 1.59) is vulnerable in that it allows an attacker to reset the DNS information of any domain name managed by the system.</ref><ref adv="1" source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-June/034417.html">20050606 Lpanel.NET&apos;s Lpanel (all versions up to and including 1.59) is vulnerable to the unauthorized viewing of client invoice information.</ref><ref adv="1" source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-June/034416.html">20050606 Lpanel.NET&apos;s Lpanel (all versions up to and including 1.59) is vulnerable to unauthorized domain management access.</ref><ref adv="1" source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-June/034418.html">20050606 Lpanel.NET&apos;s Lpanel (all versions up to and including 1.59) is vulnerable in that it allows an attacker to respond to any support ticket on the system.</ref><ref source="" url="http://www.lpanel.net/changelog.php">http://www.lpanel.net/changelog.php</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/13869">13869</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/15589/">15589</ref></refs><vuln_soft><prod name="LPanel" vendor="LPanel"><vers num="1.596"/><vers num="1.594"/><vers num="1.593"/><vers num="1.59"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-25" name="CVE-2005-1933" published="2005-06-13" seq="2005-1933" severity="High" type="CVE"><desc><descript source="cve">Dashboard in Apple Mac OS X Tiger 10.4 allows attackers to execute arbitrary commands by overriding the behavior of system widgets via a user widget with the same bundle identifier (CFBundleIdentifier), a different vulnerability than CVE-2005-1474.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://www1.cs.columbia.edu/~aaron/files/widgets/">http://www1.cs.columbia.edu/~aaron/files/widgets/</ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/983429">VU#983429</ref></refs><vuln_soft><prod name="Mac OS X" vendor="Apple"><vers num="10.4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1934" published="2005-05-19" seq="2005-1934" severity="Medium" type="CVE"><desc><descript source="cve">Gaim before 1.3.1 allows remote attackers to cause a denial of service (crash) via a malformed MSN message that leads to a memory allocation of a large size, possibly due to an integer signedness error.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="CONFIRM" url="http://sourceforge.net/tracker/index.php?func=detail&amp;aid=1205290&amp;group_id=235&amp;atid=100235">http://sourceforge.net/tracker/index.php?func=detail&amp;aid=1205290&amp;group_id=235&amp;atid=100235</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200506-11.xml">GLSA-200506-11</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:099">MDKSA-2005:099</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-734">DSA-734</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval263.html">OVAL263</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/426078/100/0/threaded">FLSA:158543</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-518.html">RHSA-2005:518</ref><ref source="BID" url="http://www.securityfocus.com/bid/13932">13932</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_36_sudo.html">SUSE-SA:2005:036</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:263">oval:org.mitre.oval:def:263</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:099">MDKSA-2005:099</ref></refs><vuln_soft><prod name="Gaim" vendor="Rob Flynn"><vers num="1.3.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-04-19" name="CVE-2005-1935" published="2005-06-13" seq="2005-1935" severity="High" type="CVE"><desc><descript source="cve">Heap-based buffer overflow in the BERDecBitString function in Microsoft ASN.1 library (MSASN1.DLL) allows remote attackers to execute arbitrary code via nested constructed bit strings, which leads to a realloc of a non-null pointer and causes the function to overwrite previously freed memory, as demonstrated using a SPNEGO token with a constructed bit string during HTTP authentication, and a different vulnerability than CVE-2003-0818.  NOTE: the researcher has claimed that MS:MS04-007 fixes this issue.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="MISC" url="http://www.phreedom.org/solar/exploits/msasn1-bitstring/">http://www.phreedom.org/solar/exploits/msasn1-bitstring/</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/20870">asn1-constructed-heap-overflow(20870)</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num="Workstation 4.0 SP6a"/><vers num="Server 4.0 SP6a"/><vers num="Terminal Server 4.0 SP6"/></prod><prod name="Windows XP" vendor="Microsoft"><vers num="Gold"/><vers edition="Tablet PC" num="SP1"/><vers num="64-bit"/><vers edition="SP1" num="64-bit"/><vers edition="SP1" num="64-bit Version 2003"/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers num="R2"/><vers num="64-bit"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num="SP2"/><vers num="SP3"/><vers edition="FR" num="SP4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1936" published="2005-06-13" seq="2005-1936" severity="High" type="CVE"><desc><descript source="cve">Unknown vulnerability in the web server for the ESS/ Network Controller for Xerox Document Centre 240 through 555 running System Software 27.18.017 and earlier allows attackers to &quot;gain unauthorized access.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CONFIRM" url="http://www.xerox.com/downloads/usa/en/c/cert_XRX05_003.pdf">http://www.xerox.com/downloads/usa/en/c/cert_XRX05_003.pdf</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/12783">12783</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/0255">ADV-2005-0255</ref><ref source="OSVDB" url="http://www.osvdb.org/14659">14659</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14556">14556</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19661">xerox-document-security-bypass(19661)</ref></refs><vuln_soft><prod name="Document Centre" vendor="Xerox"><vers num="555"/><vers num="545"/><vers num="535"/><vers num="490"/><vers num="480"/><vers num="470"/><vers num="460"/><vers num="440"/><vers num="432"/><vers num="430"/><vers num="426"/><vers num="425"/><vers num="420"/><vers num="340"/><vers num="332"/><vers num="265"/><vers num="255"/><vers num="240"/><vers num="230"/><vers num="220"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-25" name="CVE-2005-1937" published="2005-06-14" seq="2005-1937" severity="Low" type="CVE"><desc><descript source="cve">A regression error in Firefox 1.0.3 and Mozilla 1.7.7 allows remote attackers to inject arbitrary Javascript from one page into the frameset of another site, aka the frame injection spoofing vulnerability, a re-introduction of a vulnerability that was originally identified and addressed by CVE-2004-0718.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/><user_init/></range><refs><ref source="Secunia" url="http://secunia.com/advisories/15601/">Mozilla / Mozilla Firefox Frame Injection Vulnerability</ref><ref source="MISC" url="http://secunia.com/multiple_browsers_frame_injection_vulnerability_test/">http://secunia.com/multiple_browsers_frame_injection_vulnerability_test/</ref><ref source="" url="https://bugzilla.mozilla.org/show_bug.cgi?id=296850">https://bugzilla.mozilla.org/show_bug.cgi?id=296850</ref><ref source="" url="http://www.mozilla.org/security/announce/mfsa2005-51.html">http://www.mozilla.org/security/announce/mfsa2005-51.html</ref><ref source="BID" url="http://www.securityfocus.com/bid/14242">14242</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/1075">ADV-2005-1075</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15601">15601</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-777">DSA-777</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-810">DSA-810</ref><ref source="FEDORA" url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=160202">FLSA:160202</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval637.html">OVAL637</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval759.html">OVAL759</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval100007.html">OVAL100007</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-586.html">RHSA-2005:586</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-587.html">RHSA-2005:587</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101952-1">101952</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_45_mozilla.html">SUSE-SA:2005:045</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_18_sr.html">SUSE-SR:2005:018</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:637">oval:org.mitre.oval:def:637</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:759">oval:org.mitre.oval:def:759</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100007">oval:org.mitre.oval:def:100007</ref></refs><vuln_soft><prod name="Mozilla" vendor="Mozilla"><vers num="1.7.7"/></prod><prod name="Firefox" vendor="Mozilla"><vers num="1.0.3"/></prod></vuln_soft></entry><entry modified="2005-10-25" name="CVE-2005-1938" published="2005-06-30" reject="1" seq="2005-1938" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2005-1250.  Reason: This candidate is a duplicate of CVE-2005-1250.  Notes: this duplicate occurred as a result of multiple independent discoveries and insufficient coordination by the vendor and CNA.  All CVE users should reference CVE-2005-1250 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript></desc><refs/></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-17" name="CVE-2005-1939" published="2005-12-31" seq="2005-1939" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in Ipswitch WhatsUp Small Business 2004 allows remote attackers to read arbitrary files via &quot;..&quot; (dot dot) sequences in a request to the Report service (TCP 8022).</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://secunia.com/secunia_research/2005-14/advisory/"></ref><ref adv="1" source="" url="http://cirt.dk/advisories/cirt-40-advisory.pdf"></ref><ref source="BID" url="http://www.securityfocus.com/bid/15291">15291</ref><ref source="BID" url="http://www.securityfocus.com/bid/15500">15500</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/15500">15500</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015141">1015141</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/22969">whatsup-smallbusiness-dotdot-traversal(22969)</ref></refs><vuln_soft><prod name="WhatsUp Small Business" vendor="Ipswitch"><vers num="2004"/></prod></vuln_soft></entry><entry CVSS_base_score="3.7" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="6.4" CVSS_score="3.7" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1941" published="2005-06-08" seq="2005-1941" severity="Low" type="CVE"><desc><descript source="cve">SilverCity before 0.9.5-r1 installs (1) cgi-styler-form.py, (2) cgi-styler.py, and (3) source2html.py with read and write world permissions, which allows local users to execute arbitrary code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><local/><user_init/></range><refs><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200506-05.xml">GLSA-200506-05</ref><ref adv="1" patch="1" source="MISC" url="http://bugs.gentoo.org/show_bug.cgi?id=93558">http://bugs.gentoo.org/show_bug.cgi?id=93558</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014153">1014153</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15632">15632</ref></refs><vuln_soft><prod name="SilverCity" vendor="SilverCity"><vers num="0.9.5 r1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1942" published="2005-06-10" seq="2005-1942" severity="High" type="CVE"><desc><descript source="cve">Cisco switches that support 802.1x security allow remote attackers to bypass port security and gain access to the VLAN via spoofed Cisco Discovery Protocol (CDP) messages.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111842833009771&amp;w=2">20050610 Voice VLAN Access/Abuse Possible on Cisco voice-enabled, 802.1x-secured Interfaces Vulnerability Discovery: FishNet Security</ref><ref adv="1" source="MISC" url="http://www.fishnetsecurity.com/csirt/disclosure/cisco/Cisco+802.1x+Advisory.pdf">http://www.fishnetsecurity.com/csirt/disclosure/cisco/Cisco+802.1x+Advisory.pdf</ref><ref adv="1" source="CISCO" url="http://www.cisco.com/en/US/products/sw/voicesw/ps556/products_security_notice09186a008048e0d6.html">20050608 Cisco 802.1x Voice-Enabled Interfaces Allow Anonymous Voice VLAN Access</ref><ref adv="1" source="SECTRACK" url="http://www.securitytracker.com/alerts/2005/Jun/1014135.html">1014135</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/20939">cisco-callmanager-voice-gain-access(20939)</ref><ref source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-sn-20050608-8021x.shtml">20050608 Cisco 802.1x Voice-Enabled Interfaces Allow Anonymous Voice VLAN Access</ref></refs><vuln_soft><prod name="Catalyst" vendor="Cisco"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1943" published="2005-06-08" seq="2005-1943" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in Loki download manager 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) password field to default.asp or (2) cat parameter to catinfo.asp.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111826992711703&amp;w=2">20050608 2 SQL injection in Loki download manager v2.0</ref><ref source="BID" url="http://www.securityfocus.com/bid/13898">13898</ref><ref source="BID" url="http://www.securityfocus.com/bid/13900">13900</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014147">1014147</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15633">15633</ref></refs><vuln_soft><prod name="Loki Download Manager Catgory Version" vendor="Loki"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1944" published="2005-06-09" seq="2005-1944" severity="Low" type="CVE"><desc><descript source="cve">xmysqladmin 1.0 and earlier allows local users to delete arbitrary files via a symlink attack on a database backup file in /tmp.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111833993822553&amp;w=2">20050609 xmysqladmin insecure temporary file creation</ref><ref source="CONFIRM" url="http://bugs.gentoo.org/show_bug.cgi?id=93792">http://bugs.gentoo.org/show_bug.cgi?id=93792</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15635">15635</ref><ref source="" url="http://www.zataz.net/adviso/xmysqladmin-05292005.txt"></ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014172">1014172</ref></refs><vuln_soft><prod name="xMySQLadmin" vendor="xMySQLadmin"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1945" published="2005-06-09" seq="2005-1945" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in the convert_highlite_words function in Invision Blog before 1.1.2 Final allows remote attackers to inject arbitrary web script or HTML via double hex encoded highlight data.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111833601302752&amp;w=2">20050609 Invision Community Blog Vulnerabilities</ref><ref adv="1" patch="1" source="MISC" url="http://www.gulftech.org/?node=research&amp;article_id=00078-06072005">http://www.gulftech.org/?node=research&amp;article_id=00078-06072005</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15626">15626</ref></refs><vuln_soft><prod name="Invision Community Blog" vendor="Invision Power Services"><vers num="1.1"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1946" published="2005-06-09" seq="2005-1946" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in Invision Blog before 1.1.2 Final allow remote attackers to execute arbitrary SQL commands via the (1) eid parameter to an editentry, replyentry, or editcomment action, or (2) the mid parameter to an aboutme action.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111833601302752&amp;w=2">20050609 Invision Community Blog Vulnerabilities</ref><ref adv="1" patch="1" source="MISC" url="http://www.gulftech.org/?node=research&amp;article_id=00078-06072005">http://www.gulftech.org/?node=research&amp;article_id=00078-06072005</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15626">15626</ref></refs><vuln_soft><prod name="Invision Community Blog" vendor="Invision Power Services"><vers num="1.1"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1947" published="2005-06-09" seq="2005-1947" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site request forgery (CSRF) vulnerability in Invision Gallery before 1.3.1 allows remote attackers to delete albums and images as another user via a link or IMG tag to the (1) albums or (2) delimg actions.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111834146710329&amp;w=2">20050609 Invision Gallery Vulnerabilities</ref><ref adv="1" patch="1" source="MISC" url="http://www.gulftech.org/?node=research&amp;article_id=00079-06092005">http://www.gulftech.org/?node=research&amp;article_id=00079-06092005</ref></refs><vuln_soft><prod name="Invision Gallery" vendor="Invision Power Services"><vers num="1.3"/><vers num="1.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1948" published="2005-06-09" seq="2005-1948" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in Invision Gallery before 1.3.1 allow remote attackers to execute arbitrary SQL commands via (1) the comment parameter in an editcomment action or (2) the rating parameter when voting on a photo.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111834146710329&amp;w=2">20050609 Invision Gallery Vulnerabilities</ref><ref adv="1" patch="1" source="MISC" url="http://www.gulftech.org/?node=research&amp;article_id=00079-06092005">http://www.gulftech.org/?node=research&amp;article_id=00079-06092005</ref><ref source="BID" url="http://www.securityfocus.com/bid/13907">13907</ref></refs><vuln_soft><prod name="Invision Gallery" vendor="Invision Power Services"><vers num="1.3"/><vers num="1.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1949" published="2005-06-16" seq="2005-1949" severity="High" type="CVE"><desc><descript source="cve">The eping_validaddr function in functions.php for the ePing plugin for e107 portal allows remote attackers to execute arbitrary commands via shell metacharacters after a valid argument to the eping_host parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111835539312985&amp;w=2">20050609 Arbitrary code execution in eping plugin</ref><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111868460811287&amp;w=2">20050610 Re: Arbitrary code execution in eping plugin</ref><ref source="" url="http://e107plugins.co.uk/news.php">http://e107plugins.co.uk/news.php</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15678">15678</ref></refs><vuln_soft><prod name="e107" vendor="e107"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1950" published="2005-06-09" seq="2005-1950" severity="High" type="CVE"><desc><descript source="cve">hints.pl in Webhints 1.03 allows remote attackers to execute arbitrary commands via shell metacharacters in the argument.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111842893001406&amp;w=2">20050609 Webhints v1.03 Remote Command Execution</ref><ref source="BID" url="http://www.securityfocus.com/bid/13930">13930</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014173">1014173</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15652">15652</ref></refs><vuln_soft><prod name="Webhints" vendor="Darryl Burgdorf"><vers num="1.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1951" published="2005-06-16" seq="2005-1951" severity="Medium" type="CVE"><desc><descript source="cve">Multiple HTTP Response Splitting vulnerabilities in osCommerce 2.2 Milestone 2 and earlier allow remote attackers to spoof web content and poison web caches via hex-encoded CRLF (&quot;%0d%0a&quot;) sequences in the (1) products_id or (2) pid parameter to index.php or (3) goto parameter to banner.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111842744205117&amp;w=2">20050610 osCommere HTTP Response Splitting</ref><ref source="BID" url="http://www.securityfocus.com/bid/13979">13979</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15670">15670</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111936255011735&amp;w=2">20050616 RE: osCommere HTTP Response Splitting (Solution)</ref></refs><vuln_soft><prod name="osCommerce" vendor="osCommerce"><vers num="2.2 ms2"/><vers num="2.2 ms1"/><vers num="2.2 cvs"/><vers num="2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1952" published="2005-06-16" seq="2005-1952" severity="High" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in Pico Server (pServ) 3.3 allows remote attackers to read arbitrary files and execute arbitrary commands via a /./ (slash dot slash) before each .. (dot dot) sequence in the URL, which results in an incorrect directory depth count.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111852830111316&amp;w=2">20050611 Multiple vulnerabilities in Pico Server (pServ) v3.3</ref><ref patch="1" source="CONFIRM" url="http://sourceforge.net/project/shownotes.php?group_id=59378&amp;release_id=334036">http://sourceforge.net/project/shownotes.php?group_id=59378&amp;release_id=334036</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15663">15663</ref></refs><vuln_soft><prod name="Pico Server" vendor="Pico Server"><vers num="3.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1953" published="2005-06-11" seq="2005-1953" severity="High" type="CVE"><desc><descript source="cve">Heap-based buffer overflow in the CGI extension for Pico Server (pServ) 3.3 allows remote attackers to execute arbitrary code via a long HTTP request.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111852830111316&amp;w=2">20050611 Multiple vulnerabilities in Pico Server (pServ) v3.3</ref><ref adv="1" patch="1" source="CONFIRM" url="http://sourceforge.net/project/shownotes.php?group_id=59378&amp;release_id=334036">http://sourceforge.net/project/shownotes.php?group_id=59378&amp;release_id=334036</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15663">15663</ref></refs><vuln_soft><prod name="Pico Server" vendor="Pico Server"><vers num="3.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1954" published="2005-06-16" seq="2005-1954" severity="Medium" type="CVE"><desc><descript source="cve">singapore 0.9.11 allows remote attackers to obtain sensitive information via a direct request to (1) admin.class.php, (2) any .tpl.php file in templates/admin_default/, or (3) any .tpl.php file in templates/default/, which reveal the path in an error message.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111868634003167&amp;w=2">20050612 singapore v0.9.11 cross site scripting and path disclosure</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014186">1014186</ref></refs><vuln_soft><prod name="singapore" vendor="singapore"><vers num="0.9.11"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1955" published="2005-06-12" seq="2005-1955" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in singapore 0.9.11 allows remote attackers to inject arbitrary web script or HTML via the gallery parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111868634003167&amp;w=2">20050612 singapore v0.9.11 cross site scripting and path disclosure</ref><ref source="BID" url="http://www.securityfocus.com/bid/13938">13938</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014186">1014186</ref></refs><vuln_soft><prod name="singapore" vendor="singapore"><vers num="0.9.11 beta"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1956" published="2005-06-12" seq="2005-1956" severity="Medium" type="CVE"><desc><descript source="cve">File Upload Manager allows remote attackers to upload arbitrary files by modifying the test variable to contain a value of &apos;~~~~~~&apos; (six tildes), which bypasses the file extension checks.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111868578006615&amp;w=2">20050612 File Upload Manager Sploits</ref><ref source="OSVDB" url="http://www.osvdb.org/20257">20257</ref></refs><vuln_soft><prod name="File Upload Manager" vendor="File Upload Manager"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-01-03" name="CVE-2005-1957" published="2005-06-12" seq="2005-1957" severity="High" type="CVE"><desc><descript source="cve">mtnpeak.net File Upload Manager does not properly check user authentication for certain actions, which allows remote attackers to provide a modified base64-encoded file parameter and (1) read arbitrary files via the &quot;view&quot; action or (2) delete arbitrary files via the del action.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111868578006615&amp;w=2">20050612 File Upload Manager Sploits</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111868578006615&amp;w=2">20050612 File Upload Manager Sploits</ref><ref source="OSVDB" url="http://www.osvdb.org/20258">20258</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2005-06/0116.html">20050615 Re: File Upload Manager Sploits</ref><ref source="OSVDB" url="http://www.osvdb.org/17435">17435</ref></refs><vuln_soft><prod name="File Upload Manager" vendor="Adam Mmedici"><vers num=""/></prod></vuln_soft></entry><entry modified="2005-10-25" name="CVE-2005-1958" published="2005-06-07" reject="1" seq="2005-1958" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2005-1855.  Reason: This candidate is a duplicate of CVE-2005-1855.  Notes: All CVE users should reference CVE-2005-1855 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><config/></vuln_types><refs/></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1959" published="2005-06-12" seq="2005-1959" severity="High" type="CVE"><desc><descript source="cve">jammail.pl in jamchen JamMail 1.8 allows remote attackers to execute arbitrary commands via shell metacharacters in the mail parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="SECTRACK" url="http://securitytracker.com/id?1014175">1014175</ref><ref source="BID" url="http://www.securityfocus.com/bid/13937">13937</ref></refs><vuln_soft><prod name="JamMail" vendor="JamMail"><vers num="1.8"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1960" published="2005-06-08" seq="2005-1960" severity="High" type="CVE"><desc><descript source="cve">The getemails function in C.J. Steele Tattle allows remote attackers to execute arbitrary commands via shell metacharacters in certain log entries, as demonstrated using shell metacharacters in an FTP username.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2005-06/0057.html">20050607 remote command execution in &apos;tattle&apos;</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/15582">15582</ref></refs><vuln_soft><prod name="tattle" vendor="C.J. Steele"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1961" published="2005-06-07" seq="2005-1961" severity="Medium" type="CVE"><desc><descript source="cve">Unknown vulnerability in ObjectWeb Consortium C-JDBC before 1.3.1 allows local users to bypass intended access restrictions and obtain the cache results from another user.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="SECTRACK" url="http://securitytracker.com/id?1014118">1014118</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/15627">15627</ref></refs><vuln_soft><prod name="Consortium C-JDBC" vendor="ObjectWeb"><vers num="1.3"/><vers num="1.2.1"/><vers num="1.2"/><vers num="1.1"/><vers num="1.0.4"/><vers num="1.0.3"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1962" published="2005-06-16" seq="2005-1962" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Cerberus Helpdesk 0.97.3 allows remote attackers to inject arbitrary web script or HTML via the (1) errorcode parameter to index.php or (2) certain fields to clients.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MISC" url="http://echo.or.id/adv/adv15-theday-2005.txt">http://echo.or.id/adv/adv15-theday-2005.txt</ref><ref source="CONFIRM" url="http://forum.cerberusweb.com/showthread.php?threadid=5162&amp;goto=newpost">http://forum.cerberusweb.com/showthread.php?threadid=5162&amp;goto=newpost</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014128">1014128</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15641">15641</ref></refs><vuln_soft><prod name="Cerberus Helpdesk" vendor="Cerberus"><vers num="0.97.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1963" published="2005-06-16" seq="2005-1963" severity="Medium" type="CVE"><desc><descript source="cve">Cerberus Helpdesk 0.97.3 allows remote attackers to obtain sensitive information via certain requests to (1) reports.php, (2) knowledgebase.php, or (3) configuration.php, which leaks the information in a PHP error message.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref source="MISC" url="http://echo.or.id/adv/adv15-theday-2005.txt">http://echo.or.id/adv/adv15-theday-2005.txt</ref><ref source="CONFIRM" url="http://forum.cerberusweb.com/showthread.php?threadid=5162&amp;goto=newpost">http://forum.cerberusweb.com/showthread.php?threadid=5162&amp;goto=newpost</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014128">1014128</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15641">15641</ref><ref source="" url="http://www.wgmdev.com/jira/browse/CERB-170"></ref></refs><vuln_soft><prod name="Cerberus Helpdesk" vendor="Cerberus"><vers num="0.97.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-21" name="CVE-2005-1964" published="2005-06-09" seq="2005-1964" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in utilit.php for Ovidentia Portal allows remote attackers to execute arbitrary PHP code via the babInstallPath parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="SECTRACK" url="http://securitytracker.com/id?1014149">1014149</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15658">15658</ref></refs><vuln_soft><prod name="Ovidentia" vendor="Cantico"><vers num="FX"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-01-03" name="CVE-2005-1965" published="2005-06-16" seq="2005-1965" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in siteframe.php for Broadpool Siteframe allows remote attackers to execute arbitrary code via a URL in the LOCAL_PATH parameter.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/13928">13928</ref><ref source="OSVDB" url="http://www.osvdb.org/17246">17246</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014150">1014150</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/15657">15657</ref><ref source="MLIST" url="http://list.broadpool.com/pipermail/siteframe-announce/2005-June/000020.html">[Siteframe-Announce] 20060621 WARNING: Security Vulnerability identified in Siteframe 3.x</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20973">siteframe-localpath-file-include(20973)</ref></refs><vuln_soft><prod name="Siteframe" vendor="Glen Campbell"><vers num="3.2 p5"/><vers num="3.1.9"/><vers num="3.1.8 BETA"/><vers num="3.1.6"/><vers num="3.1.4"/><vers num="3.1.2"/><vers num="3.1.1"/><vers num="3.1"/><vers num="3.0.2"/><vers num="3.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1966" published="2005-06-10" seq="2005-1966" severity="High" type="CVE"><desc><descript source="cve">The eTrace_validaddr function in eTrace plugin for e107 portal allows remote attackers to execute arbitrary commands via shell metacharacters after a valid argument to the etrace_host parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111868460811287&amp;w=2">20050610 Re: Arbitrary code execution in eping plugin</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/13934">13934</ref></refs><vuln_soft><prod name="e107" vendor="e107"><vers num="1.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-25" name="CVE-2005-1967" published="2005-06-16" seq="2005-1967" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in ProductCart Ecommerce before 2.7 allow remote attackers to execute arbitrary SQL commands via the (1) idcategory parameter to viewPrd.asp, (2) lid parameter to editCategories.asp, (3) icd parameter to modCustomCardPaymentOpt.asp, or (4) idccr parameter to OptionFieldsEdit.asp.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MISC" url="http://echo.or.id/adv/adv16-theday-2005.txt">http://echo.or.id/adv/adv16-theday-2005.txt</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014129">1014129</ref></refs><vuln_soft><prod name="ProductCart Ecommerce" vendor="Early Impact"><vers num="2.7" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1968" published="2005-06-08" seq="2005-1968" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in ProductCart Ecommerce before 2.7 allows remote attackers to inject arbitrary web script or HTML via the error parameter to techErr.asp.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://echo.or.id/adv/adv16-theday-2005.txt">http://echo.or.id/adv/adv16-theday-2005.txt</ref><ref adv="1" source="SECTRACK" url="http://securitytracker.com/id?1014129">1014129</ref></refs><vuln_soft><prod name="ProductCart" vendor="Early Impact"><vers num="2.7"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-04-07" name="CVE-2005-1969" published="2005-06-07" seq="2005-1969" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Pragma Systems Telnetserver 6.0 allows remote attackers to inject arbitrary web script or HTML, and hide activities in log files, via a &quot;&lt;!--&quot; (HTML comment) in a session.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://www.rgod.altervista.org/pragma.html">http://www.rgod.altervista.org/pragma.html</ref><ref adv="1" source="SECTRACK" url="http://securitytracker.com/id?1014127">1014127</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15642">15642</ref></refs><vuln_soft><prod name="Pragma TelnetServer" vendor="Pragma Systems"><vers num="6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1970" published="2005-06-16" seq="2005-1970" severity="High" type="CVE"><desc><descript source="cve">Symantec pcAnywhere 10.5x and 11.x before 11.5, with &quot;Launch with Windows&quot; enabled, allows local users with physical access to execute arbitrary commands via the Caller Properties feature.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CONFIRM" url="http://securityresponse.symantec.com/avcenter/security/Content/2005.06.10.html">http://securityresponse.symantec.com/avcenter/security/Content/2005.06.10.html</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/13933">13933</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014178">1014178</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15673">15673</ref></refs><vuln_soft><prod name="pcAnywhere" vendor="Symantec"><vers num="11.0"/><vers num="10.5"/><vers num="10.0"/><vers num="9.2"/><vers num="9.0.1"/><vers num="9.0"/><vers num="8.0.2"/><vers num="8.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1971" published="2005-06-16" seq="2005-1971" severity="High" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in InteractivePHP FusionBB .11 Beta and earlier allows remote attackers to include arbitrary local files via &quot;..&quot; sequences in the language parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MISC" url="http://www.gulftech.org/?node=research&amp;article_id=00081-06132005">http://www.gulftech.org/?node=research&amp;article_id=00081-06132005</ref><ref source="CONFIRM" url="http://www.interactivephp.com/misc/CHANGELOG.html">http://www.interactivephp.com/misc/CHANGELOG.html</ref></refs><vuln_soft><prod name="FusionBB" vendor="InteractivePHP"><vers num="11 Beta"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1972" published="2005-06-13" seq="2005-1972" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in InteractivePHP FusionBB .11 Beta and earlier allow remote attackers to execute arbitrary SQL commands via (1) the username, which is not properly handled by the insertUser function, or (2) the bb_session_id value in a cookie.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="MISC" url="http://www.gulftech.org/?node=research&amp;article_id=00081-06132005">http://www.gulftech.org/?node=research&amp;article_id=00081-06132005</ref><ref adv="1" patch="1" source="CONFIRM" url="http://www.interactivephp.com/misc/CHANGELOG.html">http://www.interactivephp.com/misc/CHANGELOG.html</ref></refs><vuln_soft><prod name="FusionBB" vendor="InteractivePHP"><vers num="11 Beta"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1973" published="2005-06-16" seq="2005-1973" severity="Medium" type="CVE"><desc><descript source="cve">Java Web Start in Java 2 Platform Standard Edition (J2SE) 5.0 and 5.0 Update 1 allows applications to assign permissions to themselves and gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><design/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101748-1">101748</ref><ref source="BID" url="http://www.securityfocus.com/bid/13958">13958</ref><ref source="HP" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112870351003598&amp;w=2">HPSBUX01214</ref><ref source="BID" url="http://www.securityfocus.com/bid/13945">13945</ref><ref source="SREASON" url="http://securityreason.com/securityalert/61">61</ref></refs><vuln_soft><prod name="J2SE" vendor="Sun"><vers edition="SDK" num="5.0"/><vers edition="SDK" num="5.0 Update1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-06-15" name="CVE-2005-1974" published="2005-06-16" seq="2005-1974" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Java 2 Platform, Standard Edition (J2SE) 5.0 and 5.0 Update 1 and J2SE 1.4.2 up to 1.4.2_07, as used in multiple products and platforms including (1) HP-UX and (2) APC PowerChute, allows applications to assign permissions to themselves and gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><other/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101749-1">101749</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/2150">ADV-2005-2150</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17272">17272</ref><ref source="BID" url="http://www.securityfocus.com/bid/13958">13958</ref><ref source="" url="http://nam-en.apc.com/cgi-bin/nam_en.cfg/php/enduser/std_adp.php?p_faqid=7638"></ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015643">1015643</ref><ref source="HP" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112861772130119&amp;w=2">HPSBUX01215</ref><ref source="HP" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112992075412844&amp;w=2">HPSBMA01234</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101799-1">101799</ref><ref source="" url="http://rpmfind.net/linux/RPM/suse/updates/9.3/i386/rpm/i586/java-1_4_2-sun-src-1.4.2.08-0.1.i586.html"></ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_32_java2.html">SUSE-SA:2005:032</ref><ref source="SREASON" url="http://securityreason.com/securityalert/56">56</ref></refs><vuln_soft><prod name="J2SE" vendor="Sun"><vers edition="SDK" num="5.0"/><vers edition="SDK" num="5.0 Update1"/><vers edition="SDK" num="1.4.2_07"/><vers edition="SDK" num="1.4.2_06"/><vers edition="SDK" num="1.4.2_05"/><vers edition="SDK" num="1.4.2_04"/><vers edition="SDK" num="1.4.2_03"/><vers edition="SDK" num="1.4.2_02"/><vers edition="SDK" num="1.4.2_01"/><vers edition="SDK" num="1.4.2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1975" published="2005-06-16" seq="2005-1975" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Annuaire 1Two 1.1 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the id parameter to index.php, or the (2) site_id, (3) nom, (4) email, or (5) commentaire parameters in commentaires.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="SECTRACK" url="http://securitytracker.com/id?1014187">1014187</ref><ref source="MISC" url="http://www.hackisknowledge.org/Advisories/Annuaire%201Two%20v1.0/Annuaire%201Two%20v1.0.html">http://www.hackisknowledge.org/Advisories/Annuaire%201Two%20v1.0/Annuaire%201Two%20v1.0.html</ref><ref source="BID" url="http://www.securityfocus.com/bid/13960">13960</ref><ref source="BID" url="http://www.securityfocus.com/bid/13612">13612</ref><ref source="BID" url="http://www.securityfocus.com/bid/13961">13961</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15708">15708</ref></refs><vuln_soft><prod name="1Two" vendor="Annuaire"><vers num="1.1" prev="1"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="1.7" CVSS_exploit_subscore="3.1" CVSS_impact_subscore="2.9" CVSS_score="1.7" CVSS_vector="(AV:L/AC:L/Au:S/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2005-06-21" modified="2006-06-06" name="CVE-2005-1976" published="2005-12-31" seq="2005-1976" severity="Low" type="CVE"><desc><descript source="cve">Novell NetMail 3.5.2a, 3.5.2b, and 3.5.2c, when running on Linux, sets the owner and group ID to 500 for certain files, which could allow users or groups with that ID to execute arbitrary code or cause a denial of service by modifying those files.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref patch="1" source="" url="http://support.novell.com/cgi-bin/search/searchtid.cgi?/10098022.htm"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/14005">14005</ref><ref patch="1" source="OSVDB" url="http://www.osvdb.org/17456">17456</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014251">1014251</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/15763">15763</ref></refs><vuln_soft><prod name="NetMail" vendor="Novell"><vers edition="a" num="3.5.2"/><vers edition="b" num="3.5.2"/><vers edition="c" num="3.5.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1978" published="2005-10-12" seq="2005-1978" severity="High" type="CVE"><desc><descript source="cve">COM+ in Microsoft Windows does not properly &quot;create and use memory structures,&quot; which allows local users or remote attackers to execute arbitrary code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="MS" url="http://www.microsoft.com/technet/security/Bulletin/MS05-051.mspx">MS05-051</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA05-284A.html">TA05-284A</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/950516">VU#950516</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1261.html">OVAL1261</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1269.html">OVAL1269</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1466.html">OVAL1466</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1499.html">OVAL1499</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval576.html">OVAL576</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval816.html">OVAL816</ref><ref source="BID" url="http://www.securityfocus.com/bid/15057">15057</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17161">17161</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2005-214.pdf"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/17172">17172</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17223">17223</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17509">17509</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1261">oval:org.mitre.oval:def:1261</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1269">oval:org.mitre.oval:def:1269</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1466">oval:org.mitre.oval:def:1466</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1499">oval:org.mitre.oval:def:1499</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:576">oval:org.mitre.oval:def:576</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:816">oval:org.mitre.oval:def:816</ref></refs><vuln_soft><prod name="Windows XP" vendor="Microsoft"><vers edition="Tablet PC" num="SP1"/><vers edition="Tablet PC" num="SP2"/><vers edition="64-bit" num="Professional"/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers num="R2"/><vers num="SP1"/><vers num="Itanium"/><vers edition="Itanium" num="SP1"/><vers num="64-bit"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers edition="FR" num="SP4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1979" published="2005-10-12" seq="2005-1979" severity="Medium" type="CVE"><desc><descript source="cve">Distributed Transaction Controller in Microsoft Windows allows remote servers to cause a denial of service (MSDTC service exception and exit) via an &quot;unexpected protocol command during the reconnection request,&quot; which is not properly handled by the Transaction Internet Protocol (TIP) functionality.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=320&amp;type=vulnerabilities">20051011 Microsoft Distributed Transaction Controller TIP DoS Vulnerability</ref><ref adv="1" patch="1" source="MS" url="http://www.microsoft.com/technet/security/Bulletin/MS05-051.mspx">MS05-051</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1134.html">OVAL1134</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1283.html">OVAL1283</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1338.html">OVAL1338</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1513.html">OVAL1513</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1550.html">OVAL1550</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval686.html">OVAL686</ref><ref source="BID" url="http://www.securityfocus.com/bid/15058">15058</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015037">1015037</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17161">17161</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2005-214.pdf"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/17172">17172</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17223">17223</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17509">17509</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1134">oval:org.mitre.oval:def:1134</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1283">oval:org.mitre.oval:def:1283</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1338">oval:org.mitre.oval:def:1338</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1513">oval:org.mitre.oval:def:1513</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1550">oval:org.mitre.oval:def:1550</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:686">oval:org.mitre.oval:def:686</ref></refs><vuln_soft><prod name="Windows XP" vendor="Microsoft"><vers edition="Tablet PC" num="SP1"/><vers edition="Tablet PC" num="SP2"/><vers edition="64-bit" num="Professional"/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers num="R2"/><vers num="SP1"/><vers num="Itanium"/><vers edition="Itanium" num="SP1"/><vers num="64-bit"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers edition="FR" num="SP4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1980" published="2005-10-12" seq="2005-1980" severity="Medium" type="CVE"><desc><descript source="cve">Distributed Transaction Controller in Microsoft Windows allows remote servers to cause a denial of service (MSDTC service hang) via a crafted Transaction Internet Protocol (TIP) message that causes DTC to repeatedly connect to a target IP and port number after an error occurs, aka the &quot;Distributed TIP Vulnerability.&quot;</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=319&amp;type=vulnerabilities">20051011 Microsoft Distributed Transaction Controller Packet Relay DoS Vulnerability</ref><ref adv="1" patch="1" source="MS" url="http://www.microsoft.com/technet/security/Bulletin/MS05-051.mspx">MS05-051</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1136.html">OVAL1136</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1182.html">OVAL1182</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1203.html">OVAL1203</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1253.html">OVAL1253</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1325.html">OVAL1325</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1413.html">OVAL1413</ref><ref source="BID" url="http://www.securityfocus.com/bid/15059">15059</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015037">1015037</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17161">17161</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2005-214.pdf"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/17172">17172</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17223">17223</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17509">17509</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1136">oval:org.mitre.oval:def:1136</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1182">oval:org.mitre.oval:def:1182</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1203">oval:org.mitre.oval:def:1203</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1253">oval:org.mitre.oval:def:1253</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1325">oval:org.mitre.oval:def:1325</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1413">oval:org.mitre.oval:def:1413</ref></refs><vuln_soft><prod name="Windows XP" vendor="Microsoft"><vers edition="Tablet PC" num="SP1"/><vers edition="Tablet PC" num="SP2"/><vers edition="64-bit" num="Professional"/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers num="R2"/><vers num="SP1"/><vers num="Itanium"/><vers edition="Itanium" num="SP1"/><vers num="64-bit"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers edition="FR" num="SP4"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1981" published="2005-08-10" seq="2005-1981" severity="Low" type="CVE"><desc><descript source="cve">Unknown vulnerability in Microsoft Windows 2000 Server and Windows Server 2003 domain controllers allows remote authenticated users to cause a denial of service (system crash) via a crafted Kerberos message.</descript></desc><loss_types><avail/></loss_types><range><local/></range><refs><ref patch="1" source="MS" url="http://www.microsoft.com/technet/Security/bulletin/ms05-042.mspx">MS05-042</ref><ref patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA05-221A.html">TA05-221A</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/16368/">16368</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval100095.html">OVAL100095</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval100097.html">OVAL100097</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval100099.html">OVAL100099</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval100101.html">OVAL100101</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval100103.html">OVAL100103</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval100105.html">OVAL100105</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/610133">VU#610133</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014642">1014642</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100095">oval:org.mitre.oval:def:100095</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100097">oval:org.mitre.oval:def:100097</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100099">oval:org.mitre.oval:def:100099</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100101">oval:org.mitre.oval:def:100101</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100103">oval:org.mitre.oval:def:100103</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100105">oval:org.mitre.oval:def:100105</ref></refs><vuln_soft><prod name="Windows Server 2003" vendor="Microsoft"><vers num=""/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num="Server"/></prod></vuln_soft></entry><entry CVSS_base_score="3.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="4.9" CVSS_score="3.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-06-14" name="CVE-2005-1982" published="2005-08-10" seq="2005-1982" severity="Low" type="CVE"><desc><descript source="cve">Unknown vulnerability in the PKINIT Protocol for Microsoft Windows 2000, Windows XP, and Windows Server 2003 could allow a local user to obtain information and spoof a server via a man-in-the-middle (MITM) attack between a client and a domain controller when PKINIT smart card authentication is being used.</descript></desc><loss_types><conf/><int/></loss_types><range><local/></range><refs><ref patch="1" source="MS" url="http://www.microsoft.com/technet/Security/bulletin/ms05-042.mspx">MS05-042</ref><ref patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA05-221A.html">TA05-221A</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/16368/">16368</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval100096.html">OVAL100096</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval100098.html">OVAL100098</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval100100.html">OVAL100100</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval100102.html">OVAL100102</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval100104.html">OVAL100104</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval100106.html">OVAL100106</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/477341">VU#477341</ref><ref source="BID" url="http://www.securityfocus.com/bid/14520">14520</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014642">1014642</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100096">oval:org.mitre.oval:def:100096</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100098">oval:org.mitre.oval:def:100098</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100100">oval:org.mitre.oval:def:100100</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100102">oval:org.mitre.oval:def:100102</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100104">oval:org.mitre.oval:def:100104</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100106">oval:org.mitre.oval:def:100106</ref></refs><vuln_soft><prod name="Windows XP" vendor="Microsoft"><vers edition="Gold" num="Professional"/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers edition="64-bit" num="R2"/><vers edition="64-bit" num="Enterprise"/><vers edition="64-bit" num="Standard"/><vers num="Web"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num="Advanced Server"/><vers num="Datacenter Server"/><vers num="Professional"/><vers num="Server"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1983" published="2005-08-10" seq="2005-1983" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in the Plug and Play (PnP) service for Microsoft Windows 2000 and Windows XP Service Pack 1 allows remote attackers to execute arbitrary code via a crafted packet, and local users to gain privileges via a malicious application, as exploited by the Zotob (aka Mytob) worm.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref patch="1" source="MS" url="http://www.microsoft.com/technet/Security/bulletin/ms05-039.mspx">MS05-039</ref><ref patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA05-221A.html">TA05-221A</ref><ref source="ISS" url="http://xforce.iss.net/xforce/alerts/id/202">20050809 Windows Plug and Play Remote Compromise</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/998653">VU#998653</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/p-266.shtml">P-266</ref><ref source="MISC" url="http://www.securiteam.com/windowsntfocus/5YP0E00GKW.html">http://www.securiteam.com/windowsntfocus/5YP0E00GKW.html</ref><ref source="MISC" url="http://www.frsirt.com/english/alerts/20050814.ZotobA.php">http://www.frsirt.com/english/alerts/20050814.ZotobA.php</ref><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2005-08/0384.html">20050811 Windows 2000 universal exploit for MS05-039</ref><ref source="BID" url="http://www.securityfocus.com/bid/14513">14513</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/1354">ADV-2005-1354</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16372">16372</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014640">1014640</ref><ref source="OSVDB" url="http://www.osvdb.org/18605">18605</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/21602">win-plugandplay-bo(21602)</ref><ref source="MISC" url="http://www.hsc.fr/ressources/presentations/null_sessions/">http://www.hsc.fr/ressources/presentations/null_sessions/</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval100073.html">OVAL100073</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100073">oval:org.mitre.oval:def:100073</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:160">oval:org.mitre.oval:def:160</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:267">oval:org.mitre.oval:def:267</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:474">oval:org.mitre.oval:def:474</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:497">oval:org.mitre.oval:def:497</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:783">oval:org.mitre.oval:def:783</ref></refs><vuln_soft><prod name="Windows XP" vendor="Microsoft"><vers edition="Tablet PC" num="SP1"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1984" published="2005-08-10" seq="2005-1984" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the Print Spooler service (Spoolsv.exe) for Microsoft Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code via a malicious message.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref patch="1" source="MS" url="http://www.microsoft.com/technet/Security/bulletin/ms05-043.mspx">MS05-043</ref><ref patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA05-221A.html">TA05-221A</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/16356/">16356</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/220821">VU#220821</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval100077.html">OVAL100077</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1045.html">OVAL1045</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1405.html">OVAL1405</ref><ref source="BID" url="http://www.securityfocus.com/bid/14514">14514</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014638">1014638</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100077">oval:org.mitre.oval:def:100077</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1045">oval:org.mitre.oval:def:1045</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1405">oval:org.mitre.oval:def:1405</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:256">oval:org.mitre.oval:def:256</ref></refs><vuln_soft><prod name="Windows XP" vendor="Microsoft"><vers edition="Tablet PC" num="SP1"/><vers edition="Tablet PC" num="SP2"/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers num="R2"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers edition="FR" num="SP4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1985" published="2005-10-13" seq="2005-1985" severity="High" type="CVE"><desc><descript source="cve">The Client Service for NetWare (CSNW) on Microsoft Windows 2000 SP4, XP SP1 and Sp2, and Server 2003 SP1 and earlier, allows remote attackers to execute arbitrary code due to an &quot;unchecked buffer&quot; when processing certain crafted network messages.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms05-046.mspx">MS05-046</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1106.html">OVAL1106</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1210.html">OVAL1210</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1536.html">OVAL1536</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1544.html">OVAL1544</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval910.html">OVAL910</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015041">1015041</ref><ref source="BID" url="http://www.securityfocus.com/bid/15066">15066</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17165">17165</ref><ref source="OSVDB" url="http://www.osvdb.org/19922">19922</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/21700">win-csnw-bo(21700)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1106">oval:org.mitre.oval:def:1106</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1210">oval:org.mitre.oval:def:1210</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1536">oval:org.mitre.oval:def:1536</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1544">oval:org.mitre.oval:def:1544</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:910">oval:org.mitre.oval:def:910</ref></refs><vuln_soft><prod name="Windows XP" vendor="Microsoft"><vers edition="Tablet PC" num="SP1"/><vers edition="Tablet PC" num="SP2"/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers num="R2"/><vers num="SP1"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers edition="FR" num="SP4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-11-30" name="CVE-2005-1987" published="2005-10-13" seq="2005-1987" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Collaboration Data Objects (CDO), as used in Microsoft Windows and Microsoft Exchange Server, allows remote attackers to execute arbitrary code when CDOSYS or CDOEX processes an e-mail message with a large header name, as demonstrated using the &quot;Content-Type&quot; string.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms05-048.mspx">MS05-048</ref><ref adv="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA05-284A.html">TA05-284A</ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/883460">VU#883460</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112915118302012&amp;w=2">20051012 [SEC-1 Advisory] Collaboration Data Objects Buffer Overflow Vulnerability</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1130.html">OVAL1130</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1201.html">OVAL1201</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1406.html">OVAL1406</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1420.html">OVAL1420</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1515.html">OVAL1515</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval581.html">OVAL581</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval848.html">OVAL848</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015038">1015038</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015039">1015039</ref><ref source="BID" url="http://www.securityfocus.com/bid/15067">15067</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17167">17167</ref><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2005-10/0289.html">20051012 [SEC-1 Advisory] Collaboration Data Objects Buffer Overflow Vulnerability</ref><ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q907245">Q907245</ref><ref source="OSVDB" url="http://www.osvdb.org/19905">19905</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/22495">win-cdo-bo(22495)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1130">oval:org.mitre.oval:def:1130</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1201">oval:org.mitre.oval:def:1201</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1406">oval:org.mitre.oval:def:1406</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1420">oval:org.mitre.oval:def:1420</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1515">oval:org.mitre.oval:def:1515</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:581">oval:org.mitre.oval:def:581</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:848">oval:org.mitre.oval:def:848</ref></refs><vuln_soft><prod name="exchange srv" vendor="Microsoft"><vers num="2000 SP3"/></prod><prod name="Windows XP" vendor="Microsoft"><vers edition="Tablet PC" num="SP1"/><vers edition="Tablet PC" num="SP2"/><vers edition="64-bit" num="Professional"/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers num="R2"/><vers num="SP1"/><vers num="Itanium"/><vers edition="Itanium" num="SP1"/><vers num="64-bit"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers edition="FR" num="SP4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1988" published="2005-08-10" seq="2005-1988" severity="Medium" type="CVE"><desc><descript source="cve">Unknown vulnerability in Internet Explorer 5.0, 5.5, and 6.0 allows remote attackers to execute arbitrary code via a web site or an HTML e-mail containing a crafted JPEG image that causes memory corruption, aka &quot;JPEG Image Rendering Memory Corruption Vulnerability&quot;.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><range><network/><user_init/></range><refs><ref patch="1" source="MS" url="http://www.microsoft.com/technet/Security/bulletin/ms05-038.mspx">MS05-038</ref><ref patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA05-221A.html">TA05-221A</ref><ref patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/965206">VU#965206</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/16373/">16373</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/1353">ADV-2005-1353</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1140.html">OVAL1140</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1216.html">OVAL1216</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1335.html">OVAL1335</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval390.html">OVAL390</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1140">oval:org.mitre.oval:def:1140</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1216">oval:org.mitre.oval:def:1216</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1335">oval:org.mitre.oval:def:1335</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:390">oval:org.mitre.oval:def:390</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="5.01"/><vers num="5.5"/><vers edition="Windows Server 2003 SP1" num="6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1989" published="2005-08-10" seq="2005-1989" severity="High" type="CVE"><desc><descript source="cve">Unknown vulnerability in Internet Explorer 5.0, 5.5, and 6.0 allows remote attackers to obtain information and possibly execute code when browsing from a web site to a web folder view using WebDAV, aka &quot;Web Folder Behaviors Cross-Domain Vulnerability&quot;.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><range><network/></range><refs><ref patch="1" source="MS" url="http://www.microsoft.com/technet/Security/bulletin/ms05-038.mspx">MS05-038</ref><ref patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA05-221A.html">TA05-221A</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/16373/">16373</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/1353">ADV-2005-1353</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval100081.html">OVAL100081</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval100082.html">OVAL100082</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1319.html">OVAL1319</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval697.html">OVAL697</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval790.html">OVAL790</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval888.html">OVAL888</ref><ref source="BID" url="http://www.securityfocus.com/bid/14512">14512</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100081">oval:org.mitre.oval:def:100081</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100082">oval:org.mitre.oval:def:100082</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1319">oval:org.mitre.oval:def:1319</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:697">oval:org.mitre.oval:def:697</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:790">oval:org.mitre.oval:def:790</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:888">oval:org.mitre.oval:def:888</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="5.01"/><vers num="5.5"/><vers edition="Windows Server 2003 SP1" num="6"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-25" name="CVE-2005-1990" published="2005-08-10" seq="2005-1990" severity="Medium" type="CVE"><desc><descript source="cve">Internet Explorer 5.0, 5.5, and 6.0 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a web page with embedded CLSIDs that reference certain COM objects that are not ActiveX controls, including (1) devenum.dll, (2) diactfrm.dll, (3) wmm2filt.dll, (4) fsusd.dll, (5) dmdskmgr.dll, (6) browsewm.dll, (7) browseui.dll, (8) shell32.dll, (9) mshtml.dll, (10) inetcfg.dll, (11) infosoft.dll, (12) query.dll, (13) syncui.dll, (14) clbcatex.dll, (15) clbcatq.dll, (16) comsvcs.dll, and (17) msconf.dll, which causes memory corruption, aka &quot;COM Object Instantiation Memory Corruption Vulnerability,&quot; a different vulnerability than CVE-2005-2087.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><exception/></vuln_types><range><network/><user_init/></range><refs><ref patch="1" source="MS" url="http://www.microsoft.com/technet/Security/bulletin/ms05-038.mspx">MS05-038</ref><ref patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA05-221A.html">TA05-221A</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/16373/">16373</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/959049">VU#959049</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/1353">ADV-2005-1353</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1061.html">OVAL1061</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1221.html">OVAL1221</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1235.html">OVAL1235</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1337.html">OVAL1337</ref><ref source="BID" url="http://www.securityfocus.com/bid/14511">14511</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014643">1014643</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1061">oval:org.mitre.oval:def:1061</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1221">oval:org.mitre.oval:def:1221</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1235">oval:org.mitre.oval:def:1235</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1337">oval:org.mitre.oval:def:1337</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100082">oval:org.mitre.oval:def:100082</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="5.01"/><vers num="5.5"/><vers edition="Windows Server 2003 SP1" num="6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1992" published="2005-06-20" seq="2005-1992" severity="High" type="CVE"><desc><descript source="cve">The XMLRPC server in utils.rb for the ruby library (libruby) 1.8 sets an invalid default value that prevents &quot;security protection&quot; using handlers, which allows remote attackers to execute arbitrary commands.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="CONFIRM" url="http://blade.nagaokaut.ac.jp/cgi-bin/scat.rb/ruby/ruby-core/5237">http://blade.nagaokaut.ac.jp/cgi-bin/scat.rb/ruby/ruby-core/5237</ref><ref source="CONFIRM" url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=315064">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=315064</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-748">DSA-748</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/Sep/msg00002.html">APPLE-SA-2005-09-22</ref><ref source="AUSCERT" url="http://www.auscert.org.au/5509">ESB-2005.0732</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/p-312.shtml">P-312</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16920/">16920</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/684913">VU#684913</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-543.html">RHSA-2005:543</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_18_sr.html">SUSE-SR:2005:018</ref></refs><vuln_soft><prod name="Ruby" vendor="Yukihiro Matsumoto"><vers num="1.8"/></prod></vuln_soft></entry><entry CVSS_base_score="3.7" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="6.4" CVSS_score="3.7" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1993" published="2005-06-20" seq="2005-1993" severity="Low" type="CVE"><desc><descript source="cve">Race condition in sudo 1.3.1 up to 1.6.8p8, when the ALL pseudo-command is used after a user entry in the sudoers file, allows local users to gain privileges via a symlink attack.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><race/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/402741">20050620 Sudo version 1.6.8p9 now available, fixes security issue.</ref><ref source="CONFIRM" url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=161116">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=161116</ref><ref source="BID" url="http://www.securityfocus.com/bid/13993">13993</ref><ref source="" url="http://www.sudo.ws/sudo/alerts/path_race.html">http://www.sudo.ws/sudo/alerts/path_race.html</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-735">DSA-735</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-535.html">RHSA-2005:535</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1242.html">OVAL1242</ref><ref source="APPLE" url="http://docs.info.apple.com/article.html?artnum=302847">APPLE-SA-2005-11-29</ref><ref source="BID" url="http://www.securityfocus.com/bid/15647">15647</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15744">15744</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17813">17813</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/0821">ADV-2005-0821</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/2659">ADV-2005-2659</ref><ref source="OSVDB" url="http://www.osvdb.org/17396">17396</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/21080">sudo-pathname-race-condition(21080)</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/425974/100/0/threaded">FLSA:162750</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_36_sudo.html">SUSE-SA:2005:036</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1242">oval:org.mitre.oval:def:1242</ref></refs><vuln_soft><prod name="Sudo" vendor="Todd Miller"><vers num="1.6.8 p7"/><vers num="1.6.8 p8"/><vers num="1.6.8 p1"/><vers num="1.6.8"/><vers num="1.6.7 p5"/><vers num="1.6.7"/><vers num="1.6.6"/><vers num="1.6.5 p2"/><vers num="1.6.5 p1"/><vers num="1.6.5"/><vers num="1.6.4 p2"/><vers num="1.6.4 p1"/><vers num="1.6.4"/><vers num="1.6.3 p7"/><vers num="1.6.3 p6"/><vers num="1.6.3 p5"/><vers num="1.6.3 p4"/><vers num="1.6.3 p3"/><vers num="1.6.3 p2"/><vers num="1.6.3 p1"/><vers num="1.6.3"/><vers num="1.6.2"/><vers num="1.6.1"/><vers num="1.6"/><vers num="1.5.9"/><vers num="1.5.8"/><vers num="1.5.7"/><vers num="1.5.6"/><vers num="1.3.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1994" published="2005-06-14" seq="2005-1994" severity="Medium" type="CVE"><desc><descript source="cve">Finjan SurfinGate 7.0SP2 and SP3 allows remote attackers to download blocked files via hex-encoded characters in a filename, as demonstrated using &quot;%2e&quot;.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111877410528692&amp;w=2">20050614 URL-Encoding Problem in Finjan SurfinGate</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/0778">ADV-2005-0778</ref><ref source="OSVDB" url="http://www.osvdb.org/17324">17324</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/15711">15711</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/21010">finjan-surfingate-security-bypass(21010)</ref></refs><vuln_soft><prod name="SurfinGate" vendor="Finjan Software"><vers num="7.0 SP2"/><vers num="7.0 SP3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1995" published="2005-06-15" seq="2005-1995" severity="Medium" type="CVE"><desc><descript source="cve">Bitrix Site Manager 4.0.x allows remote attackers to obtain sensitive information via direct request to (1) subscr_form.php or (2) dbquery_error.php, which reveals the path in an error message.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111885652331100&amp;w=2">20050615 Vulnerability: Bitrix Web Server Paths</ref><ref patch="1" source="OSVDB" url="http://www.osvdb.org/17348">17348</ref><ref patch="1" source="OSVDB" url="http://www.osvdb.org/17376">17376</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/21019">bitrix-site-path-disclosure(21019)</ref></refs><vuln_soft><prod name="Bitrix Site Manager" vendor="Bitrix"><vers num="4.0.0"/><vers num="4.0.2"/><vers num="4.0.3"/><vers num="4.0.4"/><vers num="4.0.5"/><vers num="4.0.6"/><vers num="4.0.7"/><vers num="4.0.8"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-27" name="CVE-2005-1996" published="2005-06-15" seq="2005-1996" severity="Medium" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in start.php in Bitrix Site Manager 4.0.x allows remote attackers to execute arbitrary PHP code via the _SERVER[DOCUMENT_ROOT] parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111885605913761&amp;w=2">20050615 Vulnerability: Bitrix Php inclusion</ref><ref patch="1" source="CONFIRM" url="http://www.bitrixsoft.com/support/forum/read.php?FID=10&amp;TID=1872">http://www.bitrixsoft.com/support/forum/read.php?FID=10&amp;TID=1872</ref><ref patch="1" source="CONFIRM" url="http://www.bitrixsoft.com/sitemanager/versions.php?module=main">http://www.bitrixsoft.com/sitemanager/versions.php?module=main</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/0779">ADV-2005-0779</ref><ref patch="1" source="OSVDB" url="http://www.osvdb.org/17341">17341</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/15726">15726</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/21018">bitrix-serverdocumentroot-file-include(21018)</ref><ref source="BID" url="http://www.securityfocus.com/bid/13965">13965</ref></refs><vuln_soft><prod name="Bitrix Site Manager" vendor="Bitrix"><vers num="4.0.0"/><vers num="4.0.2"/><vers num="4.0.3"/><vers num="4.0.4"/><vers num="4.0.5"/><vers num="4.0.6"/><vers num="4.0.7"/><vers num="4.0.8"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1997" published="2005-06-15" seq="2005-1997" severity="Medium" type="CVE"><desc><descript source="cve">show.php in McGallery 1.1 allows remote attackers to connect to arbitrary databases, or gain sensitive information by triggering an error, via a modified host parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111885559100231&amp;w=2">20050615 Vulnerability: McGallery v 1.1 Mysql DB including</ref><ref source="OSVDB" url="http://www.osvdb.org/17344">17344</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/15727">15727</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014215">1014215</ref></refs><vuln_soft><prod name="McGallery" vendor="McGallery"><vers num="1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1998" published="2005-06-15" seq="2005-1998" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in admin.php in McGallery 1.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the lang parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111885505600482&amp;w=2">20050615 Vulnerability: McGallery v 1.1  files reading on disk</ref><ref source="OSVDB" url="http://www.osvdb.org/17343">17343</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/15727">15727</ref><ref source="BID" url="http://www.securityfocus.com/bid/13963">13963</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014215">1014215</ref></refs><vuln_soft><prod name="McGallery" vendor="McGallery"><vers num="1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-1999" published="2005-06-15" seq="2005-1999" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in pafiledb.php in paFileDB 3.1 allow remote attackers to inject arbitrary web script or HTML via the (1) sortby or (2) filelist parameters to the category action (category.php), or (3) pages parameter in the viewall action (viewall.php).</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111885787217807&amp;w=2">20050615 Multiple paFileDB Vulnerabilities</ref><ref patch="1" source="MISC" url="http://www.gulftech.org/?node=research&amp;article_id=00082-06142005">http://www.gulftech.org/?node=research&amp;article_id=00082-06142005</ref><ref patch="1" source="CONFIRM" url="http://www.phparena.net/">http://www.phparena.net/</ref><ref patch="1" source="CONFIRM" url="http://www.phparena.net/pafiledb_patch/">http://www.phparena.net/pafiledb_patch/</ref></refs><vuln_soft><prod name="paFileDB" vendor="PHP Arena"><vers num="3.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2000" published="2005-06-15" seq="2005-2000" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in paFileDB 3.1 and earlier allow remote attackers to execute arbitrary SQL commands via the formname parameter (1) in the login form, (2) in the team login form, or (3) to auth.php, (4) select, (5) id, or (6) query parameter to pafiledb.php, or (7) string parameter to search.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111885787217807&amp;w=2">20050615 Multiple paFileDB Vulnerabilities</ref><ref patch="1" source="MISC" url="http://www.gulftech.org/?node=research&amp;article_id=00082-06142005">http://www.gulftech.org/?node=research&amp;article_id=00082-06142005</ref><ref patch="1" source="CONFIRM" url="http://www.phparena.net/">http://www.phparena.net/</ref><ref patch="1" source="CONFIRM" url="http://www.phparena.net/pafiledb_patch/">http://www.phparena.net/pafiledb_patch/</ref></refs><vuln_soft><prod name="paFileDB" vendor="PHP Arena"><vers num="3.1"/><vers num="3.0 Beta 3.1"/><vers num="3.0"/><vers num="2.1.1"/><vers num="1.1.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2001" published="2005-06-15" seq="2005-2001" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in pafiledb.php in paFileDB 3.1 and earlier allows remote attackers to include arbitrary files via a .. (dot dot) in the action parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111885787217807&amp;w=2">20050615 Multiple paFileDB Vulnerabilities</ref><ref patch="1" source="MISC" url="http://www.gulftech.org/?node=research&amp;article_id=00082-06142005">http://www.gulftech.org/?node=research&amp;article_id=00082-06142005</ref><ref patch="1" source="CONFIRM" url="http://www.phparena.net/">http://www.phparena.net/</ref><ref patch="1" source="CONFIRM" url="http://www.phparena.net/pafiledb_patch/">http://www.phparena.net/pafiledb_patch/</ref></refs><vuln_soft><prod name="paFileDB" vendor="PHP Arena"><vers num="3.1"/><vers num="3.0 Beta 3.1"/><vers num="3.0"/><vers num="2.1.1"/><vers num="1.1.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2002" published="2005-06-15" seq="2005-2002" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in content.php in Mambo 4.5.2.2 and earlier allows remote attackers to execute arbitrary SQL commands via the user_rating parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111885974124936&amp;w=2">20050615 Mambo 4.5.2.2 SQL Injection in UPDATE statement</ref><ref adv="1" source="CONFIRM" url="http://mamboforge.net/frs/download.php/6153/CHANGELOG">http://mamboforge.net/frs/download.php/6153/CHANGELOG</ref><ref source="OSVDB" url="http://www.osvdb.org/17323">17323</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/15710">15710</ref><ref source="BID" url="http://www.securityfocus.com/bid/13966">13966</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014222">1014222</ref></refs><vuln_soft><prod name="Mambo" vendor="Mambo"><vers num="4.5.2.2"/><vers num="4.5.2"/><vers num="4.5.1.3"/><vers edition="a" num="4.5.1a"/><vers num="4.5.0.2"/><vers num="4.5_1.0.9"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2003" published="2005-06-16" seq="2005-2003" severity="Medium" type="CVE"><desc><descript source="cve">Ultimate PHP Board (UPB) 1.9.6 GOLD allows remote attackers to obtain sensitive information via an invalid (zero) id parameter to (1) viewtopic.php, (2) profile.php, or (3) newpost.php, which reveals the path in an error message.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111893777504821&amp;w=2">20050616 M4DR007-06SA (security advisory): Multiple vulnerabilities in UPB 1.9.6 GOLD</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/15732">15732</ref></refs><vuln_soft><prod name="Ultimate PHP Board" vendor="Ultimate PHP Board"><vers num="1.9.6 GOLD"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2004" published="2005-06-17" seq="2005-2004" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting vulnerabilities in Ultimate PHP Board (UPB) 1.9.6 GOLD and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) ref parameter to login.php, (2) id or (3) page parameter to viewtopic.php, id parameter to (4) profile.php, (5) newpost.php, (6) email.php, (7) icq.php, or (8) aol.php, (9) t_id parameter to newpost.php, (10) ref parameter to getpass.php, or (11) sText parameter to search.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111893777504821&amp;w=2">20050616 M4DR007-06SA (security advisory): Multiple vulnerabilities in UPB 1.9.6 GOLD</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/15732">15732</ref></refs><vuln_soft><prod name="Ultimate PHP Board" vendor="Ultimate PHP Board"><vers num="1.9.6"/><vers num="1.9"/><vers num="1.8.2"/><vers num="1.8"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2005" published="2005-06-16" seq="2005-2005" severity="Medium" type="CVE"><desc><descript source="cve">Ultimate PHP Board (UPB) 1.9.6 GOLD and earlier stores the users.dat file under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information on registered users via a direct request to db/users.dat.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111893777504821&amp;w=2">20050616 M4DR007-06SA (security advisory): Multiple vulnerabilities in UPB 1.9.6 GOLD</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/15732">15732</ref></refs><vuln_soft><prod name="Ultimate PHP Board" vendor="Ultimate PHP Board"><vers num="1.9.6"/><vers num="1.9"/><vers num="1.8.2"/><vers num="1.8"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2006" published="2005-06-17" seq="2005-2006" severity="Medium" type="CVE"><desc><descript source="cve">JBOSS 3.2.2 through 3.2.7 and 4.0.2 allows remote attackers to obtain sensitive information via a GET request (1) with a &quot;%.&quot; (percent dot), which reveals the installation path or (2) with a % (percent) before a filename, which reveals the contents of the file.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111911095424496&amp;w=2">20050617 JBOSS 3.2.2-3.2.7 / 4.0.2 installation path disclosure / config disclosure / version fingerprinting</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/0815">ADV-2005-0815</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/15746">15746</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17559">17559</ref><ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=c00597967">HPSBMA02096</ref><ref source="BID" url="http://www.securityfocus.com/bid/13985">13985</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0497">ADV-2006-0497</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015605">1015605</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18789">18789</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/440641/100/100/threaded">20060720 Cisco MARS &lt; 4.2.1 remote compromise</ref><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2006-07/0424.html">20060720 Cisco MARS &lt; 4.2.1 remote compromise</ref><ref source="SREASON" url="http://securityreason.com/securityalert/439">439</ref></refs><vuln_soft><prod name="JBoss" vendor="JBoss Group"><vers num="3.2.2"/><vers num="3.2.3"/><vers num="3.2.4"/><vers num="3.2.5"/><vers num="3.2.6"/><vers num="3.2.7"/><vers num="4.0.2"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-20" name="CVE-2005-2007" published="2005-06-19" seq="2005-2007" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in Edgewall Trac 0.8.3 and earlier allows remote attackers to read or write arbitrary files via a .. (dot dot) in the id parameter to the (1) upload or (2) attachment scripts.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-June/034618.html">20050619 Advisory 01/2005: Fileupload/download vulnerability in Trac</ref><ref adv="1" patch="1" source="MISC" url="http://www.hardened-php.net/advisory-012005.php">http://www.hardened-php.net/advisory-012005.php</ref><ref source="CONFIRM" url="http://svn.edgewall.com/repos/trac/tags/trac-0.8.4/ChangeLog">http://svn.edgewall.com/repos/trac/tags/trac-0.8.4/ChangeLog</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/15752">15752</ref></refs><vuln_soft><prod name="Trac" vendor="Edgewall Software"><vers num="0.8.3"/><vers num="0.8.2"/><vers num="0.8.1"/><vers num="0.8"/><vers num="0.7.1"/><vers num="0.7"/><vers num="0.6.1"/><vers num="0.6"/><vers num="0.5.2"/><vers num="0.5.1"/><vers num="0.5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2008" published="2005-06-17" seq="2005-2008" severity="Medium" type="CVE"><desc><descript source="cve">Yaws Webserver 1.55 and earlier allows remote attackers to obtain the source code for yaws scripts via a request to a yaw script with a trailing %00 (null).</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111927717726371&amp;w=2">20050617 Source Code Disclosure in Yaws Webserver &lt;1.56</ref><ref adv="1" patch="1" source="CONFIRM" url="http://yaws.hyber.org/yaws-1.55_to_1.56.patch">http://yaws.hyber.org/yaws-1.55_to_1.56.patch</ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/17375">17375</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/15740">15740</ref></refs><vuln_soft><prod name="Webserver" vendor="Yaws"><vers num="1.55"/><vers num="1.54"/><vers num="1.53"/><vers num="1.52"/><vers num="1.51"/><vers num="1.50"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2009" published="2005-06-20" seq="2005-2009" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in Ublog Reload 1.0.5 allow remote attackers to execute arbitrary SQL commands via the (1) ci, (2) d, or (3) m parameter to index.asp, or the (4) bi parameter to blog_comment.asp.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111928552304897&amp;w=2">20050620 [ECHO_ADV_18$2005] Multiple SQL INJECTION in Ublog Reload 1.0.5</ref><ref adv="1" source="MISC" url="http://echo.or.id/adv/adv18-theday-2005.txt">http://echo.or.id/adv/adv18-theday-2005.txt</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/0818">ADV-2005-0818</ref></refs><vuln_soft><prod name="Reload" vendor="Ublog"><vers num="1.0.5"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-22" name="CVE-2005-2010" published="2005-06-20" seq="2005-2010" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in trackback.asp in Ublog Reload 1.0.5 allows remote attackers to inject arbitrary web script or HTML via the btitle parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111928552304897&amp;w=2">20050620 [ECHO_ADV_18$2005] Multiple SQL INJECTION in Ublog Reload 1.0.5</ref><ref adv="1" source="MISC" url="http://echo.or.id/adv/adv18-theday-2005.txt">http://echo.or.id/adv/adv18-theday-2005.txt</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/0818">ADV-2005-0818</ref><ref source="BID" url="http://www.securityfocus.com/bid/13994">13994</ref></refs><vuln_soft><prod name="Ublog Reload" vendor="Uapplication"><vers num="1.0.5"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2011" published="2005-06-20" seq="2005-2011" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in paFAQ 1.0 Beta 4 allow remote attackers to inject arbitrary web script or HTML, as demonstrated via the id parameter in a Question action.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111928841328681&amp;w=2">20050620 paFaq Multiple Vulnerabilities</ref><ref source="MISC" url="http://www.gulftech.org/?node=research&amp;article_id=00083-06202005">http://www.gulftech.org/?node=research&amp;article_id=00083-06202005</ref></refs><vuln_soft><prod name="paFaq" vendor="PHP Arena"><vers num="1.0 Beta 4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2012" published="2005-06-20" seq="2005-2012" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in login in paFAQ 1.0 Beta 4 allow remote attackers to execute arbitrary SQL commands and bypass authentication via the (1) username or (2) id parameters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111928841328681&amp;w=2">20050620 paFaq Multiple Vulnerabilities</ref><ref source="MISC" url="http://www.gulftech.org/?node=research&amp;article_id=00083-06202005">http://www.gulftech.org/?node=research&amp;article_id=00083-06202005</ref></refs><vuln_soft><prod name="paFaq" vendor="PHP Arena"><vers num="1.0 Beta 4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2013" published="2005-06-20" seq="2005-2013" severity="Medium" type="CVE"><desc><descript source="cve">paFAQ 1.0 Beta 4 allows remote attackers to obtain sensitive information via a direct request to admin/backup.php, which contains a backup of the database including usernames and passwords.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111928841328681&amp;w=2">20050620 paFaq Multiple Vulnerabilities</ref><ref source="MISC" url="http://www.gulftech.org/?node=research&amp;article_id=00083-06202005">http://www.gulftech.org/?node=research&amp;article_id=00083-06202005</ref></refs><vuln_soft><prod name="paFaq" vendor="PHP Arena"><vers num="1.0 Beta 4"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2014" published="2005-06-20" seq="2005-2014" severity="Medium" type="CVE"><desc><descript source="cve">The &quot;upload a language pack&quot; feature in paFAQ 1.0 Beta 4 allows remote authenticated administrators to execute arbitrary PHP commands by uploading a malicious language pack.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111928841328681&amp;w=2">20050620 paFaq Multiple Vulnerabilities</ref></refs><vuln_soft><prod name="paFaq" vendor="PHP Arena"><vers num="1.0 Beta 4"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-08-16" name="CVE-2005-2017" published="2005-08-30" seq="2005-2017" severity="High" type="CVE"><desc><descript source="cve">Symantec AntiVirus 9 Corporate Edition allows local users to gain privileges via the &quot;Scan for viruses&quot; option, which launches a help window with raised privileges, a re-introduction of a vulnerability that was originally identified and addressed by CVE-2002-1540.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=298&amp;type=vulnerabilities">20050829 Symantec AntiVirus 9 Corporate Edition Local Privilege Escalation Vulnerability</ref><ref adv="1" source="SYMANTEC" url="http://www.symantec.com/avcenter/security/Content/2005.08.24.html">SYM05-012 </ref></refs><vuln_soft><prod name="Symantec AntiVirus" vendor="Symantec"><vers edition="Corporate" num="9.0.1.1000"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2019" published="2005-07-05" seq="2005-2019" severity="Medium" type="CVE"><desc><descript source="cve">ipfw in FreeBSD 5.4, when running on Symmetric Multi-Processor (SMP) or Uni Processor (UP) systems with the PREEMPTION kernel option enabled, does not sufficiently lock certain resources while performing table lookups, which can cause the cache results to be corrupted during multiple concurrent lookups, allowing remote attackers to bypass intended access restrictions.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="FREEBSD" url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-05:13.ipfw.asc">FreeBSD-SA-05:13</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="5.4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2020" published="2005-09-08" seq="2005-2020" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in the web server for 3Com Network Supervisor 5.0.2 allows remote attackers to read arbitrary files via &quot;..&quot; sequences in the URL to TCP port 21700.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=300&amp;type=vulnerabilities&amp;flashstatus=true">20050902 3Com Network Supervisor Directory Traversal Vulnerability</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/1611">ADV-2005-1611</ref><ref adv="1" patch="1" source="SECTRACK" url="http://securitytracker.com/id?1014836">1014836</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/16639">16639</ref></refs><vuln_soft><prod name="Network Supervisor" vendor="3Com"><vers num="5.0.2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2021" published="2005-06-20" seq="2005-2021" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in cPanel 9.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the user parameter in the login page.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/13996">13996</ref></refs><vuln_soft><prod name="cPanel" vendor="cPanel"><vers num="9.1"/><vers num="9.0"/><vers num="8.0"/><vers num="7.0"/><vers num="6.4.2 Stable_48"/><vers num="6.4.2"/><vers num="6.4.1"/><vers num="6.4"/><vers num="6.2"/><vers num="6.0"/><vers num="5.3"/><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-10-06" name="CVE-2005-2022" published="2005-06-17" seq="2005-2022" severity="Medium" type="CVE"><desc><descript source="cve">Unknown vulnerability in Webmail in iPlanet Messaging Server 5.2 Patch 1 and Sun ONE Messaging Server 6.2 allows remote attackers to execute arbitrary Javascript, possibly due to a cross-site scripting (XSS) vulnerability.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101770-1">101770</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/0816">ADV-2005-0816</ref></refs><vuln_soft><prod name="iPlanet Messaging Server" vendor="Sun"><vers num="5.2 patch1"/></prod><prod name="ONE Messaging Server" vendor="Sun"><vers num="6.2"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2023" published="2005-06-17" seq="2005-2023" severity="High" type="CVE"><desc><descript source="cve">The send_pinentry_environment function in asshelp.c in gpg2 on SUSE Linux 9.3 does not properly handle certain options, which can prevent pinentry from being found and causes S/MIME signing to fail.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_16_sr.html">SUSE-SR:2005:016</ref><ref source="Security Focus" url="http://www.securityfocus.com/bid/13980/info">GnuPG S/MIME Signing Unspecified Vulnerability</ref><ref source="MLIST" url="http://lists.gnupg.org/pipermail/gpa-dev/2005-June/002291.html">[gpa-dev] 20050531 S/MIME signing fails on a SUSE 9.3 system</ref><ref source="MLIST" url="http://lists.gnupg.org/pipermail/gpa-dev/2005-June/002294.html">[gpa-dev] 20050603 Re: S/MIME signing fails on a SUSE 9.3 system</ref></refs><vuln_soft><prod name="SuSE Linux" vendor="SuSE"><vers num="9.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2024" published="2005-06-17" seq="2005-2024" severity="Medium" type="CVE"><desc><descript source="cve">Vipul Razor Agents (razor-agents) before 2.70 allows remote attackers to cause a denial of service via (1) certain &quot;unusual HTML messages&quot; or (2) &quot;certain malformed headers&quot; such as Content-Type.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CONFIRM" url="http://sourceforge.net/mailarchive/forum.php?thread_id=7520323&amp;forum_id=4259">http://sourceforge.net/mailarchive/forum.php?thread_id=7520323&amp;forum_id=4259</ref><ref adv="1" patch="1" source="MISC" url="http://bugs.gentoo.org/show_bug.cgi?id=95492">http://bugs.gentoo.org/show_bug.cgi?id=95492</ref><ref adv="1" patch="1" source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200506-17.xml">GLSA-200506-17</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/13984">13984</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-738">DSA-738</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_35_razor_agents.html">SUSE-SA:2005:035</ref></refs><vuln_soft><prod name="razor-agents" vendor="Vipul"><vers num="2.72"/><vers num="2.71"/><vers num="2.70"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-22" name="CVE-2005-2025" published="2005-06-20" seq="2005-2025" severity="Medium" type="CVE"><desc><descript source="cve">Cisco VPN 3000 Concentrator before 4.1.7.F allows remote attackers to determine valid groupnames by sending an IKE Aggressive Mode packet with the groupname in the ID field, which generates a response if the groupname is valid, but does not generate a response for an invalid groupname.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="MISC" url="http://www.nta-monitor.com/news/vpn-flaws/cisco/VPN-Concentrator/index.htm">http://www.nta-monitor.com/news/vpn-flaws/cisco/VPN-Concentrator/index.htm</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/13992">13992</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/0822">ADV-2005-0822</ref></refs><vuln_soft><prod name="Cisco VPN" vendor="Cisco"><vers num="3080 Concentrator"/><vers num="3060 Concentrator"/><vers num="3030 Concentrator"/><vers num="3020 Concentrator"/><vers num="3015 Concentrator"/><vers num="3005 Concentrator 4.0.1"/><vers num="3005 Concentrator 4.0"/><vers num="3005 Concentrator 3.6.7 F"/><vers num="3005 Concentrator 3.6.7 D"/><vers num="3005 Concentrator 3.6.7 C"/><vers num="3005 Concentrator 3.6.7 B"/><vers num="3005 Concentrator 3.6.7 A"/><vers num="3005 Concentrator 3.6.7"/><vers num="3005 Concentrator 3.6.5"/><vers num="3005 Concentrator 3.6.3"/><vers num="3000 Concentrator 4.1.5 .B"/><vers num="3000 Concentrator 4.1 .x"/><vers num="3000 Concentrator 4.0.5 .B"/><vers num="3000 Concentrator 4.0.1"/><vers num="3000 Concentrator 4.0 .x"/><vers num="3000 Concentrator 4.0"/><vers num="3000 Concentrator 3.6.7 D"/><vers num="3000 Concentrator 3.6.7"/><vers num="3000 Concentrator 3.6.1"/><vers num="3000 Concentrator 3.6"/><vers num="3000 Concentrator 3.5.5"/><vers num="3000 Concentrator 3.5.4"/><vers num="3000 Concentrator 3.5.3"/><vers num="3000 Concentrator 3.5.2"/><vers num="3000 Concentrator 3.5.1"/><vers num="3000 Concentrator 3.5 (Rel)"/><vers num="3000 Concentrator 3.1.4"/><vers num="3000 Concentrator 3.1.2"/><vers num="3000 Concentrator 3.1.1"/><vers num="3000 Concentrator 3.1 (Rel)"/><vers num="3000 Concentrator 3.1"/><vers num="3000 Concentrator 3.0.4"/><vers num="3000 Concentrator 3.0.3 (B)"/><vers num="3000 Concentrator 3.0.3 (A)"/><vers num="3000 Concentrator 3.0"/><vers num="3000 Concentrator 2.5.2 (F)"/><vers num="3000 Concentrator 2.5.2 (D)"/><vers num="3000 Concentrator 2.5.2 (C)"/><vers num="3000 Concentrator 2.5.2 (B)"/><vers num="3000 Concentrator 2.5.2 (A)"/><vers num="3000 Concentrator 2.0"/><vers num="3000 Concentrator 4.1.7.B"/><vers num="3000 Concentrator 4.1.7.A"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2026" published="2005-06-16" seq="2005-2026" severity="High" type="CVE"><desc><descript source="cve">Enterasys Vertical Horizon VH-2402S before firmware 2.05.05.09 has a hard-coded account and password for debugging, which allows remote attackers to gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CONFIRM" url="http://www.enterasys.com/support/relnotes/VH-4802-2050509-patch-rel.pdf">http://www.enterasys.com/support/relnotes/VH-4802-2050509-patch-rel.pdf</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/15757">15757</ref></refs><vuln_soft><prod name="VH-2402S" vendor="Enterasys"><vers num="2.05.00"/><vers num="2.05.08.01"/><vers num="2.05.09.07"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2027" published="2005-06-16" seq="2005-2027" severity="Medium" type="CVE"><desc><descript source="cve">Enterasys Vertical Horizon VH-2402S before firmware 2.05.05.09 does not properly restrict certain debugging commands to the ADMIN account, which could allow attackers to obtain sensitive information or modify the registry.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CONFIRM" url="http://www.enterasys.com/support/relnotes/VH-4802-2050509-patch-rel.pdf">http://www.enterasys.com/support/relnotes/VH-4802-2050509-patch-rel.pdf</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/15757">15757</ref></refs><vuln_soft><prod name="VH-2402S" vendor="Enterasys"><vers num="2.05.00"/><vers num="2.05.08.01"/><vers num="2.05.09.07"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-10-06" name="CVE-2005-2028" published="2005-06-21" seq="2005-2028" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in index.php for MercuryBoard 1.1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the User-Agent HTTP header.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111938068428037&amp;w=2">20050621 MercuryBoard  1.1.4 SQL Injection</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/14015">14015</ref></refs><vuln_soft><prod name="MercuryBoard Message Board" vendor="MercuryBoard"><vers num="1.1.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2029" published="2005-06-17" seq="2005-2029" severity="High" type="CVE"><desc><descript source="cve">amaroK Web Frontend 1.3 stores the globals.inc file under the web root without a .php extension and insufficient access control, which allows remote attackers to obtain the database username and password via a direct request to the file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CONFIRM" url="http://sourceforge.net/project/shownotes.php?release_id=335719">http://sourceforge.net/project/shownotes.php?release_id=335719</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/15736">15736</ref></refs><vuln_soft><prod name="Web Frontend" vendor="amaroK"><vers num="1.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-25" name="CVE-2005-2030" published="2005-06-16" seq="2005-2030" severity="Medium" type="CVE"><desc><descript source="cve">Ultimate PHP Board (UPB) 1.9.6 GOLD uses weak encryption for passwords in the users.dat file, which allows attackers to easily decrypt the passwords and gain privileges, possibly after exploiting CVE-2005-2005 to obtain users.dat.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111893777504821&amp;w=2">20050616 M4DR007-06SA (security advisory): Multiple vulnerabilities in UPB 1.9.6 GOLD</ref><ref source="BID" url="http://www.securityfocus.com/bid/13975">13975</ref></refs><vuln_soft><prod name="Ultimate PHP Board" vendor="Ultimate PHP Board"><vers num="1.9.6"/><vers num="1.9"/><vers num="1.8.2"/><vers num="1.8"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2031" published="2005-06-16" seq="2005-2031" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in socialMPN allow remote attackers to execute arbitrary SQL commands via (1) the sid parameter to article.php, (2) uname parameter to user.php, (3) siteid parameter to viewforum.php, (4) username parameter to newtopic.php, the (5) secid or (6) artid parameter to sections.php, (7) siteid parameter to index.php, or (8) sid parameter to friend.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="SECTRACK" url="http://securitytracker.com/id?1014214">1014214</ref></refs><vuln_soft><prod name="SocialMPN" vendor="SocialMPN"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2032" published="2005-06-16" seq="2005-2032" severity="Low" type="CVE"><desc><descript source="cve">Unknown vulnerability in lpadmin on Sun Solaris 7, 8, and 9 allows local users to overwrite arbitrary files.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101768-1">101768</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/15723">15723</ref><ref source="BID" url="http://www.securityfocus.com/bid/13968">13968</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014218">1014218</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers edition="x86" num="7.0"/><vers num="7.0"/><vers edition="x86" num="8.0"/><vers num="8.0"/><vers edition="x86" num="9.0"/><vers edition="SPARC" num="9.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2008-01-03" name="CVE-2005-2033" published="2005-06-20" seq="2005-2033" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in folderview.asp for Blue-Collar Productions i-Gallery 3.3 allows remote attackers to read arbitrary files and directories via the folder parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111936111630489&amp;w=2">20050620 [Hat-Squad] i-Gallery directory traversal</ref><ref source="BID" url="http://www.securityfocus.com/bid/14000">14000</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/0825">ADV-2005-0825</ref></refs><vuln_soft><prod name="i-Gallery" vendor="Blue-Collar Productions"><vers num="3.3"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2034" published="2005-06-20" seq="2005-2034" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in folderview.asp for BlueCollar iGallery 3.3 allows remote attackers to inject arbitrary web script or HTML via the folder parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111936111630489&amp;w=2">20050620 [Hat-Squad] i-Gallery directory traversal</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/14000">14000</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/0825">ADV-2005-0825</ref></refs><vuln_soft><prod name="i-Gallery" vendor="Blue-Collar Productions"><vers num="3.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-08-26" name="CVE-2005-2035" published="2005-06-16" seq="2005-2035" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in login.asp for Cool Cafe (Cool Caf&amp;#xe9;) Chat 1.2.1 allows remote attackers to execute arbitrary SQL commands via the password.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="FULLDISC" url="http://seclists.org/lists/fulldisclosure/2005/Jun/0205.html">20050616 CoolCafe Chat SQL injection</ref><ref adv="1" source="MISC" url="http://exploitlabs.com/files/advisories/EXPL-A-2005-009-coolcafe.txt">http://exploitlabs.com/files/advisories/EXPL-A-2005-009-coolcafe.txt</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014221">1014221</ref><ref source="OSVDB" url="http://www.osvdb.org/17349">17349</ref></refs><vuln_soft><prod name="Cool Cafe Chat" vendor="Cool Cafe Chat"><vers num="1.2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-08-26" name="CVE-2005-2036" published="2005-06-16" seq="2005-2036" severity="High" type="CVE"><desc><descript source="cve">modifyUser.asp in Cool Cafe (Cool Caf&amp;#xe9;) Chat 1.2.1 allows remote attackers to obtain the administrator password and email address via a modified nickname value.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="FULLDISC" url="http://seclists.org/lists/fulldisclosure/2005/Jun/0205.html">20050616 CoolCafe Chat SQL injection</ref><ref source="MISC" url="http://exploitlabs.com/files/advisories/EXPL-A-2005-009-coolcafe.txt">http://exploitlabs.com/files/advisories/EXPL-A-2005-009-coolcafe.txt</ref><ref source="OSVDB" url="http://www.osvdb.org/17350">17350</ref></refs><vuln_soft><prod name="Cool Cafe Chat" vendor="Cool Cafe Chat"><vers num="1.2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2037" published="2005-06-21" seq="2005-2037" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in Fortibus CMS 4.0.0 allow remote attackers to execute arbitrary SQL commands via (1) the username or password to logon.asp, (2) WeeklyNotesDisplay.asp, or (3) the Search page.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/0827">ADV-2005-0827</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014242">1014242</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/15762">15762</ref></refs><vuln_soft><prod name="Fortibus CMS" vendor="Fortibus"><vers num="4.0.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2038" published="2005-06-20" seq="2005-2038" severity="Medium" type="CVE"><desc><descript source="cve">Fortibus CMS 4.0.0 allows remote attackers to modify information of other users, including Admin, via the &quot;My info&quot; page.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="SECTRACK" url="http://securitytracker.com/id?1014242">1014242</ref></refs><vuln_soft><prod name="Fortibus CMS" vendor="Fortibus"><vers num="4.0.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2039" published="2005-06-19" seq="2005-2039" severity="Medium" type="CVE"><desc><descript source="cve">Unknown vulnerability in &quot;various plugins&quot; for NanoBlogger 3.2.1 and earlier allows remote attackers to execute arbitrary commands.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="CONFIRM" url="http://nanoblogger.sourceforge.net/downloads/nanoblogger-3.2.3.tar.gz">http://nanoblogger.sourceforge.net/downloads/nanoblogger-3.2.3.tar.gz</ref><ref patch="1" source="OSVDB" url="http://www.osvdb.org/17392">17392</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/15754">15754</ref></refs><vuln_soft><prod name="NanoBlogger" vendor="NanoBlogger"><vers num="3.2.1" prev="1"/><vers num="3.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-22" name="CVE-2005-2040" published="2005-06-20" seq="2005-2040" severity="Medium" type="CVE"><desc><descript source="cve">Multiple buffer overflows in the getterminaltype function in telnetd for Heimdal before 0.6.5 may allow remote attackers to execute arbitrary code, a different vulnerability than CVE-2005-0468 and CVE-2005-0469.</descript></desc><loss_types><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="CONFIRM" url="http://www.pdc.kth.se/heimdal/advisory/2005-06-20/">http://www.pdc.kth.se/heimdal/advisory/2005-06-20/</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/15718">15718</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-758">DSA-758</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200506-24.xml">GLSA-200506-24</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_40_heimdal.html">SUSE-SA:2005:040</ref></refs><vuln_soft><prod name="telnetd" vendor="telnetd"><vers num="0.6.2"/><vers num="0.6.1"/><vers num="0.6"/><vers num="0.5.3"/><vers num="0.5.2"/><vers num="0.5.1"/><vers num="0.5.0"/><vers num="0.4e"/><vers num="0.4d"/><vers num="0.4c"/><vers num="0.4b"/><vers num="0.4a"/><vers num="0.3f"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2041" published="2005-06-15" seq="2005-2041" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in addschup in HAURI ViRobot 2.0, and possibly other products, allows remote attackers to execute arbitrary code via a long ViRobot_ID cookie (HTTP_COOKIE).</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MISC" url="http://www.securiteam.com/exploits/5TP0C1FG1I.html">http://www.securiteam.com/exploits/5TP0C1FG1I.html</ref><ref adv="1" source="MISC" url="http://www.digitalmunition.com/DMA%5B2005-0614a%5D.txt">http://www.digitalmunition.com/DMA%5B2005-0614a%5D.txt</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15700">15700</ref><ref source="" url="http://www.globalhauri.com/html/download/down_unixpatch.html"></ref><ref source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=111880273631392&amp;w=2">20050615 DMA[2005-0614a] - &apos;Global Hauri ViRobot Server cookie overflow&apos;</ref><ref source="BID" url="http://www.securityfocus.com/bid/12964">12964</ref><ref source="OSVDB" url="http://www.osvdb.org/17320">17320</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/21000">virobot-addschup-bo(21000)</ref></refs><vuln_soft><prod name="ViRobot Linux Server" vendor="Hauri"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2042" published="2005-06-16" seq="2005-2042" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in ajax-spell before 1.8 allows remote attackers to inject arbitrary web script or HTML via onmouseover or other events in HTML tags.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="CONFIRM" url="http://sourceforge.net/project/shownotes.php?release_id=335556">http://sourceforge.net/project/shownotes.php?release_id=335556</ref><ref adv="1" patch="1" source="CONFIRM" url="http://www.broken-notebook.com/spell_checker/index.php">http://www.broken-notebook.com/spell_checker/index.php</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/13986">13986</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/15737">15737</ref></refs><vuln_soft><prod name="ajax-spell" vendor="ajax-spell"><vers num="1.7"/><vers num="1.6"/><vers num="1.5"/><vers num="1.4"/><vers num="1.3"/><vers num="1.2"/><vers num="1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2043" published="2005-06-17" seq="2005-2043" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in XAMPP before 1.4.14 allows remote attackers to inject arbitrary HTML and PHP code via lang.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="CONFIRM" url="http://sourceforge.net/project/shownotes.php?release_id=335710">http://sourceforge.net/project/shownotes.php?release_id=335710</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/13983">13983</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/15735">15735</ref></refs><vuln_soft><prod name="Apache Distribution" vendor="XAMPP"><vers num="1.4.13"/><vers num="1.4.12"/><vers num="1.4.11"/><vers num="1.4.10a"/><vers num="1.4.10"/><vers num="1.4.9"/><vers num="1.4.8"/><vers num="1.4.7"/><vers num="1.4.6"/><vers num="1.4.5"/><vers num="1.4.4"/><vers num="1.4.3"/><vers num="1.4.2"/><vers num="1.4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-08-23" name="CVE-2005-2044" published="2005-06-16" seq="2005-2044" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in ATutor 1.4.3 and 1.5 RC 1 allow remote attackers to inject arbitrary web script or HTML via the (1) show_course parameter to browse.php, (2) subject parameter to contact.php, (3) cid parameter to content.php, (4) l parameter to inbox/send_message.php, the (5) search, (6) words, (7) include, (8) find_in, (9) display_as, or (10) search parameter to search.php, the (11) submit, (12) query, or (13) field parameter to tile.php, the (14) us parameter to forum/subscribe_forum.php, or the (15) roles[], (16) status, (17) submit, or (18) reset_filter parameters to directory.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="MISC" url="http://lostmon.blogspot.com/2005/06/atutor-multiple-variable-cross-site.html">http://lostmon.blogspot.com/2005/06/atutor-multiple-variable-cross-site.html</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/13972">13972</ref><ref source="OSVDB" url="http://www.osvdb.org/17351">17351</ref><ref source="OSVDB" url="http://www.osvdb.org/17352">17352</ref><ref source="OSVDB" url="http://www.osvdb.org/17353">17353</ref><ref source="OSVDB" url="http://www.osvdb.org/17354">17354</ref><ref source="OSVDB" url="http://www.osvdb.org/17355">17355</ref><ref source="OSVDB" url="http://www.osvdb.org/17356">17356</ref><ref source="OSVDB" url="http://www.osvdb.org/17357">17357</ref><ref source="OSVDB" url="http://www.osvdb.org/17358">17358</ref><ref source="OSVDB" url="http://www.osvdb.org/17359">17359</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014216">1014216</ref></refs><vuln_soft><prod name="ATutor" vendor="Adaptive Technology Resource Centre"><vers num="1.4.3"/><vers num="1.5 RC 1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2045" published="2005-06-22" seq="2005-2045" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in DUware DUportal PRO 3.4.3 allow remote attackers to execute arbitrary SQL commands via the (1) iChannel parameter to default.asp, (2) iData parameter to detail.asp, (3) iMem parameter to members.asp, (4) iCat parameter to cat.asp, (5) offset parameter to members_listing_approval.asp, or (6) iChannel parameter to channels_edit.asp.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111945219205114&amp;w=2">20050622 [ECHO_ADV_19$2005] Multiple SQL INJECTION in DUWARE Products</ref><ref adv="1" source="MISC" url="http://echo.or.id/adv/adv19-theday-2005.txt">http://echo.or.id/adv/adv19-theday-2005.txt</ref><ref source="OSVDB" url="http://www.osvdb.org/17597">17597</ref><ref source="OSVDB" url="http://www.osvdb.org/17598">17598</ref><ref source="OSVDB" url="http://www.osvdb.org/17599">17599</ref></refs><vuln_soft><prod name="DUportal Pro" vendor="DUware"><vers num="3.4.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2046" published="2005-06-22" seq="2005-2046" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in DUware DUamazon Pro 3.0 and 3.1 allow remote attackers to execute arbitrary SQL commands via the (1) iCat parameter to cat.asp, (2) iSub parameter to sub.asp, (3) iSub parameter to detail.asp, (4) iPro parameter to review.asp, iCat parameter to (5) catEdit.asp, (6) catDelete.asp, (7) productEdit.asp, or (8) productDelete.asp, or (9) iType parameter to type.asp.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111945219205114&amp;w=2">20050622 [ECHO_ADV_19$2005] Multiple SQL INJECTION in DUWARE Products</ref><ref adv="1" source="MISC" url="http://echo.or.id/adv/adv19-theday-2005.txt">http://echo.or.id/adv/adv19-theday-2005.txt</ref></refs><vuln_soft><prod name="DUamazon Pro" vendor="DUware"><vers num="3.0"/><vers num="3.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2047" published="2005-06-22" seq="2005-2047" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in DUware DUpaypal Pro 3.0 allow remote attackers to execute arbitrary SQL commands via the (1) iCat parameter to cat.asp, (2) iPro parameter to detail.asp, (3) iSub parameter to sub.asp, (4) iCat parameter to catEdit.asp.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111945219205114&amp;w=2">20050622 [ECHO_ADV_19$2005] Multiple SQL INJECTION in DUWARE Products</ref><ref adv="1" source="MISC" url="http://echo.or.id/adv/adv19-theday-2005.txt">http://echo.or.id/adv/adv19-theday-2005.txt</ref></refs><vuln_soft><prod name="DUpaypal Pro" vendor="DUware"><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-12-11" name="CVE-2005-2048" published="2005-06-22" seq="2005-2048" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in DUware DUforum 3.1, and possibly other versions, allow remote attackers to execute arbitrary SQL commands via the (1) iMsg parameter to messages.asp, iFor parameter to (2) post.asp or (3) forums.asp, or (4) id parameter to userEdit.asp.  NOTE: vectors 1 and 3 were later reported to affect version 3.0.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111945219205114&amp;w=2">20050622 [ECHO_ADV_19$2005] Multiple SQL INJECTION in DUWARE Products</ref><ref adv="1" source="MISC" url="http://echo.or.id/adv/adv19-theday-2005.txt">http://echo.or.id/adv/adv19-theday-2005.txt</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/453330/100/0/threaded">20061202 [Aria-Security Team] DuWare DuForum SQL Injection Vuln</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/30668">duforum-messages-forums-sql-injection(30668)</ref></refs><vuln_soft><prod name="DUforum" vendor="DUware"><vers num="3.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2049" published="2005-06-22" seq="2005-2049" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in DUware DUclassmate 1.2 allow remote attackers to execute arbitrary SQL commands via the (1) iState parameter to default.asp or (2) iPro parameter to edit.asp.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111945219205114&amp;w=2">20050622 [ECHO_ADV_19$2005] Multiple SQL INJECTION in DUWARE Products</ref><ref adv="1" source="MISC" url="http://echo.or.id/adv/adv19-theday-2005.txt">http://echo.or.id/adv/adv19-theday-2005.txt</ref><ref source="BID" url="http://www.securityfocus.com/bid/14036">14036</ref></refs><vuln_soft><prod name="DUclassmate" vendor="DUware"><vers num="1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2050" published="2005-06-28" seq="2005-2050" severity="Medium" type="CVE"><desc><descript source="cve">Unknown vulnerability in Tor before 0.1.0.10 allows remote attackers to read arbitrary memory and possibly key information from the exit server&apos;s process space.</descript></desc><loss_types><conf/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref patch="1" source="or-announce Archives" url="http://archives.seul.org/or/announce/Jun-2005/msg00001.html">Security bug in 0.0.9.x Tor servers</ref><ref patch="1" source="GENTOO" url="http://bugs.gentoo.org/show_bug.cgi?id=96320">96320</ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200506-18.xml">GLSA-200506-18</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/15764/">15764</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/21093">tor-information-disclosure(21093)</ref></refs><vuln_soft><prod name="Tor" vendor="Tor"><vers num="0.0.9.9"/><vers num="0.0.9.8"/><vers num="0.0.9.7"/><vers num="0.0.9.6"/><vers num="0.0.9.5"/><vers num="0.0.9.4"/><vers num="0.0.9.3"/><vers num="0.0.9.2"/><vers num="0.0.9.1"/><vers num="0.0.9"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-03-27" name="CVE-2005-2051" published="2005-06-28" seq="2005-2051" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the VERITAS Backup Exec Web Administration Console (BEWAC) 9.0 4367 through 10.0 rev. 5484 allows remote attackers to execute arbitrary code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://seer.support.veritas.com/docs/276606.htm">http://seer.support.veritas.com/docs/276606.htm</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111954711532252&amp;w=2">20050623 Buffer overflow vulnerability in VERITAS Software Backup Exec Web Administration Console (BEWAC)</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15789">15789</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/p-232.shtml">P-232</ref><ref source="BID" url="http://www.securityfocus.com/bid/14025">14025</ref></refs><vuln_soft><prod name="Backup Exec" vendor="Symantec Veritas"><vers num="10.0"/><vers num="10.0 rev.5484"/><vers num="9.0"/><vers num="9.0 rev.4367"/><vers num="9.0 rev.4454"/><vers num="9.1"/><vers num="9.1 rev.4691"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-08-22" name="CVE-2005-2052" published="2005-06-28" seq="2005-2052" severity="Medium" type="CVE"><desc><descript source="cve">Heap-based buffer overflow in vidplin.dll in RealPlayer 10 and 10.5 (6.0.12.1040 through 1069), RealOne Player v1 and v2, RealPlayer 8 and RealPlayer Enterprise allows remote attackers to execute arbitrary code via an .avi file with a modified strf structure value.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111955853611840&amp;w=2">20050623 eEye Advisory - EEYEB-200505 - RealPlayer AVI Processing Overflow</ref><ref adv="1" patch="1" source="" url="http://service.real.com/help/faq/security/050623_player/EN/">http://service.real.com/help/faq/security/050623_player/EN/</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111955853611840&amp;w=2">20050623 eEye Advisory - EEYEB-200505 - RealPlayer AVI Processing Overflow</ref></refs><vuln_soft><prod name="RealPlayer" vendor="RealNetworks"><vers num="10.0"/><vers num="8.0"/><vers edition="Enterprise" num="Any"/><vers num="10.5_6.0.12.1040"/><vers num="10.5_6.0.12.1069"/></prod><prod name="RealOne Player" vendor="RealNetworks"><vers num="2.0"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-20" name="CVE-2005-2053" published="2005-06-28" seq="2005-2053" severity="Medium" type="CVE"><desc><descript source="cve">Just another flat file (JAF) CMS before 3.0 Final allows remote attackers to obtain sensitive information via (1) an * (asterisk) in the id parameter, (2) a blank id parameter, or (3) an * (asterisk) in the disp parameter to index.php, which reveals the path in an error message.  NOTE: a followup suggests that this may be a directory traversal or file inclusion vulnerability.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111954840611126&amp;w=2">20050623 [ECHO_ADV_20$2005] Full path disclosure JAF CMS</ref><ref adv="1" source="MISC" url="http://echo.or.id/adv/adv20-theday-2005.txt">http://echo.or.id/adv/adv20-theday-2005.txt</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111990004028512&amp;w=2">20050626 Re: [ECHO_ADV_20$2005] Full path disclosure JAF CMS</ref></refs><vuln_soft><prod name="JAF CMS" vendor="Salims Softhouse"><vers edition="RC2" num="3.0"/><vers edition="RC fixed" num="3.0"/><vers edition="RC" num="3.0"/><vers num="2.5"/><vers num="2.1.0"/><vers num="2.0.5"/><vers edition="final" num="2.0"/><vers edition="Beta" num="2.0"/><vers num="1.5"/><vers edition="final" num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-01-05" name="CVE-2005-2054" published="2005-06-29" seq="2005-2054" severity="Medium" type="CVE"><desc><descript source="cve">Unknown vulnerability in RealPlayer 10 and 10.5 (6.0.12.1040-1069) and RealOne Player v1 and v2 allows remote attackers to overwrite arbitrary files or execute arbitrary ActiveX controls via a crafted MP3 file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="" url="http://service.real.com/help/faq/security/050623_player/EN/">http://service.real.com/help/faq/security/050623_player/EN/</ref></refs><vuln_soft><prod name="RealPlayer" vendor="RealNetworks"><vers num="10.0"/><vers num="10.5_6.0.12.1040_1069"/></prod><prod name="RealOne Player" vendor="RealNetworks"><vers num="1.0"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-01-05" name="CVE-2005-2055" published="2005-06-29" seq="2005-2055" severity="Medium" type="CVE"><desc><descript source="cve">RealPlayer 8, 10, 10.5 (6.0.12.1040-1069), and Enterprise and RealOne Player v1 and v2 allows remote malicious web server to create an arbitrary HTML file that executes an RM file via &quot;default settings of earlier Internet Explorer browsers&quot;.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://service.real.com/help/faq/security/050623_player/EN/">http://service.real.com/help/faq/security/050623_player/EN/</ref></refs><vuln_soft><prod name="RealPlayer" vendor="RealNetworks"><vers num="8.0"/><vers num="10.0"/><vers num="10.5_6.0.12.1040_1069"/><vers edition="Enterprise" num="Any"/></prod><prod name="RealOne Player" vendor="RealNetworks"><vers num="1.0"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2056" published="2005-06-29" seq="2005-2056" severity="Low" type="CVE"><desc><descript source="cve">The Quantum archive decompressor in Clam AntiVirus (ClamAV) before 0.86.1 allows remote attackers to cause a denial of service (application crash) via a crafted Quantum archive.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref patch="1" source="" url="http://sourceforge.net/project/shownotes.php?release_id=337279">http://sourceforge.net/project/shownotes.php?release_id=337279</ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200506-23.xml">GLSA-200506-23</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15811">15811</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-737">DSA-737</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_38_clamav.html">SUSE-SA:2005:038</ref></refs><vuln_soft><prod name="ClamAV" vendor="Clam Anti-Virus"><vers num="0.86"/><vers num="0.86"/><vers num="0.85.1"/><vers num="0.85"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2057" published="2005-06-29" seq="2005-2057" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Infopop UBB.Threads before 6.5.2 Beta allow remote attackers to inject arbitrary web script or HTML via the (1) Searchpage parameter to dosearch.php, (2) Number, (3) what, or (4) page parameter to newreply.php, (5) Number, (6) Board, or (7) what parameter to showprofile.php, (8) fpart or (9) page parameter to showflat.php, or (10) like parameter to showmembers.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111963737202040&amp;w=2">20050624 Infopop UBB Threads Multiple Vulnerabilities</ref><ref adv="1" patch="1" source="MISC" url="http://www.gulftech.org/?node=research&amp;article_id=00084-06232005">http://www.gulftech.org/?node=research&amp;article_id=00084-06232005</ref><ref patch="1" source="MISC" url="http://www.ubbcentral.com/boards/showflat.php/Cat/0/Number/42351/Main/42351/#Post42351">http://www.ubbcentral.com/boards/showflat.php/Cat/0/Number/42351/Main/42351/#Post42351</ref></refs><vuln_soft><prod name="UBB.threads" vendor="UBBCentral"><vers num="6.5.1.1"/><vers num="6.5.1"/><vers num="6.5"/><vers num="6.4.4"/><vers num="6.4.3"/><vers num="6.4.2"/><vers num="6.4.1"/><vers num="6.4"/><vers num="6.3.1"/><vers num="6.3"/><vers num="6.2.3"/><vers num="6.2.2"/><vers num="6.2.1"/><vers num="6.2"/><vers num="6.1.1"/><vers num="6.1"/><vers num="6.0.3"/><vers num="6.0.2"/><vers num="6.0.1"/><vers num="6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2058" published="2005-06-29" seq="2005-2058" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in Infopop UBB.Threads before 6.5.2 Beta allow remote attackers to execute arbitrary SQL commands via the Number parameter to (1) download.php, (2) modifypost.php, (3) mailthread.php, or (4) notifymod.php, (5) month or (6) year parameter to calendar.php, (7) message parameter to viewmessage.php, (8) main parameter to addfav.php, or (9) posted parameter to grabnext.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111963737202040&amp;w=2">20050624 Infopop UBB Threads Multiple Vulnerabilities</ref><ref adv="1" patch="1" source="MISC" url="http://www.gulftech.org/?node=research&amp;article_id=00084-06232005">http://www.gulftech.org/?node=research&amp;article_id=00084-06232005</ref><ref patch="1" source="MISC" url="http://www.ubbcentral.com/boards/showflat.php/Cat/0/Number/42351/Main/42351/#Post42351">http://www.ubbcentral.com/boards/showflat.php/Cat/0/Number/42351/Main/42351/#Post42351</ref></refs><vuln_soft><prod name="UBB.threads" vendor="UBBCentral"><vers num="6.5.1.1"/><vers num="6.5.1"/><vers num="6.5"/><vers num="6.4.4"/><vers num="6.4.3"/><vers num="6.4.2"/><vers num="6.4.1"/><vers num="6.4"/><vers num="6.3.1"/><vers num="6.3"/><vers num="6.2.3"/><vers num="6.2.2"/><vers num="6.2.1"/><vers num="6.2"/><vers num="6.1.1"/><vers num="6.1"/><vers num="6.0.3"/><vers num="6.0.2"/><vers num="6.0.1"/><vers num="6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2059" published="2005-06-29" seq="2005-2059" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site request forgery (CSRF) vulnerabilities in (1) addaddress.php, (2) toggleignore.php, (3) removeignore.php, and (4) removeaddress.php in Infopop UBB.Threads before 6.5.2 Beta allow remote attackers to modify settings as another user via a link or IMG tag.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111963737202040&amp;w=2">20050624 Infopop UBB Threads Multiple Vulnerabilities</ref><ref adv="1" patch="1" source="MISC" url="http://www.gulftech.org/?node=research&amp;article_id=00084-06232005">http://www.gulftech.org/?node=research&amp;article_id=00084-06232005</ref><ref patch="1" source="MISC" url="http://www.ubbcentral.com/boards/showflat.php/Cat/0/Number/42351/Main/42351/#Post42351">http://www.ubbcentral.com/boards/showflat.php/Cat/0/Number/42351/Main/42351/#Post42351</ref></refs><vuln_soft><prod name="UBB.threads" vendor="UBBCentral"><vers num="6.5.1.1"/><vers num="6.5.1"/><vers num="6.5"/><vers num="6.4.4"/><vers num="6.4.3"/><vers num="6.4.2"/><vers num="6.4.1"/><vers num="6.4"/><vers num="6.3.1"/><vers num="6.3"/><vers num="6.2.3"/><vers num="6.2.2"/><vers num="6.2.1"/><vers num="6.2"/><vers num="6.1.1"/><vers num="6.1"/><vers num="6.0.3"/><vers num="6.0.2"/><vers num="6.0.1"/><vers num="6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2060" published="2005-06-29" seq="2005-2060" severity="Medium" type="CVE"><desc><descript source="cve">Multiple HTTP Response Splitting vulnerabilities in (1) toggleshow.php, (2) togglecats.php, and (3) showprofile.php in Infopop UBB.Threads before 6.5.2 Beta allow remote attackers to spoof web content and poison web caches via CRLF (&quot;%0d%0a&quot;) sequences in the Cat parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111963737202040&amp;w=2">20050624 Infopop UBB Threads Multiple Vulnerabilities</ref><ref adv="1" patch="1" source="MISC" url="http://www.gulftech.org/?node=research&amp;article_id=00084-06232005">http://www.gulftech.org/?node=research&amp;article_id=00084-06232005</ref><ref patch="1" source="MISC" url="http://www.ubbcentral.com/boards/showflat.php/Cat/0/Number/42351/Main/42351/#Post42351">http://www.ubbcentral.com/boards/showflat.php/Cat/0/Number/42351/Main/42351/#Post42351</ref></refs><vuln_soft><prod name="UBB.threads" vendor="UBBCentral"><vers num="6.5.1.1"/><vers num="6.5.1"/><vers num="6.5"/><vers num="6.4.4"/><vers num="6.4.3"/><vers num="6.4.2"/><vers num="6.4.1"/><vers num="6.4"/><vers num="6.3.1"/><vers num="6.3"/><vers num="6.2.3"/><vers num="6.2.2"/><vers num="6.2.1"/><vers num="6.2"/><vers num="6.1.1"/><vers num="6.1"/><vers num="6.0.3"/><vers num="6.0.2"/><vers num="6.0.1"/><vers num="6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2061" published="2005-06-29" seq="2005-2061" severity="Medium" type="CVE"><desc><descript source="cve">Infopop UBB.Threads before 6.5.2 Beta allows remote attackers to include arbitrary files via the language parameter in a cookie followed by a null (%00) byte.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111963737202040&amp;w=2">20050624 Infopop UBB Threads Multiple Vulnerabilities</ref><ref adv="1" patch="1" source="MISC" url="http://www.gulftech.org/?node=research&amp;article_id=00084-06232005">http://www.gulftech.org/?node=research&amp;article_id=00084-06232005</ref><ref patch="1" source="MISC" url="http://www.ubbcentral.com/boards/showflat.php/Cat/0/Number/42351/Main/42351/#Post42351">http://www.ubbcentral.com/boards/showflat.php/Cat/0/Number/42351/Main/42351/#Post42351</ref></refs><vuln_soft><prod name="UBB.threads" vendor="UBBCentral"><vers num="6.5.1.1"/><vers num="6.5.1"/><vers num="6.5"/><vers num="6.4.4"/><vers num="6.4.3"/><vers num="6.4.2"/><vers num="6.4.1"/><vers num="6.4"/><vers num="6.3.1"/><vers num="6.3"/><vers num="6.2.3"/><vers num="6.2.2"/><vers num="6.2.1"/><vers num="6.2"/><vers num="6.1.1"/><vers num="6.1"/><vers num="6.0.3"/><vers num="6.0.2"/><vers num="6.0.1"/><vers num="6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-08-14" name="CVE-2005-2062" published="2005-06-29" seq="2005-2062" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in ActiveBuyAndSell 6.2 allow remote attackers to execute arbitrary SQL commands via the catid parameter to (1) default.asp or (2) buyersend.asp, (3) Administrator ID field in admin.asp, E-mail field in (4) advertiserstart.asp or (5) buyer.asp, or Keyword field in search.asp.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111963341429906&amp;w=2">20050624 [ECHO_ADV_21$2005] MUltiple Vulnarable In ActiveBuyAndSell</ref><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3550">
3550</ref><ref source="BID" url="http://www.securityfocus.com/bid/23110">
23110</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1096">
ADV-2007-1096</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/33183">
activebuyandsell-buyersend-sql-injection(33183)</ref></refs><vuln_soft><prod name="ActiveBuyAndSell" vendor="Active Web Softwares"><vers num="6.2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-08-14" name="CVE-2005-2063" published="2005-06-29" seq="2005-2063" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in ActiveBuyAndSell 6.2 allow remote attackers to inject arbitrary web script or HTML via the (1) Title parameter to sendpassword.asp or (2) Keyword field in search.asp.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111963341429906&amp;w=2">20050624 [ECHO_ADV_21$2005] MUltiple Vulnarable In ActiveBuyAndSell</ref></refs><vuln_soft><prod name="ActiveBuyAndSell" vendor="Active Web Softwares"><vers num="6.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2064" published="2005-06-29" seq="2005-2064" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting vulnerabilities in ASP Nuke 0.80 allow remote attackers to inject arbitrary web script or HTML via the (1) email parameter to forgot_password.asp, or the (2) FirstName, (3) LastName, (4) Username, (5) Password, (6) Address1, (7) Address2, (8) City, (9) ZipCode, (10) Email parameter to register.asp.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111989223906484&amp;w=2">20050626 M4DR007-07SA (security advisory): Multiple vulnerabilities in ASP Nuke 0.80</ref><ref source="BID" url="http://www.securityfocus.com/bid/14062">14062</ref></refs><vuln_soft><prod name="ASP-Nuke" vendor="ASP-Nuke"><vers num="0.80"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2065" published="2005-06-29" seq="2005-2065" severity="Medium" type="CVE"><desc><descript source="cve">HTTP response splitting vulnerability in language_select.asp in ASP Nuke 0.80 allows remote attackers to spoof web content and poison web caches via CRLF (&quot;%0d%0a&quot;) sequences in the LangCode parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111989223906484&amp;w=2">20050626 M4DR007-07SA (security advisory): Multiple vulnerabilities in ASP Nuke 0.80</ref><ref source="BID" url="http://www.securityfocus.com/bid/14063">14063</ref></refs><vuln_soft><prod name="ASP-Nuke" vendor="ASP-Nuke"><vers num="0.80"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2066" published="2005-06-29" seq="2005-2066" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in comment_post.asp in ASP Nuke 0.80 allows remote attackers to execute arbitrary SQL statements via the TaskID parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111989223906484&amp;w=2">20050626 M4DR007-07SA (security advisory): Multiple vulnerabilities in ASP Nuke 0.80</ref><ref source="BID" url="http://www.securityfocus.com/bid/14064">14064</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111999188612055&amp;w=2">20050627 SQL Injection Exploit for ASPNuke &lt;= 0.80</ref></refs><vuln_soft><prod name="ASP-Nuke" vendor="ASP-Nuke"><vers num="0.80"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2067" published="2005-06-29" seq="2005-2067" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in article.asp in unknown versions of aspnuke allows remote attackers to execute arbitrary SQL commands via the articleid parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111989828622112&amp;w=2">20050627 aspnuke is vulnerable to sql injection</ref><ref source="" url="http://downloads.securityfocus.com/vulnerabilities/exploits/ASPNuke-0601-sql.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/18215">18215</ref></refs><vuln_soft><prod name="ASP-Nuke" vendor="ASP-Nuke"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2068" published="2005-07-05" seq="2005-2068" severity="Medium" type="CVE"><desc><descript source="cve">FreeBSD 4.x through 4.11 and 5.x through 5.4 allows remote attackers to modify certain TCP options via a TCP packet with the SYN flag set for an already established session.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="FREEBSD" url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-05:15.tcp.asc">FreeBSD-SA-05:15</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="5.4"/><vers num="5.3"/><vers num="5.2.1"/><vers num="5.2"/><vers num="5.1"/><vers num="5.0"/><vers num="4.11"/><vers num="4.10"/><vers num="4.9"/><vers num="4.8"/><vers num="4.7"/><vers num="4.6.2"/><vers num="4.6"/><vers num="4.5"/><vers num="4.4"/><vers num="4.3"/><vers num="4.2"/><vers num="4.1.1"/><vers num="4.1"/><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-21" name="CVE-2005-2069" published="2005-06-30" seq="2005-2069" severity="Medium" type="CVE"><desc><descript source="cve">pam_ldap and nss_ldap, when used with OpenLDAP and connecting to a slave using TLS, does not use TLS for the subsequent connection if the client is referred to a master, which may cause a password to be sent in cleartext and allows remote attackers to sniff the password.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="MISC" url="http://www.openldap.org/its/index.cgi/Incoming?id=3791">http://www.openldap.org/its/index.cgi/Incoming?id=3791</ref><ref adv="1" patch="1" source="MISC" url="http://bugzilla.padl.com/show_bug.cgi?id=210">http://bugzilla.padl.com/show_bug.cgi?id=210</ref><ref adv="1" source="" url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=161990">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=161990</ref><ref source="MISC" url="http://bugzilla.padl.com/show_bug.cgi?id=211">http://bugzilla.padl.com/show_bug.cgi?id=211</ref><ref source="" url="http://bugs.gentoo.org/show_bug.cgi?id=96767">http://bugs.gentoo.org/show_bug.cgi?id=96767</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-751.html">RHSA-2005:751</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-767.html">RHSA-2005:767</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17233">17233</ref><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2005-07/0060.html">20050704 pam_ldap/nss_ldap password leak in a master+slave+start_tls LDAP setup</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200507-13.xml">GLSA-2005-07-13</ref><ref source="MANDRIVA" url="http://wwwnew.mandriva.com/security/advisories?name=MDKSA-2005:121">MDKSA-2005:121</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-152-1">USN-152-1</ref><ref source="BID" url="http://www.securityfocus.com/bid/14125">14125</ref><ref source="BID" url="http://www.securityfocus.com/bid/14126">14126</ref><ref source="OSVDB" url="http://www.osvdb.org/17692">17692</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/21245">ldap-tls-information-disclosure(21245)</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17845">17845</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-157.htm"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/21520">21520</ref></refs><vuln_soft><prod name="pam_ldap" vendor="Padl Software"><vers num=""/></prod><prod name="nss_ldap" vendor="Padl Software"><vers num=""/></prod><prod name="OpenLDAP" vendor="OpenLDAP"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2070" published="2005-06-29" seq="2005-2070" severity="Medium" type="CVE"><desc><descript source="cve">The ClamAV Mail fILTER (clamav-milter) 0.84 through 0.85d, when used in Sendmail using long timeouts, allows remote attackers to cause a denial of service by keeping an open connection, which prevents ClamAV from reloading.</descript></desc><loss_types><avail/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://seclists.org/lists/bugtraq/2005/Jun/0197.html">20050623 long sendmail timeouts let attacker prevent milter quiesce</ref><ref source="BID" url="http://www.securityfocus.com/bid/14047">14047</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-737">DSA-737</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_38_clamav.html">SUSE-SA:2005:038</ref></refs><vuln_soft><prod name="Sendmail" vendor="Sendmail Consortium"><vers num="8.12.11"/><vers num="8.12.9"/><vers num="8.12.8"/><vers num="8.12.7"/><vers num="8.12.6"/><vers num="8.12.5"/><vers num="8.12.4"/><vers num="8.12.3"/><vers num="8.12.2"/><vers num="8.12.1"/><vers num="8.12 beta7"/><vers num="8.12 Beta5"/><vers num="8.12 Beta16"/><vers num="8.12 Beta12"/><vers num="8.12 Beta10"/><vers num="8.12.10"/><vers num="8.12.0"/><vers num="8.11.7"/><vers num="8.11.6"/><vers num="8.11.5"/><vers num="8.11.4"/><vers num="8.11.3"/><vers num="8.11.2"/><vers num="8.11.1"/><vers num="8.11"/><vers num="8.10.2"/><vers num="8.10.1"/><vers num="8.10"/><vers num="8.9.3"/><vers num="8.9.2"/><vers num="8.9.1"/><vers num="8.9.0"/><vers num="8.8.8"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-06-15" name="CVE-2005-2071" published="2005-06-29" seq="2005-2071" severity="Medium" type="CVE"><desc><descript source="cve">traceroute in Sun Solaris 10 on x86 systems allows local users to execute arbitrary code with PRIV_NET_RAWACCESS privileges via (1) a large number of -g arguments or (2) a malformed -s argument with a trailing . (dot).</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><local/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111963068714114&amp;w=2">20050624 Solaris 10 /usr/sbin/traceroute vulnerabilities</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111964580023012&amp;w=2">20050624 Re: Solaris 10 /usr/sbin/traceroute vulnerabilities</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111963809801731&amp;w=2">20050624 Re: [Full-disclosure] Solaris 10 /usr/sbin/traceroute vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/14049">14049</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102060-1">102060</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015261">1015261</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17708">17708</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/2564">ADV-2005-2564</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers edition="SPARC" num="10.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-06-15" name="CVE-2005-2072" published="2005-06-29" seq="2005-2072" severity="High" type="CVE"><desc><descript source="cve">The runtime linker (ld.so) in Solaris 8, 9, and 10 trusts the LD_AUDIT environment variable in setuid or setgid programs, which allows local users to gain privileges by (1) modifying LD_AUDIT to reference malicious code and possibly (2) using a long value for LD_AUDIT.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-June/034730.html">20050628 Solaris 9/10 ld.so fun</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-June/034731.html">20050628 Solaris 9/10 ld.so fun</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-June/034738.html">20050628 Solaris 9/10 ld.so fun</ref><ref source="BID" url="http://www.securityfocus.com/bid/14074">14074</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101794-1">101794</ref><ref source="" url="http://www.opensolaris.org/jive/thread.jspa?messageID=3497"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/0908">ADV-2005-0908</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014537">1014537</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15841">15841</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers edition="SPARC" num="10.0"/><vers edition="x86" num="9.0"/><vers edition="SPARC" num="9.0"/><vers edition="x86" num="8.0"/><vers num="8.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2073" published="2005-06-29" seq="2005-2073" severity="Low" type="CVE"><desc><descript source="cve">Unknown vulnerability in IBM DB2 8.1.4 through 8.1.9 and 8.2.0 through 8.2.2 allows local users with SELECT privileges to conduct unauthorized activities and insert, update or delete table contents.</descript></desc><loss_types><int/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY73104&amp;apar=only">IY73104</ref></refs><vuln_soft><prod name="DB2" vendor="IBM"><vers num="8.1.4"/><vers num="8.1.5"/><vers num="8.1.6"/><vers num="8.1.7"/><vers num="8.1.8a"/><vers num="8.1.9"/><vers num="8.2.0"/><vers num="8.2.1"/><vers num="8.2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2074" published="2005-06-29" seq="2005-2074" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in PHP-Fusion 6.0.105 allows remote attackers to inject arbitrary web script or HTML via a news or article post, possibly involving the (1) news_body, (2) article_description, or (3) article_body parameters to submit.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="MISC" url="http://dark-assassins.com/forum/viewtopic.php?t=145">http://dark-assassins.com/forum/viewtopic.php?t=145</ref><ref source="BID" url="http://www.securityfocus.com/bid/14066">14066</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/0888">ADV-2005-0888</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/15830">15830</ref></refs><vuln_soft><prod name="PHP_Fusion" vendor="PHP_Fusion"><vers num="6.0.105"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2075" published="2005-06-29" seq="2005-2075" severity="Medium" type="CVE"><desc><descript source="cve">PHP-Fusion 5.0 and 6.0 stores the database file with a predictable filename under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request to the filename in the administration/db_backups directory in PHP-Fusion 6.0 or the fusion_admin/db_backups directory in 5.0.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MISC" url="http://dark-assassins.com/forum/viewtopic.php?t=142">http://dark-assassins.com/forum/viewtopic.php?t=142</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/0888">ADV-2005-0888</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/15830">15830</ref></refs><vuln_soft><prod name="PHP_Fusion" vendor="PHP_Fusion"><vers num="5.0"/><vers num="6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2076" published="2005-06-29" seq="2005-2076" severity="Low" type="CVE"><desc><descript source="cve">HP Version Control Repository Manager (VCRM) before 2.1.1.730 does not properly handle the &quot;@&quot; character in a proxy password, which could allow attackers with physical access to obtain portions of the password when it is displayed to the screen.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="HP" url="http://www.securityfocus.com/advisories/8734">HPSBMA01166</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/14032">14032</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1014267">1014267</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/15790">15790</ref></refs><vuln_soft><prod name="Version Control Repository Manager" vendor="HP"><vers num="2.1.1.720"/><vers num="2.1.1.7.10"/><vers num="2.0.1.30"/><vers num="2.0.0.50"/><vers num="1.0.3086.0"/><vers num="1.0.3085.0"/><vers num="1.0.2345.0"/><vers num="1.0.2289.0"/><vers num="1.0.2241.0"/><vers num="1.0.1288.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2077" published="2005-06-29" seq="2005-2077" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in error.asp for Hosting Controller allows remote attackers to inject arbitrary web script or HTML via the error parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/14080">14080</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/419597/100/0/threaded">20051215 Bug in HC</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111997456519685&amp;w=2">20050628 Cross-Site Scripting (CSS)  in Hosting Controller All Version and hot fix it hehe ;)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1016456">1016456</ref></refs><vuln_soft><prod name="Hosting Controller" vendor="Hosting Controller"><vers num="6.1 HotFix 2.0"/><vers num="6.1 Hotfix 1.9"/><vers num="6.1 Hotfix 1.7"/><vers num="6.1 Hotfix 1.4"/><vers num="6.1"/><vers num="1.4.1"/><vers num="1.4b"/><vers num="1.4"/><vers num="1.3"/><vers num="1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2078" published="2005-06-29" seq="2005-2078" severity="Low" type="CVE"><desc><descript source="cve">BisonFTP Server V4R1 allows remote authenticated users to cause a denial of service via an invalid command with a long argument.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><exception/></vuln_types><range><local/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/14079">14079</ref></refs><vuln_soft><prod name="BisonFTP" vendor="SofoTex"><vers num="V4R1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-03-27" name="CVE-2005-2079" published="2005-08-02" seq="2005-2079" severity="High" type="CVE"><desc><descript source="cve">Heap-based buffer overflow in the Admin Plus Pack Option for VERITAS Backup Exec 9.0 through 10.0 for Windows Servers allows remote attackers to execute arbitrary code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://seer.support.veritas.com/docs/276607.htm">http://seer.support.veritas.com/docs/276607.htm</ref><ref patch="1" source="" url="http://seer.support.veritas.com/docs/277429.htm">http://seer.support.veritas.com/docs/277429.htm</ref><ref adv="1" patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA05-180A.html">TA05-180A</ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/352625">VU#352625</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/15789">15789</ref><ref source="BID" url="http://www.securityfocus.com/bid/14023">14023</ref></refs><vuln_soft><prod name="Backup Exec" vendor="Symantec Veritas"><vers num="10.0 rev.5484"/><vers num="9.1 rev.4691"/><vers num="9.0 rev.4454"/><vers num="9.0 rev.4367"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-03-27" name="CVE-2005-2080" published="2005-06-29" seq="2005-2080" severity="High" type="CVE"><desc><descript source="cve">Unknown vulnerability in Remote Agent for Windows Servers (RAWS) in VERITAS Backup Exec 9.0 through 10.0 for Windows, and 9.0.4019 through 9.1.307 for NetWare, allows remote attackers to gain privileges by copying the handle for the server.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://seer.support.veritas.com/docs/276608.htm">http://seer.support.veritas.com/docs/276608.htm</ref><ref patch="1" source="" url="http://seer.support.veritas.com/docs/277429.htm">http://seer.support.veritas.com/docs/277429.htm</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/15789">15789</ref><ref source="BID" url="http://www.securityfocus.com/bid/14026">14026</ref></refs><vuln_soft><prod name="Backup Exec" vendor="Symantec Veritas"><vers num="10.0"/><vers num="9.1"/><vers num="9.0"/><vers num="9.1.307"/><vers num="9.1.306"/><vers num="9.1.1154"/><vers num="9.1.1152.4"/><vers num="9.1.1152"/><vers num="9.1.1151.1"/><vers num="9.1.1127.1"/><vers num="9.1.1067.3"/><vers num="9.1.1067.2"/><vers num="9.0.4202"/><vers num="9.0.4174"/><vers num="9.0.4172"/><vers num="9.0.4170"/><vers num="9.0.4019"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2081" published="2005-07-05" seq="2005-2081" severity="Medium" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in the function that parses commands in Asterisk 1.0.7, when the &apos;write = command&apos; option is enabled, allows remote attackers to execute arbitrary code via a command that has two double quotes followed by a tab character.</descript></desc><loss_types><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111946399501080&amp;w=2">20050622 Portcullis Security Advisory 05-013 - VoIP - Asterisk Stack Overflow</ref><ref adv="1" source="MISC" url="http://www.portcullis-security.com/advisory/advisory-05-013.txt">http://www.portcullis-security.com/advisory/advisory-05-013.txt</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/21115">asterisk-manager-interface-bo(21115)</ref></refs><vuln_soft><prod name="Asterisk" vendor="Digium"><vers num="1.0.7"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2082" published="2005-07-05" seq="2005-2082" severity="Medium" type="CVE"><desc><descript source="cve">im_trbbs.cgi in imTRSET 1.02 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the df parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112006605026261&amp;w=2">20050629 Original imTRBBS(ver1.02) and prior remote command execution</ref><ref source="" url="http://www.cgi-club.com/imTRBBS/">http://www.cgi-club.com/imTRBBS/</ref></refs><vuln_soft><prod name="imTRSET" vendor="cgi-club"><vers num="1.02"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-08-31" name="CVE-2005-2083" published="2005-07-05" seq="2005-2083" severity="Medium" type="CVE"><desc><descript source="cve">Format string vulnerability in IMAP4 in IA eMailServer Corporate Edition 5.2.2 build 1051 allows remote attackers to cause a denial of service (application crash) via a LIST command with format string specifiers as the second argument.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111988945819448&amp;w=2">20050627 Denial of Service Vulnerability in True North Software, Inc. IA eMailServer Corporate Edition Version: 5.2.2. Build: 1051</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/alerts/2005/Jun/1014301.html">1014301</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/21169">emailserver-list-dos(21169)</ref></refs><vuln_soft><prod name="IA eMailServer" vendor="TrueNorth Software"><vers num="Corporate 5.3.4 build 2018"/><vers num="Corporate 5.3.3"/><vers num="Corporate 5.3.2"/><vers num="Corporate 5.3.1"/><vers num="Corporate 5.2.3 build 1056"/><vers num="Corporate 5.2.2 build 1051"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2084" published="2005-07-05" seq="2005-2084" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in SearchResults.aspx in Community Forum allows remote attackers to inject arbitrary web script or HTML via the q parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111998009409469&amp;w=2">20050627 XSS IN Community forum</ref><ref source="BID" url="http://securityfocus.org/bid/14078/info"></ref></refs><vuln_soft><prod name="Community Server Forums" vendor="Telligent Systems"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-05-01" name="CVE-2005-2085" published="2005-07-05" seq="2005-2085" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in Inframail Advantage Server Edition 6.0 through 6.7 allows remote attackers to cause a denial of service (process crash) via a long (1) SMTP FROM field or possibly (2) FTP NLST command.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111998161006731&amp;w=2">20050628 Multiple buffer overflows exist in Infradig Systems Inframail Advantage Server Edition 6.0</ref></refs><vuln_soft><prod name="Inframail Advantage" vendor="Infradig Systems"><vers num="Server 6.0"/><vers num="Server 6.7"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2086" published="2005-07-05" seq="2005-2086" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in viewtopic.php in phpBB 2.0.15 and earlier allows remote attackers to execute arbitrary PHP code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/><design/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111999905917019&amp;w=2">20050628 Security Advisory - phpBB 2.0.15 PHP-code injection bug</ref><ref patch="1" source="" url="http://www.phpbb.com/phpBB/viewtopic.php?f=14&amp;t=302011">http://www.phpbb.com/phpBB/viewtopic.php?f=14&amp;t=302011</ref></refs><vuln_soft><prod name="phpBB" vendor="phpBB Group"><vers num="2.0.15"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-06-15" name="CVE-2005-2087" published="2005-07-05" seq="2005-2087" severity="Medium" type="CVE"><desc><descript source="cve">Internet Explorer 5.01 SP4 up to 6 on various Windows operating systems, including IE 6.0.2900.2180 on Windows XP, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a web page with embedded CLSIDs that reference certain COM objects that are not ActiveX controls, as demonstrated using the JVIEW Profiler (Javaprxy.dll).  NOTE: the researcher says that the vendor could not reproduce this problem.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112006764714946&amp;w=2">20050629 SEC-CONSULT SA-20050629-0</ref><ref source="MISC" url="http://www.microsoft.com/technet/security/advisory/903144.mspx">http://www.microsoft.com/technet/security/advisory/903144.mspx</ref><ref source="MS" url="http://www.microsoft.com/technet/Security/bulletin/ms05-037.mspx">MS05-037</ref><ref source="AUSCERT" url="http://www.auscert.org.au/render.html?it=5225">ESB-2005.0489</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/939605">VU#939605</ref><ref source="BID" url="http://www.securityfocus.com/bid/14087">14087</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/0935">ADV-2005-0935</ref><ref source="OSVDB" url="http://www.osvdb.org/17680">17680</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014329">1014329</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15891">15891</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/21193">ie-javaprxydll-execute-code(21193)</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA05-193A.html">TA05-193A</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1326.html">OVAL1326</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1506.html">OVAL1506</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1518.html">OVAL1518</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval793.html">OVAL793</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/404055">20050702 Microsoft Internet Explorer </ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1326">oval:org.mitre.oval:def:1326</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1506">oval:org.mitre.oval:def:1506</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1518">oval:org.mitre.oval:def:1518</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:793">oval:org.mitre.oval:def:793</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/959049">
VU#959049</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="6.0.2900.2180"/><vers num="6.0"/><vers edition="Windows Server 2003 SP1" num="6"/><vers num="5.5 SP2"/><vers num="5.5 SP1"/><vers num="5.5 preview"/><vers num="5.5"/><vers edition="Macintosh" num="5.2.3"/><vers edition="Mac OS" num="5.1"/><vers num="5.1"/><vers num="5.01 SP4"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-06-15" name="CVE-2005-2088" published="2005-07-05" seq="2005-2088" severity="Medium" type="CVE"><desc><descript source="cve">The Apache HTTP server before 1.3.34, and 2.0.x before 2.0.55, when acting as an HTTP proxy, allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a &quot;Transfer-Encoding: chunked&quot; header and a Content-Length header, which causes Apache to incorrectly handle and forward the body of the request in a way that causes the receiving server to process it as a separate HTTP request, aka &quot;HTTP Request Smuggling.&quot;</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://seclists.org/lists/bugtraq/2005/Jun/0025.html">20050606 A new whitepaper by Watchfire - HTTP Request Smuggling</ref><ref source="MISC" url="http://www.watchfire.com/resources/HTTP-Request-Smuggling.pdf">http://www.watchfire.com/resources/HTTP-Request-Smuggling.pdf</ref><ref source="MISC" url="http://www.securiteam.com/securityreviews/5GP0220G0U.html">http://www.securiteam.com/securityreviews/5GP0220G0U.html</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014323">1014323</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-803">DSA-803</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-805">DSA-805</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-160-2">USN-160-2</ref><ref source="TRUSTIX" url="http://lists.trustix.org/pipermail/tsl-announce/2005-October/000354.html">TSLSA-2005-0059</ref><ref source="APPLE" url="http://docs.info.apple.com/article.html?artnum=302847">APPLE-SA-2005-11-29</ref><ref source="BID" url="http://www.securityfocus.com/bid/15647">15647</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17813">17813</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval840.html">OVAL840</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14530">14530</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17487">17487</ref><ref source="BID" url="http://www.securityfocus.com/bid/14106">14106</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/2140">ADV-2005-2140</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/2659">ADV-2005-2659</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102197-1">102197</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102198-1">102198</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0789">ADV-2006-0789</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19072">19072</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19073">19073</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-582.html">RHSA-2005:582</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/428138/100/0/threaded">HPSBUX02074</ref><ref source="" url="http://www.apache.org/dist/httpd/CHANGES_1.3"></ref><ref source="" url="http://www.apache.org/dist/httpd/CHANGES_2.0"></ref><ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=c00612828">HPSBUX02101</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1018">ADV-2006-1018</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19317">19317</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17319">17319</ref><ref source="MLIST" url="http://marc2.theaimsgroup.com/?l=apache-httpd-announce&amp;m=112931556417329&amp;w=3">[apache-httpd-announce] 20051014 Apache HTTP Server 2.0.55 Released</ref><ref source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=PK13959&amp;apar=only">PK13959</ref><ref source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=PK16139&amp;apar=only">PK16139</ref><ref source="SLACKWARE" url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2005&amp;m=slackware-security.600000">SSA:2005-310-04</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-081.htm"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/19185">19185</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_46_apache.html">SUSE-SA:2005:046</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_18_sr.html">SUSE-SR:2005:018</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:840">oval:org.mitre.oval:def:840</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1526">oval:org.mitre.oval:def:1526</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1629">oval:org.mitre.oval:def:1629</ref><ref source="" url="https://secure-support.novell.com/KanisaPlatform/Publishing/741/3222109_f.SAL_Public.html"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/23074">23074</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/4680">ADV-2006-4680</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2005:130">
MDKSA-2005:130</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:130">MDKSA-2005:130</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1237">oval:org.mitre.oval:def:1237</ref><ref source="SREASON" url="http://securityreason.com/securityalert/604">604</ref></refs><vuln_soft><prod name="Apache" vendor="Apache Software Foundation"><vers num="1.3.29"/><vers num="2.0.45"/><vers num="1.3.33"/><vers num="1.3.32"/><vers num="1.3.31"/><vers num="1.3.30"/><vers num="2.0.54"/><vers num="2.0.53"/><vers num="2.0.52"/><vers num="2.0.51"/><vers num="2.0.50"/><vers num="2.0.49"/><vers num="2.0.48"/><vers num="2.0.47"/><vers num="2.0.46"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2089" published="2005-07-05" seq="2005-2089" severity="Medium" type="CVE"><desc><descript source="cve">Microsoft IIS 5.0 and 6.0 allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a &quot;Transfer-Encoding: chunked&quot; header and a Content-Length header, which causes IIS to incorrectly handle and forward the body of the request in a way that causes the receiving server to process it as a separate HTTP request, aka &quot;HTTP Request Smuggling.&quot;</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://seclists.org/lists/bugtraq/2005/Jun/0025.html">20050606 A new whitepaper by Watchfire - HTTP Request Smuggling</ref><ref source="MISC" url="http://www.watchfire.com/resources/HTTP-Request-Smuggling.pdf">http://www.watchfire.com/resources/HTTP-Request-Smuggling.pdf</ref><ref source="MISC" url="http://www.securiteam.com/securityreviews/5GP0220G0U.html">http://www.securiteam.com/securityreviews/5GP0220G0U.html</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/42899">microsoft-iis-hrs(42899)</ref></refs><vuln_soft><prod name="IIS" vendor="Microsoft"><vers num="5.0"/><vers num="6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2090" published="2005-07-05" seq="2005-2090" severity="Medium" type="CVE"><desc><descript source="cve">Jakarta Tomcat 5.0.19 (Coyote/1.1) and Tomcat 4.1.24 (Coyote/1.0) allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a &quot;Transfer-Encoding: chunked&quot; header and a Content-Length header, which causes Tomcat to incorrectly handle and forward the body of the request in a way that causes the receiving server to process it as a separate HTTP request, aka &quot;HTTP Request Smuggling.&quot;</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://seclists.org/lists/bugtraq/2005/Jun/0025.html">20050606 A new whitepaper by Watchfire - HTTP Request Smuggling</ref><ref source="MISC" url="http://www.watchfire.com/resources/HTTP-Request-Smuggling.pdf">http://www.watchfire.com/resources/HTTP-Request-Smuggling.pdf</ref><ref source="MISC" url="http://www.securiteam.com/securityreviews/5GP0220G0U.html">http://www.securiteam.com/securityreviews/5GP0220G0U.html</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014365">1014365</ref><ref source="" url="http://tomcat.apache.org/security-4.html"></ref><ref source="" url="http://tomcat.apache.org/security-5.html"></ref><ref source="" url="http://tomcat.apache.org/security-6.html"></ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0327.html">
RHSA-2007:0327</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=306172"></ref><ref source="" url="http://www.fujitsu.com/global/support/software/security/products-f/interstage-200703e.html"></ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2007-206.htm"></ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce//2007/Jul/msg00004.html">APPLE-SA-2007-07-31</ref><ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01178795">HPSBUX02262</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0360.html">RHSA-2007:0360</ref><ref source="BID" url="http://www.securityfocus.com/bid/25159">25159</ref><ref source="BID" url="http://www.securityfocus.com/bid/13873">13873</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/2732">ADV-2007-2732</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/3087">ADV-2007-3087</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/3386">ADV-2007-3386</ref><ref source="SECUNIA" url="http://secunia.com/advisories/26235">26235</ref><ref source="SECUNIA" url="http://secunia.com/advisories/26660">26660</ref><ref source="SECUNIA" url="http://secunia.com/advisories/27037">27037</ref><ref source="MLIST" url="http://lists.vmware.com/pipermail/security-announce/2008/000003.html">[Security-announce] 20080107 VMSA-2008-0002 Low severity security update for VirtualCenter and ESX Server 3.0.2, and ESX 3.0.1</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0065">ADV-2008-0065</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28365">28365</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/485938/100/0/threaded">20080108 VMSA-2008-0002 Low severity security update for VirtualCenter and ESX Server 3.0.2, and ESX 3.0.1</ref><ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2008-03/msg00001.html">SUSE-SR:2008:005</ref><ref source="SECUNIA" url="http://secunia.com/advisories/29242">29242</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2008-0261.html">RHSA-2008:0261</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-239312-1">239312</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/1979/references">ADV-2008-1979</ref><ref source="SECUNIA" url="http://secunia.com/advisories/30908">30908</ref><ref source="SECUNIA" url="http://secunia.com/advisories/30899">30899</ref></refs><vuln_soft><prod name="Coyote" vendor="Apache Software Foundation"><vers num="1.1"/><vers num="1.0"/></prod><prod name="Tomcat" vendor="Apache Software Foundation"><vers num="5.0.19"/><vers num="4.1.24"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2091" published="2005-07-05" seq="2005-2091" severity="Medium" type="CVE"><desc><descript source="cve">IBM WebSphere 5.1 and WebSphere 5.0 allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a &quot;Transfer-Encoding: chunked&quot; header and a Content-Length header, which causes WebSphere to incorrectly handle and forward the body of the request in a way that causes the receiving server to process it as a separate HTTP request, aka &quot;HTTP Request Smuggling.&quot;</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://seclists.org/lists/bugtraq/2005/Jun/0025.html">20050606 A new whitepaper by Watchfire - HTTP Request Smuggling</ref><ref source="MISC" url="http://www.watchfire.com/resources/HTTP-Request-Smuggling.pdf">http://www.watchfire.com/resources/HTTP-Request-Smuggling.pdf</ref><ref source="MISC" url="http://www.securiteam.com/securityreviews/5GP0220G0U.html">http://www.securiteam.com/securityreviews/5GP0220G0U.html</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014367">1014367</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/42898">ibm-websphere-hrs(42898)</ref></refs><vuln_soft><prod name="WebSphere Application Server" vendor="IBM"><vers num="5.1.0"/><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2092" published="2005-07-05" seq="2005-2092" severity="Medium" type="CVE"><desc><descript source="cve">BEA Systems WebLogic 8.1 SP1 allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a &quot;Transfer-Encoding: chunked&quot; header and a Content-Length header, which causes WebLogic to incorrectly handle and forward the body of the request in a way that causes the receiving server to process it as a separate HTTP request, aka &quot;HTTP Request Smuggling.&quot;</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://seclists.org/lists/bugtraq/2005/Jun/0025.html">20050606 A new whitepaper by Watchfire - HTTP Request Smuggling</ref><ref source="MISC" url="http://www.watchfire.com/resources/HTTP-Request-Smuggling.pdf">http://www.watchfire.com/resources/HTTP-Request-Smuggling.pdf</ref><ref source="MISC" url="http://www.securiteam.com/securityreviews/5GP0220G0U.html">http://www.securiteam.com/securityreviews/5GP0220G0U.html</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014366">1014366</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/42901">bea-weblogic-hrs(42901)</ref></refs><vuln_soft><prod name="WebLogic Server" vendor="BEA Systems"><vers num="8.1 SP1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2093" published="2005-07-05" seq="2005-2093" severity="Medium" type="CVE"><desc><descript source="cve">Oracle 9i Application Server (Oracle9iAS) 9.0.2 allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a &quot;Transfer-Encoding: chunked&quot; header and a Content-Length header, which causes Application Server to incorrectly handle and forward the body of the request in a way that causes the receiving server to process it as a separate HTTP request, aka &quot;HTTP Request Smuggling.&quot;</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://seclists.org/lists/bugtraq/2005/Jun/0025.html">20050606 A new whitepaper by Watchfire - HTTP Request Smuggling</ref><ref source="MISC" url="http://www.watchfire.com/resources/HTTP-Request-Smuggling.pdf">http://www.watchfire.com/resources/HTTP-Request-Smuggling.pdf</ref><ref source="MISC" url="http://www.securiteam.com/securityreviews/5GP0220G0U.html">http://www.securiteam.com/securityreviews/5GP0220G0U.html</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/42902">oracle-applicationserver-hrs(42902)</ref></refs><vuln_soft><prod name="Oracle9i Application Server" vendor="Oracle"><vers num="9.0.2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2094" published="2005-07-05" seq="2005-2094" severity="Medium" type="CVE"><desc><descript source="cve">Sun SunONE web server 6.1 SP1 allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a &quot;Transfer-Encoding: chunked&quot; header and a Content-Length header, which causes SunONE to incorrectly handle and forward the body of the request in a way that causes the receiving server to process it as a separate HTTP request, aka &quot;HTTP Request Smuggling.&quot;</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://seclists.org/lists/bugtraq/2005/Jun/0025.html">20050606 A new whitepaper by Watchfire - HTTP Request Smuggling</ref><ref source="MISC" url="http://www.watchfire.com/resources/HTTP-Request-Smuggling.pdf">http://www.watchfire.com/resources/HTTP-Request-Smuggling.pdf</ref><ref source="MISC" url="http://www.securiteam.com/securityreviews/5GP0220G0U.html">http://www.securiteam.com/securityreviews/5GP0220G0U.html</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014369">1014369</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/42903">sun-sunone-hrs(42903)</ref></refs><vuln_soft><prod name="ONE Web Server" vendor="Sun"><vers num="6.1 SP1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-06-15" name="CVE-2005-2095" published="2005-07-13" seq="2005-2095" severity="Medium" type="CVE"><desc><descript source="cve">options_identities.php in SquirrelMail 1.4.4 and earlier uses the extract function to process the $_POST variable, which allows remote attackers to modify or read the preferences of other users, conduct cross-site scripting XSS) attacks, and write arbitrary files.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-756">DSA-756</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/Aug/msg00000.html">APPLE-SA-2005-08-15</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2005//Aug/msg00001.html">APPLE-SA-2005-08-17</ref><ref source="FEDORA" url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=163047">FLSA:163047</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/405202">20050714 SquirrelMail Arbitrary Variable Overwriting Vulnerability</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/405200">20050714 [SM-ANNOUNCE] Patch available for CAN-2005-2095</ref><ref source="" url="http://www.squirrelmail.org/security/issue/2005-07-13"></ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-595.html">RHSA-2005:595</ref><ref source="BID" url="http://www.securityfocus.com/bid/14254">14254</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/21359">squirrelmail-set-post-variable(21359)</ref><ref source="" url="http://www.gulftech.org/?node=research&amp;article_id=00090-07142005"></ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_18_sr.html">SUSE-SR:2005:018</ref></refs><vuln_soft><prod name="SquirrelMail" vendor="SquirrelMail"><vers num="1.44"/><vers num="1.4.3 RC1"/><vers num="1.4.3a"/><vers num="1.4.3"/><vers num="1.4.2"/><vers num="1.4.1"/><vers num="1.4.0"/><vers num="1.4"/><vers num="1.2.9"/><vers num="1.2.8"/><vers num="1.2.7"/><vers num="1.2.6"/><vers num="1.2.5"/><vers num="1.2.4"/><vers num="1.2.3"/><vers num="1.2.2"/><vers num="1.2.11"/><vers num="1.2.10"/><vers num="1.2.1"/><vers num="1.2.0"/><vers num="1.0.5"/><vers num="1.0.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2096" published="2005-07-06" seq="2005-2096" severity="High" type="CVE"><desc><descript source="cve">zlib 1.2 and later versions allows remote attackers to cause a denial of service (crash) via a crafted compressed stream with an incomplete code description of a length greater than 1, which leads to a buffer overflow, as demonstrated using a crafted PNG file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-740">DSA-740</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-569.html">RHSA-2005:569</ref><ref adv="1" patch="1" source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200507-05.xml">GLSA-200507-05</ref><ref adv="1" source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-148-1">USN-148-1</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/14162">14162</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/0978">ADV-2005-0978</ref><ref adv="1" source="SECTRACK" url="http://securitytracker.com/id?1014398">1014398</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/15949">15949</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/Aug/msg00000.html">APPLE-SA-2005-08-15</ref><ref adv="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2005//Aug/msg00001.html">APPLE-SA-2005-08-17</ref><ref adv="1" source="FEDORA" url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=162680">FLSA:162680</ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200509-18.xml">GLSA-200509-18</ref><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-797">DSA-797</ref><ref adv="1" source="" url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=162391"></ref><ref source="FREEBSD" url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-05:16.zlib.asc">FreeBSD-SA-05:16.zlib</ref><ref adv="1" patch="1" source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101989-1">101989</ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/680620">VU#680620</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/usn/usn-151-3">USN-151-3</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/421411/100/0/threaded">HPSBUX02090</ref><ref source="SCO" url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2006.6/SCOSA-2006.6.txt">SCOSA-2006.6</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0144">ADV-2006-0144</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18406">18406</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18377">18377</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2005:196">MDKSA-2005:196</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17054">17054</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17225">17225</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17236">17236</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17326">17326</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17516">17516</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19550">19550</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1026">DSA-1026</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-016.htm"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/18507">18507</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:070">MDKSA-2006:070</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1262">oval:org.mitre.oval:def:1262</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1542">oval:org.mitre.oval:def:1542</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19597">
19597</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24064">
hpux-secure-shell-dos(24064)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/464745/100/0/threaded">

20070404 VMSA-2007-0003 VMware ESX 3.0.1 and 3.0.0 server security updates</ref><ref source="" url="http://www.vmware.com/support/vi3/doc/esx-3616065-patch.html"></ref><ref source="" url="http://www.vmware.com/support/vi3/doc/esx-9916286-patch.html"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1267">
ADV-2007-1267</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24788">
24788</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/482949/100/0/threaded">20071029 Re: Windows binary of &quot;GSview 4.8&quot; contain vulnerable zlib (CAN-2005-2096)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/482950/100/0/threaded">20071029 Windows binary of &quot;Virtual Floppy Drive 2.1&quot; contains vulnerable zlib (CAN-2005-2096)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/482505/100/0/threaded">20071018 Official Windows binaries of &quot;curl&quot; contain vulnerable zlib 1.2.2 (CAN-2005-2096)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/482503/100/0/threaded">20071018 Windows binary of &quot;GSview 4.8&quot; contain vulnerable zlib (CAN-2005-2096)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/482571/100/0/threaded">20071020 Re: Windows binary of &quot;GSview 4.8&quot; contain vulnerable zlib (CAN-2005-2096)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/482601/100/0/threaded">20071021 Re: Windows binary of &quot;GSview 4.8&quot; contain vulnerable zlib (CAN-2005-2096)</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:112">MDKSA-2005:112</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:196">MDKSA-2005:196</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:070">MDKSA-2006:070</ref></refs><vuln_soft><prod name="zlib" vendor="Gnu"><vers num="1.2.2"/><vers num="1.2.1"/><vers num="1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2007-02-20" name="CVE-2005-2097" published="2005-08-16" seq="2005-2097" severity="Low" type="CVE"><desc><descript source="cve">xpdf and kpdf do not properly validate the &quot;loca&quot; table in PDF files, which allows local users to cause a denial of service (disk consumption and hang) via a PDF file with a &quot;broken&quot; loca table, which causes a large temporary file to be created when xpdf attempts to reconstruct the information.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><local/></range><refs><ref adv="1" source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-163-1">USN-163-1</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-780">DSA-780</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:138">MDKSA-2005:138</ref><ref source="BID" url="http://www.securityfocus.com/bid/14529">14529</ref><ref source="SCO" url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.42/SCOSA-2005.42.txt">SCOSA-2005.42</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/17277">17277</ref><ref adv="1" source="DEBIAN" url="http://www.debian.org/security/2006/dsa-936">DSA-936</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18398">18398</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18407">18407</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-670.html">RHSA-2005:670</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-671.html">RHSA-2005:671</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-706.html">RHSA-2005:706</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-708.html">RHSA-2005:708</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/427990/100/0/threaded">FLSA:175404</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/427053/100/0/threaded">FLSA-2006:176751</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_19_sr.html">SUSE-SR:2005:019</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1136">DSA-1136</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21339">21339</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102972-1">102972</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/2280">ADV-2007-2280</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25729">25729</ref></refs><vuln_soft><prod name="Xpdf" vendor="Xpdf"><vers num="3.0 pl3"/><vers num="3.0 pl2"/><vers num="3.0"/></prod><prod name="kpdf" vendor="KDE"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2098" published="2005-08-23" seq="2005-2098" severity="Medium" type="CVE"><desc><descript source="cve">The KEYCTL_JOIN_SESSION_KEYRING operation in the Linux kernel before 2.6.12.5 contains an error path that does not properly release the session management semaphore, which allows local users or remote attackers to cause a denial of service (semaphore hang) via a new session keyring (1) with an empty name string, (2) with a long name string, (3) with the key quota reached, or (4) ENOMEM.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="KERNEL" url="http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.12.5"></ref><ref adv="1" source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-169-1">USN-169-1</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/16355/">16355</ref><ref source="MANDRAKE" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2005:220">MDKSA-2005:220</ref><ref source="BID" url="http://www.securityfocus.com/bid/14521">14521</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-514.html">RHSA-2005:514</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/427980/100/0/threaded">FLSA:157459-3</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17073">17073</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:220">MDKSA-2005:220</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.6 test9 CVS"/><vers num="2.6 test9"/><vers num="2.6 test8"/><vers num="2.6 test7"/><vers num="2.6 test6"/><vers num="2.6 test5"/><vers num="2.6 test4"/><vers num="2.6 test3"/><vers num="2.6 test2"/><vers num="2.6 test11"/><vers num="2.6 test10"/><vers num="2.6 test1"/><vers edition="2.6.20" num="2.6.9"/><vers edition="PowerPC_smp" num="2.6.8.1.5"/><vers edition="PowerPC" num="2.6.8.1.5"/><vers edition="Power4_smp" num="2.6.8.1.5"/><vers edition="Power4" num="2.6.8.1.5"/><vers edition="Power3_smp" num="2.6.8.1.5"/><vers edition="Power3" num="2.6.8.1.5"/><vers edition="K7_smp" num="2.6.8.1.5"/><vers edition="K7" num="2.6.8.1.5"/><vers edition="AMD64_Xeon" num="2.6.8.1.5"/><vers edition="AMD64_K8_smp" num="2.6.8.1.5"/><vers edition="AMD64_K8" num="2.6.8.1.5"/><vers edition="AMD64" num="2.6.8.1.5"/><vers edition="686_smp" num="2.6.8.1.5"/><vers edition="686" num="2.6.8.1.5"/><vers edition="386" num="2.6.8.1.5"/><vers num="2.6.8.1.5"/><vers num="2.6.8.1"/><vers num="2.6.8 rc3"/><vers num="2.6.8 rc2"/><vers num="2.6.8 rc1"/><vers num="2.6.8"/><vers num="2.6.7 rc1"/><vers num="2.6.7"/><vers num="2.6.6 rc1"/><vers num="2.6.6"/><vers num="2.6.5"/><vers num="2.6.4"/><vers num="2.6.3"/><vers num="2.6.2"/><vers num="2.6.12 rc4"/><vers num="2.6.12 rc1"/><vers num="2.6.11 rc4"/><vers num="2.6.11 rc3"/><vers num="2.6.11 rc2"/><vers num="2.6.11 rc1 bk6"/><vers num="2.6.11.8"/><vers num="2.6.11.7"/><vers num="2.6.11.6"/><vers num="2.6.11.5"/><vers num="2.6.11.4"/><vers num="2.6.11.3"/><vers num="2.6.11.2"/><vers num="2.6.11.1"/><vers num="2.6.11"/><vers num="2.6.10 rc2"/><vers num="2.6.10"/><vers num="2.6.1 rc2"/><vers num="2.6.1 rc1"/><vers num="2.6.1"/><vers num="2.6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-06-14" name="CVE-2005-2099" published="2005-08-23" seq="2005-2099" severity="Medium" type="CVE"><desc><descript source="cve">The Linux kernel before 2.6.12.5 does not properly destroy a keyring that is not instantiated properly, which allows local users or remote attackers to cause a denial of service (kernel oops) via a keyring with a payload that is not empty, which causes the creation to fail, leading to a null dereference in the keyring destructor.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="KERNEL" url="http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.12.5"></ref><ref adv="1" source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-169-1">USN-169-1</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/16355/">16355</ref><ref source="MANDRAKE" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2005:220">MDKSA-2005:220</ref><ref source="BID" url="http://www.securityfocus.com/bid/14517">14517</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014644">1014644</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-514.html">RHSA-2005:514</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/427980/100/0/threaded">FLSA:157459-3</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17073">17073</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:220">MDKSA-2005:220</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.6 test9 CVS"/><vers num="2.6 test9"/><vers num="2.6 test8"/><vers num="2.6 test7"/><vers num="2.6 test6"/><vers num="2.6 test5"/><vers num="2.6 test4"/><vers num="2.6 test3"/><vers num="2.6 test2"/><vers num="2.6 test11"/><vers num="2.6 test10"/><vers num="2.6 test1"/><vers edition="2.6.20" num="2.6.9"/><vers edition="PowerPC_smp" num="2.6.8.1.5"/><vers edition="PowerPC" num="2.6.8.1.5"/><vers edition="Power4_smp" num="2.6.8.1.5"/><vers edition="Power4" num="2.6.8.1.5"/><vers edition="Power3_smp" num="2.6.8.1.5"/><vers edition="Power3" num="2.6.8.1.5"/><vers edition="K7_smp" num="2.6.8.1.5"/><vers edition="K7" num="2.6.8.1.5"/><vers edition="AMD64_Xeon" num="2.6.8.1.5"/><vers edition="AMD64_K8_smp" num="2.6.8.1.5"/><vers edition="AMD64_K8" num="2.6.8.1.5"/><vers edition="AMD64" num="2.6.8.1.5"/><vers edition="686_smp" num="2.6.8.1.5"/><vers edition="686" num="2.6.8.1.5"/><vers edition="386" num="2.6.8.1.5"/><vers num="2.6.8.1.5"/><vers num="2.6.8.1"/><vers num="2.6.8 rc3"/><vers num="2.6.8 rc2"/><vers num="2.6.8 rc1"/><vers num="2.6.8"/><vers num="2.6.7 rc1"/><vers num="2.6.7"/><vers num="2.6.6 rc1"/><vers num="2.6.6"/><vers num="2.6.5"/><vers num="2.6.4"/><vers num="2.6.3"/><vers num="2.6.2"/><vers num="2.6.12 rc4"/><vers num="2.6.12 rc1"/><vers num="2.6.11 rc4"/><vers num="2.6.11 rc3"/><vers num="2.6.11 rc2"/><vers num="2.6.11 rc1 bk6"/><vers num="2.6.11.8"/><vers num="2.6.11.7"/><vers num="2.6.11.6"/><vers num="2.6.11.5"/><vers num="2.6.11.4"/><vers num="2.6.11.3"/><vers num="2.6.11.2"/><vers num="2.6.11.1"/><vers num="2.6.11"/><vers num="2.6.10 rc2"/><vers num="2.6.10"/><vers num="2.6.1 rc2"/><vers num="2.6.1 rc1"/><vers num="2.6.1"/><vers num="2.6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-31" name="CVE-2005-2100" published="2005-10-25" seq="2005-2100" severity="Low" type="CVE"><desc><descript source="cve">The rw_vm function in usercopy.c in the 4GB split patch for the Linux kernel in Red Hat Enterprise Linux 4 does not perform proper bounds checking, which allows local users to cause a denial of service (crash).</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/><design/></vuln_types><range><local/></range><refs><ref patch="1" source="REDHAT" url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=165547">Bugzilla Bug 165547 – CAN-2005-2100 4G/4G split bounds checking</ref><ref adv="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-514.html">RHSA-2005:514</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17073">17073</ref></refs><vuln_soft><prod name="Desktop" vendor="Red Hat"><vers num="4.0"/></prod><prod name="Enterprise Linux WS" vendor="Red Hat"><vers edition="Workstation" num="4.0"/></prod><prod name="Enterprise Linux ES" vendor="Red Hat"><vers edition="Enterprise Server" num="4.0"/></prod><prod name="Enterprise Linux AS" vendor="Red Hat"><vers edition="Advanced Server" num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2101" published="2005-08-17" seq="2005-2101" severity="Medium" type="CVE"><desc><descript source="cve">langen2kvtml in KDE 3.0 to 3.4.2 creates insecure temporary files in /tmp with predictable names, which allows local users to overwrite arbitrary files.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.kde.org/info/security/advisory-20050815-1.txt">http://www.kde.org/info/security/advisory-20050815-1.txt</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:159">MDKSA-2005:159</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-818">DSA-818</ref><ref source="BID" url="http://www.securityfocus.com/bid/14561">14561</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014675">1014675</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16428">16428</ref></refs><vuln_soft><prod name="KDE" vendor="KDE"><vers num="3.4.2"/><vers num="3.4.1"/><vers num="3.4"/><vers num="3.3.2"/><vers num="3.3.1"/><vers num="3.3"/><vers num="3.2.3"/><vers num="3.2.2"/><vers num="3.2.1"/><vers num="3.2"/><vers num="3.2.0 Beta1"/><vers num="3.1.5"/><vers num="3.1.4"/><vers num="3.1.3"/><vers num="3.1.2"/><vers num="3.1.1"/><vers num="3.1"/><vers num="3.1 Beta2"/><vers num="3.1 Beta1"/><vers num="3.1 Alpha1"/><vers num="3.0.5a"/><vers num="3.0.5"/><vers num="3.0.4"/><vers num="3.0.3"/><vers num="3.0.2"/><vers num="3.0.1"/><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2102" published="2005-08-16" seq="2005-2102" severity="Medium" type="CVE"><desc><descript source="cve">The AIM/ICQ module in Gaim before 1.5.0 allows remote attackers to cause a denial of service (application crash) via a filename that contains invalid UTF-8 characters.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="GAIM" url="http://gaim.sourceforge.net/security/?id=21">http://gaim.sourceforge.net/security/?id=21</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-168-1">USN-168-1</ref><ref source="BID" url="http://www.securityfocus.com/bid/14531">14531</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/426078/100/0/threaded">FLSA:158543</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-627.html">RHSA-2005:627</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_19_sr.html">SUSE-SR:2005:019</ref></refs><vuln_soft><prod name="Gaim" vendor="Rob Flynn"><vers num="1.3.0"/><vers num="1.2.1"/><vers num="1.2.0"/><vers num="1.1.4"/><vers num="1.1.3"/><vers num="1.1.2"/><vers num="1.1.1"/><vers num="1.1.0"/><vers num="1.0.3"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0.0"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2103" published="2005-08-16" seq="2005-2103" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the AIM and ICQ module in Gaim before 1.5.0 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via an away message with a large number of AIM substitution strings, such as %t or %n.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="GAIM" url="http://gaim.sourceforge.net/security/?id=22">http://gaim.sourceforge.net/security/?id=22</ref><ref adv="1" source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-168-1">USN-168-1</ref><ref source="BID" url="http://www.securityfocus.com/bid/14531">14531</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/426078/100/0/threaded">FLSA:158543</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-589.html">RHSA-2005:589</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-627.html">RHSA-2005:627</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_19_sr.html">SUSE-SR:2005:019</ref></refs><vuln_soft><prod name="Gaim" vendor="Rob Flynn"><vers num="1.4.0"/><vers num="1.3.1"/><vers num="1.3.0"/><vers num="1.2.1"/><vers num="1.2.0"/><vers num="1.1.4"/><vers num="1.1.3"/><vers num="1.1.2"/><vers num="1.1.1"/><vers num="1.1.0"/><vers num="1.0.3"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0.0"/><vers num="1.0"/><vers num="0.82.1"/><vers num="0.82"/><vers num="0.81"/><vers num="0.80"/><vers num="0.79"/><vers num="0.78"/><vers num="0.77"/><vers num="0.76"/><vers num="0.75"/><vers num="0.74"/><vers num="0.73"/><vers num="0.72"/><vers num="0.71"/><vers num="0.70"/><vers num="0.69"/><vers num="0.68"/><vers num="0.67"/><vers num="0.66"/><vers num="0.65"/><vers num="0.64"/><vers num="0.63"/><vers num="0.62"/><vers num="0.61"/><vers num="0.60"/><vers num="0.59.1"/><vers num="0.59"/><vers num="0.58"/><vers num="0.57"/><vers num="0.56"/><vers num="0.55"/><vers num="0.54"/><vers num="0.53"/><vers num="0.52"/><vers num="0.51"/><vers num="0.50"/><vers num="0.10.3"/><vers num="0.10"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2104" published="2005-10-07" seq="2005-2104" severity="Low" type="CVE"><desc><descript source="cve">sysreport before 1.3.7 allows local users to obtain sensitive information via a symlink attack on a temporary directory.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" source="" url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=162978"></ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-598.html">RHSA-2005:598</ref><ref source="OSVDB" url="http://www.osvdb.org/18682">18682</ref><ref adv="1" patch="1" source="SECTRACK" url="http://securitytracker.com/id?1014653">1014653</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/16381">16381</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/21770">sysreport-race-condition(21770)</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-announce-list/2005-November/msg00034.html">FEDORA-2005-1071</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-announce-list/2005-November/msg00035.html">FEDORA-2005-1072</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17539">17539</ref></refs><vuln_soft><prod name="sysreport" vendor="Red Hat"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2105" published="2005-07-05" seq="2005-2105" severity="High" type="CVE"><desc><descript source="cve">Cisco IOS 12.2T through 12.4 allows remote attackers to bypass Authentication, Authorization, and Accounting (AAA) RADIUS authentication, if the fallback method is set to none, via a long username.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-sa-20050629-aaa.shtml">20050629 RADIUS Authentication Bypass</ref><ref patch="1" source="SECTRACK" url="http://www.securitytracker.com/alerts/2005/Jun/1014330.html">1014330</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/21190">radius-authentication-bypass(21190)</ref></refs><vuln_soft><prod name="IOS" vendor="Cisco"><vers num="12.2T"/><vers num="12.2XB"/><vers num="12.2XC"/><vers num="12.2XD"/><vers num="12.2XE"/><vers num="12.2XF"/><vers num="12.2XG"/><vers num="12.2XH"/><vers num="12.2XI"/><vers num="12.2XJ"/><vers num="12.2XK"/><vers num="12.2XL"/><vers num="12.2XM"/><vers num="12.2XQ"/><vers num="12.2XR"/><vers num="12.2(2)XR"/><vers num="12.2(4)XR"/><vers num="12.2XT"/><vers num="12.2XW"/><vers num="12.2YA"/><vers num="12.2YB"/><vers num="12.2YC"/><vers num="12.2YD"/><vers num="12.2YF"/><vers num="12.2YG"/><vers num="12.2YH"/><vers num="12.2YJ"/><vers num="12.2YL"/><vers num="12.2YM"/><vers num="12.2YN"/><vers num="12.2YP"/><vers num="12.2YQ"/><vers num="12.2YR"/><vers num="12.2YT"/><vers num="12.2YU"/><vers num="12.2YV"/><vers num="12.2YW"/><vers num="12.2YY"/><vers num="12.2ZB"/><vers num="12.2ZC"/><vers num="12.2ZD"/><vers num="12.2ZE"/><vers num="12.2ZF"/><vers num="12.2ZG"/><vers num="12.2ZH"/><vers num="12.2ZJ"/><vers num="12.2ZL"/><vers num="12.2ZN"/><vers num="12.2ZO"/><vers num="12.2ZP"/><vers num="12.3B"/><vers num="12.3BC"/><vers num="12.3BW"/><vers num="12.3JA"/><vers num="12.3T"/><vers num="12.3XA"/><vers num="12.3XB"/><vers num="12.3XC"/><vers num="12.3XD"/><vers num="12.3XE"/><vers num="12.3XF"/><vers num="12.3XG"/><vers num="12.3XH"/><vers num="12.3XI"/><vers num="12.3XJ"/><vers num="12.3XK"/><vers num="12.3XL"/><vers num="12.3XM"/><vers num="12.3XN"/><vers num="12.3XQ"/><vers num="12.3XR"/><vers num="12.3XS"/><vers num="12.3XT"/><vers num="12.3XU"/><vers num="12.3XW"/><vers num="12.3XX"/><vers num="12.3XY"/><vers num="12.3YA"/><vers num="12.3YB"/><vers num="12.3YD"/><vers num="12.3YF"/><vers num="12.3YG"/><vers num="12.3YH"/><vers num="12.3YI"/><vers num="12.3YJ"/><vers num="12.3YK"/><vers num="12.3YL"/><vers num="12.3YN"/><vers num="12.3YR"/><vers num="12.3YS"/><vers num="12.3YQ"/><vers num="12.4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2106" published="2005-07-05" seq="2005-2106" severity="Medium" type="CVE"><desc><descript source="cve">Unknown vulnerability in Drupal 4.5.0 through 4.5.3, 4.6.0, and 4.6.1 allows remote attackers to execute arbitrary PHP code via a public comment or posting.</descript></desc><loss_types><int/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112015287827452&amp;w=2">20050629 [DRUPAL-SA-2005-002] Drupal 4.6.2 / 4.5.4 fixes input validation issue</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/15872">15872</ref><ref source="" url="http://www.drupal.org/security/drupal-sa-2005-002/advisory.txt">http://www.drupal.org/security/drupal-sa-2005-002/advisory.txt</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-745">DSA-745</ref><ref source="BID" url="http://www.securityfocus.com/bid/14110">14110</ref></refs><vuln_soft><prod name="Drupal" vendor="Drupal"><vers num="4.5.0"/><vers num="4.5.1"/><vers num="4.5.2"/><vers num="4.5.3"/><vers num="4.6.0"/><vers num="4.6.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2107" published="2005-07-05" seq="2005-2107" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in post.php in WordPress 1.5.1.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) p or (2) comment parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112006967221438&amp;w=2">20050629 WordPress 1.5.1.2 &amp;&amp; Earlier Multiple Vulnerabilities</ref><ref adv="1" source="MISC" url="http://www.gulftech.org/?node=research&amp;article_id=00085-06282005">http://www.gulftech.org/?node=research&amp;article_id=00085-06282005</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/15831">15831</ref></refs><vuln_soft><prod name="WordPress" vendor="WordPress"><vers num="1.5.1.2"/><vers num="1.5.1"/><vers num="1.5"/><vers num="1.2"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2108" published="2005-07-05" seq="2005-2108" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in XMLRPC server in WordPress 1.5.1.2 and earlier allows remote attackers to execute arbitrary SQL commands via input that is not filtered in the HTTP_RAW_POST_DATA variable, which stores the data in an XML file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112006967221438&amp;w=2">20050629 WordPress 1.5.1.2 &amp;&amp; Earlier Multiple Vulnerabilities</ref><ref adv="1" source="MISC" url="http://www.gulftech.org/?node=research&amp;article_id=00085-06282005">http://www.gulftech.org/?node=research&amp;article_id=00085-06282005</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/15831">15831</ref></refs><vuln_soft><prod name="WordPress" vendor="WordPress"><vers num="1.5.1.2"/><vers num="1.5.1"/><vers num="1.5"/><vers num="1.2"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2109" published="2005-07-05" seq="2005-2109" severity="Medium" type="CVE"><desc><descript source="cve">wp-login.php in WordPress 1.5.1.2 and earlier allows remote attackers to change the content of the forgotten password e-mail message via the message variable, which is not initialized before use.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112006967221438&amp;w=2">20050629 WordPress 1.5.1.2 &amp;&amp; Earlier Multiple Vulnerabilities</ref><ref adv="1" source="MISC" url="http://www.gulftech.org/?node=research&amp;article_id=00085-06282005">http://www.gulftech.org/?node=research&amp;article_id=00085-06282005</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/15831">15831</ref></refs><vuln_soft><prod name="WordPress" vendor="WordPress"><vers num="1.5.1.2"/><vers num="1.5.1"/><vers num="1.5"/><vers num="1.2"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-06-15" name="CVE-2005-2110" published="2005-07-05" seq="2005-2110" severity="Medium" type="CVE"><desc><descript source="cve">WordPress 1.5.1.2 and earlier allows remote attackers to obtain sensitive information via (1) a direct request to menu-header.php or a &quot;1&quot; value in the feed parameter to (2) wp-atom.php, (3) wp-rss.php, or (4) wp-rss2.php, which reveal the path in an error message.  NOTE: vector [1] was later reported to also affect WordPress 2.0.1.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112006967221438&amp;w=2">20050629 WordPress 1.5.1.2 &amp;&amp; Earlier Multiple Vulnerabilities</ref><ref adv="1" source="MISC" url="http://www.gulftech.org/?node=research&amp;article_id=00085-06282005">http://www.gulftech.org/?node=research&amp;article_id=00085-06282005</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/15831">15831</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426304/100/0/threaded">20060227 WordPress 2.0.1 Multiple Vulnerabilities</ref><ref source="" url="http://NeoSecurityTeam.net/advisories/Advisory-17.txt"></ref></refs><vuln_soft><prod name="WordPress" vendor="WordPress"><vers num="1.5.1.2"/><vers num="1.5.1"/><vers num="1.5"/><vers num="1.2"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2111" published="2005-07-05" seq="2005-2111" severity="High" type="CVE"><desc><descript source="cve">login.cgi in Community Link Pro Web Editor allows remote attackers to execute arbitrary commands via the file parameter.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112006558125309&amp;w=2">20050629 [badroot security] Community link pro web editor: Remote command</ref><ref adv="1" source="MISC" url="http://www.badroot.org/advisories/SA0x05">http://www.badroot.org/advisories/SA0x05</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/15880">15880</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014345">1014345</ref></refs><vuln_soft><prod name="Community Link Pro Web Editor" vendor="Community Link Pro Web Editor"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2112" published="2005-07-05" seq="2005-2112" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in XOOPS 2.0.11 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) order parameter to edit.php or (2) cid parameter to comment_edit.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112006318512991&amp;w=2">20050629 XOOPS 2.0.11 &amp;&amp; Earlier Multiple Vulnerabilities</ref><ref adv="1" patch="1" source="MISC" url="http://www.gulftech.org/?node=research&amp;article_id=00086-06292005">http://www.gulftech.org/?node=research&amp;article_id=00086-06292005</ref><ref patch="1" source="" url="http://www.xoops.org/modules/news/article.php?storyid=2383">http://www.xoops.org/modules/news/article.php?storyid=2383</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15843">15843</ref></refs><vuln_soft><prod name="XOOPS" vendor="XOOPS"><vers num="2.0.11"/><vers num="2.0.10"/><vers num="2.0.9.3"/><vers num="2.0.9.2"/><vers num="2.0.9"/><vers num="2.0.7"/><vers num="2.0.6"/><vers num="2.0.5.2"/><vers num="2.0.5.1"/><vers num="2.0.5"/><vers num="2.0.4"/><vers num="2.0.3"/><vers num="2.0.2"/><vers num="2.0.1"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2113" published="2005-07-05" seq="2005-2113" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in the loginUser function in the XMLRPC server in XOOPS 2.0.11 and earlier allows remote attackers to execute arbitrary SQL commands and bypass authentication via crafted values in an XML file, as demonstrated using the blogger.getPost method.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112006318512991&amp;w=2">20050629 XOOPS 2.0.11 &amp;&amp; Earlier Multiple Vulnerabilities</ref><ref adv="1" source="MISC" url="http://www.gulftech.org/?node=research&amp;article_id=00086-06292005">http://www.gulftech.org/?node=research&amp;article_id=00086-06292005</ref><ref patch="1" source="" url="http://www.xoops.org/modules/news/article.php?storyid=2383">http://www.xoops.org/modules/news/article.php?storyid=2383</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15843">15843</ref></refs><vuln_soft><prod name="XOOPS" vendor="XOOPS"><vers num="2.0.11"/><vers num="2.0.10"/><vers num="2.0.9.3"/><vers num="2.0.9.2"/><vers num="2.0.9"/><vers num="2.0.7"/><vers num="2.0.6"/><vers num="2.0.5.2"/><vers num="2.0.5.1"/><vers num="2.0.5"/><vers num="2.0.4"/><vers num="2.0.3"/><vers num="2.0.2"/><vers num="2.0.1"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2114" published="2005-07-05" seq="2005-2114" severity="Medium" type="CVE"><desc><descript source="cve">Mozilla 1.7.8, Firefox 1.0.4, Camino 0.8.4, Netscape 8.0.2, and K-Meleon 0.9, and possibly other products that use the Gecko engine, allow remote attackers to cause a denial of service (application crash) via JavaScript that repeatedly calls an empty function.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112008299210033&amp;w=2">20050629 Mozilla Multiple Product JavaScript Issue</ref><ref adv="1" source="MISC" url="http://www.kurczaba.com/html/security/0506241.htm">http://www.kurczaba.com/html/security/0506241.htm</ref><ref source="MISC" url="http://www.securiteam.com/securitynews/5OP0U00G1G.html">http://www.securiteam.com/securitynews/5OP0U00G1G.html</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014349">1014349</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014372">1014372</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014294">1014294</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014293">1014293</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014292">1014292</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/21188">mozilla-mult-browsers-javascript-dos(21188)</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-586.html">RHSA-2005:586</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-587.html">RHSA-2005:587</ref></refs><vuln_soft><prod name="Mozilla" vendor="Mozilla"><vers num="1.7.8"/></prod><prod name="Camino" vendor="Mozilla"><vers num="0.8.4"/></prod><prod name="Firefox" vendor="Mozilla"><vers num="1.0.4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2115" published="2005-07-05" seq="2005-2115" severity="Medium" type="CVE"><desc><descript source="cve">Soldier of Fortune II 1.02x and 1.03 allows remote attackers to cause a denial of service (server crash) via a large ID value in the ignore command, which is used as an array index and causes an out-of-bounds operation.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Luigi Auriemma" url="http://aluigi.altervista.org/adv/sof2ignore-adv.txt"></ref><ref source="OSVDB" url="http://www.osvdb.org/17649">17649</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/15868">15868</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112008428126593&amp;w=2">20050629 In-game /ignore crash in Soldier of Fortune II 1.03</ref></refs><vuln_soft><prod name="Soldier Of Fortune 2" vendor="Raven Software"><vers num="1.02"/><vers num="1.03"/></prod></vuln_soft></entry><entry modified="2005-10-25" name="CVE-2005-2116" published="2005-07-05" reject="1" seq="2005-2116" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2005-1921.  Reason: This candidate is a duplicate of CVE-2005-1921.  Notes: All CVE users should reference CVE-2005-1921 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><other/></vuln_types><refs/></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-08-28" name="CVE-2005-2117" published="2005-10-21" seq="2005-2117" severity="Medium" type="CVE"><desc><descript source="cve">Web View in Windows Explorer on Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 does not properly handle certain HTML characters in preview fields, which allows remote user-assisted attackers to execute arbitrary code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms05-049.mspx">MS05-049</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA05-284A.html">TA05-284A</ref><ref patch="1" source="Secunia" url="http://secunia.com/advisories/15017/">Microsoft Windows Explorer Web View Script Insertion Vulnerability</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1291.html">OVAL1291</ref><ref source="BID" url="http://www.securityfocus.com/bid/15064">15064</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17168">17168</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2005-214.pdf"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/17172">17172</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17223">17223</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1291">oval:org.mitre.oval:def:1291</ref></refs><vuln_soft><prod name="Windows XP" vendor="Microsoft"><vers edition="Tablet PC" num="SP1"/><vers edition="Tablet PC" num="SP2"/></prod><prod name="Windows Explorer" vendor="Microsoft"><vers num=""/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers num="R2"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers edition="FR" num="SP4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-08-28" name="CVE-2005-2118" published="2005-10-21" seq="2005-2118" severity="Medium" type="CVE"><desc><descript source="cve">Windows Shell for Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 allows remote user-assisted attackers to execute arbitrary commands via a crafted shortcut (.lnk) file with long font properties that lead to a buffer overflow when the user views the file&apos;s properties using Windows Explorer, a different vulnerability than CVE-2005-2122.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="argeniss" url="http://www.argeniss.com/research/MSBugPaper.pdf">Story of a dumb patch</ref><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms05-049.mspx">MS05-049</ref><ref adv="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA05-284A.html">TA05-284A</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1116.html">OVAL1116</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1192.html">OVAL1192</ref><ref source="BID" url="http://www.securityfocus.com/bid/15070">15070</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015040">1015040</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/17168">17168</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2005-214.pdf"></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/17172">17172</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/17223">17223</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1116">oval:org.mitre.oval:def:1116</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1192">oval:org.mitre.oval:def:1192</ref></refs><vuln_soft><prod name="Windows XP" vendor="Microsoft"><vers edition="SP2" num="Tablet PC"/><vers edition="SP2" num="Tablet PC"/><vers edition="Gold" num="Professional"/><vers edition="Gold" num="Professional"/><vers edition="SP1" num="Media Center"/><vers num="Media Center"/><vers edition="SP1" num="Home"/><vers num="Home"/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers num="R2"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num="Server SP4"/><vers num="Server SP3"/><vers num="Server SP2"/><vers num="Server SP1"/><vers num="Server"/><vers num="Professional SP4"/><vers num="Professional SP3"/><vers num="Professional SP2"/><vers num="Professional SP1"/><vers num="Professional"/><vers num="Datacenter Server SP4"/><vers num="Datacenter Server SP3"/><vers num="Datacenter Server SP2"/><vers num="Datacenter Server SP1"/><vers num="Datacenter Server"/><vers num="Advanced Server SP4"/><vers num="Advanced Server SP3"/><vers num="Advanced Server SP2"/><vers num="Advanced Server SP1"/><vers num="Advanced Server"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2119" published="2005-10-12" seq="2005-2119" severity="Medium" type="CVE"><desc><descript source="cve">The MIDL_user_allocate function in the Microsoft Distributed Transaction Coordinator (MSDTC) proxy (MSDTCPRX.DLL) allocates a 4K page of memory regardless of the required size, which allows attackers to overwrite arbitrary memory locations using an incorrect size value that is provided to the NdrAllocate function, which writes management data to memory outside of the allocated buffer.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/MS05-051.mspx">MS05-051</ref><ref source="OSVDB" url="http://www.osvdb.org/18828">18828</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA05-284A.html">TA05-284A</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/180868">VU#180868</ref><ref source="EEYE" url="http://www.eeye.com/html/research/advisories/AD20051011b.html">AD20051011b</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1071.html">OVAL1071</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1452.html">OVAL1452</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval551.html">OVAL551</ref><ref source="BID" url="http://www.securityfocus.com/bid/15056">15056</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015037">1015037</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17161">17161</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2005-214.pdf"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/17172">17172</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17223">17223</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17509">17509</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1071">oval:org.mitre.oval:def:1071</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1452">oval:org.mitre.oval:def:1452</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:551">oval:org.mitre.oval:def:551</ref><ref source="SREASON" url="http://securityreason.com/securityalert/73">73</ref></refs><vuln_soft><prod name="Windows XP" vendor="Microsoft"><vers edition="Tablet PC" num="SP1"/><vers edition="Tablet PC" num="SP2"/><vers edition="64-bit" num="Professional"/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers num="R2"/><vers num="SP1"/><vers num="Itanium"/><vers edition="Itanium" num="SP1"/><vers num="64-bit"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers edition="FR" num="SP4"/></prod></vuln_soft></entry><entry CVSS_base_score="6.5" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="6.4" CVSS_score="6.5" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-03-09" name="CVE-2005-2120" published="2005-10-13" seq="2005-2120" severity="Medium" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in the Plug and Play (PnP) service (UMPNPMGR.DLL) in Microsoft Windows 2000 SP4, and XP SP1 and SP2, allows remote or local authenticated attackers to execute arbitrary code via a large number of &quot;\&quot; (backslash) characters in a registry key name, which triggers the overflow in a wsprintfW function call.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms05-047.mspx">MS05-047</ref><ref adv="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA05-284A.html">TA05-284A</ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/214572">VU#214572</ref><ref source="OSVDB" url="http://www.osvdb.org/18830">18830</ref><ref adv="1" patch="1" source="EEYE" url="http://www.eeye.com/html/research/advisories/AD20051011c.html">AD20051011c</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1244.html">OVAL1244</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1328.html">OVAL1328</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1519.html">OVAL1519</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015042">1015042</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/15065">15065</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/17166">17166</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2005-214.pdf"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/17172">17172</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17223">17223</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1244">oval:org.mitre.oval:def:1244</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1328">oval:org.mitre.oval:def:1328</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1519">oval:org.mitre.oval:def:1519</ref><ref source="SREASON" url="http://securityreason.com/securityalert/71">71</ref></refs><vuln_soft><prod name="Windows XP" vendor="Microsoft"><vers edition="Tablet PC" num="SP1"/><vers edition="Tablet PC" num="SP2"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers edition="FR" num="SP4"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-06-13" name="CVE-2005-2122" published="2005-10-21" seq="2005-2122" severity="High" type="CVE"><desc><descript source="cve">Windows Shell for Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 allows remote attackers to execute arbitrary commands via a shortcut (.lnk) file with long font properties that lead to a buffer overflow in the Client/Server Runtime Server Subsystem (CSRSS), a different vulnerability than CVE-2005-2118.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="argeniss" url="http://www.argeniss.com/research/MSBugPaper.pdf">Story of a dumb patch</ref><ref adv="1" patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms05-049.mspx">MS05-049</ref><ref adv="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA05-284A.html">TA05-284A</ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/922708">VU#922708</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1329.html">OVAL1329</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1488.html">OVAL1488</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1517.html">OVAL1517</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1537.html">OVAL1537</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1551.html">OVAL1551</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval708.html">OVAL708</ref><ref source="BID" url="http://www.securityfocus.com/bid/15069">15069</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015040">1015040</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/17168">17168</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2005-214.pdf"></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/17172">17172</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/17223">17223</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1329">oval:org.mitre.oval:def:1329</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1488">oval:org.mitre.oval:def:1488</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1517">oval:org.mitre.oval:def:1517</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1537">oval:org.mitre.oval:def:1537</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1551">oval:org.mitre.oval:def:1551</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:708">oval:org.mitre.oval:def:708</ref></refs><vuln_soft><prod name="Windows XP" vendor="Microsoft"><vers edition="SP2" num="Tablet PC"/><vers edition="SP2" num="Tablet PC"/><vers edition="Gold" num="Professional"/><vers edition="Gold" num="Professional"/><vers edition="SP1" num="Media Center"/><vers num="Media Center"/><vers edition="SP1" num="Home"/><vers num="Home"/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers num="R2"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num="Server SP4"/><vers num="Server SP3"/><vers num="Server SP2"/><vers num="Server SP1"/><vers num="Server"/><vers num="Professional SP4"/><vers num="Professional SP3"/><vers num="Professional SP2"/><vers num="Professional SP1"/><vers num="Professional"/><vers num="Datacenter Server SP4"/><vers num="Datacenter Server SP3"/><vers num="Datacenter Server SP2"/><vers num="Datacenter Server SP1"/><vers num="Datacenter Server"/><vers num="Advanced Server SP4"/><vers num="Advanced Server SP3"/><vers num="Advanced Server SP2"/><vers num="Advanced Server SP1"/><vers num="Advanced Server"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2005-11-30" name="CVE-2005-2123" published="2005-11-29" seq="2005-2123" severity="High" type="CVE"><desc><descript source="cve">Multiple integer overflows in the Graphics Rendering Engine (GDI32.DLL) in Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 allow remote attackers to execute arbitrary code via crafted Windows Metafile (WMF) and Enhanced Metafile (EMF) format images that lead to heap-based buffer overflows, as demonstrated using MRBP16::bCheckRecord.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.eeye.com/html/research/advisories/AD20051108b.html"></ref><ref adv="1" patch="1" source="MS" url="http://www.microsoft.com/technet/security/Bulletin/MS05-053.mspx">MS05-053</ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/300549">VU#300549</ref><ref source="BID" url="http://www.securityfocus.com/bid/15352">15352</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1063.html">OVAL1063</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1175.html">OVAL1175</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1263.html">OVAL1263</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1546.html">OVAL1546</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval701.html">OVAL701</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015168">1015168</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/2348">ADV-2005-2348</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17498">17498</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2005-228.pdf"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/17461">17461</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17223">17223</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1063">oval:org.mitre.oval:def:1063</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1175">oval:org.mitre.oval:def:1175</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1263">oval:org.mitre.oval:def:1263</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1546">oval:org.mitre.oval:def:1546</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:701">oval:org.mitre.oval:def:701</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA05-312A.html">TA05-312A</ref></refs><vuln_soft><prod name="Windows XP" vendor="Microsoft"><vers edition="Tablet PC" num="SP1"/><vers edition="Tablet PC" num="SP2"/><vers edition="64-bit" num="Professional"/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers num="R2"/><vers num="SP1"/><vers num="Itanium"/><vers edition="Itanium" num="SP1"/><vers num="64-bit"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers edition="FR" num="SP4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="10.0" CVSS_score="7.6" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2005-12-06" name="CVE-2005-2124" published="2005-11-29" seq="2005-2124" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the Graphics Rendering Engine (GDI32.DLL) in Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1, related to &quot;An unchecked buffer&quot; and possibly buffer overflows, allows remote attackers to execute arbitrary code via a crafted Windows Metafile (WMF) format image, aka &quot;Windows Metafile Vulnerability.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/><env/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="eEye Digital Security" url="http://www.eeye.com/html/research/advisories/AD20051108b.html">Windows Metafile Multiple Heap Overflows</ref><ref adv="1" patch="1" source="MS" url="http://www.microsoft.com/technet/security/Bulletin/MS05-053.mspx">MS05-053</ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/433341">VU#433341</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015168">1015168</ref><ref source="" url="http://www.eeye.com/html/research/advisories/AD20051108a.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/15356">15356</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/2348">ADV-2005-2348</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17498">17498</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2005-228.pdf"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/17461">17461</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17223">17223</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA05-312A.html">TA05-312A</ref><ref source="SREASON" url="http://securityreason.com/securityalert/161">161</ref></refs><vuln_soft><prod name="Windows XP" vendor="Microsoft"><vers edition="Tablet PC" num="SP2"/><vers edition="Tablet PC" num="SP1"/><vers edition="64-bit" num="Professional"/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers num="R2"/><vers num="SP1"/><vers num="Itanium"/><vers edition="Itanium" num="SP1"/><vers num="64-bit"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers edition="FR" num="SP4"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-08-28" name="CVE-2005-2126" published="2005-10-21" seq="2005-2126" severity="Low" type="CVE"><desc><descript source="cve">The FTP client in Windows XP SP1 and Server 2003, and Internet Explorer 6 SP1 on Windows 2000 SP4, when &quot;Enable Folder View for FTP Sites&quot; is enabled and the user manually initiates a file transfer, allows user-assisted, remote FTP servers to overwrite files in arbitrary locations via crafted filenames.</descript></desc><loss_types><int/></loss_types><vuln_types><config/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms05-044.mspx">MS05-044</ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/415828">VU#415828</ref><ref patch="1" source="" url="http://www.securiteam.com/windowsntfocus/6M00I0KEAU.html"></ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/17163">17163</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1146.html">OVAL1146</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1284.html">OVAL1284</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1416.html">OVAL1416</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015036">1015036</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2005-214.pdf"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/17172">17172</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17223">17223</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1146">oval:org.mitre.oval:def:1146</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1284">oval:org.mitre.oval:def:1284</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1416">oval:org.mitre.oval:def:1416</ref></refs><vuln_soft><prod name="Windows XP" vendor="Microsoft"><vers edition="Tablet PC" num="SP1"/></prod><prod name="Internet Explorer" vendor="Microsoft"><vers num="6.0 SP1"/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers num="R2"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers edition="FR" num="SP4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-11-02" name="CVE-2005-2127" published="2005-08-19" seq="2005-2127" severity="High" type="CVE"><desc><descript source="cve">Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a web page with embedded CLSIDs that reference certain COM objects that are not intended for use within Internet Explorer, as originally demonstrated using the (1) DDS Library Shape Control (Msdds.dll) COM object, and other objects including (2) Blnmgrps.dll, (3) Ciodm.dll, (4) Comsvcs.dll, (5) Danim.dll, (6) Htmlmarq.ocx, (7) Mdt2dd.dll (as demonstrated using a heap corruption attack with uninitialized memory), (8) Mdt2qd.dll, (9) Mpg4ds32.ax, (10) Msadds32.ax, (11) Msb1esen.dll, (12) Msb1fren.dll, (13) Msb1geen.dll, (14) Msdtctm.dll, (15) Mshtml.dll, (16) Msoeacct.dll, (17) Msosvfbr.dll, (18) Mswcrun.dll, (19) Netshell.dll, (20) Ole2disp.dll, (21) Outllib.dll, (22) Psisdecd.dll, (23) Qdvd.dll, (24) Repodbc.dll, (25) Shdocvw.dll, (26) Shell32.dll, (27) Soa.dll, (28) Srchui.dll, (29) Stobject.dll, (30) Vdt70.dll, (31) Vmhelper.dll, and (32) Wbemads.dll, aka a variant of the &quot;COM Object Instantiation Memory Corruption vulnerability.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="MS" url="http://www.microsoft.com/technet/security/advisory/906267.mspx">http://www.microsoft.com/technet/security/advisory/906267.mspx</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/14594">14594</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/1450">ADV-2005-1450</ref><ref adv="1" patch="1" source="SECTRACK" url="http://securitytracker.com/id?1014727">1014727</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/16480">16480</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/21895">Win-msdss-command-execution(21895)</ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/740372">VU#740372</ref><ref source="MISC" url="http://isc.sans.org/diary.php?date=2005-08-18">http://isc.sans.org/diary.php?date=2005-08-18</ref><ref adv="1" patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms05-052.mspx">MS05-052</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA05-284A.html">TA05-284A</ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/959049">VU#959049</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/898241">VU#898241</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1155.html">OVAL1155</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1454.html">OVAL1454</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1464.html">OVAL1464</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1468.html">OVAL1468</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1535.html">OVAL1535</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1538.html">OVAL1538</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA05-347A.html">TA05-347A</ref><ref source="BID" url="http://www.securityfocus.com/bid/15061">15061</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2005-214.pdf"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/17172">17172</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17223">17223</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17509">17509</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-220A.html">TA06-220A</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1155">oval:org.mitre.oval:def:1155</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1454">oval:org.mitre.oval:def:1454</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1464">oval:org.mitre.oval:def:1464</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1468">oval:org.mitre.oval:def:1468</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1535">oval:org.mitre.oval:def:1535</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1538">oval:org.mitre.oval:def:1538</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/470690/100/0/threaded">20070606 IE 6/Microsoft Html Popup Window (mshtml.dll) DoS</ref><ref source="SREASON" url="http://securityreason.com/securityalert/72">72</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/34754">microsoft-ie-mshtml-dos(34754)</ref></refs><vuln_soft><prod name="Visual Studio .NET" vendor="Microsoft"><vers edition="Enterprise Architect" num="2003"/><vers edition="Gold" num="2003"/><vers edition="Gold" num="2002"/><vers edition="Trial" num="Gold"/><vers edition="Professional" num="Gold"/><vers edition="Enterprise Developer" num="Gold"/><vers edition="Enterprise Architect" num="Gold"/><vers edition="Academic" num="Gold"/></prod><prod name="Project" vendor="Microsoft"><vers num="98"/><vers num="2003 SP1"/><vers num="2003"/><vers num="2002 SP1"/><vers num="2002"/><vers num="2000"/></prod><prod name="Catalyst Driver" vendor="ATI Technologies"><vers num=""/></prod><prod name="Office" vendor="Microsoft"><vers num="XP SP3"/><vers num="XP SP1"/><vers num="XP SP2"/><vers num=""/><vers edition="Korean" num="2000"/><vers edition="Japanese" num="2000"/><vers edition="Chinese" num="2000"/><vers num="2000 SP3"/><vers num="2000 SP2"/><vers num="2000 SP1"/><vers num="2000"/><vers edition="Developer" num="XP"/></prod><prod name=".NET Framework" vendor="Microsoft"><vers num="1.1 SP3"/><vers num="1.1 SP2"/><vers num="1.1 SP1"/><vers num="1.1"/></prod><prod name="Visio" vendor="Microsoft"><vers edition="Professional" num="2002"/><vers edition="Standard" num="2003"/><vers edition="Professional" num="2003"/><vers num="2003 SP1"/><vers num="2003"/><vers edition="Standard" num="2002 SP2"/><vers edition="Professional" num="2002 SP2"/><vers num="2002 SP2"/><vers num="2002 SP1"/><vers num="2002"/><vers edition="Enterprise" num="2000 SR1"/><vers edition="Enterprise" num="2000"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2128" published="2005-10-12" seq="2005-2128" severity="Medium" type="CVE"><desc><descript source="cve">QUARTZ.DLL in Microsoft Windows Media Player 9 allows remote attackers to write a null byte to arbitrary memory via an AVI file with a crafted strn element with a modified length value.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/MS05-050.mspx">MS05-050</ref><ref source="OSVDB" url="http://www.osvdb.org/18822">18822</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA05-284A.html">TA05-284A</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/995220">VU#995220</ref><ref source="EEYE" url="http://www.eeye.com/html/research/advisories/AD20051011a.html">AD20051011a</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1149.html">OVAL1149</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1231.html">OVAL1231</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1267.html">OVAL1267</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1424.html">OVAL1424</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1434.html">OVAL1434</ref><ref source="BID" url="http://www.securityfocus.com/bid/15063">15063</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17160">17160</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2005-214.pdf"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/17172">17172</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17509">17509</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1149">oval:org.mitre.oval:def:1149</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1231">oval:org.mitre.oval:def:1231</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1267">oval:org.mitre.oval:def:1267</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1424">oval:org.mitre.oval:def:1424</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1434">oval:org.mitre.oval:def:1434</ref></refs><vuln_soft><prod name="Windows Media Player" vendor="Microsoft"><vers num="9"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2132" published="2005-08-03" seq="2005-2132" severity="Low" type="CVE"><desc><descript source="cve">RPC portmapper (rpcbind) in SCO UnixWare 7.1.1 m5, 7.1.3 mp5, and 7.1.4 mp2 allows remote attackers or local users to cause a denial of service (lack of response) via multiple invalid portmap requests.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="SCO" url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.31/SCOSA-2005.31.txt">SCOSA-2005.31</ref><ref source="BID" url="http://www.securityfocus.com/bid/14360">14360</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16228">16228</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112247187722821&amp;w=2">20050727 [NILESA-20050701] UnixWare 7.x RPC portmapper Dos Vulnerability</ref></refs><vuln_soft><prod name="UnixWare" vendor="SCO"><vers num="7.1.1 m5"/><vers num="7.1.3 mp5"/><vers num="7.1.4 mp2"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-25" name="CVE-2005-2133" published="2005-07-05" seq="2005-2133" severity="Low" type="CVE"><desc><descript source="cve">DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2005-1915.  Reason: This candidate is a duplicate of CVE-2005-1915.  Notes: All CVE users should reference CVE-2005-1915 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref patch="1" source="" url="http://bugs.gentoo.org/show_bug.cgi?id=94069">http://bugs.gentoo.org/show_bug.cgi?id=94069</ref></refs><vuln_soft><prod name="log4sh" vendor="log4sh"><vers num="1.2.4"/><vers num="1.2.3"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2134" published="2005-07-05" seq="2005-2134" severity="Low" type="CVE"><desc><descript source="cve">The (1) clcs and (2) emuxki drivers in NetBSD 1.6 through 2.0.2 allow local users to cause a denial of service (kernel crash) by using the set-parameters ioctl on an audio device to change the block size and set the pause state to &quot;unpaused&quot; in the same ioctl, which causes a divide-by-zero error.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><local/></range><refs><ref adv="1" source="NETBSD" url="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2005-002.txt.asc">NetBSD-SA2005-002</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15874/">15874</ref></refs><vuln_soft><prod name="NetBSD" vendor="NetBSD"><vers num="1.6.2"/><vers num="1.6.1"/><vers num="1.6"/><vers num="2.0"/><vers num="2.0.1"/><vers num="2.0.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2135" published="2005-07-05" seq="2005-2135" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in verify.asp in EtoShop Dynamic Biz Website Builder (QuickWeb) 1.0 allows remote attackers to execute arbitrary SQL commands via the (1) T1 or (2) T2 parameters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/15818">15818</ref></refs><vuln_soft><prod name="Dynamic Biz Website Builder QuickWeb" vendor="EtoShop"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2136" published="2005-07-05" seq="2005-2136" severity="Medium" type="CVE"><desc><descript source="cve">Raritan Dominion SX (DSX) Console Servers DSX16, DSX32, DSX4, DSX8, and DSXA-48 set (1) world-readable permissions for /etc/shadow and (2) world-writable permissions for /bin/busybox, which allows local users to obtain hashed passwords or execute arbitrary code as other users.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://seclists.org/lists/bugtraq/2005/Jun/0251.html">20050628 Access right escalation / severe permission problems on Raritan Console Servers</ref><ref source="BID" url="http://www.securityfocus.com/bid/14084">14084</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/15853">15853</ref></refs><vuln_soft><prod name="Dominion" vendor="Raritan"><vers num="SXA-48"/><vers num="SX8"/><vers num="SX4"/><vers num="SX32 2.4.6 firmware"/><vers num="SX32"/><vers num="SX16"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2137" published="2005-07-05" seq="2005-2137" severity="Medium" type="CVE"><desc><descript source="cve">Unknown vulnerability in NateOn Messenger 3.0 allows remote attackers to list arbitrary directories via unknown attack vectors.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/14100">14100</ref><ref source="OSVDB" url="http://www.osvdb.org/17619">17619</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/15819">15819</ref></refs><vuln_soft><prod name="NateOn Messenger" vendor="NateOn"><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-05" name="CVE-2005-2138" published="2005-07-05" seq="2005-2138" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in Comdev eCommerce 3.0 and 3.1 allows remote attackers to inject arbitrary web script or HTML via Javascript in the onMouseOver event of an &quot;A&quot; tag in a review message.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://k.domaindlx.com/shellcore/advisories.asp?bug_report=display&amp;infamous_group=64">http://k.domaindlx.com/shellcore/advisories.asp?bug_report=display&amp;infamous_group=64</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/15865">15865</ref></refs><vuln_soft><prod name="Comdev eCommerce" vendor="Comdev"><vers num="3.0"/><vers num="3.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2139" published="2005-07-05" seq="2005-2139" severity="Medium" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in user_check.php for Pavsta Auto Site allows remote attackers to execute arbitrary PHP code via the sitepath parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/0930">ADV-2005-0930</ref><ref source="OSVDB" url="http://www.osvdb.org/17631">17631</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014321">1014321</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/15873">15873</ref></refs><vuln_soft><prod name="Pavsta Auto Site" vendor="Pavsta"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2140" published="2005-07-05" seq="2005-2140" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in default.asp for FSboard 2.0 allows remote attackers to read arbitrary files via &quot;..&quot; sequences in the filename parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/14111">14111</ref></refs><vuln_soft><prod name="FSboard" vendor="FSboard"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2141" published="2005-07-05" seq="2005-2141" severity="Medium" type="CVE"><desc><descript source="cve">TCP Chat 1.0 allows remote attackers to cause a denial of service (crash) via a long string to the chat service, possibly triggering a buffer overflow.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="SECTRACK" url="http://securitytracker.com/id?1014371">1014371</ref><ref source="" url="http://k.domaindlx.com/shellcore/advisories.asp?bug_report=display&amp;infamous_group=65"></ref><ref source="" url="http://addict3d.org/index.php?page=viewarticle&amp;type=security&amp;ID=4377"></ref></refs><vuln_soft><prod name="TCP Chat" vendor="Jollybox.de"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2142" published="2005-07-05" seq="2005-2142" severity="Low" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in Golden FTP Server 2.60 allows remote authenticated attackers to list arbitrary directories via a &quot;\..&quot;  (backslash dot dot) in an LS (LIST) command.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/15840">15840</ref></refs><vuln_soft><prod name="Golden FTP Server" vendor="KMiNT21 Software"><vers num="2.60"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2143" published="2005-07-05" seq="2005-2143" severity="Medium" type="CVE"><desc><descript source="cve">Microsoft Front Page allows attackers to cause a denial of service (crash) via a crafted style tag in a web page.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref source="MISC" url="http://www.freewebs.com/xxosfilexx/HungFPage.html">http://www.freewebs.com/xxosfilexx/HungFPage.html</ref><ref adv="1" source="SECTRACK" url="http://securitytracker.com/id?1014352">1014352</ref></refs><vuln_soft><prod name="FrontPage" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2144" published="2005-07-05" seq="2005-2144" severity="Low" type="CVE"><desc><descript source="cve">Prevx Pro 2005 1.0 allows local users to bypass file protection and modify files by using MapViewOfFile to perform memory mapping on the file.</descript></desc><loss_types><int/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" source="SECTRACK" url="http://securitytracker.com/id?1014346">1014346</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/15885">15885</ref></refs><vuln_soft><prod name="Prevx Pro 2005" vendor="Prevx"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2145" published="2005-07-05" seq="2005-2145" severity="Medium" type="CVE"><desc><descript source="cve">The kernel driver in Prevx Pro 2005 1.0 does not verify the source of certain messages, which allows local users to bypass protection by sending certain messages to the driver, as demonstrated by sending an &quot;allow&quot; message to bypass a warning message.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref source="SECTRACK" url="http://securitytracker.com/id?1014346">1014346</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/15885">15885</ref></refs><vuln_soft><prod name="Prevx Pro 2005" vendor="Prevx"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-05" name="CVE-2005-2146" published="2005-07-05" seq="2005-2146" severity="Medium" type="CVE"><desc><descript source="cve">SSH Tectia Server 4.3.1 and earlier, and SSH Secure Shell for Windows Servers, uses insecure permissions when generating the Secure Shell host identification key, which allows local users to access the key and spoof the server.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="" url="http://www.ssh.com/company/newsroom/article/653/">http://www.ssh.com/company/newsroom/article/653/</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/15894">15894</ref></refs><vuln_soft><prod name="Tectia Server" vendor="SSH Communications Security"><vers num="4.3.1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2147" published="2005-07-06" seq="2005-2147" severity="Medium" type="CVE"><desc><descript source="cve">Trac before 0.8.4 allows remote attackers to read or upload arbitrary files via a full pathname in the id parameter to the (1) upload or (2) attachment viewer scripts.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="MISC" url="http://www.hardened-php.net/advisory-012005.php">http://www.hardened-php.net/advisory-012005.php</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/13990">13990</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/15752">15752</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-739">DSA-739</ref></refs><vuln_soft><prod name="Trac" vendor="Edgewall Software"><vers num="0.8.3"/><vers num="0.8.1"/><vers num="0.7.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-08-28" name="CVE-2005-2148" published="2005-07-06" seq="2005-2148" severity="High" type="CVE"><desc><descript source="cve">Cacti 0.8.6e and earlier does not perform proper input validation to protect against common attacks, which allows remote attackers to execute arbitrary commands or SQL by sending a legitimate value in a POST request or cookie, then specifying the attack string in the URL, which causes the get_request_var function to return the wrong value in the $_REQUEST variable, which is cleansed while the original malicious $_GET value remains unmodified, as demonstrated in (1) graph_image.php and (2) graph.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="MISC" url="http://www.hardened-php.net/advisory-032005.php">http://www.hardened-php.net/advisory-032005.php</ref><ref patch="1" source="MISC" url="http://www.hardened-php.net/advisory-042005.php">http://www.hardened-php.net/advisory-042005.php</ref><ref patch="1" source="MLIST" url="http://sourceforge.net/mailarchive/forum.php?forum_id=10360&amp;max_rows=25&amp;style=flat&amp;viewmonth=200507&amp;viewday=1">[cacti-announce] 20050701 Cacti 0.8.6f Released</ref><ref patch="1" source="" url="http://www.cacti.net/downloads/patches/0.8.6e/cacti-0.8.6f_security.patch">http://www.cacti.net/downloads/patches/0.8.6e/cacti-0.8.6f_security.patch</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/404054">20050702 Advisory 03/2005: Cacti Multiple SQL Injection Vulnerabilities [FIXED]</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/404047/30/30/threaded">20050702 Advisory 04/2005: Cacti Remote Command Execution Vulnerability</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-764">DSA-764</ref><ref source="BID" url="http://www.securityfocus.com/bid/14027">14027</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15490">15490</ref><ref source="BID" url="http://www.securityfocus.com/bid/14128">14128</ref><ref source="BID" url="http://www.securityfocus.com/bid/14129">14129</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/0951">ADV-2005-0951</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014361">1014361</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/21266">cacti-graph-post-cookie-sql-injection(21266)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/21270">cacti-request-array-command-execution(21270)</ref></refs><vuln_soft><prod name="Cacti" vendor="The Cacti Group"><vers num="0.8.6e"/><vers num="0.8.6d"/><vers num="0.8.6c"/><vers num="0.8.6b"/><vers num="0.8.6a"/><vers num="0.8.6"/><vers num="0.8.5a"/><vers num="0.8.5"/><vers num="0.8.4"/><vers num="0.8.3a"/><vers num="0.8.3"/><vers num="0.8.2a"/><vers num="0.8.2"/><vers num="0.8.1"/><vers num="0.8"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-08-28" name="CVE-2005-2149" published="2005-07-06" seq="2005-2149" severity="High" type="CVE"><desc><descript source="cve">config.php in Cacti 0.8.6e and earlier allows remote attackers to set the no_http_headers switch, then modify session information to gain privileges and disable the use of addslashes to conduct SQL injection attacks.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="MISC" url="http://www.hardened-php.net/advisory-052005.php">http://www.hardened-php.net/advisory-052005.php</ref><ref patch="1" source="MLIST" url="http://sourceforge.net/mailarchive/forum.php?forum_id=10360&amp;max_rows=25&amp;style=flat&amp;viewmonth=200507&amp;viewday=1">[cacti-announce] 20050701 Cacti 0.8.6f Released</ref><ref patch="1" source="" url="http://www.cacti.net/downloads/patches/0.8.6e/cacti-0.8.6f_security.patch">http://www.cacti.net/downloads/patches/0.8.6e/cacti-0.8.6f_security.patch</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/404040">20050702 Advisory 05/2005: Cacti Authentification/Addslashes Bypass Vulnerability</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-764">DSA-764</ref><ref source="BID" url="http://www.securityfocus.com/bid/14130">14130</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/0951">ADV-2005-0951</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014361">1014361</ref></refs><vuln_soft><prod name="Cacti" vendor="The Cacti Group"><vers num="0.8.6e"/><vers num="0.8.6d"/><vers num="0.8.6c"/><vers num="0.8.6b"/><vers num="0.8.6a"/><vers num="0.8.6"/><vers num="0.8.5a"/><vers num="0.8.5"/><vers num="0.8.4"/><vers num="0.8.3a"/><vers num="0.8.3"/><vers num="0.8.2a"/><vers num="0.8.2"/><vers num="0.8.1"/><vers num="0.8"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2150" published="2005-07-11" seq="2005-2150" severity="Medium" type="CVE"><desc><descript source="cve">Windows NT 4.0 and Windows 2000 before URP1 for Windows 2000 SP4 does not properly prevent NULL sessions from accessing certain alternate named pipes, which allows remote attackers to (1) list Windows services via svcctl or (2) read eventlogs via eventlog.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112076409813099&amp;w=2">20050707 NULL sessions vulnerabilities using alternate named pipes</ref><ref source="MISC" url="http://www.hsc.fr/ressources/presentations/null_sessions/">http://www.hsc.fr/ressources/presentations/null_sessions/</ref><ref source="BID" url="http://www.securityfocus.com/bid/14177">14177</ref><ref source="BID" url="http://www.securityfocus.com/bid/14178">14178</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014417">1014417</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14189">14189</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/21286">win-name-pipe-null-information-disclosure(21286)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/21288">win-pipe-null-eventlog-information-disclosure(21288)</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num="4.0"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2151" published="2005-07-06" seq="2005-2151" severity="Medium" type="CVE"><desc><descript source="cve">spf.c in Courier Mail Server does not properly handle DNS failures when looking up Sender Policy Framework (SPF) records, which could allow attackers to cause memory corruption.</descript></desc><loss_types><int/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="MISC" url="http://www.courier-mta.org/?changelog.html">http://www.courier-mta.org/?changelog.html</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/15901">15901</ref></refs><vuln_soft><prod name="Courier Mail Server" vendor="Double Precision Incorporated"><vers num="0.50.0"/><vers num="0.49.0"/><vers num="0.48.2"/><vers num="0.48.1"/><vers num="0.48"/><vers num="0.47"/><vers num="0.46"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2152" published="2005-07-06" seq="2005-2152" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in Geeklog before 1.3.11 allows remote attackers to execute arbitrary SQL commands via user comments for an article.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.geeklog.net/article.php/geeklog-1.3.11sr1">http://www.geeklog.net/article.php/geeklog-1.3.11sr1</ref><ref adv="1" patch="1" source="MISC" url="http://www.hardened-php.net/advisory-062005.php">http://www.hardened-php.net/advisory-062005.php</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014381">1014381</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15914">15914</ref></refs><vuln_soft><prod name="Geeklog" vendor="Geeklog"><vers num="1.3.10"/><vers num="1.3.9 sr3"/><vers num="1.3.9 sr2"/><vers num="1.3.9 sr1"/><vers num="1.3.8_1 sr6"/><vers num="1.3.8_1 sr5"/><vers num="1.3.8_1 sr4"/><vers num="1.3.8_1 sr3"/><vers num="1.3.8_1 sr2"/><vers num="1.3.8_1 sr1"/><vers num="1.3.8_1"/><vers num="1.3.8"/><vers num="1.3.7 sr5"/><vers num="1.3.7 sr4"/><vers num="1.3.7 sr3"/><vers num="1.3.7 sr2"/><vers num="1.3.7 sr1"/><vers num="1.3.7"/><vers num="1.3.6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2153" published="2005-07-06" seq="2005-2153" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in class.ticket.php in osTicket 1.3.1 beta and earlier allows remote attackers to execute arbitrary SQL commands via the ticket variable.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://seclists.org/lists/bugtraq/2005/Jul/0009.html">20050701 [SECURITY ALERT] osTicket bugs</ref><ref source="BID" url="http://www.securityfocus.com/bid/14127">14127</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014373">1014373</ref></refs><vuln_soft><prod name="osTicket STS" vendor="osTicket"><vers num="1.3 Beta"/><vers num="1.2.7"/><vers num="1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2154" published="2005-07-06" seq="2005-2154" severity="High" type="CVE"><desc><descript source="cve">PHP local file inclusion vulnerability in (1) view.php and (2) open.php in osTicket 1.3.1 beta and earlier allows remote attackers to include and possibly execute arbitrary local files via the inc parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://seclists.org/lists/bugtraq/2005/Jul/0009.html">20050701 [SECURITY ALERT] osTicket bugs</ref><ref source="BID" url="http://www.securityfocus.com/bid/14127">14127</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014373">1014373</ref></refs><vuln_soft><prod name="osTicket STS" vendor="osTicket"><vers num="1.3 Beta"/><vers num="1.2.7"/><vers num="1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2155" published="2005-07-06" seq="2005-2155" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in EasyPHPCalendar 6.1.5 and earlier allows remote attackers to execute arbitrary code via the serverPath parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/15893">15893</ref><ref adv="1" source="" url="http://www.frsirt.com/english/advisories/2005/0959"></ref></refs><vuln_soft><prod name="EasyPHPCalendar" vendor="EasyPHPCalendar"><vers num="6.1.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2156" published="2005-07-06" seq="2005-2156" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in news.php in PHPNews 1.2.5 allows remote attackers to execute arbitrary SQL commands via the prevnext parameter.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://sourceforge.net/project/shownotes.php?group_id=66322&amp;release_id=339317">http://sourceforge.net/project/shownotes.php?group_id=66322&amp;release_id=339317</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/14133">14133</ref></refs><vuln_soft><prod name="PHPNews" vendor="PHPNews"><vers num="1.2.5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2157" published="2005-07-06" seq="2005-2157" severity="Medium" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in survey.inc.php for nabopoll 1.2 allows remote attackers to execute arbitrary PHP code via the path parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/0954">ADV-2005-0954</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014355">1014355</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/15910">15910</ref></refs><vuln_soft><prod name="nabopoll" vendor="Nabocorp"><vers num="1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-25" name="CVE-2005-2158" published="2005-07-06" seq="2005-2158" severity="High" type="CVE"><desc><descript source="cve">A regression error in the embedded HSQLDB in JBoss jBPM 2.0 allows remote attackers to execute arbitrary comands, a re-introduction of a vulnerability that was originally identified by CVE-2003-0845.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112051548512338&amp;w=2">20050703 JBoss jBPM 2.0: Remote code execution and classloader covert channel</ref><ref adv="1" patch="1" source="MISC" url="http://www.illegalaccess.org/java/jboss.php">http://www.illegalaccess.org/java/jboss.php</ref></refs><vuln_soft><prod name="jBPM" vendor="JBoss Group"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2159" published="2005-07-06" seq="2005-2159" severity="Medium" type="CVE"><desc><descript source="cve">mshftp.dll in PlanetDNS PlanetFileServer 2.0.1.3 allows remote attackers to cause a denial of service (application crash) via a long request.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112051398718830&amp;w=2">20050704 PlanetFileServer v2.0.1.3 - Denial Of Service</ref><ref source="BID" url="http://www.securityfocus.com/bid/14138">14138</ref></refs><vuln_soft><prod name="PlanetFileServer" vendor="PlanetDNS"><vers num="2.0.1.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2160" published="2005-07-06" seq="2005-2160" severity="Medium" type="CVE"><desc><descript source="cve">IMail stores usernames and passwords in cleartext in a cookie, which allows remote attackers to obtain sensitive information.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112060187204457&amp;w=2">20050705 Imail Cookie Vulnerability (unhashed)</ref></refs><vuln_soft><prod name="IMail" vendor="IPSwitch"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2161" published="2005-07-06" seq="2005-2161" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in phpBB 2.0.16 allows remote attackers to inject arbitrary web script or HTML via nested [url] tags.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112059951605939&amp;w=2">20050705 XSS in nested tag in phpbb 2.0.16</ref><ref source="MISC" url="http://www.securitylab.ru/55612.html">http://www.securitylab.ru/55612.html</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-768">
DSA-768</ref></refs><vuln_soft><prod name="phpBB" vendor="phpBB Group"><vers num="2.0.16"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2162" published="2005-07-06" seq="2005-2162" severity="Medium" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in form.inc.php3 in MyGuestbook 0.6.1 allows remote attackers to execute arbitrary PHP code via the lang parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112059876828730&amp;w=2">20050705 MyGuestbook Remote File Inclusion.</ref><ref source="MISC" url="http://www.soulblack.com.ar/repo/papers/advisory/myguestbook_advisory.txt">http://www.soulblack.com.ar/repo/papers/advisory/myguestbook_advisory.txt</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014387">1014387</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15927">15927</ref></refs><vuln_soft><prod name="MyGuestbook" vendor="Levcgi.com"><vers num="0.6.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2163" published="2005-07-06" seq="2005-2163" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in AutoIndex PHP Script 1.5.2 allows remote attackers to inject arbitrary web script or HTML via the search parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112059745606348&amp;w=2">20050705 Re: [badroot security] AutoIndex PHP Script: XSS vulnerability</ref><ref adv="1" source="MISC" url="http://www.badroot.org/advisories/SA0x07">http://www.badroot.org/advisories/SA0x07</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/15928">15928</ref></refs><vuln_soft><prod name="PHP Script" vendor="AutoIndex"><vers num="1.5.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2164" published="2005-07-06" seq="2005-2164" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in Covide Groupware-CRM allows remote attackers to execute arbitrary SQL commands via unknown attack vectors.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112060007704577&amp;w=2">20050705 [covide] possible sql injection</ref><ref patch="1" source="MISC" url="http://sourceforge.net/project/shownotes.php?release_id=339047">http://sourceforge.net/project/shownotes.php?release_id=339047</ref><ref source="BID" url="http://securityfocus.com/bid/14156/info">14156</ref></refs><vuln_soft><prod name="covide" vendor="Covide Groupware-CRM"><vers num="5.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2165" published="2005-07-06" seq="2005-2165" severity="High" type="CVE"><desc><descript source="cve">read.cgi in GlobalNoteScript allows remote attackers to execute arbitrary commands via shell metacharacters in the file parameters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://zone-h.org/advisories/read/id=7765">http://zone-h.org/advisories/read/id=7765</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014375">1014375</ref></refs><vuln_soft><prod name="GlobalNoteScript" vendor="GlobalNoteScript"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2166" published="2005-07-06" seq="2005-2166" severity="Medium" type="CVE"><desc><descript source="cve">SQL injection vulnerability in index.php in Plague News System 0.6 and earlier allows remote attackers to execute arbitrary SQL commands via the cid parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://dark-assassins.com/forum/viewtopic.php?t=90">http://dark-assassins.com/forum/viewtopic.php?t=90</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/15902">15902</ref></refs><vuln_soft><prod name="Plague News System" vendor="frozenplague.net"><vers num="0.6"/><vers num="0.4rc4"/><vers num="0.4rc3"/><vers num="0.4"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2167" published="2005-07-06" seq="2005-2167" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in Plague News System 0.6 and earlier allows remote attackers to inject arbitrary web script or HTML via the cid parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://dark-assassins.com/forum/viewtopic.php?t=90">http://dark-assassins.com/forum/viewtopic.php?t=90</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/15902">15902</ref></refs><vuln_soft><prod name="Plague News System" vendor="frozenplague.net"><vers num="0.6"/><vers num="0.4rc4"/><vers num="0.4rc3"/><vers num="0.4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2168" published="2005-07-06" seq="2005-2168" severity="Medium" type="CVE"><desc><descript source="cve">delete.php in Plague News System 0.6 and earlier allows remote unauthenticated attackers to delete news, comments, and shoutbox posts by modifying the id parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://dark-assassins.com/forum/viewtopic.php?t=90">http://dark-assassins.com/forum/viewtopic.php?t=90</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/15902">15902</ref></refs><vuln_soft><prod name="Plague News System" vendor="frozenplague.net"><vers num="0.6"/><vers num="0.4rc4"/><vers num="0.4rc3"/><vers num="0.4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-04-07" name="CVE-2005-2169" published="2005-07-06" seq="2005-2169" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in source.php in Quick &amp; Dirty PHPSource Printer 1.1 and earlier allows remote attackers to read arbitrary files via &quot;.../...//&quot; sequences in the file parameter, which are reduced to &quot;../&quot; when PHPSource Printer uses a regular expression to remove &quot;../&quot; sequences.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://guff.szub.net/2005/07/04/quick-and-dirty-security/">http://guff.szub.net/2005/07/04/quick-and-dirty-security/</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014376">1014376</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/15900">15900</ref></refs><vuln_soft><prod name="Quick &amp; Dirty PHPSource Printer" vendor="Kaf Oseo"><vers num="1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2170" published="2005-07-11" seq="2005-2170" severity="Medium" type="CVE"><desc><descript source="cve">The LCF component (lcfd) in IBM Tivoli Management Framework Endpoint allows remote attackers to cause a denial of service (process exit and connection loss) by connecting to LCF and ending the connection without sending any data.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www-1.ibm.com/support/entdocview.wss?uid=swg21210334">http://www-1.ibm.com/support/entdocview.wss?uid=swg21210334</ref><ref adv="1" source="MISC" url="http://www.corsaire.com/advisories/c041127-001.txt">http://www.corsaire.com/advisories/c041127-001.txt</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/14194">14194</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/1018">ADV-2005-1018</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/15953">15953</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014424">1014424</ref></refs><vuln_soft><prod name="Tivoli Management Framework" vendor="IBM"><vers num="4.1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2173" published="2005-07-08" seq="2005-2173" severity="Medium" type="CVE"><desc><descript source="cve">The Flag::validate and Flag::modify functions in Bugzilla 2.17.1 to 2.18.1 and 2.19.1 to 2.19.3 do not verify that the flag ID is appropriate for the given bug or attachment ID, which allows users to change flags on arbitrary bugs and obtain a bug summary via process_bug.cgi.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.bugzilla.org/security/2.18.1/">http://www.bugzilla.org/security/2.18.1/</ref><ref patch="1" source="" url="https://bugzilla.mozilla.org/show_bug.cgi?id=293159">https://bugzilla.mozilla.org/show_bug.cgi?id=293159</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014428">1014428</ref></refs><vuln_soft><prod name="Bugzilla" vendor="Mozilla"><vers num="2.19.3"/><vers num="2.19.2"/><vers num="2.19.1"/><vers num="2.19"/><vers num="2.18.1"/><vers num="2.18"/><vers num="2.18 rc3"/><vers num="2.18 rc2"/><vers num="2.18 rc1"/><vers num="2.17.7"/><vers num="2.17.6"/><vers num="2.17.5"/><vers num="2.17.4"/><vers num="2.17.3"/><vers num="2.17.1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2174" published="2005-07-08" seq="2005-2174" severity="Low" type="CVE"><desc><descript source="cve">Bugzilla 2.17.x, 2.18 before 2.18.2, 2.19.x, and 2.20 before 2.20rc1 inserts a bug into the database before it is marked private, which introduces a race condition and allows attackers to access information about the bug via buglist.cgi before MySQL replication is complete.</descript></desc><loss_types><conf/></loss_types><vuln_types><race/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.bugzilla.org/security/2.18.1/">http://www.bugzilla.org/security/2.18.1/</ref><ref patch="1" source="" url="https://bugzilla.mozilla.org/show_bug.cgi?id=293159">https://bugzilla.mozilla.org/show_bug.cgi?id=293159</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014428">1014428</ref></refs><vuln_soft><prod name="Bugzilla" vendor="Mozilla"><vers num="2.19.3"/><vers num="2.19.2"/><vers num="2.19.1"/><vers num="2.19"/><vers num="2.18.1"/><vers num="2.18"/><vers num="2.18 rc3"/><vers num="2.18 rc2"/><vers num="2.18 rc1"/><vers num="2.17.7"/><vers num="2.17.6"/><vers num="2.17.5"/><vers num="2.17.4"/><vers num="2.17.3"/><vers num="2.17.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-21" name="CVE-2005-2175" published="2005-07-09" seq="2005-2175" severity="Medium" type="CVE"><desc><descript source="cve">The web interface for Lotus Notes mail automatically processes HTML in an attachment without prompting the user to save or open it, which makes it easier for remote attackers to conduct web-based attacks and steal cookies.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2005-07/0075.html">20050706 Cross site scripting in Lotus Notes web mail</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014440">1014440</ref></refs><vuln_soft><prod name="Lotus Notes" vendor="IBM"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2176" published="2005-07-09" seq="2005-2176" severity="Medium" type="CVE"><desc><descript source="cve">Novell NetMail automatically processes HTML in an attachment without prompting the user to save or open it, which makes it easier for remote attackers to conduct web-based attacks and steal cookies.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/14171">14171</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/0994">ADV-2005-0994</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/15962">15962</ref><ref source="" url="http://support.novell.com/cgi-bin/search/searchtid.cgi?/2972340.htm"></ref><ref source="" url="http://support.novell.com/cgi-bin/search/searchtid.cgi?/2972433.htm"></ref><ref source="" url="http://support.novell.com/cgi-bin/search/searchtid.cgi?/2972438.htm"></ref><ref source="OSVDB" url="http://www.osvdb.org/17821">17821</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014439">1014439</ref></refs><vuln_soft><prod name="NetMail" vendor="Novell"><vers edition="c1" num="3.5.2"/><vers edition="c" num="3.5.2"/><vers edition="b" num="3.5.2"/><vers edition="a" num="3.5.2"/><vers edition="e-ftfl" num="3.5.2"/><vers edition="h" num="3.10"/><vers edition="g" num="3.10"/><vers edition="f" num="3.10"/><vers edition="e" num="3.10"/><vers edition="d" num="3.10"/><vers edition="c" num="3.10"/><vers edition="b" num="3.10"/><vers edition="a" num="3.10"/><vers num="3.10"/><vers edition="f" num="3.1"/><vers num="3.1"/><vers edition="b" num="3.0.3a"/><vers edition="a" num="3.0.3a"/><vers num="3.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2008-01-03" name="CVE-2005-2177" published="2005-07-11" seq="2005-2177" severity="Medium" type="CVE"><desc><descript source="cve">Net-SNMP 5.0.x before 5.0.10.2, 5.2.x before 5.2.1.2, and 5.1.3, when net-snmp is using stream sockets such as TCP, allows remote attackers to cause a denial of service (daemon hang and CPU consumption) via a TCP packet of length 1, which triggers an infinite loop.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref patch="1" source="MLIST" url="http://sourceforge.net/mailarchive/forum.php?thread_id=7659656&amp;forum_id=12455">[net-snmp-announce] 20050701 Multiple new Net-SNMP releases to fix a security related bug</ref><ref adv="1" patch="1" source="TRUSTIX" url="http://www.trustix.org/errata/2005/0034/">2005-0034</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/15930">15930</ref><ref source="BID" url="http://www.securityfocus.com/bid/14168">14168</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-190-1">USN-190-1</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2005-225.pdf"></ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-873">DSA-873</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:025">MDKSA-2006:025</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18635">18635</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/17217">17217</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/17343">17343</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-373.html">RHSA-2005:373</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-395.html">RHSA-2005:395</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-720.html">RHSA-2005:720</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_24_sr.html">SUSE-SR:2005:024</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/17135">17135</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/17282">17282</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/16999">16999</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/17007">17007</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/451404/100/0/threaded">20061113 VMSA-2006-0006 - VMware ESX Server 2.5.3 Upgrade Patch 4</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/451419/100/200/threaded">20061113 VMSA-2006-0005 - VMware ESX Server 2.5.4 Upgrade Patch 1</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/451417/100/200/threaded">20061113 VMSA-2006-0007 - VMware ESX Server 2.1.3 Upgrade Patch 2</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/451426/100/200/threaded">20061113 VMSA-2006-0008 - VMware ESX Server 2.0.2 Upgrade Patch 2</ref><ref source="" url="http://www.vmware.com/download/esx/esx-202-200610-patch.html"></ref><ref source="" url="http://www.vmware.com/download/esx/esx-213-200610-patch.html"></ref><ref source="" url="http://www.vmware.com/download/esx/esx-254-200610-patch.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/4502">ADV-2006-4502</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/22875">22875</ref><ref source="" url="http://www.net-snmp.org/about/ChangeLog.html"></ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102725-1">102725</ref><ref source="BID" url="http://www.securityfocus.com/bid/21256">21256</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/4677">ADV-2006-4677</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017273">1017273</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/23058">23058</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/1883">ADV-2007-1883</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/25373">25373</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:025">MDKSA-2006:025</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_12_sr.html">SUSE-SR:2007:012</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2007_13_sr.html">SUSE-SR:2007:013</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/25432">25432</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/25787">25787</ref></refs><vuln_soft><prod name="Net-SNMP" vendor="Net-SNMP"><vers num="5.2.1"/><vers num="5.2"/><vers num="5.1.3"/><vers num="5.0.10"/><vers num="5.0.9"/><vers num="5.0.8"/><vers num="5.0.7"/><vers num="5.0.6"/><vers num="5.0.5"/><vers num="5.0.4 pre2"/><vers num="5.0.3"/><vers num="5.0.2"/><vers num="5.0.1"/><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2178" published="2005-07-11" seq="2005-2178" severity="High" type="CVE"><desc><descript source="cve">probe.cgi allows remote attackers to execute arbitrary commands via shell metacharacters in the olddat parameter.  NOTE: it is unclear which product or vendor this program is associated with, if any.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112059815028059&amp;w=2">20050705 [badroot security] probe.cgi: Remote Command Execution</ref><ref adv="1" source="MISC" url="http://www.badroot.org/advisories/SA0x06">http://www.badroot.org/advisories/SA0x06</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014393">1014393</ref></refs><vuln_soft><prod name="probe.cgi" vendor="probe.cgi"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2179" published="2005-07-11" seq="2005-2179" severity="Medium" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in BlogModel.php in Jaws 0.5.2 and earlier allows remote attackers to execute arbitrary PHP code via the path parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112067013827970&amp;w=2">20050706 Advisory 07/2005: Jaws Multiple Remote Code Execution Vulnerabilities</ref><ref adv="1" source="MISC" url="http://www.hardened-php.net/advisory-072005.php">http://www.hardened-php.net/advisory-072005.php</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014395">1014395</ref></refs><vuln_soft><prod name="JAWS" vendor="JAWS"><vers num="0.5.2"/><vers num="0.5.1"/><vers num="0.5.0"/><vers num="0.5.0 beta2"/><vers num="0.5.0 beta1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2180" published="2005-07-11" seq="2005-2180" severity="Low" type="CVE"><desc><descript source="cve">gen-index in GNATS 4.0, 4.1.0, and possibly earlier versions, when installed setuid, does not properly check files passed to the -o argument and opens the file with write access, which allows local users to overwrite arbitrary files.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112066901231154&amp;w=2">20050706 GNATS - gen-index</ref><ref source="MISC" url="http://www.pi3.int.pl/adv/gnats.txt">http://www.pi3.int.pl/adv/gnats.txt</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15963">15963</ref></refs><vuln_soft><prod name="GNATS" vendor="GNU"><vers num="4.0"/><vers num="4.1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2181" published="2005-07-11" seq="2005-2181" severity="Medium" type="CVE"><desc><descript source="cve">Cisco 7940/7960 Voice over IP (VoIP) phones do not properly check the Call-ID, branch, and tag values in a NOTIFY message to verify a subscription, which allows remote attackers to spoof messages such as the &quot;Messages waiting&quot; message.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112067698624686&amp;w=2">20050706 VoIP-Phones: Weakness in proccessing SIP-Notify-Messages</ref><ref adv="1" source="MISC" url="http://pentest.tele-consulting.com/advisories/05_07_06_voip-phones.txt">http://pentest.tele-consulting.com/advisories/05_07_06_voip-phones.txt</ref><ref source="SECTRACK" url="http://www.securitytracker.com/alerts/2005/Jul/1014406.html">1014406</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/21260">sip-notify-message-spoof(21260)</ref></refs><vuln_soft><prod name="7960" vendor="Cisco"><vers num=""/></prod><prod name="7940" vendor="Cisco"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2182" published="2005-07-11" seq="2005-2182" severity="Medium" type="CVE"><desc><descript source="cve">Grandstream BudgeTone (BT) 100 Voice over IP (VoIP) phones do not properly check the Call-ID, branch, and tag values in a NOTIFY message to verify a subscription, which allows remote attackers to spoof messages such as the &quot;Messages waiting&quot; message.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112067698624686&amp;w=2">20050706 VoIP-Phones: Weakness in proccessing SIP-Notify-Messages</ref><ref adv="1" source="MISC" url="http://pentest.tele-consulting.com/advisories/05_07_06_voip-phones.txt">http://pentest.tele-consulting.com/advisories/05_07_06_voip-phones.txt</ref><ref source="SECTRACK" url="http://www.securitytracker.com/alerts/2005/Jul/1014407.html">1014407</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/21260">sip-notify-message-spoof(21260)</ref></refs><vuln_soft><prod name="BudgeTone" vendor="Grandstream"><vers num="100"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2183" published="2005-07-11" seq="2005-2183" severity="High" type="CVE"><desc><descript source="cve">class.xmail.php in PhpXmail 0.7 through 1.1 does not properly handle large passwords, which prevents an error message from being returned and allows remote attackers to bypass authentication and gain unauthorized access.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112067694016410&amp;w=2">20050706 PHPXMAIL - Authentication Bypass</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/15951">15951</ref><ref source="BID" url="http://www.securityfocus.com/bid/14175">14175</ref></refs><vuln_soft><prod name="PHPXmail" vendor="PHPXmail"><vers num="1.1"/><vers num="0.7"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2184" published="2005-07-11" seq="2005-2184" severity="High" type="CVE"><desc><descript source="cve">eRoom 6.x does not properly restrict files that can be attached, which allows remote attackers to execute arbitrary commands via a .lnk file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112069267700034&amp;w=2">20050706 eRoom Multiple Security Issues</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15940">15940</ref></refs><vuln_soft><prod name="eRoom" vendor="EMC Corporation"><vers num="6.0.7"/><vers num="6.0.6"/><vers num="6.0.5"/><vers num="6.0.4"/><vers num="6.0.3"/><vers num="6.0.2"/><vers num="6.0.1"/><vers num="6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2185" published="2005-07-11" seq="2005-2185" severity="High" type="CVE"><desc><descript source="cve">eRoom does not set an expiration for Cookies, which allows remote attackers to capture cookies and conduct replay attacks.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112069267700034&amp;w=2">20050706 eRoom Multiple Security Issues</ref></refs><vuln_soft><prod name="eRoom" vendor="EMC Corporation"><vers num="6.0.7"/><vers num="6.0.6"/><vers num="6.0.5"/><vers num="6.0.4"/><vers num="6.0.3"/><vers num="6.0.2"/><vers num="6.0.1"/><vers num="6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="1.9" CVSS_exploit_subscore="3.4" CVSS_impact_subscore="2.9" CVSS_score="1.9" CVSS_vector="(AV:L/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2186" published="2005-07-11" seq="2005-2186" severity="Low" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in McAfee IntruShield Security Management System allow remote authenticated users to inject arbitrary web script or HTML via the (1) thirdMenuName or (2) resourceName parameter to SystemEvent.jsp.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112066594312876&amp;w=2">20050706 McAfee Intrushield IPS Abuse</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112076813804503&amp;w=2">20050706 Re: Re: McAfee Intrushield IPS Abuse</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014422">1014422</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15961">15961</ref></refs><vuln_soft><prod name="IntruShield Security Management System" vendor="McAfee"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2187" published="2005-07-11" seq="2005-2187" severity="Medium" type="CVE"><desc><descript source="cve">McAfee IntruShield Security Management System allows remote authenticated users to access the &quot;Generate Reports&quot; feature and modify alerts by setting the Access option to true, as demonstrated using the (1) fullAccess or (2) fullAccessRight parameter in reports-column-center.jsp, or (3) fullAccess parameter to SystemEvent.jsp.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112066594312876&amp;w=2">20050706 McAfee Intrushield IPS Abuse</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112076813804503&amp;w=2">20050706 Re: Re: McAfee Intrushield IPS Abuse</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014422">1014422</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15961">15961</ref></refs><vuln_soft><prod name="IntruShield Security Management System" vendor="McAfee"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2188" published="2005-07-11" seq="2005-2188" severity="High" type="CVE"><desc><descript source="cve">McAfee IntruShield Security Management System obtains the user ID from the URL, which allows remote attackers to guess the Manager account and possibly gain privileges via a brute force attack.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112066594312876&amp;w=2">20050706 McAfee Intrushield IPS Abuse</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112076813804503&amp;w=2">20050706 Re: Re: McAfee Intrushield IPS Abuse</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014422">1014422</ref></refs><vuln_soft><prod name="IntruShield Security Management System" vendor="McAfee"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2189" published="2005-07-11" seq="2005-2189" severity="Medium" type="CVE"><desc><descript source="cve">Lantronix SecureLinx console server running firmware 2.0 and 3.0 stores /etc/ssh under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information such as SSH private keys.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112075990621765&amp;w=2">20050707 Multiple vulnerabilities in Lantronix SLC console server</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15979">15979</ref></refs><vuln_soft><prod name="SecureLinx" vendor="Lantronix"><vers num="2.0"/><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2190" published="2005-07-11" seq="2005-2190" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in Comersus shopping cart allow remote attackers to execute arbitrary SQL commands via the (1) email parameter to comersus_optAffiliateRegistrationExec.asp or (2) idProduct parameter to comersus_optReviewReadExec.asp.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112077057001064&amp;w=2">20050707 [Bday release] Comersus shopping cart has multiple Sql injection</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014419">1014419</ref></refs><vuln_soft><prod name="Comersus Cart" vendor="Comersus Open Technologies"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2191" published="2005-07-11" seq="2005-2191" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Comersus shopping cart allow remote attackers to inject arbitrary web script or HTML via the (1) name parameter to comersus_backoffice_listAssignedPricesToCustomer.asp or (2) message parameter to comersus_backoffice_message.asp.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112077057001064&amp;w=2">20050707 [Bday release] Comersus shopping cart has multiple Sql injection</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014419">1014419</ref><ref source="" url="http://downloads.securityfocus.com/vulnerabilities/exploits/backoffice_mult_exp.pl"></ref><ref source="BID" url="http://www.securityfocus.com/bid/15251">15251</ref></refs><vuln_soft><prod name="Comersus Cart" vendor="Comersus Open Technologies"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-08-24" name="CVE-2005-2192" published="2005-07-11" seq="2005-2192" severity="Medium" type="CVE"><desc><descript source="cve">SimplePHPBlog 0.4.0 stores password hashes in config/password.txt with insufficient access control, which allows remote attackers to obtain passwords via a brute force attack.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112075901100640&amp;w=2">20050707 SimplePHPBlog 0.4.0 &lt;= Remote Password Disclosure</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15954">15954</ref></refs><vuln_soft><prod name="Simple PHP blog" vendor="Alexander Palmo"><vers num="0.4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2193" published="2005-07-11" seq="2005-2193" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in the user profile edit module in profile.php for PunBB 1.2.5 and earlier allows remote attackers to execute arbitrary SQL statements via the temp array, which is not initialized before it is used and prevents the attacker-supplied portions of the array from being properly escaped.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112084384928950&amp;w=2">20050707 Advisory 08/2005: PunBB SQL Injection Vulnerability</ref><ref adv="1" patch="1" source="MISC" url="http://www.hardened-php.net/advisory-082005.php">http://www.hardened-php.net/advisory-082005.php</ref><ref source="MISC" url="http://www.punbb.org/">http://www.punbb.org/</ref></refs><vuln_soft><prod name="PunBB" vendor="PunBB"><vers num="1.2.4"/><vers num="1.2.3"/><vers num="1.2.2"/><vers num="1.2.1"/><vers num="1.1.5"/><vers num="1.1.4"/><vers num="1.1.3"/><vers num="1.1.2"/><vers num="1.1.1"/><vers num="1.1"/><vers num="1.0.1"/><vers num="1.0 RC2"/><vers num="1.0 RC1"/><vers num="1.0 Beta3"/><vers num="1.0 Beta2"/><vers num="1.0 Beta1"/><vers num="1.0 alpha"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-08-08" name="CVE-2005-2194" published="2005-12-31" seq="2005-2194" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the Apple Mac OS X kernel before 10.4.2 allows remote attackers to cause a denial of service (kernel panic) via a crafted TCP packet, possibly related to source routing or loose source routing.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="" url="http://docs.info.apple.com/article.html?artnum=301948"></ref><ref source="APPLE" url="http://lists.apple.com/archives/Security-announce/2005/Jul/msg00000.html">APPLE-SA-2005-07-12</ref></refs><vuln_soft><prod name="Mac OS X" vendor="Apple"><vers num="10.4.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-25" name="CVE-2005-2195" published="2005-07-18" seq="2005-2195" severity="Medium" type="CVE"><desc><descript source="cve">Apple Darwin Streaming Server 5.5 and earlier allows remote attackers to cause a denial of service (application crash) via a URL with a filename containing a .cgi extension and an MS-DOS device name such as AUX, CON, PRN, COM1, or LPT1, a different vulnerability than CVE-2003-0421 and CVE-2003-0502.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="MISC" url="http://secway.org/Advisory/AD20050713.txt">http://secway.org/Advisory/AD20050713.txt</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014474">1014474</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16056">16056</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112126999514361&amp;w=2">20050713 APPLE Darwin Streaming Server Web Admin Remote Denial of Serivce</ref></refs><vuln_soft><prod name="Darwin Streaming Server" vendor="Apple"><vers num="5.5" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2196" published="2005-07-19" seq="2005-2196" severity="Low" type="CVE"><desc><descript source="cve">The Apple AirPort card uses a default WEP key when not connected to a known or trusted network, which can cause it to automatically connect to a malicious network.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/14321">14321</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014522">1014522</ref></refs><vuln_soft><prod name="AirPort Card" vendor="Apple"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2197" published="2005-07-11" seq="2005-2197" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in sql.cls.php in Id Board 1.1.3 allows remote attackers to modify SQL queries, as demonstrated using the f parameter to index.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=112098888903080&amp;w=2">20050710 ID Board 1.1.3 SQL Injection Vulnerability</ref><ref adv="1" source="SECTRACK" url="http://securitytracker.com/id?1014438">1014438</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15976">15976</ref><ref source="BID" url="http://www.securityfocus.com/bid/14204">14204</ref></refs><vuln_soft><prod name="Id Board" vendor="Id Board"><vers num="1.1.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2198" published="2005-07-11" seq="2005-2198" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in lang.php in SPiD before 1.3.1 allows remote attackers to execute arbitrary code via the lang_path parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://spid.adnx.net/index_en.html#log">http://spid.adnx.net/index_en.html#log</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014437">1014437</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/16022">16022</ref><ref source="BID" url="http://www.securityfocus.com/bid/14208">14208</ref></refs><vuln_soft><prod name="SPiD" vendor="SPiD"><vers num="1.3.0"/><vers num="1.2.3"/><vers num="1.2.2"/><vers num="1.2.1"/><vers num="1.2.0"/><vers num="1.1.0"/><vers num="1.0.4"/><vers num="1.0.3"/><vers num="1.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-10-05" name="CVE-2005-2199" published="2005-07-11" seq="2005-2199" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in inc/functions.inc.php in PPA web photo gallery 0.5.6 allows remote attackers to execute arbitrary code via the config[ppa_root_path] variable.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="SECTRACK" url="http://securitytracker.com/id?1014436">1014436</ref><ref source="BID" url="http://www.securityfocus.com/bid/14209">14209</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16011">16011</ref></refs><vuln_soft><prod name="PPA Gallery" vendor="Skrypty"><vers num="0.5.6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2200" published="2005-07-11" seq="2005-2200" severity="High" type="CVE"><desc><descript source="cve">Multiple unknown vulnerabilities in the MicroServer Web Server for Xerox WorkCentre Pro Color 2128, 2636, and 3545, version 0.001.04.044 through 0.001.04.504, allow attackers to bypass authentication.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.xerox.com/downloads/usa/en/c/cert_XRX05_006.pdf">http://www.xerox.com/downloads/usa/en/c/cert_XRX05_006.pdf</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1014429">1014429</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/15970">15970</ref></refs><vuln_soft><prod name="WorkCentre Pro Color" vendor="Xerox"><vers num="3545 0.001.04.504"/><vers num="3545 0.001.04.044"/><vers num="2636 0.001.04.504"/><vers num="2636 0.001.04.044"/><vers num="2128 0.001.04.504"/><vers num="2128 0.001.04.044"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2201" published="2005-07-11" seq="2005-2201" severity="Medium" type="CVE"><desc><descript source="cve">Unknown vulnerability in the MicroServer Web Server for Xerox WorkCentre Pro Color 2128, 2636, and 3545, version 0.001.04.044 through 0.001.04.504, allow attackers to cause a denial of service or access files via crafted HTTP requests.</descript></desc><loss_types><avail/><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.xerox.com/downloads/usa/en/c/cert_XRX05_006.pdf">http://www.xerox.com/downloads/usa/en/c/cert_XRX05_006.pdf</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1014429">1014429</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/15970">15970</ref></refs><vuln_soft><prod name="WorkCentre Pro Color" vendor="Xerox"><vers num="3545 0.001.04.504"/><vers num="3545 0.001.04.044"/><vers num="2636 0.001.04.504"/><vers num="2636 0.001.04.044"/><vers num="2128 0.001.04.504"/><vers num="2128 0.001.04.044"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2202" published="2005-07-11" seq="2005-2202" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in the MicroServer Web Server for Xerox WorkCentre Pro Color 2128, 2636, and 3545, version 0.001.04.044 through 0.001.04.504, allows remote attackers to inject arbitrary web script or HTML via unknown vectors.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.xerox.com/downloads/usa/en/c/cert_XRX05_006.pdf">http://www.xerox.com/downloads/usa/en/c/cert_XRX05_006.pdf</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1014429">1014429</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/15970">15970</ref></refs><vuln_soft><prod name="WorkCentre Pro Color" vendor="Xerox"><vers num="3545 0.001.04.504"/><vers num="3545 0.001.04.044"/><vers num="2636 0.001.04.504"/><vers num="2636 0.001.04.044"/><vers num="2128 0.001.04.504"/><vers num="2128 0.001.04.044"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2203" published="2005-07-11" seq="2005-2203" severity="High" type="CVE"><desc><descript source="cve">login.php in phpWishlist before 0.1.15 allows remote attackers to bypass authentication via a direct request to admin.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://unix.freshmeat.net/projects/phpwishlist/?branch_id=53897&amp;release_id=200925">http://unix.freshmeat.net/projects/phpwishlist/?branch_id=53897&amp;release_id=200925</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1014432">1014432</ref></refs><vuln_soft><prod name="phpWishlist" vendor="phpWishlist"><vers num="0.1.14"/><vers num="0.1.13"/><vers num="0.1.12"/><vers num="0.1.11"/><vers num="0.1.10"/><vers num="0.1.9"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2204" published="2005-07-11" seq="2005-2204" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Computer Associates (CA) eTrust SiteMinder 5.5, when the &quot;CSSChecking&quot; parameter is set to &quot;NO,&quot; allows remote attackers to inject arbitrary web script or HTML via the (1) PASSWORD or (2) BUFFER parameters to smpwservicescgi.exe, (3) the TARGET parameter to login.fcc, and possibly other vectors.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112084050624959&amp;w=2">20050708 SiteMinder Multiple Vulnerabilities</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112110963416714&amp;w=2">20050711 Re: SiteMinder Multiple Vulnerabilities</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014433">1014433</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/1040">ADV-2005-1040</ref><ref source="OSVDB" url="http://www.osvdb.org/17809">17809</ref><ref source="OSVDB" url="http://www.osvdb.org/17810">17810</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15956">15956</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/21305">ca-siteminder-smpwservicescgi-xss(21305)</ref></refs><vuln_soft><prod name="eTrust SiteMinder" vendor="Computer Associates"><vers num="5.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2205" published="2005-07-11" seq="2005-2205" severity="High" type="CVE"><desc><descript source="cve">The ReadLog function in kaiseki.cgi in pngren allows remote attackers to execute arbitrary commands via shell metacharacters in the query string.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://seclists.org/lists/bugtraq/2005/Jul/0097.html">20050705 PNG remote commands execution vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/14182">14182</ref><ref source="OSVDB" url="http://www.osvdb.org/17784">17784</ref><ref adv="1" source="SECTRACK" url="http://securitytracker.com/id?1014426">1014426</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/15981">15981</ref></refs><vuln_soft><prod name="pngren" vendor="pngren"><vers num="2.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-08-28" name="CVE-2005-2206" published="2005-07-11" seq="2005-2206" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in CartWIZ allow remote attackers to modify SQL statements via the (1) idProduct parameter to tellAFriend.asp, (2) sortType parameter to viewSupportTickets.asp, or the id parameter to (3) updateCreditCards.asp or (4) deleteCreditCards.asp.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://digitalparadox.org/viewadvisories.ah?view=42">http://digitalparadox.org/viewadvisories.ah?view=42</ref><ref adv="1" source="SECTRACK" url="http://securitytracker.com/id?1014418">1014418</ref></refs><vuln_soft><prod name="CartWIZ" vendor="Elemental Software"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-08-28" name="CVE-2005-2207" published="2005-07-11" seq="2005-2207" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in store/login.asp in CartWIZ allows remote attackers to inject arbitrary web script or HTML via the message parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://digitalparadox.org/viewadvisories.ah?view=42">http://digitalparadox.org/viewadvisories.ah?view=42</ref><ref adv="1" source="SECTRACK" url="http://securitytracker.com/id?1014418">1014418</ref></refs><vuln_soft><prod name="CartWIZ" vendor="Elemental Software"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2208" published="2005-07-11" seq="2005-2208" severity="Medium" type="CVE"><desc><descript source="cve">PrivaShare 1.1b allows remote attackers to cause a denial of service (crash) via a malformed message.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref source="MISC" url="http://k.domaindlx.com/shellcore/advisories.asp?bug_report=display&amp;infamous_group=66">http://k.domaindlx.com/shellcore/advisories.asp?bug_report=display&amp;infamous_group=66</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15933">15933</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014412">1014412</ref></refs><vuln_soft><prod name="PrivaShare" vendor="PrivaShare"><vers num="1.1b"/></prod></vuln_soft></entry><entry CVSS_base_score="1.9" CVSS_exploit_subscore="3.4" CVSS_impact_subscore="2.9" CVSS_score="1.9" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2209" published="2005-07-11" seq="2005-2209" severity="Low" type="CVE"><desc><descript source="cve">Capturix ScanShare 1.06 build 50 stores sensitive information such as the password in cleartext in capturixss_cfg.ini, which is readable by local users.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="SECTRACK" url="http://securitytracker.com/id?1014409">1014409</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15995">15995</ref></refs><vuln_soft><prod name="ScanShare" vendor="Capturix"><vers num="1.06 build 50"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2210" published="2005-07-11" seq="2005-2210" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in Internet Download Manager 4.05 allows remote attackers to execute arbitrary code via a long URL.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="MISC" url="http://www.ihsteam.com/download/ihsexpl/dlm.c">http://www.ihsteam.com/download/ihsexpl/dlm.c</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014404">1014404</ref></refs><vuln_soft><prod name="Internet Download Manager" vendor="Tonec Inc."><vers num="4.05"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2211" published="2005-07-11" seq="2005-2211" severity="Medium" type="CVE"><desc><descript source="cve">Backup Manager 0.5.8a creates temporary files insecurely, which allows local users to conduct unauthorized file operations when a user is burning a CDR.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><env/></vuln_types><range><local/></range><refs><ref patch="1" source="" url="http://www.sukria.net/packages/backup-manager/">http://www.sukria.net/packages/backup-manager/</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/15989">15989</ref></refs><vuln_soft><prod name="Backup Manager" vendor="Sukria"><vers num="0.5.8a"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2212" published="2005-07-11" seq="2005-2212" severity="Medium" type="CVE"><desc><descript source="cve">Backup Manager 0.5.8a creates an archive repository with world readable and writable permissions, which allows attackers to modify or read the repository.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://www.sukria.net/packages/backup-manager/">http://www.sukria.net/packages/backup-manager/</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/15989">15989</ref></refs><vuln_soft><prod name="Backup Manager" vendor="Sukria"><vers num="0.5.8a"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2213" published="2005-07-11" seq="2005-2213" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the mms_interp_header function in mms.c in MMS Ripper before 0.6.4 might allow remote attackers to execute arbitrary code via a file with more than 20 streams.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="" url="http://nbenoit.tuxfamily.org/projects/mmsrip/ChangeLog">http://nbenoit.tuxfamily.org/projects/mmsrip/ChangeLog</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/15987">15987</ref><ref patch="1" source="FRESHMEAT" url="http://freshmeat.net/projects/mmsrip/?branch_id=56514&amp;release_id=201125">MMS Ripper 0.6.4 (Default)</ref></refs><vuln_soft><prod name="MMS Ripper" vendor="MMS Ripper"><vers num="0.6.2"/><vers num="0.6.0"/><vers num="0.4.2"/><vers num="0.4.1"/><vers num="0.4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2214" published="2005-07-11" seq="2005-2214" severity="Medium" type="CVE"><desc><descript source="cve">apt-setup in Debian GNU/Linux installs the apt.conf file with insecure permissions, which allows local users to obtain sensitive information such as passwords.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="Debian" url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=305142">305142: apt-setup creates a world readable apt.conf file</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15955">15955</ref><ref source="BID" url="http://www.securityfocus.com/bid/14173">14173</ref></refs><vuln_soft><prod name="apt-setup" vendor="Debian"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-25" name="CVE-2005-2215" published="2005-07-12" seq="2005-2215" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in MediaWiki before 1.4.x before 1.4.6 and 1.5 before 1.5beta3 allows remote attackers to inject arbitrary web script or HTML via a parameter in the page move template, a different vulnerability than CVE-2005-1888.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://sourceforge.net/project/shownotes.php?release_id=340290">http://sourceforge.net/project/shownotes.php?release_id=340290</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/14181">14181</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/15950">15950</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_19_sr.html">SUSE-SR:2005:019</ref></refs><vuln_soft><prod name="MediaWiki" vendor="MediaWiki"><vers num="1.5 Beta2"/><vers num="1.5 Beta1"/><vers num="1.5 alpha2"/><vers num="1.5 alpha1"/><vers num="1.4.5"/><vers num="1.4.3"/><vers num="1.4.2"/><vers num="1.4.1"/><vers num="1.4 beta6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-22" name="CVE-2005-2216" published="2005-07-12" seq="2005-2216" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in gals.php in PhotoGal Photo Gallery 1.5 and earlier allows remote attackers to execute arbitrary code via the news_file parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="SECTRACK" url="http://securitytracker.com/id?1014397">1014397</ref></refs><vuln_soft><prod name="PhotoGal Photo Gallery" vendor="PhotoGal"><vers num="1.5" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-08-31" name="CVE-2005-2217" published="2005-07-12" seq="2005-2217" severity="Medium" type="CVE"><desc><descript source="cve">Dansie Shopping Cart stores the vars.dat file under the web root with insufficient access control, which might allow remote attackers to obtain sensitive information such as program variables.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/><input/></vuln_types><range><network/></range><refs><ref source="SECTRACK" url="http://securitytracker.com/id?1014396">1014396</ref></refs><vuln_soft><prod name="Dansie Shopping Cart" vendor="Craig Dansie"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2218" published="2005-07-26" seq="2005-2218" severity="High" type="CVE"><desc><descript source="cve">The device file system (devfs) in FreeBSD 5.x does not properly check parameters of the node type when creating a device node, which makes hidden devices available to attackers, who can then bypass restrictions on a jailed process.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref source="FREEBSD" url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-05:17.devfs.asc">FreeBSD-SA-05:17</ref><ref source="BID" url="http://www.securityfocus.com/bid/14334">14334</ref><ref source="OSVDB" url="http://www.osvdb.org/18123">18123</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014536">1014536</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16145">16145</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/21451">freebsd-devfs-gain-privileges(21451)</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="5.4 Releng"/><vers num="5.4 Release"/><vers num="5.4 pre"/><vers num="5.4"/><vers num="5.3 Stable"/><vers num="5.3 Releng"/><vers num="5.3 Release"/><vers num="5.3"/><vers num="5.2 Release"/><vers num="5.2.1 Release"/><vers num="5.2.1"/><vers num="5.2 Releng"/><vers num="5.2"/><vers num="5.1 Release"/><vers num="5.1 Releng"/><vers num="5.1 p5 Release"/><vers num="5.1 Release Alpha"/><vers num="5.1"/><vers num="5.0 Releng"/><vers num="5.0 p14 Release"/><vers num="5.0 alpha"/><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2219" published="2005-07-12" seq="2005-2219" severity="Medium" type="CVE"><desc><descript source="cve">Hosting Controller 6.1 Hotfix 2.1 allows remote authenticated users to perform unauthorized actions, such as modifying the credit limit, via a direct request to AccountActions.asp and modifying the CreditLimit parameter in an UpdateCreditLimit action.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref source="SECTRACK" url="http://securitytracker.com/id?1014443">1014443</ref></refs><vuln_soft><prod name="Hosting Controller" vendor="Hosting Controller"><vers num="6.1 Hotfix 2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-06-15" name="CVE-2005-2220" published="2005-07-12" seq="2005-2220" severity="Medium" type="CVE"><desc><descript source="cve">** DISPUTED **  Dragonfly Commerce allows remote attackers to change a product price by modifying the x_DragonflyCartProductPrice hidden field to (1) dc_Categorieslist.asp, (2) dc_Categoriesview.asp, (3) dc_productslist.asp, and (4) dc_productslist_Clearance.asp.  NOTE: the vendor has disputed this issue, saying that &quot;Dragonfly Commerce does not allow for editing prices nor does it allow for viewing information about clients stored in the database except by the store owner and authorized staff as appointed in the store administration.&quot;  However, SecurityTracker claims that they have been able to confirm the problem.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="SECTRACK" url="http://securitytracker.com/id?1014451">1014451</ref><ref source="MISC" url="http://www.digitalparadox.org/viewadvisories.ah?view=46">http://www.digitalparadox.org/viewadvisories.ah?view=46</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112121930328341&amp;w=2">20050712 Dragonfly Shopping Cart Multiple vulnerabilities</ref></refs><vuln_soft><prod name="Dragonfly Commerce" vendor="Incredible Interactive"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-06-15" name="CVE-2005-2221" published="2005-07-12" seq="2005-2221" severity="High" type="CVE"><desc><descript source="cve">** DISPUTED **  Multiple SQL injection vulnerabilities in Dragonfly Commerce allows remote attackers to modify SQL statements and possibly execute arbitrary SQL commands via the (1) key parameter to dc_Categoriesview.asp, (2) dc_productslist_Clearance.asp, (3) PID parameter to ratings.asp, (4) dc_Productsview.asp, (5) start, (6) key_mp, (7) searchtype, or (8) psearch parameters to dc_forum_Postslist.asp.  NOTE: the vendor has disputed this issue, saying that the error messages arise from invalid category and product numbers.  Assuming that this is the case, the issue still satisfies the CVE definition of &quot;exposure.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="SECTRACK" url="http://securitytracker.com/id?1014451">1014451</ref><ref source="MISC" url="http://www.digitalparadox.org/viewadvisories.ah?view=46">http://www.digitalparadox.org/viewadvisories.ah?view=46</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112121930328341&amp;w=2">20050712 Dragonfly Shopping Cart Multiple vulnerabilities</ref></refs><vuln_soft><prod name="Dragonfly Commerce" vendor="Incredible Interactive"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-06-26" name="CVE-2005-2222" published="2005-07-12" seq="2005-2222" severity="High" type="CVE"><desc><descript source="cve">Unknown vulnerability in the HTTPMail service in MailEnable Professional before 1.6 has unknown impact and attack vectors.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs><ref source="" url="http://www.mailenable.com/professionalhistory.asp">http://www.mailenable.com/professionalhistory.asp</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1014427">1014427</ref></refs><vuln_soft><prod name="MailEnable Professional" vendor="MailEnable"><vers num="1.54"/><vers num="1.53"/><vers num="1.52"/><vers num="1.51"/><vers num="1.5"/><vers num="1.2a"/><vers num="1.17"/><vers num="1.18"/><vers num="1.19"/><vers num="1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2007-07-24" name="CVE-2005-2223" published="2005-07-12" seq="2005-2223" severity="Medium" type="CVE"><desc><descript source="cve">Unknown vulnerability in the SMTP service in MailEnable Standard before 1.9 and Professional before 1.6 allows remote attackers to cause a denial of service (crash) during authentication.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref source="" url="http://www.mailenable.com/professionalhistory.asp">http://www.mailenable.com/professionalhistory.asp</ref><ref source="" url="http://www.mailenable.com/standardhistory.asp">http://www.mailenable.com/standardhistory.asp</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1014427">1014427</ref></refs><vuln_soft><prod name="MailEnable Professional" vendor="MailEnable"><vers num="1.54"/><vers num="1.53"/><vers num="1.52"/><vers num="1.51"/><vers num="1.5"/><vers num="1.2a"/><vers num="1.17"/><vers num="1.18"/><vers num="1.19"/><vers num="1.2"/></prod><prod name="MailEnable Standard" vendor="MailEnable"><vers num="1.8"/><vers num="1.72"/><vers num="1.71"/><vers num="1.704"/><vers num="1.703"/><vers num="1.702"/><vers num="1.701"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2224" published="2005-07-12" seq="2005-2224" severity="Medium" type="CVE"><desc><descript source="cve">aspnet_wp.exe in Microsoft ASP.NET web services allows remote attackers to cause a denial of service (CPU consumption from infinite loop) via a crafted SOAP message to an RPC/Encoded method.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://www.spidynamics.com/spilabs/advisories/aspRCP.html">http://www.spidynamics.com/spilabs/advisories/aspRCP.html</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/16005">16005</ref><ref source="BID" url="http://www.securityfocus.com/bid/14217">14217</ref></refs><vuln_soft><prod name="ASP.NET" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2225" published="2005-07-12" seq="2005-2225" severity="Medium" type="CVE"><desc><descript source="cve">Microsoft MSN Messenger allows remote attackers to cause a denial of service via a plaintext message containing the &quot;.pif&quot; string, which is interpreted as a malicious file extension and causes users to be kicked from a group conversation.  NOTE: it has been reported that Gaim is also affected, so this may be an issue in the protocol or MSN servers.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://www.digitalparadox.org/viewadvisories.ah?view=45">http://www.digitalparadox.org/viewadvisories.ah?view=45</ref><ref adv="1" source="MISC" url="http://www.messenger-blog.com/?p=146">http://www.messenger-blog.com/?p=146</ref><ref adv="1" source="SECTRACK" url="http://securitytracker.com/id?1014444">1014444</ref></refs><vuln_soft><prod name="MSN Messenger Service" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2226" published="2005-07-12" seq="2005-2226" severity="Medium" type="CVE"><desc><descript source="cve">Microsoft Outlook Express 6.0 leaks the default news server account when a user responds to a &quot;watched&quot; conversation thread, which could allow remote attackers to obtain sensitive information.</descript></desc><loss_types><conf/></loss_types><range><network/></range><refs><ref patch="1" source="MSKB" url="http://support.microsoft.com/default.aspx/kb/900930">900930</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/14225">14225</ref></refs><vuln_soft><prod name="Outlook Express" vendor="Microsoft"><vers num="6.0 SP2"/><vers num="6.0 SP1"/><vers num="6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2227" published="2005-07-12" seq="2005-2227" severity="High" type="CVE"><desc><descript source="cve">Softiacom wMailserver 1.0 stores passwords in plaintext in the Darsite\MAILSRV\Admin key, which allows local users to gain administrator privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112120030308592&amp;w=2">20050712 SoftiaCom MailServer - Local Password Disclosure Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/14212">14212</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014450">1014450</ref></refs><vuln_soft><prod name="wMailserver" vendor="Softiacom"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-22" name="CVE-2005-2228" published="2005-07-12" seq="2005-2228" severity="Medium" type="CVE"><desc><descript source="cve">Web Wiz Forums 7.9 and 8.0 allows remote attackers to view message titles of a hidden forum.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/14207">14207</ref></refs><vuln_soft><prod name="Web Wiz Forums" vendor="BDC Enterprises"><vers num="8.0 alpha"/><vers num="7.91"/><vers num="7.9"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2229" published="2005-07-12" seq="2005-2229" severity="High" type="CVE"><desc><descript source="cve">Blog Torrent 0.92 and earlier stores sensitive files under the web document root in the (1) data or (2) torrents directories with insufficient access control, which allows remote attackers to obtain sensitive information such as account names and password hashes, as demonstrated using data/newusers.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref source="SECTRACK" url="http://securitytracker.com/id?1014449">1014449</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15983">15983</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112110868021563&amp;w=2">20050711 blogtorrent remote/local user password disclosure</ref></refs><vuln_soft><prod name="Blog Torrent" vendor="Blog Torrent"><vers num="0.92" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2230" published="2005-07-12" seq="2005-2230" severity="Low" type="CVE"><desc><descript source="cve">Electronic Mail Operator (elmo) 1.3.2-r1 and earlier creates the elmostats temporary file insecurely, which allows local users to overwrite arbitrary files.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/15977">15977</ref><ref source="" url="http://www.zataz.net/adviso/elmo-06272005.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/14235">14235</ref></refs><vuln_soft><prod name="Elmo" vendor="Elmo"><vers num="1.3.2 r1"/><vers num="1.3.1"/><vers num="1.3.0"/><vers num="1.2.0"/><vers num="1.1.0"/><vers num="1.0.4"/><vers num="1.0.3"/><vers num="1.0.2"/><vers num="1.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2231" published="2005-07-12" seq="2005-2231" severity="Low" type="CVE"><desc><descript source="cve">High Availability Linux Project Heartbeat 1.2.3 allows local users to overwrite arbitrary files via a symlink attack on temporary files.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/16039">16039</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-761">DSA-761</ref></refs><vuln_soft><prod name="Heartbeat" vendor="High Availability Linux Project"><vers num="1.2.3"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2232" published="2005-07-12" seq="2005-2232" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in invscout in IBM AIX 5.1.0 through 5.3.0 might allow local users to execute arbitrary code via a long command line argument.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="MISC" url="http://www.caughq.org/advisories/CAU-2005-0002.txt">http://www.caughq.org/advisories/CAU-2005-0002.txt</ref><ref adv="1" source="" url="http://www.securityfocus.com/advisories/8816">http://www.securityfocus.com/advisories/8816</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/13909">13909</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014132">1014132</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/15636">15636</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="5.1"/><vers num="5.2"/><vers num="5.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2233" published="2005-07-12" seq="2005-2233" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in multiple &quot;p&quot; commands in IBM AIX 5.1, 5.2 and 5.3 might allow local users to execute arbitrary code via long command line arguments to (1) penable or other hard-linked files including (2) pdisable, (3) pstart, (4) phold, (5) pdelay, or (6) pshare.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="MISC" url="http://www.caughq.org/advisories/CAU-2005-0006.txt">http://www.caughq.org/advisories/CAU-2005-0006.txt</ref><ref adv="1" patch="1" source="" url="http://www.security-focus.com/advisories/8684">http://www.security-focus.com/advisories/8684</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/13915">13915</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014132">1014132</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/15636">15636</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="5.3 L"/><vers num="5.3"/><vers num="5.2.2"/><vers num="5.2 L"/><vers num="5.2"/><vers num="5.1L"/><vers num="5.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2234" published="2005-07-12" seq="2005-2234" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the getlvname command in IBM AIX 5.1, 5.2 and 5.3, might allow local users to execute arbitrary code via long command line arguments.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="MISC" url="http://www.caughq.org/advisories/CAU-2005-0005.txt">http://www.caughq.org/advisories/CAU-2005-0005.txt</ref><ref adv="1" patch="1" source="" url="http://www.security-focus.com/advisories/8684">http://www.security-focus.com/advisories/8684</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/13914">13914</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014132">1014132</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/15636">15636</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="5.3 L"/><vers num="5.3"/><vers num="5.2.2"/><vers num="5.2 L"/><vers num="5.2"/><vers num="5.1L"/><vers num="5.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2235" published="2005-07-12" seq="2005-2235" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the diagTasksWebSM command in IBM AIX 5.1, 5.2 and 5.3, might allow local users to execute arbitrary code via long command line arguments.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="MISC" url="http://www.caughq.org/advisories/CAU-2005-0004.txt">http://www.caughq.org/advisories/CAU-2005-0004.txt</ref><ref adv="1" patch="1" source="" url="http://www.security-focus.com/advisories/8819">http://www.security-focus.com/advisories/8819</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/13912">13912</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014132">1014132</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/15636">15636</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="5.3 L"/><vers num="5.3"/><vers num="5.2.2"/><vers num="5.2 L"/><vers num="5.2"/><vers num="5.1L"/><vers num="5.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2236" published="2005-07-12" seq="2005-2236" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in the paginit command in IBM AIX 5.3, and possibly other versions, might allow local users to execute arbitrary code via format strings in command line arguments.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" source="MISC" url="http://www.caughq.org/advisories/CAU-2005-0003.txt">http://www.caughq.org/advisories/CAU-2005-0003.txt</ref><ref source="BID" url="http://www.securityfocus.com/bid/13911">13911</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014132">1014132</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="5.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2237" published="2005-07-12" seq="2005-2237" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in the swcons command in IBM AIX 5.3, and possibly other versions, might allow local users to execute arbitrary code via long command line arguments.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" source="MISC" url="http://www.caughq.org/advisories/CAU-2005-0007.txt">http://www.caughq.org/advisories/CAU-2005-0007.txt</ref><ref source="BID" url="http://www.securityfocus.com/bid/13921">13921</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014132">1014132</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="5.3"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2238" published="2005-07-12" seq="2005-2238" severity="Low" type="CVE"><desc><descript source="cve">ftpd in IBM AIX 5.1, 5.2 and 5.3 allows remote authenticated users to cause a denial of service (port exhaustion and memory consumption) by using all ephemeral ports.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1014421">1014421</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="5.1"/><vers num="5.2"/><vers num="5.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2239" published="2005-07-12" seq="2005-2239" severity="Medium" type="CVE"><desc><descript source="cve">oftpd 0.3.7 allows remote attackers to cause a denial of service via a USER command with a large number of null (\0) characters.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref source="SECTRACK" url="http://securitytracker.com/id?1014413">1014413</ref></refs><vuln_soft><prod name="oftpd" vendor="oftpd"><vers num="0.3.7"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2240" published="2005-07-12" seq="2005-2240" severity="Low" type="CVE"><desc><descript source="cve">xpvm.tcl in xpvm 1.2.5 allows local users to overwrite arbitrary files via a symlink attack on the xpvm.trace.$user temporary file.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/16040">16040</ref><ref source="" url="http://www.zataz.net/adviso/xpvm-06272005.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/14228">14228</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1003">DSA-1003</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19251">19251</ref></refs><vuln_soft><prod name="xpvm" vendor="xpvm"><vers num="1.2.5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2241" published="2005-07-12" seq="2005-2241" severity="Medium" type="CVE"><desc><descript source="cve">Cisco CallManager (CCM) 3.2 and earlier, 3.3 before 3.3(5), 4.0 before 4.0(2a)SR2b, and 4.1 4.1 before 4.1(3)SR1 does not quickly time out Realtime Information Server Data Collection (RISDC) sockets, which results in a &quot;resource leak&quot; that allows remote attackers to cause a denial of service (memory and connection consumption) in RisDC.exe.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-sa-20050712-ccm.shtml">20050712 Cisco CallManager Memory Handling Vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/14250">14250</ref></refs><vuln_soft><prod name="Call Manager" vendor="Cisco"><vers num="3.2"/><vers num="3.3"/><vers num="4.0"/><vers num="4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2242" published="2005-07-12" seq="2005-2242" severity="Medium" type="CVE"><desc><descript source="cve">Cisco CallManager (CCM) 3.2 and earlier, 3.3 before 3.3(5), 4.0 before 4.0(2a)SR2b, and 4.1 4.1 before 4.1(3)SR1 allows remote attackers to cause a denial of service (memory consumption and restart) via crafted packets to (1) the CTI Manager (ctimgr.exe) or (2) the CallManager (ccm.exe).</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-sa-20050712-ccm.shtml">20050712 Cisco CallManager Memory Handling Vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/14251">14251</ref><ref source="BID" url="http://www.securityfocus.com/bid/14252">14252</ref></refs><vuln_soft><prod name="Call Manager" vendor="Cisco"><vers num="3.2"/><vers num="3.3"/><vers num="4.0"/><vers num="4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2243" published="2005-07-12" seq="2005-2243" severity="Medium" type="CVE"><desc><descript source="cve">Memory leak in inetinfo.exe in Cisco CallManager (CCM) 3.2 and earlier, 3.3 before 3.3(5), 4.0 before 4.0(2a)SR2b, and 4.1 4.1 before 4.1(3)SR1, when Multi Level Admin (MLA) is enabled, allows remote attackers to cause a denial of service (memory consumption) via a large number of Admin Service Tool (AST) logins that fail.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-sa-20050712-ccm.shtml">20050712 Cisco CallManager Memory Handling Vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/14253">14253</ref></refs><vuln_soft><prod name="Call Manager" vendor="Cisco"><vers num="3.2"/><vers num="3.3"/><vers num="4.0"/><vers num="4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2244" published="2005-07-12" seq="2005-2244" severity="Medium" type="CVE"><desc><descript source="cve">The aupair service (aupair.exe) in Cisco CallManager (CCM) 3.2 and earlier, 3.3 before 3.3(5), 4.0 before 4.0(2a)SR2b, and 4.1 4.1 before 4.1(3)SR1 allows remote attackers to execute arbitrary code or corrupt memory via crafted packets that trigger a memory allocation failure and lead to a buffer overflow.</descript></desc><loss_types><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-sa-20050712-ccm.shtml">20050712 Cisco CallManager Memory Handling Vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/14255">14255</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19053">malloc-return-value-dos(19053)</ref></refs><vuln_soft><prod name="Call Manager" vendor="Cisco"><vers num="3.2"/><vers num="3.3"/><vers num="4.0"/><vers num="4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2245" published="2005-07-12" seq="2005-2245" severity="High" type="CVE"><desc><descript source="cve">Unknown vulnerability in F5 BIG-IP 9.0.2 through 9.1 allows attackers to &quot;subvert the authentication of SSL transactions,&quot; via unknown attack vectors, possibly involving NATIVE ciphers.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/16008">16008</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1014452">1014452</ref><ref source="BID" url="http://www.securityfocus.com/bid/14215">14215</ref></refs><vuln_soft><prod name="BigIP" vendor="F5"><vers num="9.0.2"/><vers num="9.0.3"/><vers num="9.0.4"/><vers num="9.0.5"/><vers num="9.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2246" published="2005-07-12" seq="2005-2246" severity="High" type="CVE"><desc><descript source="cve">Multiple PHP remote file inclusion vulnerabilities in iPhotoAlbum 1.1 allow remote attackers to execute arbitrary code via the (1) doc_path parameter to getpage.php or (2) set_menu parameter to lib/static/header.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="SECTRACK" url="http://securitytracker.com/id?1014448">1014448</ref><ref source="BID" url="http://www.securityfocus.com/bid/14229">14229</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16031">16031</ref><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/3596">

3596</ref><ref source="VIM" url="http://www.attrition.org/pipermail/vim/2007-March/001474.html">
20070329 iPhotoAlbum v1.1(header.php)Remote File Include Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/23189">
23189</ref></refs><vuln_soft><prod name="iPhotoAlbum" vendor="iPhotoAlbum"><vers num="1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2247" published="2005-07-12" seq="2005-2247" severity="High" type="CVE"><desc><descript source="cve">Multiple unknown vulnerabilities in Moodle before 1.5.1 have unknown impact and attack vectors.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref source="" url="http://moodle.org/doc/?frame=release.html">http://moodle.org/doc/?frame=release.html</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/16028">16028</ref></refs><vuln_soft><prod name="moodle" vendor="Moodle"><vers num="1.5"/><vers num="1.5 Beta"/><vers num="1.4.5"/><vers num="1.4.4"/><vers num="1.4.3"/><vers num="1.4.2"/><vers num="1.4.1"/><vers num="1.3.4"/><vers num="1.3.3"/><vers num="1.3.2"/><vers num="1.3.1"/><vers num="1.3"/><vers num="1.2.1"/><vers num="1.2"/><vers num="1.1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2248" published="2005-07-13" seq="2005-2248" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in DownloadProtect before 1.0.3 allows remote attackers to read files above the download folder.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/16003">16003</ref><ref source="BID" url="http://www.securityfocus.com/bid/14211">14211</ref></refs><vuln_soft><prod name="DownloadProtect" vendor="Sven-Ove Bjerkan"><vers num="1.0.2b"/><vers num="1.0.1"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2249" published="2005-07-13" seq="2005-2249" severity="High" type="CVE"><desc><descript source="cve">Multiple unknown vulnerabilities in Jinzora 2.0.1 have unknown impact and attack vectors, possibly involving a PHP file inclusion vulnerability.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://freshmeat.net/projects/jinzora/?branch_id=43140&amp;release_id=200390">http://freshmeat.net/projects/jinzora/?branch_id=43140&amp;release_id=200390</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/15952">15952</ref></refs><vuln_soft><prod name="Jinzora" vendor="Jinzora"><vers num="2.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2250" published="2005-07-13" seq="2005-2250" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Bluetooth FTP client (BTFTP) in Nokia Affix 2.1.2 and 3.2.0 allows remote attackers to execute arbitrary code via a long filename in an OBEX file share.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://www.digitalmunition.com/DMA%5B2005-0712a%5D.txt">http://www.digitalmunition.com/DMA%5B2005-0712a%5D.txt</ref><ref patch="1" source="" url="http://affix.sourceforge.net/affix_212_sec.patch">http://affix.sourceforge.net/affix_212_sec.patch</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/14230">14230</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-762">DSA-762</ref></refs><vuln_soft><prod name="Affix" vendor="Nokia"><vers num="3.2"/><vers num="3.1"/><vers num="3.0"/><vers num="2.3.0"/><vers num="2.1.2"/><vers num="2.1.1"/><vers num="2.1"/><vers num="2.0.2"/><vers num="2.0.1"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-25" name="CVE-2005-2251" published="2005-07-13" seq="2005-2251" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in secure.php in PHPSecurePages (phpSP) 0.28beta and earlier allows remote attackers to execute arbitrary code via the cfgProgDir parameter, a variant of CVE-2001-1468.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="SECTRACK" url="http://securitytracker.com/id?1014410">1014410</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15994">15994</ref><ref source="" url="http://www.milw0rm.com/exploits/2452"></ref><ref source="BID" url="http://www.securityfocus.com/bid/14201">14201</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/29263">phpsecurepages-secure-file-include(29263)</ref></refs><vuln_soft><prod name="phpSecurePages" vendor="Secure Reality"><vers num="0.11 Beta"/><vers num="0.12 Beta"/><vers num="0.13 Beta"/><vers num="0.14 Beta"/><vers num="0.15 Beta"/><vers num="0.16 Beta"/><vers num="0.17 Beta"/><vers num="0.18 Beta"/><vers num="0.19 Beta"/><vers num="0.20 Beta"/><vers num="0.21 Beta"/><vers num="0.22 Beta"/><vers num="0.23 Beta"/><vers num="0.24 Beta"/><vers num="0.25 Beta"/><vers num="0.26 Beta"/><vers num="0.27 Beta"/><vers num="0.28 Beta"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2252" published="2005-07-13" seq="2005-2252" severity="High" type="CVE"><desc><descript source="cve">PhpAuction 2.5 allows remote attackers to bypass authentication and gain privileges as another user by setting the PHPAUCTION_RM_ID cookie to the user ID.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="SECTRACK" url="http://securitytracker.com/id?1014423">1014423</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15967">15967</ref></refs><vuln_soft><prod name="PHPAuction" vendor="Gianluca Baldo"><vers num="2.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2253" published="2005-07-13" seq="2005-2253" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in PhpAuction 2.5 allow remote attackers to modify SQL queries via the category parameter to adsearch.php. NOTE: there is evidence that viewnews.php may not be part of the PhpAuction product, so it is not included in this description.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="SECTRACK" url="http://securitytracker.com/id?1014423">1014423</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15967">15967</ref></refs><vuln_soft><prod name="PHPAuction" vendor="Gianluca Baldo"><vers num="2.5"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2254" published="2005-07-13" seq="2005-2254" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in PhpAuction 2.5 allow remote attackers to inject arbitrary web script or HTML via the lan parameter to(1) index.php or (2) admin/index.php, or (3) the auction_id parameter to profile.php.  NOTE: there is evidence that viewnews.php and login.php may not be part of the PhpAuction product, so they are not included in this description.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="SECTRACK" url="http://securitytracker.com/id?1014423">1014423</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15967">15967</ref></refs><vuln_soft><prod name="PHPAuction" vendor="Gianluca Baldo"><vers num="2.5"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2255" published="2005-07-13" seq="2005-2255" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in PhpAuction 2.5 allows remote attackers to read arbitrary files, include local PHP files, or obtain sensitive path information via &quot;..&quot;  sequences in the lan parameter to (1) index.php or (2) admin/index.php.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="SECTRACK" url="http://securitytracker.com/id?1014423">1014423</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15967">15967</ref></refs><vuln_soft><prod name="PHPAuction" vendor="Gianluca Baldo"><vers num="2.5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2256" published="2005-07-13" seq="2005-2256" severity="Medium" type="CVE"><desc><descript source="cve">Encoded directory traversal vulnerability in phpPgAdmin 3.1 to 3.5.3 allows remote attackers to access arbitrary files via &quot;%2e%2e%2f&quot; (encoded dot dot) sequences in the formLanguage parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/14142">14142</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014414">1014414</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/15941">15941</ref><ref adv="1" source="MISC" url="http://www.vuxml.org/freebsd/88188a8c-eff6-11d9-8310-0001020eed82.html">http://www.vuxml.org/freebsd/88188a8c-eff6-11d9-8310-0001020eed82.html</ref><ref source="MLIST" url="http://archives.neohapsis.com/archives/dailydave/2005-q3/0010.html">[Dailydave] 20050704 !!! pre-authenticated remote code inclusion vulnerability inside phppgadmin !!!</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-759">DSA-759</ref><ref source="" url="http://sourceforge.net/project/shownotes.php?release_id=342261">http://sourceforge.net/project/shownotes.php?release_id=342261</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16116">16116</ref></refs><vuln_soft><prod name="phpPgAdmin" vendor="phpPgAdmin"><vers num="3.5.3"/><vers num="3.4.1"/><vers num="3.4"/><vers num="3.3"/><vers num="3.2"/><vers num="3.1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2257" published="2005-07-13" seq="2005-2257" severity="High" type="CVE"><desc><descript source="cve">The saveProfile function in PhpSlash 0.8.0 allows remote attackers to modify arbitrary profiles and gain privileges by modifying the author_id parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112076117708139&amp;w=2">20050707 phpSlash account hijacking vulnerability</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/15936">15936</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014415">1014415</ref></refs><vuln_soft><prod name="PHPSlash" vendor="PHPSlash"><vers num="0.8.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2258" published="2005-07-13" seq="2005-2258" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in photolist.inc.php in Squito Gallery 1.33 allows remote attackers to execute arbitrary code via the photoroot parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="SECTRACK" url="http://securitytracker.com/id?1014447">1014447</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/16009">16009</ref><ref source="BID" url="http://www.securityfocus.com/bid/14219">14219</ref></refs><vuln_soft><prod name="Squito Gallery" vendor="SquitoSoft"><vers num="1.33"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2259" published="2005-07-13" seq="2005-2259" severity="High" type="CVE"><desc><descript source="cve">The dispallclosed2 function in dispallclosed.pl for multiple USANet Creations products, including (1) USANet Shopping Mall Software, (2) Domain Name Auction Software, (3) Standard Classified Ads Software, and (4) MakeBid Reverse Auction allows remote attackers to execute arbitrary code via shell metacharacters in the DISPCLOSED parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/14179">14179</ref><ref adv="1" source="SECTRACK" url="http://securitytracker.com/id?1014411">1014411</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15985">15985</ref></refs><vuln_soft><prod name="MakeBid Auction Standard" vendor="USANet Creations"><vers num=""/></prod><prod name="Standard Classified Ads" vendor="USANet Creations"><vers num=""/></prod><prod name="MakeBid Auction Deluxe" vendor="USANet Creations"><vers num="3.30"/><vers num=""/></prod><prod name="USANet Shopping Mall" vendor="USANet Creations"><vers num=""/></prod><prod name="MakeBid Reverse Auction" vendor="USANet Creations"><vers num=""/></prod><prod name="Domain Name Auction" vendor="USANet Creations"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2260" published="2005-07-13" seq="2005-2260" severity="High" type="CVE"><desc><descript source="cve">The browser user interface in Firefox before 1.0.5, Mozilla before 1.7.9, and Netscape 8.0.2 and 7.2 does not properly distinguish between user-generated events and untrusted synthetic events, which makes it easier for remote attackers to perform dangerous actions that normally could only be performed manually by the user.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.mozilla.org/security/announce/mfsa2005-45.html">http://www.mozilla.org/security/announce/mfsa2005-45.html</ref><ref adv="1" source="MISC" url="https://bugzilla.mozilla.org/show_bug.cgi?id=289940">https://bugzilla.mozilla.org/show_bug.cgi?id=289940</ref><ref source="MISC" url="http://www.networksecurity.fi/advisories/netscape-multiple-issues.html">http://www.networksecurity.fi/advisories/netscape-multiple-issues.html</ref><ref source="MISC" url="http://bugzilla.mozilla.org/show_bug.cgi?id=289940">http://bugzilla.mozilla.org/show_bug.cgi?id=289940</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/p-252.shtml">P-252</ref><ref source="BID" url="http://www.securityfocus.com/bid/14242">14242</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/1075">ADV-2005-1075</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16043">16043</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16044">16044</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16059">16059</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-810">DSA-810</ref><ref source="FEDORA" url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=160202">FLSA:160202</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval100013.html">OVAL100013</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1226.html">OVAL1226</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval742.html">OVAL742</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-586.html">RHSA-2005:586</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-587.html">RHSA-2005:587</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_45_mozilla.html">SUSE-SA:2005:045</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_18_sr.html">SUSE-SR:2005:018</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100013">oval:org.mitre.oval:def:100013</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1226">oval:org.mitre.oval:def:1226</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:742">oval:org.mitre.oval:def:742</ref></refs><vuln_soft><prod name="Mozilla" vendor="Mozilla"><vers num="1.7.8"/><vers num="1.7.7"/><vers num="1.7.6"/><vers num="1.7.5"/><vers num="1.7.3"/><vers num="1.7.2"/><vers num="1.7.1"/><vers num="1.7 rc3"/><vers num="1.7 rc2"/><vers num="1.7 rc1"/><vers num="1.7 Beta"/><vers num="1.7 alpha"/><vers num="1.7"/><vers num="1.6 Beta"/><vers num="1.6 alpha"/><vers num="1.6"/><vers num="1.5.1"/><vers num="1.5 rc2"/><vers num="1.5 rc1"/><vers num="1.5 alpha"/><vers num="1.5"/><vers num="1.4a"/><vers num="1.4.1"/><vers num="1.4"/><vers num="1.3"/></prod><prod name="Firefox" vendor="Mozilla"><vers num="1.0.4"/><vers num="1.0.3"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0"/><vers num="0.9.3"/><vers num="0.9.2"/><vers num="0.9.1"/><vers edition="rc" num="0.9"/><vers num="0.9"/><vers num="0.8"/><vers num="0.10.1"/><vers num="0.10"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2261" published="2005-07-13" seq="2005-2261" severity="High" type="CVE"><desc><descript source="cve">Firefox before 1.0.5, Thunderbird before 1.0.5, Mozilla before 1.7.9, Netscape 8.0.2, and K-Meleon 0.9 runs XBL scripts even when Javascript has been disabled, which makes it easier for remote attackers to bypass such protection.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.mozilla.org/security/announce/mfsa2005-46.html">http://www.mozilla.org/security/announce/mfsa2005-46.html</ref><ref adv="1" source="MISC" url="https://bugzilla.mozilla.org/show_bug.cgi?id=292591">https://bugzilla.mozilla.org/show_bug.cgi?id=292591</ref><ref adv="1" source="MISC" url="https://bugzilla.mozilla.org/show_bug.cgi?id=292589">https://bugzilla.mozilla.org/show_bug.cgi?id=292589</ref><ref source="MISC" url="http://www.networksecurity.fi/advisories/netscape-multiple-issues.html">http://www.networksecurity.fi/advisories/netscape-multiple-issues.html</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/p-252.shtml">P-252</ref><ref source="BID" url="http://www.securityfocus.com/bid/14242">14242</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/1075">ADV-2005-1075</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16043">16043</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16044">16044</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16059">16059</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-810">DSA-810</ref><ref source="FEDORA" url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=160202">FLSA:160202</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval100012.html">OVAL100012</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1348.html">OVAL1348</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval808.html">OVAL808</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-586.html">RHSA-2005:586</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-587.html">RHSA-2005:587</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-601.html">RHSA-2005:601</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_04_25.html">SUSE-SA:2006:022</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19823">19823</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_45_mozilla.html">SUSE-SA:2005:045</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_18_sr.html">SUSE-SR:2005:018</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100012">oval:org.mitre.oval:def:100012</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1348">oval:org.mitre.oval:def:1348</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:808">oval:org.mitre.oval:def:808</ref></refs><vuln_soft><prod name="Mozilla" vendor="Mozilla"><vers num="1.7.8"/><vers num="1.7.7"/><vers num="1.7.6"/><vers num="1.7.5"/><vers num="1.7.3"/><vers num="1.7.2"/><vers num="1.7.1"/><vers num="1.7 rc3"/><vers num="1.7 rc2"/><vers num="1.7 rc1"/><vers num="1.7 Beta"/><vers num="1.7 alpha"/><vers num="1.7"/><vers num="1.6 Beta"/><vers num="1.6 alpha"/><vers num="1.6"/><vers num="1.5.1"/><vers num="1.5 rc2"/><vers num="1.5 rc1"/><vers num="1.5 alpha"/><vers num="1.5"/><vers num="1.4a"/><vers num="1.4.1"/><vers num="1.4"/><vers num="1.3"/></prod><prod name="Thunderbird" vendor="Mozilla"><vers num="1.0.4"/><vers num="1.0.3"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0"/><vers num="0.9"/><vers num="0.8"/><vers num="0.7.3"/><vers num="0.7.2"/><vers num="0.7.1"/><vers num="0.7"/><vers num="0.6"/><vers num="0.5"/><vers num="0.4"/><vers num="0.3"/><vers num="0.2"/><vers num="0.1"/></prod><prod name="Firefox" vendor="Mozilla"><vers num="1.0.4"/><vers num="1.0.3"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0"/><vers num="0.9.3"/><vers num="0.9.2"/><vers num="0.9.1"/><vers edition="rc" num="0.9"/><vers num="0.9"/><vers num="0.8"/><vers num="0.10.1"/><vers num="0.10"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2262" published="2005-07-13" seq="2005-2262" severity="Medium" type="CVE"><desc><descript source="cve">Firefox 1.0.3 and 1.0.4, and Netscape 8.0.2, allows remote attackers to execute arbitrary code by tricking the user into using the &quot;Set As Wallpaper&quot; (in Firefox) or &quot;Set as Background&quot; (in Netscape) context menu on an image URL that is really a javascript: URL with an eval statement, aka &quot;Firewalling.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><other/></vuln_types><range><network/><user_init/></range><refs><ref source="MISC" url="http://www.mikx.de/firewalling/">http://www.mikx.de/firewalling/</ref><ref source="" url="http://www.mozilla.org/security/announce/mfsa2005-47.html">http://www.mozilla.org/security/announce/mfsa2005-47.html</ref><ref source="MISC" url="http://www.networksecurity.fi/advisories/netscape-multiple-issues.html">http://www.networksecurity.fi/advisories/netscape-multiple-issues.html</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/p-252.shtml">P-252</ref><ref source="MISC" url="http://www.securiteam.com/securitynews/5ZP0E0UGAK.html">http://www.securiteam.com/securitynews/5ZP0E0UGAK.html</ref><ref source="BID" url="http://www.securityfocus.com/bid/14242">14242</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/1075">ADV-2005-1075</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16043">16043</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16044">16044</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval100011.html">OVAL100011</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-586.html">RHSA-2005:586</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_45_mozilla.html">SUSE-SA:2005:045</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_18_sr.html">SUSE-SR:2005:018</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100011">oval:org.mitre.oval:def:100011</ref></refs><vuln_soft><prod name="Firefox" vendor="Mozilla"><vers num="1.0.3"/><vers num="1.0.4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2263" published="2005-07-13" seq="2005-2263" severity="Medium" type="CVE"><desc><descript source="cve">The InstallTrigger.install method in Firefox before 1.0.5 and Mozilla before 1.7.9 allows remote attackers to execute a callback function in the context of another domain by forcing a page navigation after the install method has been called, which causes the callback to be run in the context of the new page and results in a same origin violation.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.mozilla.org/security/announce/mfsa2005-48.html">http://www.mozilla.org/security/announce/mfsa2005-48.html</ref><ref adv="1" source="MISC" url="https://bugzilla.mozilla.org/show_bug.cgi?id=293331">https://bugzilla.mozilla.org/show_bug.cgi?id=293331</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/p-252.shtml">P-252</ref><ref source="BID" url="http://www.securityfocus.com/bid/14242">14242</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/1075">ADV-2005-1075</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16043">16043</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16059">16059</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-810">DSA-810</ref><ref source="FEDORA" url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=160202">FLSA:160202</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval100010.html">OVAL100010</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval100016.html">OVAL100016</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1281.html">OVAL1281</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1311.html">OVAL1311</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-586.html">RHSA-2005:586</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-587.html">RHSA-2005:587</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_45_mozilla.html">SUSE-SA:2005:045</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_18_sr.html">SUSE-SR:2005:018</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100010">oval:org.mitre.oval:def:100010</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100016">oval:org.mitre.oval:def:100016</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1281">oval:org.mitre.oval:def:1281</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1311">oval:org.mitre.oval:def:1311</ref></refs><vuln_soft><prod name="Mozilla" vendor="Mozilla"><vers num="1.7.8"/><vers num="1.7.7"/><vers num="1.7.6"/><vers num="1.7.5"/><vers num="1.7.3"/><vers num="1.7.2"/><vers num="1.7.1"/><vers num="1.7 rc3"/><vers num="1.7 rc2"/><vers num="1.7 rc1"/><vers num="1.7 Beta"/><vers num="1.7 alpha"/><vers num="1.7"/><vers num="1.6 Beta"/><vers num="1.6 alpha"/><vers num="1.6"/><vers num="1.5.1"/><vers num="1.5 rc2"/><vers num="1.5 rc1"/><vers num="1.5 alpha"/><vers num="1.5"/><vers num="1.4a"/><vers num="1.4.1"/><vers num="1.4"/><vers num="1.3"/></prod><prod name="Firefox" vendor="Mozilla"><vers num="1.0.4"/><vers num="1.0.3"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0"/><vers num="0.9.3"/><vers num="0.9.2"/><vers num="0.9.1"/><vers edition="rc" num="0.9"/><vers num="0.9"/><vers num="0.8"/><vers num="0.10.1"/><vers num="0.10"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2264" published="2005-07-13" seq="2005-2264" severity="High" type="CVE"><desc><descript source="cve">Firefox before 1.0.5 allows remote attackers to steal sensitive information by opening a malicious link in the Firefox sidebar using the _search target, then injecting script into other pages via a data: URL.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.mozilla.org/security/announce/mfsa2005-49.html">http://www.mozilla.org/security/announce/mfsa2005-49.html</ref><ref adv="1" source="MISC" url="https://bugzilla.mozilla.org/show_bug.cgi?id=294074">https://bugzilla.mozilla.org/show_bug.cgi?id=294074</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/p-252.shtml">P-252</ref><ref source="BID" url="http://www.securityfocus.com/bid/14242">14242</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/1075">ADV-2005-1075</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16043">16043</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval100009.html">OVAL100009</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-586.html">RHSA-2005:586</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_45_mozilla.html">SUSE-SA:2005:045</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_18_sr.html">SUSE-SR:2005:018</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100009">oval:org.mitre.oval:def:100009</ref></refs><vuln_soft><prod name="Firefox" vendor="Mozilla"><vers num="1.0.4"/><vers num="1.0.3"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0"/><vers num="0.9.3"/><vers num="0.9.2"/><vers num="0.9.1"/><vers edition="rc" num="0.9"/><vers num="0.9"/><vers num="0.8"/><vers num="0.10.1"/><vers num="0.10"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2265" published="2005-07-13" seq="2005-2265" severity="Medium" type="CVE"><desc><descript source="cve">Firefox before 1.0.5, Mozilla before 1.7.9, and Netscape 8.0.2 and 7.2 allows remote attackers to cause a denial of service (access violation and crash), and possibly execute arbitrary code, by calling InstallVersion.compareTo with an object instead of a string.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="MISC" url="http://www.mozilla.org/security/announce/mfsa2005-50.html">http://www.mozilla.org/security/announce/mfsa2005-50.html</ref><ref adv="1" source="MISC" url="https://bugzilla.mozilla.org/show_bug.cgi?id=295854">https://bugzilla.mozilla.org/show_bug.cgi?id=295854</ref><ref source="MISC" url="http://www.networksecurity.fi/advisories/netscape-multiple-issues.html">http://www.networksecurity.fi/advisories/netscape-multiple-issues.html</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/p-252.shtml">P-252</ref><ref source="BID" url="http://www.securityfocus.com/bid/14242">14242</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/1075">ADV-2005-1075</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16043">16043</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16044">16044</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16059">16059</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-810">DSA-810</ref><ref source="FEDORA" url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=160202">FLSA:160202</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval100008.html">OVAL100008</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval417.html">OVAL417</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval781.html">OVAL781</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-586.html">RHSA-2005:586</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-587.html">RHSA-2005:587</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-601.html">RHSA-2005:601</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_04_25.html">SUSE-SA:2006:022</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19823">19823</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_45_mozilla.html">SUSE-SA:2005:045</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_18_sr.html">SUSE-SR:2005:018</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100008">oval:org.mitre.oval:def:100008</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:417">oval:org.mitre.oval:def:417</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:781">oval:org.mitre.oval:def:781</ref></refs><vuln_soft><prod name="Mozilla" vendor="Mozilla"><vers num="1.7.8"/><vers num="1.7.7"/><vers num="1.7.6"/><vers num="1.7.5"/><vers num="1.7.3"/><vers num="1.7.2"/><vers num="1.7.1"/><vers num="1.7 rc3"/><vers num="1.7 rc2"/><vers num="1.7 rc1"/><vers num="1.7 Beta"/><vers num="1.7 alpha"/><vers num="1.7"/><vers num="1.6 Beta"/><vers num="1.6 alpha"/><vers num="1.6"/><vers num="1.5.1"/><vers num="1.5 rc2"/><vers num="1.5 rc1"/><vers num="1.5 alpha"/><vers num="1.5"/><vers num="1.4a"/><vers num="1.4.1"/><vers num="1.4"/><vers num="1.3"/></prod><prod name="Firefox" vendor="Mozilla"><vers num="1.0.4"/><vers num="1.0.3"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0"/><vers num="0.9.3"/><vers num="0.9.2"/><vers num="0.9.1"/><vers edition="rc" num="0.9"/><vers num="0.9"/><vers num="0.8"/><vers num="0.10.1"/><vers num="0.10"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2266" published="2005-07-13" seq="2005-2266" severity="Medium" type="CVE"><desc><descript source="cve">Firefox before 1.0.5 and Mozilla before 1.7.9 allows a child frame to call top.focus and other methods in a parent frame, even when the parent is in a different domain, which violates the same origin policy and allows remote attackers to steal sensitive information such as cookies and passwords from web sites whose child frames do not verify that they are in the same domain as their parents.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.mozilla.org/security/announce/mfsa2005-52.html">http://www.mozilla.org/security/announce/mfsa2005-52.html</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15549">15549</ref><ref source="BID" url="http://www.securityfocus.com/bid/14242">14242</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/1075">ADV-2005-1075</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15551">15551</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15553">15553</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/21332">mozilla-frame-topfocus-xss(21332)</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-810">DSA-810</ref><ref source="FEDORA" url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=160202">FLSA:160202</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval100107.html">OVAL100107</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1415.html">OVAL1415</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval773.html">OVAL773</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-586.html">RHSA-2005:586</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-587.html">RHSA-2005:587</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-601.html">RHSA-2005:601</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_04_25.html">SUSE-SA:2006:022</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19823">19823</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_45_mozilla.html">SUSE-SA:2005:045</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_18_sr.html">SUSE-SR:2005:018</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100107">oval:org.mitre.oval:def:100107</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1415">oval:org.mitre.oval:def:1415</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:773">oval:org.mitre.oval:def:773</ref></refs><vuln_soft><prod name="Mozilla" vendor="Mozilla"><vers num="1.7.8"/><vers num="1.7.7"/><vers num="1.7.6"/><vers num="1.7.5"/><vers num="1.7.3"/><vers num="1.7.2"/><vers num="1.7.1"/><vers num="1.7 rc3"/><vers num="1.7 rc2"/><vers num="1.7 rc1"/><vers num="1.7 Beta"/><vers num="1.7 alpha"/><vers num="1.7"/><vers num="1.6 Beta"/><vers num="1.6 alpha"/><vers num="1.6"/><vers num="1.5.1"/><vers num="1.5 rc2"/><vers num="1.5 rc1"/><vers num="1.5 alpha"/><vers num="1.5"/><vers num="1.4a"/><vers num="1.4.1"/><vers num="1.4"/><vers num="1.3"/></prod><prod name="Firefox" vendor="Mozilla"><vers num="1.0.4"/><vers num="1.0.3"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0"/><vers num="0.9.3"/><vers num="0.9.2"/><vers num="0.9.1"/><vers edition="rc" num="0.9"/><vers num="0.9"/><vers num="0.8"/><vers num="0.10.1"/><vers num="0.10"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2267" published="2005-07-13" seq="2005-2267" severity="High" type="CVE"><desc><descript source="cve">Firefox before 1.0.5 allows remote attackers to steal information and possibly execute arbitrary code by using standalone applications such as Flash and QuickTime to open a javascript: URL, which is run in the context of the previous page, and may lead to code execution if the standalone application loads a privileged chrome: URL.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="" url="http://www.mozilla.org/security/announce/mfsa2005-53.html">http://www.mozilla.org/security/announce/mfsa2005-53.html</ref><ref source="MISC" url="https://bugzilla.mozilla.org/show_bug.cgi?id=298255">https://bugzilla.mozilla.org/show_bug.cgi?id=298255</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/p-252.shtml">P-252</ref><ref source="BID" url="http://www.securityfocus.com/bid/14242">14242</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/1075">ADV-2005-1075</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014469">1014469</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16043">16043</ref><ref source="FEDORA" url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=160202">FLSA:160202</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval100006.html">OVAL100006</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1073.html">OVAL1073</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1172.html">OVAL1172</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-586.html">RHSA-2005:586</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-587.html">RHSA-2005:587</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_45_mozilla.html">SUSE-SA:2005:045</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_18_sr.html">SUSE-SR:2005:018</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100006">oval:org.mitre.oval:def:100006</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1073">oval:org.mitre.oval:def:1073</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1172">oval:org.mitre.oval:def:1172</ref></refs><vuln_soft><prod name="Firefox" vendor="Mozilla"><vers num="1.0.4"/><vers num="1.0.3"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0"/><vers num="0.9.3"/><vers num="0.9.2"/><vers num="0.9.1"/><vers edition="rc" num="0.9"/><vers num="0.9"/><vers num="0.8"/><vers num="0.10.1"/><vers num="0.10"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2268" published="2005-07-13" seq="2005-2268" severity="Low" type="CVE"><desc><descript source="cve">Firefox before 1.0.5 and Mozilla before 1.7.9 does not clearly associate a Javascript dialog box with the web page that generated it, which allows remote attackers to spoof a dialog box from a trusted site and facilitates phishing attacks, aka the &quot;Dialog Origin Spoofing Vulnerability.&quot;</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/><user_init/></range><refs><ref source="MISC" url="http://secunia.com/multiple_browsers_dialog_origin_vulnerability_test/">http://secunia.com/multiple_browsers_dialog_origin_vulnerability_test/</ref><ref adv="1" patch="1" source="" url="http://www.mozilla.org/security/announce/mfsa2005-54.html">http://www.mozilla.org/security/announce/mfsa2005-54.html</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/15489">15489</ref><ref source="BID" url="http://www.securityfocus.com/bid/14242">14242</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/1075">ADV-2005-1075</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-810">DSA-810</ref><ref source="FEDORA" url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=160202">FLSA:160202</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1268.html">OVAL1268</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1313.html">OVAL1313</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval100005.html">OVAL100005</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-586.html">RHSA-2005:586</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-587.html">RHSA-2005:587</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_45_mozilla.html">SUSE-SA:2005:045</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_18_sr.html">SUSE-SR:2005:018</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1268">oval:org.mitre.oval:def:1268</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1313">oval:org.mitre.oval:def:1313</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100005">oval:org.mitre.oval:def:100005</ref></refs><vuln_soft><prod name="Mozilla" vendor="Mozilla"><vers num="1.7.8"/><vers num="1.7.7"/><vers num="1.7.6"/><vers num="1.7.5"/><vers num="1.7.3"/><vers num="1.7.2"/><vers num="1.7.1"/><vers num="1.7 rc3"/><vers num="1.7 rc2"/><vers num="1.7 rc1"/><vers num="1.7 Beta"/><vers num="1.7 alpha"/><vers num="1.7"/><vers num="1.6 Beta"/><vers num="1.6 alpha"/><vers num="1.6"/><vers num="1.5.1"/><vers num="1.5 rc2"/><vers num="1.5 rc1"/><vers num="1.5 alpha"/><vers num="1.5"/><vers num="1.4a"/><vers num="1.4.1"/><vers num="1.4"/><vers num="1.3"/></prod><prod name="Firefox" vendor="Mozilla"><vers num="1.0.4"/><vers num="1.0.3"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0"/><vers num="0.9.3"/><vers num="0.9.2"/><vers num="0.9.1"/><vers edition="rc" num="0.9"/><vers num="0.9"/><vers num="0.8"/><vers num="0.10.1"/><vers num="0.10"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2269" published="2005-07-13" seq="2005-2269" severity="High" type="CVE"><desc><descript source="cve">Firefox before 1.0.5, Mozilla before 1.7.9, and Netscape 8.0.2 does not properly verify the associated types of DOM node names within the context of their namespaces, which allows remote attackers to modify certain tag properties, possibly leading to execution of arbitrary script or code, as demonstrated using an XHTML document with IMG tags with custom properties (&quot;XHTML node spoofing&quot;).</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.mozilla.org/security/announce/mfsa2005-55.html">http://www.mozilla.org/security/announce/mfsa2005-55.html</ref><ref adv="1" source="MISC" url="https://bugzilla.mozilla.org/show_bug.cgi?id=298892">https://bugzilla.mozilla.org/show_bug.cgi?id=298892</ref><ref source="MISC" url="http://www.networksecurity.fi/advisories/netscape-multiple-issues.html">http://www.networksecurity.fi/advisories/netscape-multiple-issues.html</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/p-252.shtml">P-252</ref><ref source="BID" url="http://www.securityfocus.com/bid/14242">14242</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/1075">ADV-2005-1075</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16043">16043</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16059">16059</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16044">16044</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-810">DSA-810</ref><ref source="FEDORA" url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=160202">FLSA:160202</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval100004.html">OVAL100004</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval100005.html">OVAL100005</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval100011.html">OVAL100011</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1258.html">OVAL1258</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval729.html">OVAL729</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-586.html">RHSA-2005:586</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-587.html">RHSA-2005:587</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-601.html">RHSA-2005:601</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_04_25.html">SUSE-SA:2006:022</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19823">19823</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_45_mozilla.html">SUSE-SA:2005:045</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_18_sr.html">SUSE-SR:2005:018</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100004">oval:org.mitre.oval:def:100004</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100005">oval:org.mitre.oval:def:100005</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100011">oval:org.mitre.oval:def:100011</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1258">oval:org.mitre.oval:def:1258</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:729">oval:org.mitre.oval:def:729</ref></refs><vuln_soft><prod name="Mozilla" vendor="Mozilla"><vers num="1.7.8"/><vers num="1.7.7"/><vers num="1.7.6"/><vers num="1.7.5"/><vers num="1.7.3"/><vers num="1.7.2"/><vers num="1.7.1"/><vers num="1.7 rc3"/><vers num="1.7 rc2"/><vers num="1.7 rc1"/><vers num="1.7 Beta"/><vers num="1.7 alpha"/><vers num="1.7"/><vers num="1.6 Beta"/><vers num="1.6 alpha"/><vers num="1.6"/><vers num="1.5.1"/><vers num="1.5 rc2"/><vers num="1.5 rc1"/><vers num="1.5 alpha"/><vers num="1.5"/><vers num="1.4a"/><vers num="1.4.1"/><vers num="1.4"/><vers num="1.3"/></prod><prod name="Firefox" vendor="Mozilla"><vers num="1.0.4"/><vers num="1.0.3"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0"/><vers num="0.9.3"/><vers num="0.9.2"/><vers num="0.9.1"/><vers edition="rc" num="0.9"/><vers num="0.9"/><vers num="0.8"/><vers num="0.10.1"/><vers num="0.10"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2270" published="2005-07-13" seq="2005-2270" severity="High" type="CVE"><desc><descript source="cve">Firefox before 1.0.5 and Mozilla before 1.7.9 does not properly clone base objects, which allows remote attackers to execute arbitrary code by navigating the prototype chain to reach a privileged object.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.mozilla.org/security/announce/mfsa2005-56.html">http://www.mozilla.org/security/announce/mfsa2005-56.html</ref><ref adv="1" source="MISC" url="https://bugzilla.mozilla.org/show_bug.cgi?id=294795">https://bugzilla.mozilla.org/show_bug.cgi?id=294795</ref><ref adv="1" source="MISC" url="https://bugzilla.mozilla.org/show_bug.cgi?id=294799">https://bugzilla.mozilla.org/show_bug.cgi?id=294799</ref><ref adv="1" source="MISC" url="https://bugzilla.mozilla.org/show_bug.cgi?id=295011">https://bugzilla.mozilla.org/show_bug.cgi?id=295011</ref><ref adv="1" source="MISC" url="https://bugzilla.mozilla.org/show_bug.cgi?id=296397">https://bugzilla.mozilla.org/show_bug.cgi?id=296397</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/p-252.shtml">P-252</ref><ref source="BID" url="http://www.securityfocus.com/bid/14242">14242</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/1075">ADV-2005-1075</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014470">1014470</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16043">16043</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16059">16059</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-810">DSA-810</ref><ref source="FEDORA" url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=160202">FLSA:160202</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval100003.html">OVAL100003</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval550.html">OVAL550</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval817.html">OVAL817</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/652366">VU#652366</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-586.html">RHSA-2005:586</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-587.html">RHSA-2005:587</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-601.html">RHSA-2005:601</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_04_25.html">SUSE-SA:2006:022</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19823">19823</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_45_mozilla.html">SUSE-SA:2005:045</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_18_sr.html">SUSE-SR:2005:018</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100003">oval:org.mitre.oval:def:100003</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:550">oval:org.mitre.oval:def:550</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:817">oval:org.mitre.oval:def:817</ref></refs><vuln_soft><prod name="Mozilla" vendor="Mozilla"><vers num="1.7.8"/><vers num="1.7.7"/><vers num="1.7.6"/><vers num="1.7.5"/><vers num="1.7.3"/><vers num="1.7.2"/><vers num="1.7.1"/><vers num="1.7 rc3"/><vers num="1.7 rc2"/><vers num="1.7 rc1"/><vers num="1.7 Beta"/><vers num="1.7 alpha"/><vers num="1.7"/><vers num="1.6 Beta"/><vers num="1.6 alpha"/><vers num="1.6"/><vers num="1.5.1"/><vers num="1.5 rc2"/><vers num="1.5 rc1"/><vers num="1.5 alpha"/><vers num="1.5"/><vers num="1.4a"/><vers num="1.4.1"/><vers num="1.4"/><vers num="1.3"/></prod><prod name="Firefox" vendor="Mozilla"><vers num="1.0.4"/><vers num="1.0.3"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0"/><vers num="0.9.3"/><vers num="0.9.2"/><vers num="0.9.1"/><vers edition="rc" num="0.9"/><vers num="0.9"/><vers num="0.8"/><vers num="0.10.1"/><vers num="0.10"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2271" published="2005-07-13" seq="2005-2271" severity="Low" type="CVE"><desc><descript source="cve">iCab 2.9.8 does not clearly associate a Javascript dialog box with the web page that generated it, which allows remote attackers to spoof a dialog box from a trusted site and facilitates phishing attacks, aka the &quot;Dialog Origin Spoofing Vulnerability.&quot;</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/><user_init/></range><refs><ref source="MISC" url="http://secunia.com/multiple_browsers_dialog_origin_vulnerability_test/">http://secunia.com/multiple_browsers_dialog_origin_vulnerability_test/</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/15477">15477</ref></refs><vuln_soft><prod name="iCab" vendor="Alexander Clauss"><vers num="2.9.8"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2272" published="2005-07-13" seq="2005-2272" severity="Low" type="CVE"><desc><descript source="cve">Safari version 2.0 (412) does not clearly associate a Javascript dialog box with the web page that generated it, which allows remote attackers to spoof a dialog box from a trusted site and facilitates phishing attacks, aka the &quot;Dialog Origin Spoofing Vulnerability.&quot;</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="MISC" url="http://secunia.com/secunia_research/2005-12/advisory/">http://secunia.com/secunia_research/2005-12/advisory/</ref><ref source="MISC" url="http://secunia.com/multiple_browsers_dialog_origin_vulnerability_test/">http://secunia.com/multiple_browsers_dialog_origin_vulnerability_test/</ref><ref source="APPLE" url="http://docs.info.apple.com/article.html?artnum=302847">APPLE-SA-2005-11-29</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015294">1015294</ref><ref source="BID" url="http://www.securityfocus.com/bid/14011">14011</ref><ref source="OSVDB" url="http://www.osvdb.org/17397">17397</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15474">15474</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17813">17813</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/21070">mozilla-javascript-dialog-box-spoofing(21070)</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/2659">ADV-2005-2659</ref></refs><vuln_soft><prod name="Safari" vendor="Apple"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2273" published="2005-07-13" seq="2005-2273" severity="Low" type="CVE"><desc><descript source="cve">Opera 7.x and 8 before 8.01 does not clearly associate a Javascript dialog box with the web page that generated it, which allows remote attackers to spoof a dialog box from a trusted site and facilitates phishing attacks, aka the &quot;Dialog Origin Spoofing Vulnerability.&quot;</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/><user_init/></range><refs><ref source="MISC" url="http://secunia.com/multiple_browsers_dialog_origin_vulnerability_test/">http://secunia.com/multiple_browsers_dialog_origin_vulnerability_test/</ref><ref source="MISC" url="http://secunia.com/secunia_research/2005-8/">http://secunia.com/secunia_research/2005-8/</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15488">15488</ref></refs><vuln_soft><prod name="Opera Web Browser" vendor="Opera Software"><vers num="8.0 Final Build 1095"/><vers num="8 Beta 3"/><vers num="7.54"/><vers num="7.53"/><vers num="7.52"/><vers num="7.51"/><vers num="7.50B1"/><vers num="7.50"/><vers num="7.23"/><vers num="7.22"/><vers num="7.21"/><vers num="7.20 Beta1 build2981"/><vers num="7.20"/><vers num="7.11j"/><vers num="7.11b"/><vers num="7.11"/><vers num="7.10"/><vers edition="win32" num="7.0.3"/><vers edition="win32" num="7.0.2"/><vers edition="win32" num="7.0.1"/><vers edition="win32" num="7.0 Beta2"/><vers edition="win32" num="7.0 Beta1"/><vers edition="win32" num="7.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2274" published="2005-07-13" seq="2005-2274" severity="Low" type="CVE"><desc><descript source="cve">Microsoft Internet Explorer 6.0 does not clearly associate a Javascript dialog box with the web page that generated it, which allows remote attackers to spoof a dialog box from a trusted site and facilitates phishing attacks, aka the &quot;Dialog Origin Spoofing Vulnerability.&quot;</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="MISC" url="http://secunia.com/secunia_research/2005-9/advisory/">http://secunia.com/secunia_research/2005-9/advisory/</ref><ref source="MISC" url="http://secunia.com/multiple_browsers_dialog_origin_vulnerability_test/">http://secunia.com/multiple_browsers_dialog_origin_vulnerability_test/</ref><ref adv="1" source="MISC" url="http://www.microsoft.com/technet/security/advisory/902333.mspx">http://www.microsoft.com/technet/security/advisory/902333.mspx</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/15491">15491</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/15492">15492</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers edition="for Microsoft Windows Server 2003 SP1.0" num="6"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-04-07" name="CVE-2005-2276" published="2005-07-26" seq="2005-2276" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Novell Groupwise WebAccess 6.5 before July 11, 2005 allows remote attackers to inject arbitrary web script or HTML via an e-mail message with an encoded javascript URI (e.g. &quot;j&amp;#X41vascript&quot; in an IMG tag.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112181451014783&amp;w=2">20050719 [ISR] - Novell Groupwise WebAccess Cross-Site Scripting</ref><ref patch="1" source="" url="http://support.novell.com/cgi-bin/search/searchtid.cgi?/10098301.htm">http://support.novell.com/cgi-bin/search/searchtid.cgi?/10098301.htm</ref><ref source="BID" url="http://www.securityfocus.com/bid/14310">14310</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/16098/">16098</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/21421">novell-groupwise-webaccess-xss(21421)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014515">1014515</ref><ref source="" url="http://www.infobyte.com.ar/adv/ISR-11.html"></ref><ref source="OSVDB" url="http://www.osvdb.org/18064">18064</ref></refs><vuln_soft><prod name="GroupWise WebAccess" vendor="Novell"><vers num="6.5 SP4"/><vers num="6.5 SP3"/><vers num="6.5 SP2"/><vers num="6.5 SP1"/><vers num="6.5"/><vers num="6.0 SP4"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2277" published="2005-07-15" seq="2005-2277" severity="High" type="CVE"><desc><descript source="cve">Bluetooth FTP client (BTFTP) in Nokia Affix 2.1.2 and 3.2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the filename argument of a PUT command.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="MISC" url="http://www.digitalmunition.com/DMA%5B2005-0712b%5D.txt">http://www.digitalmunition.com/DMA[2005-0712b].txt</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-762">DSA-762</ref><ref source="" url="http://affix.sourceforge.net/affix_212_sec.patch">http://affix.sourceforge.net/affix_212_sec.patch</ref><ref source="" url="http://affix.sourceforge.net/affix_320_sec.patch">http://affix.sourceforge.net/affix_320_sec.patch</ref><ref source="BID" url="http://www.securityfocus.com/bid/14232">14232</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112119962704397&amp;w=2">20050712 MA[2005-0712b] - &apos;Nokia Affix Bluetooth btsrv/btobex poor use of system()</ref></refs><vuln_soft><prod name="Affix" vendor="Nokia"><vers num="2.1.2"/><vers num="3.2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-07-24" name="CVE-2005-2278" published="2005-07-18" seq="2005-2278" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in the IMAP daemon (imapd) in MailEnable Professional 1.54 allows remote authenticated users to execute arbitrary code via the status command with a long mailbox name.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112127188609993&amp;w=2">20050712 CORE-2005-0629: MailEnable Buffer Overflow Vulnerability</ref><ref adv="1" patch="1" source="MISC" url="http://www.coresecurity.com/common/showdoc.php?idx=467&amp;idxseccion=10">http://www.coresecurity.com/common/showdoc.php?idx=467&amp;idxseccion=10</ref></refs><vuln_soft><prod name="MailEnable Professional" vendor="MailEnable"><vers num="1.54"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2279" published="2005-07-18" seq="2005-2279" severity="Medium" type="CVE"><desc><descript source="cve">Cisco ONS 15216 Optical Add/Drop Multiplexer (OADM) running firmware 2.2.2 and earlier allows remote attackers to cause a denial of service (management plane session loss) via crafted telnet data.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-sa-20050713-ons.shtml">20050713 Cisco ONS 15216 OADM Telnet Denial-of-Service Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/14246">14246</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014475">1014475</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16073">16073</ref><ref source="OSVDB" url="http://www.osvdb.org/17863">17863</ref></refs><vuln_soft><prod name="ONS 15216 Optical Add/Drop Multiplexer" vendor="Cisco"><vers num="2.2.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2280" published="2005-07-18" seq="2005-2280" severity="Medium" type="CVE"><desc><descript source="cve">Cisco Security Agent (CSA) 4.5 allows remote attackers to cause a denial of service (system crash) via a crafted IP packet.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-sa-20050713-csa.shtml">20050713 Cisco Security Agent Vulnerable to Crafted IP Attack</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/21344">csa-ip-dos(21344)</ref></refs><vuln_soft><prod name="Security Agent" vendor="Cisco"><vers num="4.5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2281" published="2005-07-18" seq="2005-2281" severity="Medium" type="CVE"><desc><descript source="cve">WebEOC before 6.0.2 uses a weak encryption scheme for passwords, which makes it easier for attackers to crack passwords.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="" url="http://www.kb.cert.org/vuls/id/JGEI-6BWQDQ">http://www.kb.cert.org/vuls/id/JGEI-6BWQDQ</ref><ref patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/491770">VU#491770</ref></refs><vuln_soft><prod name="WebEOC" vendor="ESi Products"><vers num="6.0.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2282" published="2005-07-18" seq="2005-2282" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in WebEOC before 6.0.2 allow remote attackers to inject arbitrary web script and HTML via unknown vectors.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/JGEI-6BVST4">http://www.kb.cert.org/vuls/id/JGEI-6BVST4</ref><ref patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/138538">VU#138538</ref></refs><vuln_soft><prod name="WebEOC" vendor="ESi Products"><vers num="6.0.2"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2283" published="2005-07-18" seq="2005-2283" severity="Low" type="CVE"><desc><descript source="cve">WebEOC before 6.0.2 does not properly restrict the size of an uploaded file, which allows remote authenticated users to cause a denial of service (system and database resource consumption) via a large file.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="" url="http://www.kb.cert.org/vuls/id/JGEI-6BWLER">http://www.kb.cert.org/vuls/id/JGEI-6BWLER</ref><ref patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/956762">VU#956762</ref></refs><vuln_soft><prod name="WebEOC" vendor="ESi Products"><vers num="6.0.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2284" published="2005-07-18" seq="2005-2284" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in WebEOC before 6.0.2 allow remote attackers to modify SQL statements via unknown attack vectors.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/JGEI-6C8Q27">http://www.kb.cert.org/vuls/id/JGEI-6C8Q27</ref><ref patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/372797">VU#372797</ref></refs><vuln_soft><prod name="WebEOC" vendor="ESi Products"><vers num="6.0.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2285" published="2005-07-18" seq="2005-2285" severity="Medium" type="CVE"><desc><descript source="cve">WebEOC before 6.0.2 stores sensitive information in locations such as URIs, web pages, and configuration files, which allows remote attackers to obtain information such as Usernames, Passwords, Emergency information, medical information, and system configuration.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="" url="http://www.kb.cert.org/vuls/id/JGEI-6BWPXL">http://www.kb.cert.org/vuls/id/JGEI-6BWPXL</ref><ref patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/165290">VU#165290</ref></refs><vuln_soft><prod name="WebEOC" vendor="ESi Products"><vers num="6.0.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2286" published="2005-07-18" seq="2005-2286" severity="High" type="CVE"><desc><descript source="cve">WebEOC before 6.0.2 does not properly check user authorization, which allows remote attackers to gain privileges via a direct request to a resource.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="" url="http://www.kb.cert.org/vuls/id/JGEI-6BWLWG">http://www.kb.cert.org/vuls/id/JGEI-6BWLWG</ref><ref patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/258834">VU#258834</ref></refs><vuln_soft><prod name="WebEOC" vendor="ESi Products"><vers num="6.0.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2287" published="2005-07-18" seq="2005-2287" severity="Medium" type="CVE"><desc><descript source="cve">SoftiaCom wMailServer 1.0 and 2.0 allows remote attackers to cause a denial of service (application crash) via a large TCP packet with a leading space, possibly triggering a buffer overflow.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112122500308722&amp;w=2">20050712 SoftiaCom MailServer v2.0 - Denial Of Service</ref></refs><vuln_soft><prod name="wMailServer" vendor="SoftiaCom"><vers num="1.0"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-22" name="CVE-2005-2288" published="2005-07-18" seq="2005-2288" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in PHPCounter 7.2 allows remote attackers to inject arbitrary web script or HTML via the EpochPrefix parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112129495128834&amp;w=2">20050713 Path Disclosure and XSS problem in PHP Counter 7.2</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/15816">15816</ref><ref source="BID" url="http://www.securityfocus.com/bid/14256">14256</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014478">1014478</ref></refs><vuln_soft><prod name="PHPCounter" vendor="PHPCounter"><vers num="7.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-22" name="CVE-2005-2289" published="2005-07-18" seq="2005-2289" severity="Medium" type="CVE"><desc><descript source="cve">PHPCounter 7.2 allows remote attackers to obtain sensitive information via a direct request to prelims.php, which reveals the path in an error message.</descript></desc><loss_types><conf/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112129495128834&amp;w=2">20050713 Path Disclosure and XSS problem in PHP Counter 7.2</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/15816">15816</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014478">1014478</ref></refs><vuln_soft><prod name="PHPCounter" vendor="PHPCounter"><vers num="7.2"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-06-15" name="CVE-2005-2290" published="2005-07-18" seq="2005-2290" severity="High" type="CVE"><desc><descript source="cve">wps_shop.cgi in WPS Web Portal System 0.7.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) art and (2) cat variables.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112128870110418&amp;w=2">20050713 WPS Web-Portal-System v.0.7.0 (wps_shop.cgi) remote commands</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/15780/">15780</ref><ref source="BID" url="http://www.securityfocus.com/bid/14245">14245</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014480">1014480</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15780">15780</ref></refs><vuln_soft><prod name="Web Portal System" vendor="WPS"><vers num="0.7.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2291" published="2005-07-18" seq="2005-2291" severity="Medium" type="CVE"><desc><descript source="cve">Oracle JDeveloper 9.0.4, 9.0.5, and 10.1.2 passes the cleartext password as a parameter when starting sqlplus, which allows local users to gain sensitive information.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112129082323341&amp;w=2">20050713 Advisory: Oracle JDeveloper passes Plaintext Password</ref><ref adv="1" patch="1" source="MISC" url="http://www.red-database-security.com/advisory/oracle_jdeveloper_passes_plaintext_password.html">http://www.red-database-security.com/advisory/oracle_jdeveloper_passes_plaintext_password.html</ref></refs><vuln_soft><prod name="JDeveloper" vendor="Oracle"><vers num="9.0.4"/><vers num="9.0.5"/><vers num="10.1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2292" published="2005-07-18" seq="2005-2292" severity="Low" type="CVE"><desc><descript source="cve">Oracle JDeveloper 9.0.4, 9.0.5, and 10.1.2 stores cleartext passwords in (1) IDEConnections.xml, (2) XSQLConfig.xml and (3) settings.xml, which allows local users to obtain sensitive information.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112129177927502&amp;w=2">20050713 Advisory: Oracle JDeveloper Plaintext Passwords</ref><ref adv="1" source="MISC" url="http://www.red-database-security.com/advisory/oracle_jdeveloper_plaintext_password.html">http://www.red-database-security.com/advisory/oracle_jdeveloper_plaintext_password.html</ref><ref adv="1" patch="1" source="" url="http://www.oracle.com/technology/deploy/security/pdf/cpujul2005.html">http://www.oracle.com/technology/deploy/security/pdf/cpujul2005.html</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/15991/">15991</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/21342">jdeveloper-config-plaintext-password(21342)</ref></refs><vuln_soft><prod name="JDeveloper" vendor="Oracle"><vers num="9.0.4"/><vers num="9.0.5"/><vers num="10.1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2293" published="2005-07-18" seq="2005-2293" severity="Low" type="CVE"><desc><descript source="cve">Oracle Formsbuilder 9.0.4 stores database usernames and passwords in a temporary file, which is not deleted after it is used, which allows local users to obtain sensitive information.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112129452232307&amp;w=2">20050713 Advisory: Oracle Forms Builder Password in Temp Files</ref><ref adv="1" patch="1" source="MISC" url="http://www.red-database-security.com/advisory/oracle_formsbuilder_temp_file_issue.html">http://www.red-database-security.com/advisory/oracle_formsbuilder_temp_file_issue.html</ref><ref adv="1" patch="1" source="" url="http://www.oracle.com/technology/deploy/security/pdf/cpujul2005.html">http://www.oracle.com/technology/deploy/security/pdf/cpujul2005.html</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/15991/">15991</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/21343">formsbuilder-temp-file-plaintext-password(21343)</ref></refs><vuln_soft><prod name="Formsbuilder" vendor="Oracle"><vers num="9.0.4"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2294" published="2005-07-18" seq="2005-2294" severity="Low" type="CVE"><desc><descript source="cve">Oracle Forms 4.5, 6.0, 6i, and 9i on Unix, when a large number of records are retrieved by an Oracle form, stores a copy of the database tables in a world-readable temporary file, which allows local users to gain sensitive information such as credit card numbers.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112129398711846&amp;w=2">20050713 Advisory: Oracle Forms Insecure Temporary File Handling</ref><ref adv="1" patch="1" source="MISC" url="http://www.red-database-security.com/advisory/oracle_forms_unsecure_temp_file_handling.html">http://www.red-database-security.com/advisory/oracle_forms_unsecure_temp_file_handling.html</ref><ref adv="1" patch="1" source="" url="http://www.oracle.com/technology/deploy/security/pdf/cpujul2005.html">http://www.oracle.com/technology/deploy/security/pdf/cpujul2005.html</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/15991/">15991</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/21347">formsbuilder-temp-file-info-disclosure(21347)</ref></refs><vuln_soft><prod name="Oracle Forms" vendor="Oracle"><vers num="4.5"/><vers num="6.0"/><vers num="6i"/><vers num="9i"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2295" published="2005-07-18" seq="2005-2295" severity="Medium" type="CVE"><desc><descript source="cve">NetPanzer 0.8 and earlier allows remote attackers to cause a denial of service (infinite loop) via a packet with a zero datablock size.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Luigi Auriemma" url="http://aluigi.altervista.org/adv/panzone-adv.txt"></ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/21361">netpanzer-datablock-dos(21361)</ref><ref source="BID" url="http://www.securityfocus.com/bid/14257">14257</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014479">1014479</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16055">16055</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112129258221823&amp;w=2">20050713 Endless loop in NetPanzer 0.8</ref></refs><vuln_soft><prod name="NetPanzer" vendor="PyroSoft Inc"><vers num="0.8"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2296" published="2005-07-18" seq="2005-2296" severity="Medium" type="CVE"><desc><descript source="cve">YabbSE 1.5.5c allows remote attackers to obtain sensitive information via a direct request to ssi_examples.php, which reveals the path.</descript></desc><loss_types><conf/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112137300014760&amp;w=2">20050714 YaBBSe 1.5.5c Path disclosure problem</ref></refs><vuln_soft><prod name="YaBB" vendor="YaBB"><vers edition="Second Edition" num="1.5.5c"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2297" published="2005-07-19" seq="2005-2297" severity="Medium" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in TreeAction.do in Sybase EAServer 4.2.5 through 5.2 allows remote authenticated users to execute arbitrary code via a large javascript parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112146180532313&amp;w=2">20050715 Stack-Based Buffer Overflow in Sybase EAServer 4.2.5 to 5.2</ref><ref adv="1" patch="1" source="MISC" url="http://www.spidynamics.com/spilabs/advisories/sybaseEAserverOverflow.htm">http://www.spidynamics.com/spilabs/advisories/sybaseEAserverOverflow.htm</ref><ref adv="1" patch="1" source="" url="http://www.sybase.com/detail?id=1036742">http://www.sybase.com/detail?id=1036742</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014497">1014497</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16108">16108</ref></refs><vuln_soft><prod name="EAServer" vendor="Sybase"><vers num="4.2.5"/><vers num="5.0"/><vers num="5.1"/><vers num="5.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2298" published="2005-07-19" seq="2005-2298" severity="Medium" type="CVE"><desc><descript source="cve">BitDefender Engine 1.6.1 and earlier does not properly scan all attachments, which allows remote attackers to bypass virus scanning via begin and end commands in the body of the e-mail, which BitDefender treats as a uuencoded attachment and stops scanning afterwards.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112137542212322&amp;w=2">20050714 05_07_14-bitdefender_malicious_content_bypass</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014495">1014495</ref></refs><vuln_soft><prod name="BitDefender Engine" vendor="SOFTWIN"><vers num="1.6.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2299" published="2005-07-19" seq="2005-2299" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Simple Message Board Version 2.0 Beta 1 allow remote attackers to inject arbitrary web script or HTML via the (1) FID parameter to forum.cfm, (2) UID parameter to user.cfm, (3) TID parameter to thread.cfm, or (4) PostDate parameter to search.cfm.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112137585701087&amp;w=2">20050714 XSS in forums Simple Message Board Version 2.0 Beta 1</ref><ref source="BID" url="http://www.securityfocus.com/bid/14266">14266</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014494">1014494</ref><ref source="BID" url="http://www.securityfocus.com/bid/14267">14267</ref><ref source="BID" url="http://www.securityfocus.com/bid/14268">14268</ref><ref source="BID" url="http://www.securityfocus.com/bid/14269">14269</ref></refs><vuln_soft><prod name="Simple Message Board" vendor="Man And Machine Ltd."><vers num="2.0 Beta1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2300" published="2005-07-19" seq="2005-2300" severity="Low" type="CVE"><desc><descript source="cve">Skype 1.1.0.20 and earlier allows local users to overwrite arbitrary files via a symlink attack on the skype_profile.jpg temporary file.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112156036013818&amp;w=2">20050716 [ZH2005-16SA] Insecure temporary file creation in Skype for Linux</ref><ref adv="1" source="MISC" url="http://www.zone-h.org/advisories/read/id=7808">http://www.zone-h.org/advisories/read/id=7808</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16105">16105</ref></refs><vuln_soft><prod name="Skype" vendor="Skype Technologies"><vers num="1.1.0.20" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2301" published="2005-07-19" seq="2005-2301" severity="Medium" type="CVE"><desc><descript source="cve">PowerDNS before 2.9.18, when running with an LDAP backend, does not properly escape LDAP queries, which allows remote attackers to cause a denial of service (failure to answer ldap questions) and possibly conduct an LDAP injection attack.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112155941310297&amp;w=2">20050716 PowerDNS 2.9.18 fixes two security issues affecting users of LDAP</ref><ref source="" url="http://doc.powerdns.com/changelog.html#CHANGELOG-2-9-18">http://doc.powerdns.com/changelog.html#CHANGELOG-2-9-18</ref><ref source="BID" url="http://www.securityfocus.com/bid/14290">14290</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014504">1014504</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_19_sr.html">SUSE-SR:2005:019</ref></refs><vuln_soft><prod name="PowerDNS" vendor="PowerDNS"><vers num="2.9.17"/><vers num="2.9.16"/><vers num="2.9.15"/><vers num="2.9.14"/><vers num="2.9.13"/><vers num="2.9.12"/><vers num="2.9.11"/><vers num="2.9.10"/><vers num="2.9.8"/><vers num="2.9.7"/><vers num="2.9.6"/><vers num="2.9.5"/><vers num="2.9.4"/><vers num="2.9.3a"/><vers num="2.9.2"/><vers num="2.9.1"/><vers num="2.9.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2302" published="2005-07-19" seq="2005-2302" severity="Low" type="CVE"><desc><descript source="cve">PowerDNS before 2.9.18, when allowing recursion to a restricted range of IP addresses, does not properly handle questions from clients that are denied recursion, which could cause a &quot;blank out&quot; of answers to those clients that are allowed to use recursion.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112155941310297&amp;w=2">20050716 PowerDNS 2.9.18 fixes two security issues affecting users of LDAP</ref><ref source="" url="http://doc.powerdns.com/changelog.html#CHANGELOG-2-9-18">http://doc.powerdns.com/changelog.html#CHANGELOG-2-9-18</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014504">1014504</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_19_sr.html">SUSE-SR:2005:019</ref></refs><vuln_soft><prod name="PowerDNS" vendor="PowerDNS"><vers num="2.9.17"/><vers num="2.9.16"/><vers num="2.9.15"/><vers num="2.9.14"/><vers num="2.9.13"/><vers num="2.9.12"/><vers num="2.9.11"/><vers num="2.9.10"/><vers num="2.9.8"/><vers num="2.9.7"/><vers num="2.9.6"/><vers num="2.9.5"/><vers num="2.9.4"/><vers num="2.9.3a"/><vers num="2.9.2"/><vers num="2.9.1"/><vers num="2.9.0"/></prod></vuln_soft></entry><entry modified="2005-10-25" name="CVE-2005-2303" published="2005-07-19" reject="1" seq="2005-2303" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2005-1218.  Reason: This candidate is a duplicate of CVE-2005-1218.  Notes: All CVE users should reference CVE-2005-1218 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><refs/></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2304" published="2005-07-19" seq="2005-2304" severity="Medium" type="CVE"><desc><descript source="cve">Microsoft MSN Messenger 9.0 and Internet Explorer 6.0 allows remote attackers to cause a denial of service (crash) via an image with an ICC Profile with a large Tag Count.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/405377">20050716 Internet Explorer / MSN ICC Profiles Crash PoC Exploit</ref><ref source="BID" url="http://www.securityfocus.com/bid/14288">14288</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers edition="for Microsoft Windows Server 2003 SP1.0" num="6"/></prod><prod name="MSN Messenger Service" vendor="Microsoft"><vers num="9.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2305" published="2005-07-19" seq="2005-2305" severity="High" type="CVE"><desc><descript source="cve">DG Remote Control Server 1.6.2 allows remote attackers to cause a denial of service (crash or CPU consumption) and possibly execute arbitrary code via a long message to TCP port 1071 or 1073, possibly due to a buffer overflow.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="MISC" url="http://k.domaindlx.com/shellcore/advisories.asp?bug_report=display&amp;infamous_group=72">http://k.domaindlx.com/shellcore/advisories.asp?bug_report=display&amp;infamous_group=72</ref><ref source="BID" url="http://www.securityfocus.com/bid/14263">14263</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16070">16070</ref></refs><vuln_soft><prod name="Remote Control Server" vendor="DG"><vers num="1.6.2"/></prod></vuln_soft></entry><entry CVSS_base_score="3.7" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="6.4" CVSS_score="3.7" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2306" published="2005-07-19" seq="2005-2306" severity="Low" type="CVE"><desc><descript source="cve">Race condition in Macromedia JRun 4.0, ColdFusion MX 6.1 and 7.0, when under heavy load, causes JRun to assign a duplicate authentication token to multiple sessions, which could allow authenticated users to gain privileges as other users.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><race/></vuln_types><range><local/></range><refs><ref patch="1" source="" url="http://www.macromedia.com/devnet/security/security_zone/mpsb05-05.html">http://www.macromedia.com/devnet/security/security_zone/mpsb05-05.html</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/16081">16081</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014489">1014489</ref></refs><vuln_soft><prod name="ColdFusion MX" vendor="Macromedia"><vers num="7.0"/><vers num="6.1"/></prod><prod name="JRun" vendor="Macromedia"><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2007-08-22" name="CVE-2005-2307" published="2005-07-19" seq="2005-2307" severity="Medium" type="CVE"><desc><descript source="cve">netman.dll in Microsoft Windows Connections Manager Library allows local users to cause a denial of service (Network Connections Service crash) via a large integer argument to a particular function, aka &quot;Network Connection Manager Vulnerability.&quot;</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/14260">14260</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/16065">16065</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1250.html">OVAL1250</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1254.html">OVAL1254</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1289.html">OVAL1289</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1532.html">OVAL1532</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval786.html">OVAL786</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2005-214.pdf"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/17172">17172</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17223">17223</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms05-045.mspx">MS05-045</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1250">oval:org.mitre.oval:def:1250</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1254">oval:org.mitre.oval:def:1254</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1289">oval:org.mitre.oval:def:1289</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1532">oval:org.mitre.oval:def:1532</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:786">oval:org.mitre.oval:def:786</ref></refs><vuln_soft><prod name="Windows XP" vendor="Microsoft"><vers edition="Gold" num="Professional"/><vers edition="Gold" num="Professional"/><vers edition="Gold" num="Professional"/><vers edition="SP2" num="Home"/><vers edition="SP1" num="Home"/><vers num="Home"/><vers edition="SP2" num="Tablet PC"/><vers edition="SP2" num="Tablet PC"/><vers edition="SP2" num="Tablet PC"/><vers edition="SP2" num="Media Center"/><vers edition="SP1" num="Media Center"/><vers num="Media Center"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num="Server SP4"/><vers num="Server SP3"/><vers num="Server SP2"/><vers num="Server SP1"/><vers num="Server"/><vers num="Professional SP4"/><vers num="Professional SP3"/><vers num="Professional SP2"/><vers num="Professional SP1"/><vers num="Professional"/><vers num="Datacenter Server SP4"/><vers num="Datacenter Server SP3"/><vers num="Datacenter Server SP2"/><vers num="Datacenter Server SP1"/><vers num="Datacenter Server"/><vers num="Advanced Server SP4"/><vers num="Advanced Server SP3"/><vers num="Advanced Server SP2"/><vers num="Advanced Server SP1"/><vers num="Advanced Server"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2308" published="2005-07-19" seq="2005-2308" severity="High" type="CVE"><desc><descript source="cve">The JPEG decoder in Microsoft Internet Explorer allows remote attackers to cause a denial of service (CPU consumption or crash) and possibly execute arbitrary code via certain crafted JPEG images, as demonstrated using (1) mov_fencepost.jpg, (2) cmp_fencepost.jpg, (3) oom_dos.jpg, or (4) random.jpg.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/><design/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/405298">20050715 Compromising pictures of Microsoft Internet Explorer!</ref><ref source="MISC" url="http://lcamtuf.coredump.cx/crash">http://lcamtuf.coredump.cx/crash</ref><ref source="BID" url="http://www.securityfocus.com/bid/14284">14284</ref><ref source="BID" url="http://www.securityfocus.com/bid/14285">14285</ref><ref source="BID" url="http://www.securityfocus.com/bid/14286">14286</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers edition="for Microsoft Windows Server 2003 SP1.0 SP2" num="6"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2309" published="2005-07-19" seq="2005-2309" severity="Medium" type="CVE"><desc><descript source="cve">Opera 8.01 allows remote attackers to cause a denial of service (CPU consumption) via a crafted JPEG image, as demonstrated using random.jpg.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/><design/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/405298">20050715 Compromising pictures of Microsoft Internet Explorer!</ref><ref source="MISC" url="http://lcamtuf.coredump.cx/crash">http://lcamtuf.coredump.cx/crash</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/405524/30/0/threaded">20050718 Re: Compromising pictures of Microsoft Internet Explorer!</ref></refs><vuln_soft><prod name="Opera Web Browser" vendor="Opera Software"><vers num="8.01"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-02-04" name="CVE-2005-2310" published="2005-07-19" seq="2005-2310" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Winamp 5.03a, 5.09 and 5.091, and other versions before 5.094, allows remote attackers to execute arbitrary code via an MP3 file with a long ID3v2 tag such as (1) ARTIST or (2) TITLE.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://security.lss.hr/index.php?page=details&amp;ID=LSS-2005-07-14">http://security.lss.hr/index.php?page=details&amp;ID=LSS-2005-07-14</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014483">1014483</ref><ref source="BID" url="http://www.securityfocus.com/bid/14276">14276</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/16077">16077</ref><ref source="" url="http://www.winamp.com/player/version_history.php"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/1106">ADV-2005-1106</ref><ref source="OSVDB" url="http://www.osvdb.org/17897">17897</ref></refs><vuln_soft><prod name="Winamp" vendor="Nullsoft"><vers num="5.03a"/><vers num="5.09"/><vers num="5.091"/><vers num="5.093" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2311" published="2005-07-19" seq="2005-2311" severity="Low" type="CVE"><desc><descript source="cve">SMS 1.9.2m and earlier allows local users to overwrite arbitrary files via a symlink attack on the (1) request1 or (2) request2 temporary files.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/16038">16038</ref></refs><vuln_soft><prod name="SMS" vendor="SMS"><vers num="1.9.2m" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2312" published="2005-07-19" seq="2005-2312" severity="High" type="CVE"><desc><descript source="cve">management.php in Realnode Emilda 1.2.2 and earlier allows remote attackers to perform actions as other users by modifying the user_id parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://sourceforge.net/project/shownotes.php?release_id=338551">http://sourceforge.net/project/shownotes.php?release_id=338551</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/14244">14244</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15857">15857</ref></refs><vuln_soft><prod name="Emilda" vendor="Realnode"><vers num="1.2.2"/><vers num="1.2.1"/><vers num="1.2 Beta"/><vers num="1.2 alpha"/><vers num="1.2"/><vers num="1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-01-04" name="CVE-2005-2313" published="2005-07-19" seq="2005-2313" severity="High" type="CVE"><desc><descript source="cve">Check Point SecuRemote NG with Application Intelligence R54 allows attackers to obtain credentials and gain privileges via unknown attack vectors.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/14221">14221</ref></refs><vuln_soft><prod name="SecuRemote NG with Application Intelligence" vendor="Checkpoint"><vers num="R54"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2314" published="2005-07-19" seq="2005-2314" severity="High" type="CVE"><desc><descript source="cve">inc.login.php in PHPsFTPd 0.2 through 0.4 allows remote attackers to obtain the administrator&apos;s username and password by setting the do_login parameter and performing an edit action using user.php, which causes the login check to be bypassed and leaks the password in the response.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://packetstorm.linuxsecurity.com/0507-exploits/phpsftpd.txt">http://packetstorm.linuxsecurity.com/0507-exploits/phpsftpd.txt</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/14222">14222</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/1101">ADV-2005-1101</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/15879">15879</ref><ref source="BUGTRAQ" url="http://cert.uni-stuttgart.de/archive/bugtraq/2005/07/msg00209.html">20050713 PHPsFTPd - Admin password leak</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014481">1014481</ref></refs><vuln_soft><prod name="PHPsFTPd" vendor="PHPsFTPd"><vers num="0.4"/><vers num="0.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-28" name="CVE-2005-2315" published="2005-12-31" seq="2005-2315" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Domain Name Relay Daemon (DNRD) before 2.19.1 allows remote attackers to execute arbitrary code via a large number of large DNS packets with the Z and QR flags cleared.</descript></desc><sols><sol source="nvd">This vulnerability is addressed in the following product release:
dnrd, dnrd, 2.19.1
This vulnerability affects all versions of dnrd prior to 2.19.1</sol></sols><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref patch="1" source="Sourceforge" url="http://sourceforge.net/forum/forum.php?forum_id=482568">DNRD 2.19.1 release</ref><ref source="FreeBSD" url="http://www.FreeBSD.org/ports/portaudit/e72fd82b-fa01-11d9-bc08-0001020eed82.html">dnrd -- remote buffer and stack overflow vulnerabilities</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014557">1014557</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/16142">16142</ref></refs><vuln_soft><prod name="dnrd" vendor="dnrd"><vers num="2.10"/><vers num="2.9"/><vers num="2.8"/><vers num="2.7"/><vers num="2.6"/><vers num="2.5"/><vers num="2.4"/><vers num="2.3"/><vers num="2.2"/><vers num="2.1"/><vers num="2.0"/><vers num="1.4"/><vers num="1.3"/><vers num="1.2"/><vers num="1.1"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-28" name="CVE-2005-2316" published="2005-12-31" seq="2005-2316" severity="Medium" type="CVE"><desc><descript source="cve">Domain Name Relay Daemon (DNRD) before 2.19.1 allows remote attackers to cause a denial of service (infinite recursion) via a DNS packet that uses message compression in the QNAME and two pointers that point to each other (circular buffer).</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://sourceforge.net/forum/forum.php?forum_id=482568"></ref><ref source="" url="http://www.FreeBSD.org/ports/portaudit/e72fd82b-fa01-11d9-bc08-0001020eed82.html"></ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014557">1014557</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/16142">16142</ref></refs><vuln_soft><prod name="dnrd" vendor="dnrd"><vers num="2.19"/><vers num="2.18"/><vers num="2.17.2"/><vers num="2.17.1"/><vers num="2.16.1"/><vers num="2.16"/><vers num="2.15"/><vers num="2.14.1"/><vers num="2.14.1"/><vers num="2.14"/><vers num="2.13"/><vers num="2.12.1"/><vers num="2.12"/><vers num="2.11"/><vers num="2.10"/><vers num="2.9"/><vers num="2.8"/><vers num="2.7"/><vers num="2.6"/><vers num="2.5"/><vers num="2.4"/><vers num="2.3"/><vers num="2.2"/><vers num="2.1"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2317" published="2005-07-19" seq="2005-2317" severity="High" type="CVE"><desc><descript source="cve">Shorewall 2.4.x before 2.4.1, 2.2.x before 2.2.5, and 2.0.x before 2.0.17, when MACLIST_TTL is greater than 0 or MACLIST_DISPOSITION is set to ACCEPT, allows remote attackers with an accepted MAC address to bypass other firewall rules or policies.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="FULLDISC" url="http://seclists.org/lists/fulldisclosure/2005/Jul/0409.html">20050718 Shorewall MACLIST Problem</ref><ref adv="1" patch="1" source="" url="http://shorewall.net/News.htm#20050717">http://shorewall.net/News.htm#20050717</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/16087">16087</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200507-20.xml">GLSA-200507-20</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-849">DSA-849</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-197-1">USN-197-1</ref><ref source="BID" url="http://www.securityfocus.com/bid/14292">14292</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17110">17110</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17113">17113</ref></refs><vuln_soft><prod name="Shorewall" vendor="Shorewall"><vers num="2.4.0 RC2"/><vers num="2.4.0 RC1"/><vers num="2.4.0"/><vers num="2.2.0"/><vers num="2.2.1"/><vers num="2.2.2"/><vers num="2.2.3"/><vers num="2.2.4"/><vers num="2.0.0"/><vers num="2.0.0a"/><vers num="2.0.0b"/><vers num="2.0.1"/><vers num="2.0.2"/><vers num="2.0.2a"/><vers num="2.0.2b"/><vers num="2.0.2c"/><vers num="2.0.2d"/><vers num="2.0.2e"/><vers num="2.0.2f"/><vers num="2.0.3"/><vers num="2.0.3a"/><vers num="2.0.3b"/><vers num="2.0.3c"/><vers num="2.0.4"/><vers num="2.0.5"/><vers num="2.0.6"/><vers num="2.0.7"/><vers num="2.0.8"/><vers num="2.0.9"/><vers num="2.0.10"/><vers num="2.0.11"/><vers num="2.0.12"/><vers num="2.0.13"/><vers num="2.0.14"/><vers num="2.0.15"/><vers num="2.0.16"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2318" published="2005-07-19" seq="2005-2318" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in showerr.asp in DVBBS 7.1 SP2 allows remote attackers to inject arbitrary web script or HTML via the action parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/14223">14223</ref></refs><vuln_soft><prod name="Dvbbs" vendor="Dvbbs"><vers num="7.1 SP2"/><vers num="7.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2319" published="2005-07-19" seq="2005-2319" severity="Medium" type="CVE"><desc><descript source="cve">PHP remote file include vulnerability in Yawp library 1.0.6 and earlier, as used in YaWiki and possibly other products, allows remote attackers to include arbitrary files via the _Yawp[conf_path] parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/404948">20050712 Advisory 10/2005: Yawp/YaWiki Remote URL Include Vulnerability</ref><ref adv="1" patch="1" source="MISC" url="http://www.hardened-php.net/advisory-102005.php">http://www.hardened-php.net/advisory-102005.php</ref><ref source="" url="http://phpyawp.com/yawiki/index.php?page=ChangeLog">http://phpyawp.com/yawiki/index.php?page=ChangeLog</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/14237">14237</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16049">16049</ref></refs><vuln_soft><prod name="Yawp" vendor="Yawp"><vers num="1.0.6"/><vers num="1.0.5"/><vers num="1.0.4"/><vers num="1.0.3"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2320" published="2005-07-19" seq="2005-2320" severity="High" type="CVE"><desc><descript source="cve">WebCalendar before 1.0.0 does not properly restrict access to assistant_edit.php, which allows remote attackers to gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/14072">14072</ref></refs><vuln_soft><prod name="WebCalendar" vendor="WebCalendar"><vers edition="RC2" num="1.0.0"/><vers edition="RC1" num="1.0.0"/><vers num="0.9.50"/><vers num="0.9.45"/><vers num="0.9.44"/><vers num="0.9.43"/><vers num="0.9.42"/><vers num="0.9.41"/><vers num="0.9.40"/><vers num="0.9.39"/><vers num="0.9.38"/><vers num="0.9.37"/><vers num="0.9.36"/><vers num="0.9.35"/><vers num="0.9.34"/><vers num="0.9.33"/><vers num="0.9.32"/><vers num="0.9.31"/><vers num="0.9.30"/><vers num="0.9.29"/><vers num="0.9.28"/><vers num="0.9.27"/><vers num="0.9.26"/><vers num="0.9.25"/><vers num="0.9.24"/><vers num="0.9.23"/><vers num="0.9.22"/><vers num="0.9.21"/><vers num="0.9.20"/><vers num="0.9.19"/><vers num="0.9.16"/><vers num="0.9.15"/><vers num="0.9.11"/><vers num="0.9.8"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-16" name="CVE-2005-2321" published="2005-07-19" seq="2005-2321" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in CaLogic 1.2.2 allows remote attackers to execute arbitrary code via the CLPATH parameter to (1) cl_minical.php, (2) clmcpreload.php, (3) mcconfig.php, or (4) mcpi-demo.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/16090">16090</ref><ref source="" url="http://www.calogic.de/modules/newbb/viewtopic.php?topic_id=333&amp;forum=7">http://www.calogic.de/modules/newbb/viewtopic.php?topic_id=333&amp;forum=7</ref><ref source="BID" url="http://www.securityfocus.com/bid/14296">14296</ref></refs><vuln_soft><prod name="CaLogic" vendor="CaLogic"><vers num="1.2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-03-27" name="CVE-2005-2322" published="2005-07-19" seq="2005-2322" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Class-1 Forum 0.24.4 and 0.23.2, and Clever Copy with forums installed, allows remote attackers to inject arbitrary web script or HTML via the (1) viewuser_id or (2) group parameter to users.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://lostmon.blogspot.com/2005/07/class-1-forum-software-cross-site.html">http://lostmon.blogspot.com/2005/07/class-1-forum-software-cross-site.html</ref><ref source="BID" url="http://www.securityfocus.com/bid/14261">14261</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014485">1014485</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014486">1014486</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/16078">16078</ref></refs><vuln_soft><prod name="Class-1 Forum" vendor="Class-1"><vers num="0.24.4"/><vers num="0.23.2"/></prod><prod name="Clever Copy" vendor="Clever Copy"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-03-27" name="CVE-2005-2323" published="2005-07-19" seq="2005-2323" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in Class-1 Forum 0.24.4 and 0.23.2, and Clever Copy with forums installed, allow remote attackers to modify SQL statements via the (1) id parameter to viewattach.php, (2) viewuser_id parameter to users.php, or the (3) id or (4) forum parameter to viewforum.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://lostmon.blogspot.com/2005/07/class-1-forum-software-cross-site.html">http://lostmon.blogspot.com/2005/07/class-1-forum-software-cross-site.html</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014485">1014485</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014486">1014486</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/16078">16078</ref></refs><vuln_soft><prod name="Class-1 Forum" vendor="Class-1"><vers num="0.24.4"/><vers num="0.23.2"/></prod><prod name="Clever Copy" vendor="Clever Copy"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-03-27" name="CVE-2005-2324" published="2005-07-19" seq="2005-2324" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Clever Copy 2.0 and 2.0a allows remote attackers to inject arbitrary web script or HTML via the searchtype or searchterm parameters to (1) results.php or (2) categorysearch.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://lostmon.blogspot.com/2005/07/clever-copy-path-disclosure-and-xss.html">http://lostmon.blogspot.com/2005/07/clever-copy-path-disclosure-and-xss.html</ref></refs><vuln_soft><prod name="Clever Copy" vendor="Clever Copy"><vers num="2.0"/><vers num="2.0a"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-03-27" name="CVE-2005-2325" published="2005-07-19" seq="2005-2325" severity="Medium" type="CVE"><desc><descript source="cve">Clever Copy 2.0 and 2.0a allows remote attackers to obtain the full path of the web root via a direct request to (1) ticker.php, (2) menu.php, (3) banned.php, (4) endlayout.php, (5) randomhlinesblock.php, (6) showlast.php, (7) showlast5class1.php, (8) showlast5phorum.php, (9) showlast5phorumblock.php, (10) showlastforumbb2.php, or (11) showlastforumbb2block.php.</descript></desc><loss_types><conf/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://lostmon.blogspot.com/2005/07/clever-copy-path-disclosure-and-xss.html">http://lostmon.blogspot.com/2005/07/clever-copy-path-disclosure-and-xss.html</ref></refs><vuln_soft><prod name="Clever Copy" vendor="Clever Copy"><vers num="2.0"/><vers num="2.0a"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-03-27" name="CVE-2005-2326" published="2005-07-19" seq="2005-2326" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Clever Copy 2.0 and 2.0a allows remote attackers to inject arbitrary web script or HTML via the yr parameter to calendar.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://lostmon.blogspot.com/2005/07/clever-copy-calendarphp-yr-variable.html">http://lostmon.blogspot.com/2005/07/clever-copy-calendarphp-yr-variable.html</ref></refs><vuln_soft><prod name="Clever Copy" vendor="Clever Copy"><vers num="2.0"/><vers num="2.0a"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2327" published="2005-07-20" seq="2005-2327" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in e107 0.617 and earlier allows remote attackers to inject arbitrary web script or HTML via nested [url] BBCode tags.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MISC" url="http://milw0rm.com/id.php?id=1106">http://milw0rm.com/id.php?id=1106</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014513">1014513</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/1106">

1106</ref></refs><vuln_soft><prod name="e107" vendor="e107"><vers num="0.617"/><vers num="0.616"/><vers num="0.615a"/><vers num="0.614"/><vers num="0.613"/><vers num="0.612"/><vers num="0.611"/><vers num="0.610"/><vers num="0.609"/><vers num="0.608"/><vers num="0.607"/><vers num="0.606"/><vers num="0.605"/><vers num="0.604"/><vers num="0.603"/><vers num="0.602"/><vers num="0.601"/><vers num="0.600"/><vers num="0.555 Beta"/><vers num="0.554 Beta"/><vers num="0.553 Beta"/><vers num="0.552 Beta"/><vers num="0.551 Beta"/><vers num="0.549 Beta"/><vers num="0.548 Beta"/><vers num="0.547 Beta"/><vers num="5.4 Beta6"/><vers num="5.4 Beta5"/><vers num="5.4 Beta4"/><vers num="5.4 Beta3"/><vers num="5.4 Beta1"/><vers num="5.3 Beta2"/><vers num="5.3 Beta"/><vers num="5.21"/><vers num="5.1"/><vers num="5.05"/><vers num="5.04"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2328" published="2005-07-20" seq="2005-2328" severity="Medium" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in im.php in Laffer 0.3.2.6 and 0.3.2.7 allows remote attackers to execute arbitrary PHP code via the CFG_PATH variable.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MISC" url="http://sourceforge.net/tracker/index.php?func=detail&amp;aid=1235463&amp;group_id=101249&amp;atid=629313">http://sourceforge.net/tracker/index.php?func=detail&amp;aid=1235463&amp;group_id=101249&amp;atid=629313</ref><ref patch="1" source="" url="http://laffer.sourceforge.net/cgi-bin/index.pl?page=news&amp;key=373747410">http://laffer.sourceforge.net/cgi-bin/index.pl?page=news&amp;key=373747410</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/14264">14264</ref></refs><vuln_soft><prod name="Laffer" vendor="Laffer"><vers num="0.3.2.7"/><vers num="0.3.2.6"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2329" published="2005-07-20" seq="2005-2329" severity="Medium" type="CVE"><desc><descript source="cve">MRV Communications In-Reach LX-8000S, LX-4000S, and LX-1000S 3.5.0, when using SSH public key authentication, does not properly restrict access to ports, which allows remote authenticated users to access the consoles of other users.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/405546">20050718 MRV In-Reach console server: Port Access Control Bypass Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/14300">14300</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014517">1014517</ref></refs><vuln_soft><prod name="In_Reach LX_1000S" vendor="MRV Communications"><vers num="3.5"/></prod><prod name="In_Reach LX_4000S" vendor="MRV Communications"><vers num="3.5"/></prod><prod name="In_Reach LX_8000S" vendor="MRV Communications"><vers num="3.5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-06-14" name="CVE-2005-2330" published="2005-07-20" seq="2005-2330" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in extras/update.php in osCommerce 2.2 allows remote attackers to read arbitrary files via (1) .. sequences or (2) a full pathname in the readme_file parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/14294">14294</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/431012">20060414 osCommerce </ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/431068">20060414 RE: osCommerce </ref><ref source="" url="http://retrogod.altervista.org/oscommerce_22_adv.html"></ref><ref source="" url="http://sourceforge.net/mailarchive/message.php?msg_id=12318248"></ref><ref source="" url="http://www.oscommerce.com/community/bugs,2835"></ref><ref source="OSVDB" url="http://www.osvdb.org/18249">18249</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015944">1015944</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25861">oscommerce-extrasupdate-info-disclosure(25861)</ref></refs><vuln_soft><prod name="osCommerce" vendor="osCommerce"><vers num="2.2 ms2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2331" published="2005-07-20" seq="2005-2331" severity="Medium" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in display.php in MooseGallery allows remote attackers to execute arbitrary PHP code via the type parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/14280">14280</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014487">1014487</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/16093">16093</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/21388">moosegallery-display-file-include(21388)</ref></refs><vuln_soft><prod name="MooseGallery" vendor="MooseGallery"><vers num="1.0.2"/><vers num="1.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2332" published="2005-07-20" seq="2005-2332" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in PHPPageProtect 1.0.0a allows remote attackers to inject arbitrary web script or HTML via the username parameter to (1) admin.php or (2) login.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="SECTRACK" url="http://securitytracker.com/id?1014510">1014510</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/16110">16110</ref><ref source="BID" url="http://www.securityfocus.com/bid/14314">14314</ref><ref source="BID" url="http://www.securityfocus.com/bid/14318">14318</ref></refs><vuln_soft><prod name="PHPPageProtect" vendor="PHP.WarpedWeb.Net"><vers num="1.0.0a"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2333" published="2005-07-20" seq="2005-2333" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in smilies_popup.php in SEO-Board 1.0 allows remote attackers to inject arbitrary web script or HTML via the doc parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="SECTRACK" url="http://securitytracker.com/id?1014509">1014509</ref><ref source="BID" url="http://www.securityfocus.com/bid/14320">14320</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16051">16051</ref></refs><vuln_soft><prod name="SEO-Board" vendor="SEO-Board"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2334" published="2005-07-20" seq="2005-2334" severity="High" type="CVE"><desc><descript source="cve">Y.SAK allows remote attackers to execute arbitrary commands via shell metacharacters in the $no variable to (1) w_s3mbfm.cgi, (2) w_s3adix.cgi, or (3) w_s3sbfm.cgi.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="SECTRACK" url="http://securitytracker.com/id?1014502">1014502</ref><ref source="BID" url="http://www.securityfocus.com/bid/14299">14299</ref></refs><vuln_soft><prod name="Y.SAK" vendor="Y.SAK"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2335" published="2005-07-27" seq="2005-2335" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in the POP3 client in Fetchmail before 6.2.5.2 allows remote POP3 servers to cause a denial of service and possibly execute arbitrary code via long UIDL responses.  NOTE: a typo in an advisory accidentally used the wrong CVE identifier for the Fetchmail issue. This is the correct identifier.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://fetchmail.berlios.de/fetchmail-SA-2005-01.txt">http://fetchmail.berlios.de/fetchmail-SA-2005-01.txt</ref><ref patch="1" source="" url="http://developer.berlios.de/project/shownotes.php?release_id=6617">http://developer.berlios.de/project/shownotes.php?release_id=6617</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-announce-list/2005-July/msg00088.html">FEDORA-2005-613</ref><ref patch="1" source="FEDORA" url="http://www.redhat.com/archives/fedora-announce-list/2005-July/msg00089.html">FEDORA-2005-614</ref><ref source="MISC" url="http://www.redhat.com/archives/fedora-announce-list/2005-July/msg00104.html">http://www.redhat.com/archives/fedora-announce-list/2005-July/msg00104.html</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/14349">14349</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/1171">ADV-2005-1171</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/16176">16176</ref><ref source="OSVDB" url="http://www.osvdb.org/18174">18174</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-774">DSA-774</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1038.html">OVAL1038</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1124.html">OVAL1124</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-640.html">RHSA-2005:640</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/435197/100/0/threaded">20060526 rPSA-2006-0084-1 fetchmail</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_18_sr.html">SUSE-SR:2005:018</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2006//Aug/msg00000.html">APPLE-SA-2006-08-01</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21253">21253</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/441856/100/200/threaded">20060801 DMA[2006-0801a] - &apos;Apple OSX fetchmail buffer overflow&apos;</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/3101">ADV-2006-3101</ref><ref source="BID" url="http://www.securityfocus.com/bid/19289">19289</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1038">oval:org.mitre.oval:def:1038</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1124">oval:org.mitre.oval:def:1124</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-214A.html">
TA06-214A</ref></refs><vuln_soft><prod name="Fetchmail" vendor="Eric Raymond"><vers num="6.2.5.1"/><vers num="6.2.5"/><vers num="6.2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-25" name="CVE-2005-2336" published="2005-09-06" seq="2005-2336" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Hiki 0.8.0 to 0.8.2 allows remote attackers to inject arbitrary web script or HTML via &quot;missing pages&quot; in which the page name is not properly escaped, a different vulnerability than CVE-2005-2803.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://hikiwiki.org/en/advisory20050804.html"></ref><ref source="" url="http://jvn.jp/jp/JVN%2338138980"></ref><ref source="" url="http://www.ipa.go.jp/security/vuln/documents/2005/JVN_38138980_Hiki.html"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/17075">17075</ref><ref source="BID" url="http://www.securityfocus.com/bid/15021">15021</ref></refs><vuln_soft><prod name="Hiki" vendor="Hiki"><vers num="0.8.0"/><vers num="0.8.1"/><vers num="0.8.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2007-01-03" name="CVE-2005-2337" published="2005-10-07" seq="2005-2337" severity="High" type="CVE"><desc><descript source="cve">Ruby 1.6.x up to 1.6.8, 1.8.x up to 1.8.2, and 1.9.0 development up to 2005-09-01 allows attackers to bypass safe level and taint flag protections and execute disallowed code when Ruby processes a program through standard input (stdin).</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.ruby-lang.org/en/20051003.html"></ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/160012">VU#160012</ref><ref source="" url="http://jvn.jp/jp/JVN%2362914675/index.html"></ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/16904">16904</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-860">DSA-860</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-862">DSA-862</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-799.html">RHSA-2005:799</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200510-05.xml">GLSA-200510-05</ref><ref source="BID" url="http://www.securityfocus.com/bid/14909">14909</ref><ref source="SECTRACK" url="http://www.securitytracker.com/alerts/2005/Sep/1014948.html">1014948</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/22360">ruby-eval-security-bypass(22360)</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-195-1">USN-195-1</ref><ref adv="1" source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:191">MDKSA-2005:191</ref><ref adv="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-864">DSA-864</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17094">17094</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/17129">17129</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/17147">17147</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/17285">17285</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_05_sr.html">SUSE-SR:2006:005</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19130">19130</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/17098">17098</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2006/May/msg00003.html">APPLE-SA-2006-05-11</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-132A.html">TA06-132A</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/20077">20077</ref><ref source="BID" url="http://www.securityfocus.com/bid/17951">17951</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1779">ADV-2006-1779</ref><ref source="SREASON" url="http://securityreason.com/securityalert/59">59</ref></refs><vuln_soft><prod name="Ruby" vendor="Yukihiro Matsumoto"><vers num="1.6"/><vers num="1.6.1"/><vers num="1.6.2"/><vers num="1.6.3"/><vers num="1.6.4"/><vers num="1.6.5"/><vers num="1.6.6"/><vers num="1.6.7"/><vers num="1.8"/><vers num="1.8.1"/><vers num="1.8.2 pre2"/><vers num="1.8.2 pre1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-31" name="CVE-2005-2338" published="2005-10-26" seq="2005-2338" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in XOOPS 2.0.12 JP and earlier, XOOPS 2.0.13.1 and earlier, and 2.2.x up to 2.2.3 RC1 allow remote attackers to inject arbitrary web script or HTML via (1) modules that use &quot;XOOPS Code&quot; and (2) newbb in the forum module.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.lac.co.jp/business/sns/intelligence/SNSadvisory_e/85_e.html"></ref><ref source="" url="http://jvn.jp/jp/JVN%2377105349/index.html"></ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/17300">17300</ref><ref source="BID" url="http://www.securityfocus.com/bid/15195">15195</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=113027315412024&amp;w=2">20051025 [SNS Advisory No.85] XOOPS Multiple Cross-site Scripting Vulnerabilities</ref></refs><vuln_soft><prod name="XOOPS" vendor="XOOPS"><vers num="2.0.12 JP" prev="1"/><vers num="2.0.13.1" prev="1"/><vers num="2.2.3 RC1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-10-31" name="CVE-2005-2339" published="2005-11-21" seq="2005-2339" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in the Unicode version of msearch (unicode-msearch) 1.51(U1)-beta1, 1.51(U1), and 1.52(U1) allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</descript></desc><loss_types><int/></loss_types><range><network/></range><refs><ref source="jvn" url="http://jvn.jp/jp/JVN%2379925E6F/index.html">JVN#79925E6F</ref></refs><vuln_soft><prod name="unicode_msearch" vendor="msearch"><vers num="1.51 U1"/><vers num="1.51 U1 Beta1"/><vers num="1.52 U1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2005-12-29" modified="2006-05-24" name="CVE-2005-2340" published="2005-12-31" seq="2005-2340" severity="High" type="CVE"><desc><descript source="cve">Heap-based buffer overflow in Apple Quicktime before 7.0.4 allows remote attackers to execute arbitrary code via a crafted (1) QuickTime Image File (QTIF), (2) PICT, or (3) JPEG format image with a long data field.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref patch="1" source="APPLE" url="http://docs.info.apple.com/article.html?artnum=303101">APPLE-SA-2006-01-10</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16202">16202</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0128">ADV-2006-0128</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18370">18370</ref><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421566/100/0/threaded">20060111 [EEYEB-20051220] Apple QuickTime QTIF Stack Overflow</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421547/100/0/threaded">20060111 Updated Advisories - Incorrect CVE Information</ref><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0392.html">20060111 [CIRT.DK] Apple QuickTime 7.0.3 and earlier - JPG/PICT Buffer Overflow</ref><ref adv="1" source="" url="http://www.cirt.dk/advisories/cirt-41-advisory.pdf"></ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/629845">VU#629845</ref><ref adv="1" patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-011A.html">TA06-011A</ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/687201">VU#687201</ref><ref source="BID" url="http://www.securityfocus.com/bid/16212">16212</ref><ref patch="1" source="OSVDB" url="http://www.osvdb.org/22333">22333</ref><ref patch="1" source="OSVDB" url="http://www.osvdb.org/22334">22334</ref><ref patch="1" source="OSVDB" url="http://www.osvdb.org/22335">22335</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015463">1015463</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/24054">quicktime-qtif-bo(24054)</ref><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0402.html">20060111 Updated Advisories - Incorrect CVE Information</ref><ref adv="1" source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0398.html">20060111 [EEYEB-20051220] Apple QuickTime QTIF Stack Overflow</ref><ref source="SREASON" url="http://securityreason.com/securityalert/332">332</ref></refs><vuln_soft><prod name="Quicktime" vendor="Apple"><vers num="7.0.3" prev="1"/><vers num="7.0.2"/><vers num="7.0.1"/><vers num="7.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-12" name="CVE-2005-2341" published="2005-12-31" seq="2005-2341" severity="High" type="CVE"><desc><descript source="cve">Heap-based buffer overflow in Research in Motion (RIM) BlackBerry Attachment Service allows remote attackers to cause a denial of service (hang) via an e-mail attachment with a crafted TIFF file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/570768">VU#570768</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015426">1015426</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0011">ADV-2006-0011</ref><ref source="BID" url="http://www.securityfocus.com/bid/16098">16098</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18277">18277</ref></refs><vuln_soft><prod name="Blackberry Enterprise Server" vendor="RIM"><vers num="4.0" prev="1"/></prod><prod name="Blackberry Attachment Service" vendor="RIM"><vers num="4.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2007-06-04" name="CVE-2005-2342" published="2005-12-31" seq="2005-2342" severity="High" type="CVE"><desc><descript source="cve">Research in Motion (RIM) BlackBerry Router allows remote attackers to cause a denial of service (communication disruption) via crafted Server Routing Protocol (SRP) packets.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/392920">VU#392920</ref><ref source="BID" url="http://www.securityfocus.com/bid/16100">16100</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015427">1015427</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0011">ADV-2006-0011</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18277">18277</ref><ref source="" url="http://www.blackberry.com/knowledgecenterpublic/livelink.exe/fetch/2000/8021/728075/728850/728215/?nodeid=1167898"></ref></refs><vuln_soft><prod name="Blackberry Router" vendor="RIM"><vers num="4.0" prev="1"/></prod><prod name="Blackberry Enterprise Server" vendor="RIM"><vers num="4.0 SP1"/><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-10" name="CVE-2005-2343" published="2005-12-31" seq="2005-2343" severity="Low" type="CVE"><desc><descript source="cve">Research in Motion (RIM) BlackBerry Handheld web browser for BlackBerry Handheld before 4.0.2 allows remote attackers to cause a denial of service (hang) via a Java Application Description (JAD) file with a long application name and vendor string, which prevents a browser dialog from being properly dismissed.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/829400">VU#829400</ref><ref source="BID" url="http://www.securityfocus.com/bid/16099">16099</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0011">ADV-2006-0011</ref><ref source="" url="http://www.blackberry.com/knowledgecenterpublic/livelink.exe/fetch/2000/8021/7925/8142/?nodeid=1167791"></ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015428">1015428</ref></refs><vuln_soft><prod name="Blackberry Desktop Manager" vendor="RIM"><vers num="4.0"/></prod><prod name="Blackberry Device Software" vendor="RIM"><vers num="4.0"/></prod><prod name="Blackberry" vendor="RIM"><vers num="8700r"/><vers num="8700f"/><vers num="8700c"/><vers num="7780"/><vers num="7750"/><vers num="7730"/><vers num="7520"/><vers num="7290"/><vers num="7280"/><vers num="7250"/><vers num="7230 4.0"/><vers num="7230 3.8"/><vers num="7230 3.7.1 .41"/><vers num="7130e"/><vers num="7105t"/><vers num="7100x"/><vers num="7100v"/><vers num="7100t"/><vers num="7100r"/><vers num="7100i"/><vers num="7100g"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2007-06-04" name="CVE-2005-2344" published="2005-12-31" seq="2005-2344" severity="Medium" type="CVE"><desc><descript source="cve">The BlackBerry Attachment Service in Research in Motion (RIM) BlackBerry Enterprise Server (BES) 4.0 to version 4.0 Service Pack 2 allows attackers to cause a denial of service via a malformed Portable Network Graphics (PNG) file that triggers a heap-based buffer overflow.</descript></desc><loss_types><int/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/646976">VU#646976</ref><ref adv="1" source="" url="http://www.blackberry.com/knowledgecenterpublic/livelink.exe/fetch/2000/8021/728075/728850/728215/?nodeid=1167794"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0127">ADV-2006-0127</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18393">18393</ref><ref source="BID" url="http://www.securityfocus.com/bid/16204">16204</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24063">blackberry-attachment-png-bo(24063)</ref></refs><vuln_soft><prod name="Blackberry Enterprise Server" vendor="RIM"><vers num="4.0"/><vers num="4.0 SP1"/><vers num="4.0 SP2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2346" published="2005-08-03" seq="2005-2346" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Novell GroupWise 6.5 Client allows remote attackers to execute arbitrary code via a GWVW02xx.INI language file with a long entry, as demonstrated using a long ES02TKS.VEW value in the Group Task section.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://support.novell.com/cgi-bin/search/searchtid.cgi?/10098314.htm">http://support.novell.com/cgi-bin/search/searchtid.cgi?/10098314.htm</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112247652532002&amp;w=2">20050727 [ISR] - Novell GroupWise Client Remote Buffer Overflow</ref></refs><vuln_soft><prod name="GroupWise" vendor="Novell"><vers num="6.5"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2353" published="2005-08-05" seq="2005-2353" severity="Low" type="CVE"><desc><descript source="cve">run-mozilla.sh in Thunderbird, with debugging enabled, allows local users to create or overwrite arbitrary files via a symlink attack on temporary files.</descript></desc><loss_types><int/></loss_types><vuln_types><config/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-157-1">USN-157-1</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:173">MDKSA-2005:173</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:174">MDKSA-2005:174</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1046">DSA-1046</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19863">19863</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1051">DSA-1051</ref><ref source="BID" url="http://www.securityfocus.com/bid/14443">14443</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19941">19941</ref></refs><vuln_soft><prod name="Thunderbird" vendor="Mozilla"><vers num=""/></prod></vuln_soft></entry><entry modified="2005-10-25" name="CVE-2005-2355" published="2005-07-25" reject="1" seq="2005-2355" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2005-2335, CVE-2005-2356.  Reason: due to a typo in an advisory, this candidate was accidentally referenced.  Notes: All CVE users should consult CVE-2005-2335 and CVE-2005-2356 to determine the appropriate identifier for the issue.</descript></desc><refs><ref source="" url="http://www.redhat.com/archives/fedora-announce-list/2005-July/msg00104.html"></ref></refs></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2357" published="2005-08-16" seq="2005-2357" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in EMC Navisphere Manager 6.4.1.0.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the URL.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/14487">14487</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/21726">emcnavispheremanager-directory-traversal(21726)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014629">1014629</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16344">16344</ref><ref source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=288&amp;type=vulnerabilities&amp;flashstatus=true">20050805 EMC Navisphere Manager Directory Traversal Vulnerability</ref></refs><vuln_soft><prod name="EMC Navisphere Manager" vendor="EMC"><vers num="6.4.1.0.0"/><vers num="6.6"/><vers num="6.5"/><vers num="6.4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2358" published="2005-08-16" seq="2005-2358" severity="Medium" type="CVE"><desc><descript source="cve">EMC Navisphere Manager 6.4.1.0.0 allows remote attackers to list arbitrary directories via an HTTP request for a directory that ends in a &quot;.&quot; (trailing dot).</descript></desc><loss_types><conf/></loss_types><vuln_types><input/><design/></vuln_types><range><network/></range><refs><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/14487">14487</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014629">1014629</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16344">16344</ref><ref source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=288&amp;type=vulnerabilities&amp;flashstatus=true">20050805 EMC Navisphere Manager Directory Traversal Vulnerability</ref></refs><vuln_soft><prod name="Navisphere Manager" vendor="EMC"><vers num="6.6"/><vers num="6.5"/><vers num="6.4.1.0"/><vers num="6.4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2359" published="2005-08-05" seq="2005-2359" severity="Medium" type="CVE"><desc><descript source="cve">The AES-XCBC-MAC algorithm in IPsec in FreeBSD 5.3 and 5.4, when used for authentication without other encryption, uses a constant key instead of the one that was assigned by the system administrator, which can allow remote attackers to spoof packets to establish an IPsec session.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="FREEBSD" url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-05:19.ipsec.asc">FreeBSD-SA-05:19</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/16244/">16244</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/21551">freebsd-aesxcbcmac-security-bypass(21551)</ref><ref source="BID" url="http://www.securityfocus.com/bid/14394">14394</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014586">1014586</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="5.3"/><vers num="5.4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2360" published="2005-08-10" seq="2005-2360" severity="Medium" type="CVE"><desc><descript source="cve">Unknown vulnerability in the LDAP dissector in Ethereal 0.8.5 through 0.10.11 allows remote attackers to cause a denial of service (free static memory and application crash) via unknown attack vectors.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref patch="1" source="" url="http://www.ethereal.com/appnotes/enpa-sa-00020.html">http://www.ethereal.com/appnotes/enpa-sa-00020.html</ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200507-27.xml">GLSA-200507-27</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00003.html">FLSA-2006:152922</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-687.html">RHSA-2005:687</ref><ref source="BID" url="http://www.securityfocus.com/bid/14399">14399</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-853">DSA-853</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16225/">16225</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17102">17102</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_19_sr.html">SUSE-SR:2005:019</ref></refs><vuln_soft><prod name="Ethereal" vendor="Ethereal Group"><vers num="0.8.5"/><vers num="0.8.6"/><vers num="0.8.7"/><vers num="0.8.8"/><vers num="0.8.9"/><vers num="0.8.10"/><vers num="0.8.11"/><vers num="0.8.12"/><vers num="0.8.13"/><vers num="0.8.14"/><vers num="0.8.15"/><vers num="0.8.16"/><vers num="0.8.17"/><vers num="0.8.18"/><vers num="0.8.19"/><vers num="0.8.20"/><vers num="0.9.0"/><vers num="0.9.1"/><vers num="0.9.2"/><vers num="0.9.3"/><vers num="0.9.4"/><vers num="0.9.5"/><vers num="0.9.6"/><vers num="0.9.7"/><vers num="0.9.8"/><vers num="0.9.9"/><vers num="0.9.10"/><vers num="0.9.11"/><vers num="0.9.12"/><vers num="0.9.13"/><vers num="0.9.14"/><vers num="0.9.15"/><vers num="0.9.16"/><vers num="0.10.0"/><vers num="0.10.1"/><vers num="0.10.2"/><vers num="0.10.3"/><vers num="0.10.4"/><vers num="0.10.5"/><vers num="0.10.6"/><vers num="0.10.7"/><vers num="0.10.8"/><vers num="0.10.9"/><vers num="0.10.10"/><vers num="0.10.11"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2361" published="2005-08-10" seq="2005-2361" severity="Medium" type="CVE"><desc><descript source="cve">Unknown vulnerability in the (1) AgentX dissector, (2) PER dissector, (3) DOCSIS dissector, (4) SCTP graphs, (5) HTTP dissector, (6) DCERPC, (7) DHCP, (8) RADIUS dissector, (9) Telnet dissector, (10) IS-IS LSP dissector, or (11) NCP dissector in Ethereal 0.8.19 through 0.10.11 allows remote attackers to cause a denial of service (application crash or abort) via unknown attack vectors.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref patch="1" source="" url="http://www.ethereal.com/appnotes/enpa-sa-00020.html">http://www.ethereal.com/appnotes/enpa-sa-00020.html</ref><ref patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200507-27.xml">GLSA-200507-27</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00003.html">FLSA-2006:152922</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-687.html">RHSA-2005:687</ref><ref source="BID" url="http://www.securityfocus.com/bid/14399">14399</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-853">DSA-853</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16225/">16225</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17102">17102</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_19_sr.html">SUSE-SR:2005:019</ref></refs><vuln_soft><prod name="Ethereal" vendor="Ethereal Group"><vers num="0.8.19"/><vers num="0.8.20"/><vers num="0.9.0"/><vers num="0.9.1"/><vers num="0.9.2"/><vers num="0.9.3"/><vers num="0.9.4"/><vers num="0.9.5"/><vers num="0.9.6"/><vers num="0.9.7"/><vers num="0.9.8"/><vers num="0.9.9"/><vers num="0.9.10"/><vers num="0.9.11"/><vers num="0.9.12"/><vers num="0.9.13"/><vers num="0.9.14"/><vers num="0.9.15"/><vers num="0.9.16"/><vers num="0.10.0"/><vers num="0.10.1"/><vers num="0.10.2"/><vers num="0.10.3"/><vers num="0.10.4"/><vers num="0.10.5"/><vers num="0.10.6"/><vers num="0.10.7"/><vers num="0.10.8"/><vers num="0.10.9"/><vers num="0.10.10"/><vers num="0.10.11"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2362" published="2005-08-10" seq="2005-2362" severity="Medium" type="CVE"><desc><descript source="cve">Unknown vulnerability several dissectors in Ethereal 0.9.0 through 0.10.11 allows remote attackers to cause a denial of service (application crash) by reassembling certain packets.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref patch="1" source="" url="http://www.ethereal.com/appnotes/enpa-sa-00020.html">http://www.ethereal.com/appnotes/enpa-sa-00020.html</ref><ref patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200507-27.xml">GLSA-200507-27</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00003.html">FLSA-2006:152922</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-687.html">RHSA-2005:687</ref><ref source="BID" url="http://www.securityfocus.com/bid/14399">14399</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16225">16225</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_19_sr.html">SUSE-SR:2005:019</ref></refs><vuln_soft><prod name="Ethereal" vendor="Ethereal Group"><vers num="0.9.0"/><vers num="0.9.1"/><vers num="0.9.2"/><vers num="0.9.3"/><vers num="0.9.4"/><vers num="0.9.5"/><vers num="0.9.6"/><vers num="0.9.7"/><vers num="0.9.8"/><vers num="0.9.9"/><vers num="0.9.10"/><vers num="0.9.11"/><vers num="0.9.12"/><vers num="0.9.13"/><vers num="0.9.14"/><vers num="0.9.15"/><vers num="0.9.16"/><vers num="0.10.0"/><vers num="0.10.1"/><vers num="0.10.2"/><vers num="0.10.3"/><vers num="0.10.4"/><vers num="0.10.5"/><vers num="0.10.6"/><vers num="0.10.7"/><vers num="0.10.8"/><vers num="0.10.9"/><vers num="0.10.10"/><vers num="0.10.11"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2363" published="2005-08-10" seq="2005-2363" severity="Medium" type="CVE"><desc><descript source="cve">Unknown vulnerability in the (1) SMPP dissector, (2) 802.3 dissector, (3) DHCP, (4) MEGACO dissector, or (5) H1 dissector in Ethereal 0.8.15 through 0.10.11 allows remote attackers to cause a denial of service (infinite loop) via unknown attack vectors.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref patch="1" source="" url="http://www.ethereal.com/appnotes/enpa-sa-00020.html">http://www.ethereal.com/appnotes/enpa-sa-00020.html</ref><ref patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200507-27.xml">GLSA-200507-27</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00003.html">FLSA-2006:152922</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-687.html">RHSA-2005:687</ref><ref source="BID" url="http://www.securityfocus.com/bid/14399">14399</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-853">DSA-853</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16225/">16225</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17102">17102</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_19_sr.html">SUSE-SR:2005:019</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_18_sr.html">SUSE-SR:2005:018</ref></refs><vuln_soft><prod name="Ethereal" vendor="Ethereal Group"><vers num="0.8.15"/><vers num="0.8.16"/><vers num="0.8.17"/><vers num="0.8.18"/><vers num="0.8.19"/><vers num="0.8.20"/><vers num="0.9.0"/><vers num="0.9.1"/><vers num="0.9.2"/><vers num="0.9.3"/><vers num="0.9.4"/><vers num="0.9.5"/><vers num="0.9.6"/><vers num="0.9.7"/><vers num="0.9.8"/><vers num="0.9.9"/><vers num="0.9.10"/><vers num="0.9.11"/><vers num="0.9.12"/><vers num="0.9.13"/><vers num="0.9.14"/><vers num="0.9.15"/><vers num="0.9.16"/><vers num="0.10.0"/><vers num="0.10.1"/><vers num="0.10.2"/><vers num="0.10.3"/><vers num="0.10.4"/><vers num="0.10.5"/><vers num="0.10.6"/><vers num="0.10.7"/><vers num="0.10.8"/><vers num="0.10.9"/><vers num="0.10.10"/><vers num="0.10.11"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2364" published="2005-08-10" seq="2005-2364" severity="Medium" type="CVE"><desc><descript source="cve">Unknown vulnerability in the (1) GIOP dissector, (2) WBXML, or (3) CAMEL dissector in Ethereal 0.8.20 through 0.10.11 allows remote attackers to cause a denial of service (application crash) via certain packets that cause a null pointer dereference.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref patch="1" source="" url="http://www.ethereal.com/appnotes/enpa-sa-00020.html">http://www.ethereal.com/appnotes/enpa-sa-00020.html</ref><ref patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200507-27.xml">GLSA-200507-27</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00003.html">FLSA-2006:152922</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-687.html">RHSA-2005:687</ref><ref source="BID" url="http://www.securityfocus.com/bid/14399">14399</ref><ref source="OSVDB" url="http://www.osvdb.org/18386">18386</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-853">DSA-853</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16225/">16225</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17102">17102</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_19_sr.html">SUSE-SR:2005:019</ref></refs><vuln_soft><prod name="Ethereal" vendor="Ethereal Group"><vers num="0.8.20"/><vers num="0.9.0"/><vers num="0.9.1"/><vers num="0.9.2"/><vers num="0.9.3"/><vers num="0.9.4"/><vers num="0.9.5"/><vers num="0.9.6"/><vers num="0.9.7"/><vers num="0.9.8"/><vers num="0.9.9"/><vers num="0.9.10"/><vers num="0.9.11"/><vers num="0.9.12"/><vers num="0.9.13"/><vers num="0.9.14"/><vers num="0.9.15"/><vers num="0.9.16"/><vers num="0.10.0"/><vers num="0.10.1"/><vers num="0.10.2"/><vers num="0.10.3"/><vers num="0.10.4"/><vers num="0.10.5"/><vers num="0.10.6"/><vers num="0.10.7"/><vers num="0.10.8"/><vers num="0.10.9"/><vers num="0.10.10"/><vers num="0.10.11"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2365" published="2005-08-10" seq="2005-2365" severity="Medium" type="CVE"><desc><descript source="cve">Unknown vulnerability in the SMB dissector in Ethereal 0.9.0 through 0.10.11 allows remote attackers to cause a buffer overflow or a denial of service (memory consumption) via unknown attack vectors.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref patch="1" source="" url="http://www.ethereal.com/appnotes/enpa-sa-00020.html">http://www.ethereal.com/appnotes/enpa-sa-00020.html</ref><ref patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200507-27.xml">GLSA-200507-27</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00003.html">FLSA-2006:152922</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-687.html">RHSA-2005:687</ref><ref source="BID" url="http://www.securityfocus.com/bid/14399">14399</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-853">DSA-853</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16225/">16225</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17102">17102</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_19_sr.html">SUSE-SR:2005:019</ref></refs><vuln_soft><prod name="Ethereal" vendor="Ethereal Group"><vers num="0.9.0"/><vers num="0.9.1"/><vers num="0.9.2"/><vers num="0.9.3"/><vers num="0.9.4"/><vers num="0.9.5"/><vers num="0.9.6"/><vers num="0.9.7"/><vers num="0.9.8"/><vers num="0.9.9"/><vers num="0.9.10"/><vers num="0.9.11"/><vers num="0.9.12"/><vers num="0.9.13"/><vers num="0.9.14"/><vers num="0.9.15"/><vers num="0.9.16"/><vers num="0.10.0"/><vers num="0.10.1"/><vers num="0.10.2"/><vers num="0.10.3"/><vers num="0.10.4"/><vers num="0.10.5"/><vers num="0.10.6"/><vers num="0.10.7"/><vers num="0.10.8"/><vers num="0.10.9"/><vers num="0.10.10"/><vers num="0.10.11"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2366" published="2005-08-10" seq="2005-2366" severity="Medium" type="CVE"><desc><descript source="cve">Unknown vulnerability in the BER dissector in Ethereal 0.10.11 allows remote attackers to cause a denial of service (abort or infinite loop) via unknown attack vectors.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref patch="1" source="" url="http://www.ethereal.com/appnotes/enpa-sa-00020.html">http://www.ethereal.com/appnotes/enpa-sa-00020.html</ref><ref patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200507-27.xml">GLSA-200507-27</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00003.html">FLSA-2006:152922</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-687.html">RHSA-2005:687</ref><ref source="BID" url="http://www.securityfocus.com/bid/14399">14399</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-853">DSA-853</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16225/">16225</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17102">17102</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_19_sr.html">SUSE-SR:2005:019</ref></refs><vuln_soft><prod name="Ethereal" vendor="Ethereal Group"><vers num="0.10.11"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2367" published="2005-08-10" seq="2005-2367" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in the proto_item_set_text function in Ethereal 0.9.4 through 0.10.11, as used in multiple dissectors, allows remote attackers to write to arbitrary memory locations and gain privileges via a crafted AFP packet.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><exception/><other/></vuln_types><range><network/></range><refs><ref adv="1" source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=289&amp;type=vulnerabilities">20050805 Multiple Vendor Ethereal AFP Protocol Dissector Format String Vulnerability</ref><ref patch="1" source="" url="http://www.ethereal.com/appnotes/enpa-sa-00020.html">http://www.ethereal.com/appnotes/enpa-sa-00020.html</ref><ref patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200507-27.xml">GLSA-200507-27</ref><ref adv="1" patch="1" source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:131">MDKSA-2005:131</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00003.html">FLSA-2006:152922</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-687.html">RHSA-2005:687</ref><ref source="BID" url="http://www.securityfocus.com/bid/14399">14399</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-853">DSA-853</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16225/">16225</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17102">17102</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_19_sr.html">SUSE-SR:2005:019</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_18_sr.html">SUSE-SR:2005:018</ref></refs><vuln_soft><prod name="Ethereal" vendor="Ethereal Group"><vers num="0.9.4"/><vers num="0.9.5"/><vers num="0.9.6"/><vers num="0.9.7"/><vers num="0.9.8"/><vers num="0.9.9"/><vers num="0.9.10"/><vers num="0.9.11"/><vers num="0.9.12"/><vers num="0.9.13"/><vers num="0.9.14"/><vers num="0.9.15"/><vers num="0.9.16"/><vers num="0.10.0"/><vers num="0.10.1"/><vers num="0.10.2"/><vers num="0.10.3"/><vers num="0.10.4"/><vers num="0.10.5"/><vers num="0.10.6"/><vers num="0.10.7"/><vers num="0.10.8"/><vers num="0.10.9"/><vers num="0.10.10"/><vers num="0.10.11"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-08-28" name="CVE-2005-2368" published="2005-07-26" seq="2005-2368" severity="High" type="CVE"><desc><descript source="cve">vim 6.3 before 6.3.082, with modelines enabled, allows external user-assisted attackers to execute arbitrary commands via shell metacharacters in the (1) glob or (2) expand commands of a foldexpr expression for calculating fold levels.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-July/035402.html">20050725 Help poor children in Uganda</ref><ref adv="1" patch="1" source="MISC" url="http://www.guninski.com/where_do_you_want_billg_to_go_today_5.html">http://www.guninski.com/where_do_you_want_billg_to_go_today_5.html</ref><ref source="BID" url="http://www.securityfocus.com/bid/14374">14374</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-745.html">RHSA-2005:745</ref></refs><vuln_soft><prod name="VIM" vendor="VIM Development Group"><vers num="6.3.081" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2369" published="2005-07-26" seq="2005-2369" severity="High" type="CVE"><desc><descript source="cve">Multiple integer signedness errors in libgadu, as used in ekg before 1.6rc2 and other packages, may allow remote attackers to cause a denial of service or execute arbitrary code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112198499417250&amp;w=2">20050721 Multiple vulnerabilities in libgadu and ekg package</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-813">DSA-813</ref><ref source="BID" url="http://www.securityfocus.com/bid/14415">14415</ref></refs><vuln_soft><prod name="ekg" vendor="ekg"><vers num="1.6 rc1"/><vers num="1.5"/><vers num="1.4"/><vers num="1.3"/><vers num="1.1"/><vers num="2005-06-05"/><vers num="2005-04-11"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-06-14" name="CVE-2005-2370" published="2005-07-26" seq="2005-2370" severity="Medium" type="CVE"><desc><descript source="cve">Multiple &quot;memory alignment errors&quot; in libgadu, as used in ekg before 1.6rc2, Gaim before 1.5.0, and other packages, allows remote attackers to cause a denial of service (bus error) on certain architectures such as SPARC via an incoming message.</descript></desc><loss_types><avail/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112198499417250&amp;w=2">20050721 Multiple vulnerabilities in libgadu and ekg package</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-813">DSA-813</ref><ref source="" url="http://gaim.sourceforge.net/security/index.php?id=20"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/16265">16265</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/426078/100/0/threaded">FLSA:158543</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-627.html">RHSA-2005:627</ref><ref source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1318">DSA-1318</ref><ref source="BID" url="http://www.securityfocus.com/bid/24600">24600</ref></refs><vuln_soft><prod name="Gaim" vendor="Rob Flynn"><vers num="1.4.0" prev="1"/></prod><prod name="ekg" vendor="ekg"><vers num="1.6 rc1"/><vers num="1.5"/><vers num="1.4"/><vers num="1.3"/><vers num="1.1"/><vers num="2005-06-05"/><vers num="2005-04-11"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2008-01-03" name="CVE-2005-2371" published="2005-07-26" seq="2005-2371" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in Oracle Reports 6.0, 6i, 9i, and 10g allows remote attackers to overwrite arbitrary files via (1) &quot;..&quot;, (2) Windows drive letter (C:), and (3) absolute path sequences in the desname parameter.  NOTE: this issue was probably fixed by REP06 in CPU Jan 2006, in which case it overlaps CVE-2006-0289.</descript></desc><loss_types><int/></loss_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112180096507467&amp;w=2">20050719 Oracle Security Advisory: Overwrite any file via desname in Oracle Reports</ref><ref adv="1" source="MISC" url="http://www.red-database-security.com/advisory/oracle_reports_overwrite_any_file.html">http://www.red-database-security.com/advisory/oracle_reports_overwrite_any_file.html</ref><ref source="BID" url="http://www.securityfocus.com/bid/14309">14309</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014524">1014524</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0323">ADV-2006-0323</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18493">18493</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18608">18608</ref><ref source="" url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24321">oracle-january2006-update(24321)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/422257/30/7430/threaded">20060117 Oracle Reports - Overwrite any application server file via desname (fixed after 889 days)</ref></refs><vuln_soft><prod name="Oracle Reports" vendor="Oracle"><vers num="6.0"/><vers num="6i"/><vers num="9i"/><vers num="10g"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2372" published="2005-07-26" seq="2005-2372" severity="High" type="CVE"><desc><descript source="cve">Oracle Forms 4.5 through 10g starts form executables from arbitrary directories and executes them as the Oracle or System user, which allows attackers to execute arbitrary code by uploading a malicious .fmx file and referencing it using an absolute pathname argument in the (1) form or (2) module parameters to f90servlet.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112180805413784&amp;w=2">20050719 Oracle Security Advisory: Run any OS Command via unauthorized Oracle Forms</ref><ref adv="1" source="MISC" url="http://www.red-database-security.com/advisory/oracle_forms_run_any_os_command.html">http://www.red-database-security.com/advisory/oracle_forms_run_any_os_command.html</ref></refs><vuln_soft><prod name="Oracle Forms" vendor="Oracle"><vers num="9i"/><vers num="6i"/><vers num="6.0"/><vers num="5.0"/><vers num="4.5"/><vers num="3.0"/><vers num="10g"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2373" published="2005-07-26" seq="2005-2373" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in SlimFTPd 3.15 and 3.16 allows remote authenticated users to execute arbitrary code via a long directory name to (1) LIST, (2) DELE or (3) RNFR commands.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112196537312610&amp;w=2">20050721 Arbitrary code execution in SlimFTPd v3.16</ref><ref source="" url="http://www.whitsoftdev.com/slimftpd/">http://www.whitsoftdev.com/slimftpd/</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16177">16177</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014542">1014542</ref></refs><vuln_soft><prod name="SlimFTPd" vendor="WhitSoft Development"><vers num="3.15"/><vers num="3.16"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2374" published="2005-07-26" seq="2005-2374" severity="High" type="CVE"><desc><descript source="cve">Belkin 54g wireless routers do not properly set an administrative password, which allows remote attackers to gain access via the (1) Telnet or (2) weba dministration interfaces.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112144089102115&amp;w=2">20050715 several vulnerabilities present in Belkin wireless routers</ref><ref source="SECTRACK" url="http://securitytracker.com/alerts/2005/Jul/1014493.html">1014493</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/21412">belkin-router-default-password(21412)</ref></refs><vuln_soft><prod name="Belkin 54g Wireless Router" vendor="Belkin"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2375" published="2005-07-26" seq="2005-2375" severity="Medium" type="CVE"><desc><descript source="cve">Format string vulnerability in Race Driver 1.20 and earlier allows remote attackers to cause a denial of service (application crash) via format string specifiers in a (1) nickname or (2) chat message.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Luigi Auriemma" url="http://aluigi.altervista.org/adv/rdrum-adv.txt"></ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112171364923678&amp;w=2">20050718 Broadcast format string and buffer-overflow in Race Driver 1.20</ref></refs><vuln_soft><prod name="ToCA Race Driver" vendor="Codemasters"><vers num="1.20" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2376" published="2005-07-26" seq="2005-2376" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in Race Driver 1.20 and earlier allows remote attackers to cause a denial of service (application crash) via a long (1) nickname or (2) chat message.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Luigi Auriemma" url="http://aluigi.altervista.org/adv/rdrum-adv.txt"></ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112171364923678&amp;w=2">20050718 Broadcast format string and buffer-overflow in Race Driver 1.20</ref></refs><vuln_soft><prod name="ToCA Race Driver" vendor="Codemasters"><vers num="1.20" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2377" published="2005-07-26" seq="2005-2377" severity="Medium" type="CVE"><desc><descript source="cve">nss_ldap 181 to versions before 213, as used in Mandrake Corporate Server and Mandrake 10.0, and other operating systems, does not properly handle a SIGPIPE signal when sending a search request to an LDAP directory server, which might allow remote attackers to cause a denial of service (crond and other application crash) if they can cause an LDAP server to become unavailable.  NOTE: it is not clear whether this attack scenario is sufficient to include this item in CVE.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref patch="1" source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:121">MDKSA-2005:121</ref><ref source="MISC" url="http://qa.mandriva.com/show_bug.cgi?id=13271">http://qa.mandriva.com/show_bug.cgi?id=13271</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/40501">nssldap-sigpipe-dos(40501)</ref></refs><vuln_soft><prod name="Mandrake Corporate Server" vendor="MandrakeSoft"><vers num=""/></prod><prod name="Mandrake Linux" vendor="MandrakeSoft"><vers num="10.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2008-01-03" name="CVE-2005-2378" published="2005-07-26" seq="2005-2378" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in Oracle Reports allows remote attackers to read arbitrary files via an absolute or relative path to the (1) CUSTOMIZE or (2) desformat parameters to rwservlet.  NOTE: vector 2 is probably the same as CVE-2006-0289, and fixed in Jan 2006 CPU.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112181242916757&amp;w=2">20050719 Oracle Security Advisory:  Read parts of any XML-file via customize parameter in Oracle Reports</ref><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112181054226520&amp;w=2">20050719 Oracle Security Advisory: Read parts of any file via desformat in Oracle Reports</ref><ref adv="1" source="MISC" url="http://www.red-database-security.com/advisory/oracle_reports_read_any_file.html">http://www.red-database-security.com/advisory/oracle_reports_read_any_file.html</ref><ref adv="1" source="MISC" url="http://www.red-database-security.com/advisory/oracle_reports_read_any_xml_file.html">http://www.red-database-security.com/advisory/oracle_reports_read_any_xml_file.html</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014525">1014525</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014527">1014527</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0323">ADV-2006-0323</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18493">18493</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18608">18608</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24321">oracle-january2006-update(24321)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/422256/30/7430/threaded">20060117 Oracle Reports - Read parts of files via desname (fixed after 874 days)</ref></refs><vuln_soft><prod name="Oracle Reports" vendor="Oracle"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2379" published="2005-07-26" seq="2005-2379" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Oracle Reports 9.0.2 allow remote attackers to inject arbitrary web script or HTML via the (1) debug parameter to showenv, (2) test parameter to parsequery, or (3) delimiter or (4) CELLWRAPPER parameter to rwservlet.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112181649831863&amp;w=2">20050719 Oracle Security Advisory: Various Cross-Site-Scripting Oracle Reports</ref><ref adv="1" source="MISC" url="http://www.red-database-security.com/advisory/oracle_reports_various_css.html">http://www.red-database-security.com/advisory/oracle_reports_various_css.html</ref></refs><vuln_soft><prod name="Oracle Reports" vendor="Oracle"><vers num="9.0.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2380" published="2005-07-26" seq="2005-2380" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting vulnerabilities in PHP Surveyor 0.98 allow remote attackers to inject arbitrary web script or HTML via the (1) sid, (2) start, and (3) id parameters to browse.php, or the sid parameter to (4) dataentry.php or (5) export.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112188282401681&amp;w=2">20050720 Multiple Vulnerabilities in PHP Surveyor</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16123">16123</ref></refs><vuln_soft><prod name="PHP Surveyor" vendor="PHP Surveyor"><vers num="0.98"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2381" published="2005-07-26" seq="2005-2381" severity="Medium" type="CVE"><desc><descript source="cve">PHP Surveyor 0.98 allows remote attackers to obtain sensitive information via a direct request to (1) question.php, (2) survey.php, or (3) group.php in the root directory, a direct request to (4) database.php, (5) sessioncontrol.php, (6) html.php, (7) sessioncontrol.php, an invalid (8) qid parameter to dumpquestion.php, or an invalid lid parameter to (9) labels.php or (10) dumplabel.php, which reveal the path in an error message.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112188282401681&amp;w=2">20050720 Multiple Vulnerabilities in PHP Surveyor</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16123">16123</ref></refs><vuln_soft><prod name="PHP Surveyor" vendor="PHP Surveyor"><vers num="0.98"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2382" published="2005-07-26" seq="2005-2382" severity="High" type="CVE"><desc><descript source="cve">Oray PeanutHull 3.0.1.0 and earlier does not properly drop SYSTEM privileges when launched from the system tray, which allows local users to gain privileges by accessing the Help functionality.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112190569628213&amp;w=2">20050720 PeanutHull Local Privilege Escalation Vulnerability</ref><ref adv="1" source="MISC" url="http://secway.org/advisory/AD20050720EN.txt">http://secway.org/advisory/AD20050720EN.txt</ref><ref source="BID" url="http://www.securityfocus.com/bid/14330">14330</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16124">16124</ref></refs><vuln_soft><prod name="PeanutHull" vendor="Oray"><vers num="3.0.1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2383" published="2005-07-26" seq="2005-2383" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in auth.php in PHPNews 1.2.5 allows remote attackers to execute arbitrary SQL commands via the user parameter in an HTTP POST request.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112189453304389&amp;w=2">20050720 PHPNews SQL injection vulnerability</ref><ref patch="1" source="" url="http://newsphp.sourceforge.net/changelog/changelog_1.30.txt">http://newsphp.sourceforge.net/changelog/changelog_1.30.txt</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16148">16148</ref><ref source="BID" url="http://www.securityfocus.com/bid/14333">14333</ref></refs><vuln_soft><prod name="PHPNews" vendor="PHPNews"><vers num="1.2.5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-04-21" name="CVE-2005-2384" published="2005-07-27" seq="2005-2384" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in a third-party compression library (UNACEV2.DLL), as used in avast! Antivirus Home/Professional Edition 4.6.665 and Server Edition 4.6.460, allows remote attackers to write arbitrary files via an ACE archive containing filenames with (1) .. or (2) absolute pathnames.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="MISC" url="http://secunia.com/secunia_research/2005-20/advisory/">http://secunia.com/secunia_research/2005-20/advisory/</ref><ref source="MISC" url="http://www.avast.com/eng/av4_revision_history.html">http://www.avast.com/eng/av4_revision_history.html</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/15776">15776</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014544">1014544</ref></refs><vuln_soft><prod name="Avast Antivirus" vendor="ALWIL"><vers edition="Home" num="4.6.665"/><vers edition="Pro" num="4.6.665"/><vers edition="Server" num="4.6.460"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-05-01" name="CVE-2005-2385" published="2005-07-27" seq="2005-2385" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in a third-party compression library (UNACEV2.DLL), as used in avast! Antivirus Home/Professional Edition 4.6.665 and Server Edition 4.6.460, allows remote attackers to execute arbitrary code via an ACE archive containing a long filename.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="MISC" url="http://secunia.com/secunia_research/2005-20/advisory/">http://secunia.com/secunia_research/2005-20/advisory/</ref><ref source="MISC" url="http://www.avast.com/eng/av4_revision_history.html">http://www.avast.com/eng/av4_revision_history.html</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/15776">15776</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014544">1014544</ref></refs><vuln_soft><prod name="Avast Antivirus" vendor="ALWIL"><vers edition="Home" num="4.6.665"/><vers edition="Pro" num="4.6.665"/><vers edition="Server" num="4.6.460"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2386" published="2005-07-27" seq="2005-2386" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in viewCart.asp in CartWIZ 1.20 allows remote attackers to inject arbitrary web script or HTML via the message parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://www.hackerscenter.com/archive/view.asp?id=4008">http://www.hackerscenter.com/archive/view.asp?id=4008</ref><ref source="BID" url="http://www.securityfocus.com/bid/14386">14386</ref></refs><vuln_soft><prod name="CartWIZ" vendor="Elemental Software"><vers num="1.20"/><vers num="1.10"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2387" published="2005-07-27" seq="2005-2387" severity="High" type="CVE"><desc><descript source="cve">Multiple stack-based buffer overflows in GoodTech SMTP server 5.16 allow remote attackers to execute arbitrary code via (1) a RCPT TO command with a long DNS name, or (2) a large number of RCPT TO commands with a long e-mail name arugment in the last command.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://seclists.org/lists/bugtraq/2005/Jul/0402.html">20050723 GoodTech SMTP server 5.16 RCPT TO command remote buffer overflow</ref><ref source="BID" url="http://www.securityfocus.com/bid/14357">14357</ref></refs><vuln_soft><prod name="GoodTech SMTP Server" vendor="GoodTech Systems"><vers num="5.16"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2388" published="2005-07-27" seq="2005-2388" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in a certain USB driver, as used on Microsoft Windows, allows attackers to execute arbitrary code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref source="MISC" url="http://www.eweek.com/article2/0,1759,1840131,00.asp">http://www.eweek.com/article2/0,1759,1840131,00.asp</ref><ref source="BID" url="http://www.securityfocus.com/bid/14376">14376</ref><ref source="OSVDB" url="http://www.osvdb.org/18493">18493</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16210">16210</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014566">1014566</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/21539">windows-usb-device-bo(21539)</ref></refs><vuln_soft><prod name="Windows 95" vendor="Microsoft"><vers num="SR2"/></prod><prod name="Windows 98" vendor="Microsoft"><vers num="SE"/><vers num="Gold"/></prod><prod name="Windows XP" vendor="Microsoft"><vers edition="64-bit" num="Professional"/><vers edition="Gold" num="Professional"/><vers edition="Gold" num="Professional"/><vers edition="Gold" num="Professional"/><vers edition="SP2" num="Home"/><vers edition="SP1" num="Home"/><vers num="Home"/><vers edition="SP1" num="Embedded"/><vers num="Embedded"/><vers edition="SP1" num="64-bit Version 2003"/><vers num="64-bit Version 2003"/><vers edition="SP1" num="64-bit"/><vers num="64-bit"/><vers edition="SP2" num="Tablet PC"/><vers edition="SP2" num="Tablet PC"/><vers edition="SP2" num="Tablet PC"/><vers edition="SP2" num="Media Center"/><vers edition="SP1" num="Media Center"/><vers num="Media Center"/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers num="Standard 64-bit"/><vers num="Enterprise 64-bit"/><vers edition="Datacenter 64-bit" num="R2"/><vers edition="SP1" num="Web"/><vers num="Web"/><vers edition="SP1" num="Standard"/><vers edition="64-bit" num="Standard"/><vers edition="SP1" num="Enterprise 64-bit"/><vers edition="SP1" num="Enterprise"/><vers edition="64-bit" num="Enterprise"/><vers edition="SP1" num="Datacenter 64-bit"/><vers edition="SP1" num="R2"/><vers edition="64-bit" num="R2"/></prod><prod name="Windows ME" vendor="Microsoft"><vers num=""/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num="Server SP4"/><vers num="Server SP3"/><vers num="Server SP2"/><vers num="Server SP1"/><vers num="Server"/><vers num="Professional SP4"/><vers num="Professional SP3"/><vers num="Professional SP2"/><vers num="Professional SP1"/><vers num="Professional"/><vers num="Datacenter Server SP4"/><vers num="Datacenter Server SP3"/><vers num="Datacenter Server SP2"/><vers num="Datacenter Server SP1"/><vers num="Datacenter Server"/><vers num="Advanced Server SP4"/><vers num="Advanced Server SP3"/><vers num="Advanced Server SP2"/><vers num="Advanced Server SP1"/><vers num="Advanced Server"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-03-27" name="CVE-2005-2389" published="2005-07-27" seq="2005-2389" severity="Medium" type="CVE"><desc><descript source="cve">NDMP server in Veritas NetBackup 5.1 allows attackers to cause a denial of service via a CONFIG message with an out-of-range timestamp, which triggers a null dereference.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://www.hat-squad.com/en/000170.html">http://www.hat-squad.com/en/000170.html</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/16187">16187</ref></refs><vuln_soft><prod name="NetBackup Server" vendor="Symantec Veritas"><vers num="5.1"/></prod><prod name="NetBackup Enterprise Server" vendor="Symantec Veritas"><vers num="5.1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2390" published="2005-07-27" seq="2005-2390" severity="Medium" type="CVE"><desc><descript source="cve">Multiple format string vulnerabilities in ProFTPD before 1.3.0rc2 allow attackers to cause a denial of service or obtain sensitive information via (1) certain inputs to the shutdown message from ftpshut, or (2) the SQLShowInfo mod_sql directive.</descript></desc><loss_types><avail/><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.proftpd.org/docs/RELEASE_NOTES-1.3.0rc2">http://www.proftpd.org/docs/RELEASE_NOTES-1.3.0rc2</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/16181">16181</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-795">DSA-795</ref><ref source="BID" url="http://www.securityfocus.com/bid/14380">14380</ref><ref source="BID" url="http://www.securityfocus.com/bid/14381">14381</ref><ref source="OPENPKG" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112604373503912&amp;w=2">OpenPKG-SA-2005.020</ref></refs><vuln_soft><prod name="ProFTPD" vendor="ProFTPD Project"><vers num="1.3.0 rc1"/><vers num="1.2.10"/><vers num="1.2.10 rc3"/><vers num="1.2.10 rc2"/><vers num="1.2.10 rc1"/><vers num="1.2.9"/><vers num="1.2.9 rc3"/><vers num="1.2.9 rc2"/><vers num="1.2.9 rc1"/><vers num="1.2.8"/><vers num="1.2.8 rc2"/><vers num="1.2.8 rc1"/><vers num="1.2.7"/><vers num="1.2.7 rc3"/><vers num="1.2.7 rc2"/><vers num="1.2.7 rc1"/><vers num="1.2.6"/><vers num="1.2.6 rc3"/><vers num="1.2.6 rc2"/><vers num="1.2.6 rc1"/><vers num="1.2.5"/><vers num="1.2.5 rc3"/><vers num="1.2.5 rc2"/><vers num="1.2.5 rc1"/><vers num="1.2.4"/><vers num="1.2.3"/><vers num="1.2.2"/><vers num="1.2.2 rc3"/><vers num="1.2.2 rc2"/><vers num="1.2.2 rc1"/><vers num="1.2.1"/><vers num="1.2.1 final"/><vers num="1.2.0 rc3"/><vers num="1.2.0 rc2"/><vers num="1.2.0 rc1"/><vers num="1.2.0 pre10"/><vers num="1.2.0 pre9"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2391" published="2005-07-27" seq="2005-2391" severity="Medium" type="CVE"><desc><descript source="cve">Unknown vulnerability in 3Com OfficeConnect Wireless 11g Access Point before 1.03.12 allows remote attackers to obtain sensitive information via the web interface.</descript></desc><loss_types><conf/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/16207">16207</ref></refs><vuln_soft><prod name="3Com OfficeConnect Wireless11g Access Point" vendor="3Com"><vers num="3CRWE454G72 1.03.07A"/><vers num="3CRWE454G72 1.03.07"/><vers num="3CRWE454G72 1.03.05"/><vers num="3CRWE454G72 1.02.11"/><vers num="3CRWE454G72 1.02.00"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-08-30" name="CVE-2005-2392" published="2005-07-27" seq="2005-2392" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in index.php for CMSimple 2.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the search parameter in the search function.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="MISC" url="http://lostmon.blogspot.com/2005/07/cmsimple-search-variable-xss.html">http://lostmon.blogspot.com/2005/07/cmsimple-search-variable-xss.html</ref><ref patch="1" source="" url="http://www.cmsimple.dk/forum/viewtopic.php?t=2470">http://www.cmsimple.dk/forum/viewtopic.php?t=2470</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/14346">14346</ref><ref source="OSVDB" url="http://www.osvdb.org/18128">18128</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1014556">1014556</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/16147">16147</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/442106/100/100/threaded">20060803 CMSimple Cross Site Scripting</ref><ref source="" url="http://www.aria-security.net/advisory/cmsimple.txt"></ref></refs><vuln_soft><prod name="CMSimple" vendor="CMSimple"><vers num="2.4 Beta 5"/><vers num="2.4 Beta 4"/><vers num="2.4 Beta 3"/><vers num="2.4 Beta 2"/><vers num="2.4 Beta 1"/><vers num="2.4 Beta"/><vers num="2.3 Beta 5"/><vers num="2.3 Beta 4"/><vers num="2.3 Beta 3"/><vers num="2.3 Beta 2"/><vers num="2.3 Beta 1"/><vers num="2.3"/><vers num="2.2 Beta 4"/><vers num="2.2 Beta 3"/><vers num="2.2 Beta 2"/><vers num="2.2 Beta 1"/><vers num="2.2"/><vers num="2.1"/><vers num="2.0 Beta 4"/><vers num="2.0 Beta 3"/><vers num="2.0 Beta 2"/><vers num="2.0 Beta 1"/><vers num="1.3 Beta 2"/><vers num="1.3 Beta 1"/><vers num="1.2"/><vers num="1.1"/><vers num="1.0"/><vers num="Beta 2"/><vers num="Beta 1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2393" published="2005-07-27" seq="2005-2393" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in CuteNews 1.3.6 allows remote attackers to inject arbitrary web script or HTML via (1) the lastusername parameter to index.php or (2) selected_search_arch parameter to search.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="SECTRACK" url="http://securitytracker.com/id?1014514">1014514</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16129">16129</ref></refs><vuln_soft><prod name="CuteNews" vendor="CutePHP"><vers num="1.3.6"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2394" published="2005-07-27" seq="2005-2394" severity="Medium" type="CVE"><desc><descript source="cve">show_news.php in CuteNews 1.3.6 allows remote attackers to obtain the full path of the server via an invalid archive parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="SECTRACK" url="http://securitytracker.com/id?1014514">1014514</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16129">16129</ref></refs><vuln_soft><prod name="CuteNews" vendor="CutePHP"><vers num="1.3.6"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2395" published="2005-07-27" seq="2005-2395" severity="Medium" type="CVE"><desc><descript source="cve">Mozilla Firefox 1.0.4 and 1.0.5 does not choose the challenge with the strongest authentication scheme available as required by RFC2617, which might cause credentials to be sent in plaintext even if an encrypted channel is available.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/405666">20050719 Mozilla cleartext credentials leak bug report to excuse myself (Re[2]: NTLM HTTP Authentication is insecure by design - a new writeup by Amit Klein)</ref><ref source="BID" url="http://www.securityfocus.com/bid/14325">14325</ref><ref source="" url="https://bugzilla.mozilla.org/show_bug.cgi?id=281851"></ref><ref source="" url="http://www.securiteam.com/securitynews/5PP0L00GUQ.html"></ref><ref source="OSVDB" url="http://www.osvdb.org/19002">19002</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/22272">mozilla-authentication-weakness(22272)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/8">8</ref></refs><vuln_soft><prod name="Firefox" vendor="Mozilla"><vers num="1.0.4"/><vers num="1.0.5"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2396" published="2005-07-27" seq="2005-2396" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in MediaWiki 1.4.6 and earlier allows remote attackers to inject arbitrary web script or HTML via a parameter to the page move template.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200507-18.xml">GLSA-200507-18</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/14327">14327</ref><ref source="OSVDB" url="http://www.osvdb.org/17763">17763</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15950">15950</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16130">16130</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/21491">mediawiki-page-move-xss(21491)</ref></refs><vuln_soft><prod name="MediaWiki" vendor="MediaWiki"><vers num="1.4.5"/><vers num="1.4.3"/><vers num="1.4.2"/><vers num="1.4.1"/><vers num="1.4 Beta6"/><vers num="1.4 Beta5"/><vers num="1.4 Beta4"/><vers num="1.4 Beta3"/><vers num="1.4 Beta2"/><vers num="1.4 Beta1"/><vers num="1.3.9"/><vers num="1.3.8"/><vers num="1.3.7"/><vers num="1.3.6"/><vers num="1.3.5"/><vers num="1.3.4"/><vers num="1.3.3"/><vers num="1.3.2"/><vers num="1.3.11"/><vers num="1.3.10"/><vers num="1.3.1"/><vers num="1.3.0"/><vers num="1.3"/><vers num="1.2.6"/><vers num="1.2.5"/><vers num="1.2.4"/><vers num="1.2.3"/><vers num="1.2.2"/><vers num="1.2.1"/><vers num="1.2.0"/><vers num="1.1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2397" published="2005-07-27" seq="2005-2397" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in guestbook.php in phpBook 1.46 allows remote attackers to inject arbitrary web script or HTML via the admin parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="SECTRACK" url="http://securitytracker.com/id?1014573">1014573</ref><ref source="BID" url="http://www.securityfocus.com/bid/14390">14390</ref><ref source="OSVDB" url="http://www.osvdb.org/18295">18295</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16192">16192</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/21538">phpbook-admin-xss(21538)</ref></refs><vuln_soft><prod name="phpBook" vendor="GNU"><vers num="1.46"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2398" published="2005-07-27" seq="2005-2398" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in PHP Surveyor 0.98 allows remote attackers to execute arbitrary SQL commands via (1) the sid, start, and id parameters to browse.php, the sid parameter to (2) dataentry.php, (3) export.php, (4) admin.php, (5) conditions.php, (6) spss.php, (7) deletesurvey.php, (8) dumpsurvey.php, or (9) statistics.php, or the lid parameter to (10) labels.php or (11) dumplabel.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112188282401681&amp;w=2">20050720 Multiple Vulnerabilities in PHP Surveyor</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/16123">16123</ref><ref source="BID" url="http://www.securityfocus.com/bid/14331">14331</ref><ref source="OSVDB" url="http://www.osvdb.org/18098">18098</ref><ref source="OSVDB" url="http://www.osvdb.org/18099">18099</ref><ref source="OSVDB" url="http://www.osvdb.org/18100">18100</ref><ref source="OSVDB" url="http://www.osvdb.org/18101">18101</ref><ref source="OSVDB" url="http://www.osvdb.org/18102">18102</ref><ref source="OSVDB" url="http://www.osvdb.org/18103">18103</ref><ref source="OSVDB" url="http://www.osvdb.org/18104">18104</ref><ref source="OSVDB" url="http://www.osvdb.org/18105">18105</ref><ref source="OSVDB" url="http://www.osvdb.org/18106">18106</ref><ref source="OSVDB" url="http://www.osvdb.org/18107">18107</ref><ref source="OSVDB" url="http://www.osvdb.org/18108">18108</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014538">1014538</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/21444">php-surveyor-sql-injection(21444)</ref></refs><vuln_soft><prod name="PHP Surveyor" vendor="PHP Surveyor"><vers num="0.98"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2399" published="2005-07-27" seq="2005-2399" severity="High" type="CVE"><desc><descript source="cve">PHP Surveyor 0.98 allows remote attackers to trigger SQL errors via missing parameters to (1) browse.php, (2) export.php, (3) conditions.php, or (4) spss.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112188282401681&amp;w=2">20050720 Multiple Vulnerabilities in PHP Surveyor</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/16123">16123</ref><ref source="BID" url="http://www.securityfocus.com/bid/14331">14331</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014538">1014538</ref></refs><vuln_soft><prod name="PHP Surveyor" vendor="PHP Surveyor"><vers num="0.98"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2400" published="2005-07-27" seq="2005-2400" severity="High" type="CVE"><desc><descript source="cve">The inc.login.php scripts in PHPFinance 0.3 allows remote attackers to bypass the login and gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://sourceforge.net/project/shownotes.php?release_id=343135">http://sourceforge.net/project/shownotes.php?release_id=343135</ref><ref source="" url="http://cvs.sourceforge.net/viewcvs.py/phpfinance/phpfinance/inc.login.php?rev=1.2&amp;view=log">http://cvs.sourceforge.net/viewcvs.py/phpfinance/phpfinance/inc.login.php?rev=1.2&amp;view=log</ref><ref source="" url="http://cvs.sourceforge.net/viewcvs.py/phpfinance/phpfinance/inc.conf.php?rev=1.2&amp;view=log">http://cvs.sourceforge.net/viewcvs.py/phpfinance/phpfinance/inc.conf.php?rev=1.2&amp;view=log</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/1133">ADV-2005-1133</ref><ref source="BID" url="http://www.securityfocus.com/bid/14322">14322</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13276">13276</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/21426">phpfinance-logon-bypass(21426)</ref></refs><vuln_soft><prod name="PHPFinance" vendor="PHPFinance"><vers num="0.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2401" published="2005-07-27" seq="2005-2401" severity="Medium" type="CVE"><desc><descript source="cve">PHP-Fusion allows remote attackers to inject arbitrary Cascading Style Sheets (CSS) via the BBCode color tag.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/14332">14332</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/16096">16096</ref><ref source="OSVDB" url="http://www.osvdb.org/18111">18111</ref></refs><vuln_soft><prod name="PHP_Fusion" vendor="PHP_Fusion"><vers num="6.0.105"/><vers num="6.0.106"/><vers num="5.01 Service Pack"/><vers num="5.0"/><vers num="4.01"/><vers num="4.00"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2402" published="2005-07-27" seq="2005-2402" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in search.php in PHPSiteSearch 1.7.7d allows remote attackers to inject arbitrary web script or HTML via the query parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MISC" url="http://www.rgod.altervista.org/PHPSiteSearch177dpoc.txt">http://www.rgod.altervista.org/PHPSiteSearch177dpoc.txt</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/16156">16156</ref><ref source="BID" url="http://www.securityfocus.com/bid/14344">14344</ref><ref source="OSVDB" url="http://www.osvdb.org/18142">18142</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/21463">phpsitesearch-query-xss(21463)</ref></refs><vuln_soft><prod name="PHPSiteSearch" vendor="PHPSiteSearch"><vers num="1.7.7d"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2403" published="2005-07-27" seq="2005-2403" severity="Medium" type="CVE"><desc><descript source="cve">The login protocol in RealChat 3.5.1b does not use authentication, which allows remote attackers to log on as other users by sniffing the beginning of a chat session and replaying it via a modified username.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://seclists.org/lists/bugtraq/2005/Jul/0403.html">20050723 Realchat user impersonation - BSA 200506110001</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014562">1014562</ref><ref source="BID" url="http://www.securityfocus.com/bid/14358">14358</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/21497">realchat-account-login(21497)</ref></refs><vuln_soft><prod name="RealChat" vendor="RealChat"><vers num="3.5.1b"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2404" published="2005-07-27" seq="2005-2404" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in sendcard.php in Sendcard 3.2.3 allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/1169">ADV-2005-1169</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/16165">16165</ref><ref source="BID" url="http://www.securityfocus.com/bid/14351">14351</ref><ref source="OSVDB" url="http://www.osvdb.org/18153">18153</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/21474">sendcard-id-sql-injection(21474)</ref></refs><vuln_soft><prod name="Sendcard" vendor="Sendcard"><vers num="3.2.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2405" published="2005-08-01" seq="2005-2405" severity="Medium" type="CVE"><desc><descript source="cve">Opera 8.01, when the &quot;Arial Unicode MS&quot; font (ARIALUNI.TTF) is installed, does not properly handle extended ASCII characters in the file download dialog box, which allows remote attackers to spoof file extensions and possibly trick users into executing arbitrary code.</descript></desc><loss_types><int/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://www.opera.com/linux/changelogs/802/">http://www.opera.com/linux/changelogs/802/</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/15870">15870</ref><ref source="BID" url="http://www.securityfocus.com/bid/14402">14402</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014592">1014592</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/21784">opera-content-disposition-extension-spoofing(21784)</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/1251">ADV-2005-1251</ref></refs><vuln_soft><prod name="Opera Web Browser" vendor="Opera Software"><vers num="8.01"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2406" published="2005-08-01" seq="2005-2406" severity="Medium" type="CVE"><desc><descript source="cve">Opera 8.01 allows remote attackers to conduct cross-site scripting (XSS) attacks or modify which files are uploaded by tricking a user into dragging an image that is a &quot;javascript:&quot; URI.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://www.opera.com/linux/changelogs/802/">http://www.opera.com/linux/changelogs/802/</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/15756">15756</ref><ref source="BID" url="http://www.securityfocus.com/bid/14410">14410</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014593">1014593</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/1251">ADV-2005-1251</ref></refs><vuln_soft><prod name="Opera Web Browser" vendor="Opera Software"><vers num="8.01"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-08-28" name="CVE-2005-2407" published="2005-08-01" seq="2005-2407" severity="Low" type="CVE"><desc><descript source="cve">A design error in Opera 8.01 and earlier allows user-assisted attackers to perform by overlaying a malicious new window above a file download dialog box, then tricking the user into double-clicking on the &quot;Run&quot; button, aka &quot;link hijacking&quot;.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/><user_init/></range><refs><ref patch="1" source="" url="http://www.opera.com/linux/changelogs/802/">http://www.opera.com/linux/changelogs/802/</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/15781">15781</ref><ref source="" url="http://secunia.com/secunia_research/2005-19/advisory/"></ref><ref source="BID" url="http://www.securityfocus.com/bid/15835">15835</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/1251">ADV-2005-1251</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015353">1015353</ref></refs><vuln_soft><prod name="Opera Web Browser" vendor="Opera Software"><vers num="8.01"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2409" published="2005-08-01" seq="2005-2409" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in util.c in nbsmtp 0.99 and earlier, while running in debug mode, allows remote attackers to execute arbitrary code via format string specifiers that are not properly handled in a syslog call.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="MISC" url="http://people.freebsd.org/~niels/issues/nbsmtp-20050726.txt">http://people.freebsd.org/~niels/issues/nbsmtp-20050726.txt</ref><ref source="" url="http://www.vuxml.org/freebsd/debbb39c-fdb3-11d9-a30d-00b0d09acbfc.html">http://www.vuxml.org/freebsd/debbb39c-fdb3-11d9-a30d-00b0d09acbfc.html</ref><ref source="BID" url="http://www.securityfocus.com/bid/14441">14441</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16279">16279</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16324">16324</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/21674">nbsmtp-format-string(21674)</ref></refs><vuln_soft><prod name="nbsmtp" vendor="nbsmtp"><vers num="0.99" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2410" published="2005-08-01" seq="2005-2410" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in the nm_info_handler function in Network Manager may allow remote attackers to execute arbitrary code via format string specifiers in a Wireless Access Point identifier, which is not properly handled in a syslog call.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MLIST" url="http://mail.gnome.org/archives/networkmanager-list/2005-July/msg00196.html">20050728 format string bug in nm_info_handler</ref><ref source="MLIST" url="http://mail.gnome.org/archives/networkmanager-list/2005-July/msg00197.html">20050729 Re: format string bug in nm_info_handler</ref><ref source="FEDORA" url="http://lwn.net/Alerts/145678/">
FEDORA-2005-680</ref></refs><vuln_soft><prod name="NetworkManager" vendor="GNOME"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-10-31" name="CVE-2005-2411" published="2005-08-01" seq="2005-2411" severity="Medium" type="CVE"><desc><descript source="cve">Cross-Site Request Forgery (CSRF) vulnerability in tDiary 2.1.1, and tDiary 2.0.1 and earlier, allows remote attackers to conduct actions as another user, and execute commands on the server, via a URL that is activated by the user.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="" url="http://sourceforge.net/forum/forum.php?forum_id=482743">http://sourceforge.net/forum/forum.php?forum_id=482743</ref><ref source="OSVDB" url="http://www.osvdb.org/18604">18604</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16329">16329</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/21735">tdiary-xs-request-forgery(21735)</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-808">DSA-808</ref><ref source="BID" url="http://www.securityfocus.com/bid/14500">14500</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16787">16787</ref></refs><vuln_soft><prod name="tDiary" vendor="tDiary"><vers num="2.1.1"/><vers num="2.0.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2412" published="2005-08-03" seq="2005-2412" severity="Medium" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in block.php in PHP FirstPost allows remote attackers to execute arbitrary PHP code via the Include parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="OSVDB" url="http://www.osvdb.org/18394">18394</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014563">1014563</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/21513">php-firstpost-block-file-include(21513)</ref><ref source="BID" url="http://www.securityfocus.com/bid/14371">14371</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112230599222543&amp;w=2">20050724 PHP FirstPost remote file include vulnerability</ref></refs><vuln_soft><prod name="PHP FirstPost" vendor="PHP FirstPost"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2413" published="2005-08-03" seq="2005-2413" severity="Medium" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in apa_phpinclude.inc.php in Atomic Photo Album (APA) allows remote attackers to execute arbitrary PHP code via the apa_module_basedir parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/14368">14368</ref><ref source="OSVDB" url="http://www.osvdb.org/18265">18265</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014569">1014569</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16201">16201</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/21562">apa-apaphpinclude-file-include(21562)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112230428725189&amp;w=2">20050723 Atomic Photo Album (APA) apa_phpinclude.inc.php remote file include</ref></refs><vuln_soft><prod name="Atomic Photo Album" vendor="Atomic Photo Album"><vers num="1.0.1"/><vers num="1.0.2"/><vers num="1.0.3"/><vers num="1.0.4"/><vers num="1.0.5"/><vers num="1.0"/><vers num="1.1.0 pre1"/><vers num="1.1.0 pre2"/><vers num="1.1.0 pre3"/><vers num="1.1.0 pre4"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2414" published="2005-08-03" seq="2005-2414" severity="Low" type="CVE"><desc><descript source="cve">Race condition in the xpcom library, as used by web browsers such as Firefox, Mozilla, Netscape, and Galeon, allows remote attackers to cause a denial of service (application crash) via a large HTML file that loads a DOM call from within nested DIV tags, which causes part of the currently rendering page and referenced objects to be deleted.</descript></desc><loss_types><avail/></loss_types><vuln_types><race/></vuln_types><range><network/></range><refs><ref source="SECTRACK" url="http://securitytracker.com/id?1014550">1014550</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014548">1014548</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/21472">mozilla-xpcom-race-condition(21472)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112199282029269&amp;w=2">20050721 Mozilla XPCOM Library Race Condition</ref><ref source="" url="http://www.gulftech.org/?node=research&amp;article_id=00091-07212005"></ref></refs><vuln_soft><prod name="xpcom" vendor="xpcom"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-08-30" name="CVE-2005-2415" published="2005-08-03" seq="2005-2415" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in Contrexx before 1.0.5 allow remote attackers to execute arbitrary SQL commands via the (1) value parameter to the poll module or (2) pId parameter to the gallery module.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="MISC" url="http://www.hardened-php.net/advisory_112005.59.html">http://www.hardened-php.net/advisory_112005.59.html</ref><ref source="BID" url="http://www.securityfocus.com/bid/14352">14352</ref><ref source="OSVDB" url="http://www.osvdb.org/18166">18166</ref><ref source="OSVDB" url="http://www.osvdb.org/18167">18167</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014554">1014554</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16169">16169</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/21482">contrexx-votingoption-pld-sql-injection(21482)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112206702015439&amp;w=2">20050722 Advisory 11/2005: Multiple vulnerabilities in Contrexx</ref></refs><vuln_soft><prod name="Contrexx" vendor="Astalavista IT Engineering"><vers num="1.0.4" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-08-30" name="CVE-2005-2416" published="2005-08-03" seq="2005-2416" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Contrexx before 1.0.5 allow remote attackers to inject arbitrary web script or HTML via the (1) term parameter to the search module or (2) title in the blog aggregation module.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="MISC" url="http://www.hardened-php.net/advisory_112005.59.html">http://www.hardened-php.net/advisory_112005.59.html</ref><ref source="BID" url="http://www.securityfocus.com/bid/14352">14352</ref><ref source="OSVDB" url="http://www.osvdb.org/18168">18168</ref><ref source="OSVDB" url="http://www.osvdb.org/18169">18169</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014554">1014554</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16169">16169</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/21487">contrexx-blog-xss(21487)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/21484">contrexx-search-xss(21484)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112206702015439&amp;w=2">20050722 Advisory 11/2005: Multiple vulnerabilities in Contrexx</ref></refs><vuln_soft><prod name="Contrexx" vendor="Astalavista IT Engineering"><vers num="1.0.4" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-08-30" name="CVE-2005-2417" published="2005-08-03" seq="2005-2417" severity="Medium" type="CVE"><desc><descript source="cve">Contrexx before 1.0.5 allows remote attackers to obtain sensitive information via a direct request to /config/version.xml.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="MISC" url="http://www.hardened-php.net/advisory_112005.59.html">http://www.hardened-php.net/advisory_112005.59.html</ref><ref source="BID" url="http://www.securityfocus.com/bid/14352">14352</ref><ref source="OSVDB" url="http://www.osvdb.org/18170">18170</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014554">1014554</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16169">16169</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/21488">contrexx-version-disclosure(21488)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112206702015439&amp;w=2">20050722 Advisory 11/2005: Multiple vulnerabilities in Contrexx</ref></refs><vuln_soft><prod name="Contrexx" vendor="Astalavista IT Engineering"><vers num="1.0.4" prev="1"/></prod></vuln_soft></entry><entry modified="2005-10-25" name="CVE-2005-2418" published="2005-08-03" reject="1" seq="2005-2418" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2005-2403.  Reason: This candidate is a duplicate of CVE-2005-2403.  Notes: All CVE users should reference CVE-2005-2403 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><refs><ref source="BID" url="http://www.securityfocus.com/bid/14358">14358</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014562">1014562</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/21497">realchat-account-login(21497)</ref></refs></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2419" published="2005-08-03" seq="2005-2419" severity="High" type="CVE"><desc><descript source="cve">B-FOCuS Router 312+ allows remote attackers to bypass authentication and gain unauthorized access via a direct request to firmwarecfg.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/14364">14364</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16205">16205</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/21521">eci-router-login-security-bypass(21521)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112230649106740&amp;w=2">20050724 ECI router login bypass</ref></refs><vuln_soft><prod name="B-FOCuS Router" vendor="ECI Telecom"><vers num="312"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2420" published="2005-08-03" seq="2005-2420" severity="High" type="CVE"><desc><descript source="cve">flsearch.pl in FtpLocate 2.02 allows remote attackers to execute arbitrary commands via shell metacharacters in an HTTP GET request.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/14367">14367</ref><ref source="OSVDB" url="http://www.osvdb.org/18305">18305</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014570">1014570</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16218">16218</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/21540">ftplocate-fsite-command-execution(21540)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112230697123357&amp;w=2">20050725 Chroot Security Group Advisory  2005-07-25  -- ftplocate</ref></refs><vuln_soft><prod name="FtpLocate" vendor="FtpLocate"><vers num="2.02"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2421" published="2005-08-03" seq="2005-2421" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in index.php and other pages in Beehive Forum allow remote attackers to execute arbitrary SQL commands via the webtag parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/14361">14361</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16217">16217</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/21535">beehiveforum-webtag-sql-injection(21535)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112230744103930&amp;w=2">20050725 Beehive Forum Multiple Vulnerabilities</ref></refs><vuln_soft><prod name="Beehive Forum" vendor="Beehive Forum"><vers num="0.6RC2"/><vers num="0.6RC1"/><vers num="0.5"/><vers num="0.4"/><vers num="0.3.1"/><vers num="0.3"/><vers num="0.2"/><vers num="0.1.1"/><vers num="0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2422" published="2005-08-03" seq="2005-2422" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in Beehive Forum allows remote attackers to inject arbitrary web script or HTML via the webtag parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/14363">14363</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16217">16217</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112230744103930&amp;w=2">20050725 Beehive Forum Multiple Vulnerabilities</ref></refs><vuln_soft><prod name="Beehive Forum" vendor="Beehive Forum"><vers num="0.6RC2"/><vers num="0.6RC1"/><vers num="0.5"/><vers num="0.4"/><vers num="0.3.1"/><vers num="0.3"/><vers num="0.2"/><vers num="0.1.1"/><vers num="0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2423" published="2005-08-03" seq="2005-2423" severity="Medium" type="CVE"><desc><descript source="cve">Beehive Forum allows remote attackers to obtain sensitive information via (1) an invalid final_uri or sort_by parameter to index.php or a direct request to (2) admin.php, (3) attachments.inc.php, (4) banned.inc.php, (5) beehive.inc.php, (6) constants.inc.php, (7) db.inc.php, (8) dictionary.inc.php or (9) search_index.php, which reveal the path in an error message.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="SECUNIA" url="http://secunia.com/advisories/16217">16217</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/21536">beehive-path-disclosure(21536)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112230744103930&amp;w=2">20050725 Beehive Forum Multiple Vulnerabilities</ref></refs><vuln_soft><prod name="Beehive Forum" vendor="Beehive Forum"><vers num="0.6RC2"/><vers num="0.6RC1"/><vers num="0.5"/><vers num="0.4"/><vers num="0.3.1"/><vers num="0.3"/><vers num="0.2"/><vers num="0.1.1"/><vers num="0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2424" published="2005-08-03" seq="2005-2424" severity="High" type="CVE"><desc><descript source="cve">The management interface for Siemens SANTIS 50 running firmware 4.2.8.0, and possibly other products including Ericsson HN294dp and Dynalink RTA300W, allows remote attackers to access the Telnet port without authentication via certain packets to the web interface that cause the interface to freeze.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://www.securenetwork.it/advisories/">http://www.securenetwork.it/advisories/</ref><ref source="BID" url="http://www.securityfocus.com/bid/14372">14372</ref><ref source="OSVDB" url="http://www.osvdb.org/18294">18294</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16215">16215</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/21552">santis50-packet-gain-access(21552)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112230914431638&amp;w=2">20050725 Siemens SANTIS 50 Authentication Vulnerability</ref></refs><vuln_soft><prod name="Santis 50" vendor="Siemens"><vers num="4.2.8.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2425" published="2005-08-03" seq="2005-2425" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in Ares FileShare 1.1 allows remote attackers or local users to execute arbitrary code via a (1) long history parameter in the configuration file (ares.conf) or (2) long search string.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/14377">14377</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014576">1014576</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/21557">ares-longconfstring-bo(21557)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/21818">aresfileshare-long-string-bo(21818)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112239196706345&amp;w=2">20050725 Ares FileShare 1.1 &apos;Long Searched String&apos; Buffer Overflow</ref></refs><vuln_soft><prod name="FileShare" vendor="Ares"><vers num="1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2426" published="2005-08-03" seq="2005-2426" severity="Low" type="CVE"><desc><descript source="cve">FTPshell Server 3.38 allows remote authenticated users to cause a denial of service (application crash) by multiple connections and disconnections without using the QUIT command.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><local/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/14382">14382</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014580">1014580</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16189">16189</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/21531">ftpshell-port-dos(21531)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112239297430460&amp;w=2">20050726 Denial of service vulnerability in FTPshell Server Version 3.38</ref></refs><vuln_soft><prod name="FTPshell Server" vendor="FTPshell"><vers num="3.38"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-08-28" name="CVE-2005-2427" published="2005-08-03" seq="2005-2427" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in viewCart.asp in CartWIZ allows remote attackers to inject arbitrary web script or HTML via the message parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/14386">14386</ref><ref source="OSVDB" url="http://www.osvdb.org/18463">18463</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014581">1014581</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/21554">cartwiz-viewcart-xss(21554)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112240525414263&amp;w=2">20050726 [HSC Security Group] XSS in CartWiz</ref></refs><vuln_soft><prod name="CartWIZ" vendor="Elemental Software"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-25" name="CVE-2005-2428" published="2005-08-03" seq="2005-2428" severity="Medium" type="CVE"><desc><descript source="cve">Lotus Domino R5 and R6 WebMail, with &quot;Generate HTML for all fields&quot; enabled, stores sensitive data from names.nsf in hidden form fields, which allows remote attackers to read the HTML source to obtain sensitive information such as (1) the password hash in the HTTPPassword field, (2) the password change date in the HTTPPasswordChangeDate field, (3) the client platform in the ClntPltfrm field, (4) the client machine name in the ClntMachine field, and (5) the client Lotus Domino release in the ClntBld field, a different vulnerability than CVE-2005-2696.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://www.cybsec.com/vuln/default_configuration_information_disclosure_lotus_domino.pdf">http://www.cybsec.com/vuln/default_configuration_information_disclosure_lotus_domino.pdf</ref><ref adv="1" source="" url="http://www-1.ibm.com/support/docview.wss?uid=swg21212934">http://www-1.ibm.com/support/docview.wss?uid=swg21212934</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/16231/">16231</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/21556">lotus-domino-names-obtain-information(21556)</ref><ref source="MISC" url="http://www.securiteam.com/securitynews/5FP0E15GLQ.html">http://www.securiteam.com/securitynews/5FP0E15GLQ.html</ref><ref source="BID" url="http://www.securityfocus.com/bid/14389">14389</ref><ref source="OSVDB" url="http://www.osvdb.org/18462">18462</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014584">1014584</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112240869130356&amp;w=2">20050726 CYBSEC - Security Advisory: Default Configuration Information</ref></refs><vuln_soft><prod name="Lotus Domino" vendor="IBM"><vers num="5.0"/><vers num="6.0"/><vers num="6.5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2429" published="2005-08-03" seq="2005-2429" severity="Medium" type="CVE"><desc><descript source="cve">Firefox, when opening Microsoft Word documents, does not properly set the permissions on shared sections, which allows remote attackers to write arbitrary data to open applications in Microsoft Office.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="SECUNIA" url="http://secunia.com/advisories/16256">16256</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112248181422193&amp;w=2">20050727 Shared section vulnerability when opening microsoft office</ref><ref source="OSVDB" url="http://www.osvdb.org/18484">18484</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24346">office-mso97shareddg-dos(24346)</ref></refs><vuln_soft><prod name="Firefox" vendor="Mozilla"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2430" published="2005-08-03" seq="2005-2430" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in GForge 4.5 allow remote attackers to inject arbitrary web script or HTML via the (1) forum_id or (2) group_id parameter to forum.php, (3) project_task_id parameter to task.php, (4) id parameter to detail.php, (5) the text field on the search page, (6) group_id parameter to qrs.php, (7) form, (8) rows, (9) cols or (10) wrap parameter to notepad.php, or the login field on the login form.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/16253/">16253</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/21558">gforge-multiple-xss(21558)</ref><ref source="BID" url="http://www.securityfocus.com/bid/14405">14405</ref><ref source="OSVDB" url="http://www.osvdb.org/18299">18299</ref><ref source="OSVDB" url="http://www.osvdb.org/18300">18300</ref><ref source="OSVDB" url="http://www.osvdb.org/18301">18301</ref><ref source="OSVDB" url="http://www.osvdb.org/18302">18302</ref><ref source="OSVDB" url="http://www.osvdb.org/18303">18303</ref><ref source="OSVDB" url="http://www.osvdb.org/18304">18304</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112259845904350&amp;w=2">20050727 Cross Site Scripting vulnerabilities in GForge</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1094">DSA-1094</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20622">20622</ref></refs><vuln_soft><prod name="GForge" vendor="GForge"><vers num="4.5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2431" published="2005-08-03" seq="2005-2431" severity="Medium" type="CVE"><desc><descript source="cve">The (1) lost password and (2) account pending features in GForge 4.5 do not properly set a limit on the number of e-mails sent to an e-mail address, which allows remote attackers to send a large number of messages to arbitrary e-mail addresses (aka mail bomb).</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112259845904350&amp;w=2">20050727 Cross Site Scripting vulnerabilities in GForge</ref></refs><vuln_soft><prod name="GForge" vendor="GForge"><vers num="4.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-10-19" name="CVE-2005-2432" published="2005-08-03" seq="2005-2432" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in PhpList allows remote attackers to modify SQL statements via the id argument to admin pages such as (1) members or (2) admin.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112291396731712&amp;w=2">20050731 PHPList Vunerability</ref><ref source="OSVDB" url="http://www.osvdb.org/18316">18316</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/16274">16274</ref><ref source="BID" url="http://www.securityfocus.com/bid/14403">14403</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014607">1014607</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/21576">phplist-id-sql-injection(21576)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112258115325054&amp;w=2">20050728 PhpList Sql Injection and Path Disclosure</ref></refs><vuln_soft><prod name="PHPList" vendor="tincan"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-10-19" name="CVE-2005-2433" published="2005-08-03" seq="2005-2433" severity="Medium" type="CVE"><desc><descript source="cve">PhpList allows remote attackers to obtain sensitive information via a direct request to (1) about.php, (2) connect.php, (3) domainstats.php or (4) usercheck.php in public_html/lists/admin directory, (5) attributes.php, (6) dbcheck.php, (7) importcsv.php, (8) user.php, (9) usermgt.php, or (10) users.php in admin/commonlib/pages directory, (11) helloworld.php, or (12) sidebar.php in public_html/lists/admin/plugins directory, or (13) main.php in public_html/lists/admin/plugsins/defaultplugin directory, which reveal the path in an error message.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="OSVDB" url="http://www.osvdb.org/18317">18317</ref><ref source="OSVDB" url="http://www.osvdb.org/18318">18318</ref><ref source="OSVDB" url="http://www.osvdb.org/18319">18319</ref><ref source="OSVDB" url="http://www.osvdb.org/18320">18320</ref><ref source="OSVDB" url="http://www.osvdb.org/18321">18321</ref><ref source="OSVDB" url="http://www.osvdb.org/18322">18322</ref><ref source="OSVDB" url="http://www.osvdb.org/18323">18323</ref><ref source="OSVDB" url="http://www.osvdb.org/18324">18324</ref><ref source="OSVDB" url="http://www.osvdb.org/18325">18325</ref><ref source="OSVDB" url="http://www.osvdb.org/18326">18326</ref><ref source="OSVDB" url="http://www.osvdb.org/18327">18327</ref><ref source="OSVDB" url="http://www.osvdb.org/18328">18328</ref><ref source="OSVDB" url="http://www.osvdb.org/18329">18329</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/21579">phplist-multiple-scripts-path-disclosure(21579)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112258115325054&amp;w=2">20050728 PhpList Sql Injection and Path Disclosure</ref></refs><vuln_soft><prod name="PHPList" vendor="tincan"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2434" published="2005-08-03" seq="2005-2434" severity="Medium" type="CVE"><desc><descript source="cve">Linksys WRT54G router uses the same private key and certificate for every router, which allows remote attackers to sniff the SSL connection and obtain sensitive information.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/14407">14407</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014596">1014596</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16271">16271</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/21635">linksys-wrt54g-session-decrypt(21635)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112258422806340&amp;w=2">20050728 Vulnerability in Linksys Router access</ref></refs><vuln_soft><prod name="WRT54G" vendor="Linksys"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2435" published="2005-08-03" seq="2005-2435" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in browse.php in Website Baker Project allows remote attackers to inject arbitrary web script or HTML via the dir parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/14404">14404</ref><ref source="OSVDB" url="http://www.osvdb.org/18342">18342</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16263">16263</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/21631">website-baker-browse-xss(21631)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112260471228762&amp;w=2">20050728 Website Baker Project Multiple Vulnerabilities</ref></refs><vuln_soft><prod name="Website Baker" vendor="Website Baker"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2436" published="2005-08-03" seq="2005-2436" severity="Medium" type="CVE"><desc><descript source="cve">browse.php in Website Baker Project allows remote attackers to obtain sensitive data via (1) a directory that does not exist in the dir parameter or (2) a direct request to certain php files, which reveal the path in an error message.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="OSVDB" url="http://www.osvdb.org/18343">18343</ref><ref source="OSVDB" url="http://www.osvdb.org/18344">18344</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16263">16263</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/21633">website-baker-url-path-disclosure(21633)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112260471228762&amp;w=2">20050728 Website Baker Project Multiple Vulnerabilities</ref></refs><vuln_soft><prod name="Website Baker" vendor="Website Baker"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2437" published="2005-08-03" seq="2005-2437" severity="Medium" type="CVE"><desc><descript source="cve">Website Baker Project does not properly verify the file extensions of uploaded files, which allows remote attackers to upload and execute arbitrary PHP code.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/14406">14406</ref><ref source="OSVDB" url="http://www.osvdb.org/18345">18345</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16263">16263</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/21634">website-baker-adminmedia-file-upload(21634)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112260471228762&amp;w=2">20050728 Website Baker Project Multiple Vulnerabilities</ref></refs><vuln_soft><prod name="Website Baker" vendor="Website Baker"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2438" published="2005-08-03" seq="2005-2438" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in UseBB 0.5.1 and earlier allows remote attackers to inject arbritrary Javascript via the BBCode color value.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="MISC" url="http://www.hardened-php.net/advisory_122005.60.html">http://www.hardened-php.net/advisory_122005.60.html</ref><ref source="" url="http://www.usebb.net/community/topic.php?id=605">http://www.usebb.net/community/topic.php?id=605</ref><ref source="BID" url="http://www.securityfocus.com/bid/14412">14412</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/21651">usebb-colorbbcode-xss(21651)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112264706213040&amp;w=2">20050728 Advisory 12/2005: UseBB Multiple Vulnerabilities</ref></refs><vuln_soft><prod name="UseBB" vendor="UseBB"><vers num="0.5.1"/><vers num="0.5"/><vers num="0.4.1"/><vers num="0.4"/><vers num="0.3.2"/><vers num="0.3.1"/><vers num="0.3"/><vers num="0.2.3a"/><vers num="0.2.3"/><vers num="0.2.2"/><vers num="0.2.1"/><vers num="0.2"/><vers num="0.1.1"/><vers num="0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2439" published="2005-08-03" seq="2005-2439" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in UseBB 0.5.1 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the search function.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="MISC" url="http://www.hardened-php.net/advisory_122005.60.html">http://www.hardened-php.net/advisory_122005.60.html</ref><ref patch="1" source="" url="http://www.usebb.net/community/topic.php?id=605">http://www.usebb.net/community/topic.php?id=605</ref><ref source="BID" url="http://www.securityfocus.com/bid/14413">14413</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/21652">usebb-search-sql-injection(21652)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112264706213040&amp;w=2">20050728 Advisory 12/2005: UseBB Multiple Vulnerabilities</ref></refs><vuln_soft><prod name="UseBB" vendor="UseBB"><vers num="0.5.1"/><vers num="0.5"/><vers num="0.4.1"/><vers num="0.4"/><vers num="0.3.2"/><vers num="0.3.1"/><vers num="0.3"/><vers num="0.2.3a"/><vers num="0.2.3"/><vers num="0.2.2"/><vers num="0.2.1"/><vers num="0.2"/><vers num="0.1.1"/><vers num="0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2440" published="2005-08-03" seq="2005-2440" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in login.asp in Thomson Web Skill Vantage Manager allows remote attackers to execute arbitrary SQL commands via the svmPassword parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/14409">14409</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/16268/">16268</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/21637">webskill-login-sql-injection(21637)</ref><ref source="OSVDB" url="http://www.osvdb.org/18330">18330</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112258777107822&amp;w=2">20050728 Thomson Web Skill Vantage Manager</ref></refs><vuln_soft><prod name="Web Skill Vantage Manager" vendor="Thomson NETg"><vers num="2.5"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2441" published="2005-08-03" seq="2005-2441" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in VBzoom allow remote attackers to inject arbitrary web script and HTML via the (1) UserName parameter to profile.php or (2) UserID parameter to login.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/14423">14423</ref><ref source="OSVDB" url="http://www.osvdb.org/18662">18662</ref><ref source="OSVDB" url="http://www.osvdb.org/18663">18663</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014614">1014614</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/21680">vbzoom-profile-login-xss(21680)</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16220">16220</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112300586019568&amp;w=2">20050729 VBZoom Cross Site Scripting Vulnerabilities</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426874/100/0/threaded">20060306 SQL injection &amp; XSS IN vbzoom v1.11</ref></refs><vuln_soft><prod name="VBzoom" vendor="VBzoom"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2442" published="2005-08-03" seq="2005-2442" severity="Medium" type="CVE"><desc><descript source="cve">Cross-Application Scripting (XAS) vulnerability in SPI Dynamics WebInspect 5.0.196 allows remote attackers to inject Javascript from one application into another.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-July/035414.html">20050726 SPIDynamics WebInspect Cross-Application Scripting (XAS)</ref><ref source="BID" url="http://www.securityfocus.com/bid/14385">14385</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/21541">spidynamics-webinspect-xas(21541)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014582">1014582</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16191">16191</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112239353829324&amp;w=2">20050726 SPIDynamics WebInspect Cross-Application Scripting (XAS)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112264765216499&amp;w=2">20050728 SPIDynamics WebInspect Cross-ApplicationScripting (XAS)</ref></refs><vuln_soft><prod name="WebInspect" vendor="SPI Dynamics"><vers num="5.0.196"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2443" published="2005-08-03" seq="2005-2443" severity="Medium" type="CVE"><desc><descript source="cve">Kshout 2.x and 3.x stores settings.dat under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information such as usernames and passwords.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="MISC" url="http://www.soulblack.com.ar/repo/papers/advisory/kshout_advisory.txt">http://www.soulblack.com.ar/repo/papers/advisory/kshout_advisory.txt</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112274114623893&amp;w=2">20050729 Kshout Data Disclosure</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24352">
kshout-settings-information-disclosure(24352)</ref></refs><vuln_soft><prod name="Kshout" vendor="Kshout"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2444" published="2005-08-03" seq="2005-2444" severity="Low" type="CVE"><desc><descript source="cve">Trillian Pro 3.1 build 121, when checking Yahoo e-mail, stores the password in plaintext in a world readable file and does not delete the file after login, which allows local users to obtain sensitive information.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="SECUNIA" url="http://secunia.com/advisories/16289">16289</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/21667">trillian-mail-plaintext-password(21667)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112274667603628&amp;w=2">20050730 Trillian Ver 3.1 saves password&apos;s in plain Text</ref></refs><vuln_soft><prod name="Trillian Pro" vendor="Cerulean Studios"><vers num="3.1 build 121"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2445" published="2005-08-03" seq="2005-2445" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in viewPrd.asp in Product Cart 2.6 allows remote attackers to execute arbitrary SQL commands via the idcategory parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/13881">13881</ref><ref source="OSVDB" url="http://www.osvdb.org/17329">17329</ref><ref source="OSVDB" url="http://www.osvdb.org/18508">18508</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014129">1014129</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14833">14833</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20956">productcart-multiple-script-sql-injection(20956)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/21672">productcart-viewprd-sql-injection(21672)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112274710020521&amp;w=2">20050730 [HSC Security Group] SQL Injection in Product Cart 2.6</ref></refs><vuln_soft><prod name="Product Cart" vendor="Early Impact"><vers num="2.6"/></prod></vuln_soft></entry><entry modified="2005-10-25" name="CVE-2005-2446" published="2005-08-03" reject="1" seq="2005-2446" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2005-2369.  Reason: This candidate is a duplicate of CVE-2005-2369.  Notes: All CVE users should reference CVE-2005-2369 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript></desc><vuln_types><input bound="1"/></vuln_types><refs/></entry><entry modified="2005-10-25" name="CVE-2005-2447" published="2005-08-03" reject="1" seq="2005-2447" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2005-2370.  Reason: This candidate is a duplicate of CVE-2005-2370.  Notes: All CVE users should reference CVE-2005-2370 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript></desc><loss_types><avail/></loss_types><vuln_types><other/></vuln_types><refs/></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2448" published="2005-08-03" seq="2005-2448" severity="Medium" type="CVE"><desc><descript source="cve">Multiple &quot;endianness errors&quot; in libgadu in ekg before 1.6rc2 allow remote attackers to cause a denial of service (invalid behavior in applications) on big-endian systems.</descript></desc><loss_types><avail/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/14415">14415</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16140">16140</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16155">16155</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16363">16363</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-813">DSA-813</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112198499417250&amp;w=2">20050721 Multiple vulnerabilities in libgadu and ekg package</ref><ref source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1318">DSA-1318</ref><ref source="BID" url="http://www.securityfocus.com/bid/24600">24600</ref></refs><vuln_soft><prod name="ekg" vendor="ekg"><vers num="1.6 rc1"/><vers num="1.5"/><vers num="1.4"/><vers num="1.3"/><vers num="1.1"/><vers num="2005-06-05"/><vers num="2005-04-11"/></prod></vuln_soft></entry><entry CVSS_base_score="1.2" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="2.9" CVSS_score="1.2" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2449" published="2005-08-03" seq="2005-2449" severity="Low" type="CVE"><desc><descript source="cve">Race condition in sandbox before 1.2.11 allows local users to create or overwrite arbitrary files via symlink attack on sandboxpids.tmp.</descript></desc><loss_types><int/></loss_types><vuln_types><race/></vuln_types><range><local/></range><refs><ref source="MISC" url="http://bugs.gentoo.org/show_bug.cgi?id=96782">http://bugs.gentoo.org/show_bug.cgi?id=96782</ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200507-22.xml">GLSA-200507-22</ref><ref source="BID" url="http://www.securityfocus.com/bid/14375">14375</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014574">1014574</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16214">16214</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/21519">sandbox-race-condition(21519)</ref></refs><vuln_soft><prod name="sandbox" vendor="sandbox"><vers num="1.2.10"/><vers num="1.2.9"/><vers num="1.2.8"/><vers num="1.2.7"/><vers num="1.2.6"/><vers num="1.2.5 r2"/><vers num="1.2.5 r1"/><vers num="1.2.5"/><vers num="1.2.4"/><vers num="1.2.3"/><vers num="1.2.2"/><vers num="1.2.1 r3"/><vers num="1.2.1"/><vers num="1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2450" published="2005-08-03" seq="2005-2450" severity="High" type="CVE"><desc><descript source="cve">Multiple integer overflows in the (1) TNEF, (2) CHM, or (3) FSG file format processors in libclamav for Clam AntiVirus (ClamAV) 0.86.1 and earlier allow remote attackers to gain privileges via a crafted e-mail message.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://sourceforge.net/project/shownotes.php?release_id=344514">http://sourceforge.net/project/shownotes.php?release_id=344514</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/21555">clam-antivirus-file-format-gain-access(21555)</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000987">CLSA-2005:987</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200507-25.xml">GLSA-200507-25</ref><ref source="BID" url="http://www.securityfocus.com/bid/14359">14359</ref><ref source="OSVDB" url="http://www.osvdb.org/18257">18257</ref><ref source="OSVDB" url="http://www.osvdb.org/18258">18258</ref><ref source="OSVDB" url="http://www.osvdb.org/18259">18259</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16180">16180</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16229">16229</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16250">16250</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16296">16296</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16458">16458</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112230864412932&amp;w=2">20050725 ClamAV Multiple Rem0te Buffer Overflows</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_18_sr.html">SUSE-SR:2005:018</ref></refs><vuln_soft><prod name="ClamAV" vendor="Clam Anti-Virus"><vers num="0.86"/><vers num="0.86"/><vers num="0.85.1"/><vers num="0.85"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2451" published="2005-08-03" seq="2005-2451" severity="Low" type="CVE"><desc><descript source="cve">Cisco IOS 12.0 through 12.4 and IOS XR before 3.2, with IPv6 enabled, allows remote attackers on a local network segment to cause a denial of service (device reload) and possibly execute arbitrary code via a crafted IPv6 packet.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-sa-20050729-ipv6.shtml">20050729 IPv6 Crafted Packet Vulnerability</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/21591">cisco-ios-ipv6-packet-command-execution(21591)</ref><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2005-07/0663.html">20050729 Cisco IOS Shellcode Presentation</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA05-210A.html">TA05-210A</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/930892">VU#930892</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16272">16272</ref><ref source="BID" url="http://www.securityfocus.com/bid/14414">14414</ref><ref source="OSVDB" url="http://www.osvdb.org/18332">18332</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014598">1014598</ref></refs><vuln_soft><prod name="IOS" vendor="Cisco"><vers num="12.0S"/><vers num="12.0SL"/><vers num="12.0ST"/><vers num="12.0SY"/><vers num="12.1XU"/><vers num="12.1XV"/><vers num="12.1YB"/><vers num="12.1YC"/><vers num="12.1YD"/><vers num="12.1YE"/><vers num="12.1YF"/><vers num="12.1YH"/><vers num="12.1YI"/><vers num="12.2B"/><vers num="12.2BC"/><vers num="12.2BW"/><vers num="12.2BY"/><vers num="12.2BX"/><vers num="12.2BZ"/><vers num="12.2CX"/><vers num="12.2CY"/><vers num="12.2DD"/><vers num="12.2DX"/><vers num="12.2EU"/><vers num="12.2EW"/><vers num="12.2EWA"/><vers num="12.2EZ"/><vers num="12.2JA"/><vers num="12.2MB"/><vers num="12.2MC"/><vers num="12.2MX"/><vers num="12.2S"/><vers num="12.2SEB"/><vers num="12.2SEC"/><vers num="12.2SO"/><vers num="12.2SU"/><vers num="12.2SV"/><vers num="12.2SW"/><vers num="12.2SX"/><vers num="12.2SXA"/><vers num="12.2SXB"/><vers num="12.2SXD"/><vers num="12.2SXE"/><vers num="12.2SY"/><vers num="12.2SZ"/><vers num="12.2T"/><vers num="12.2XA"/><vers num="12.2XB"/><vers num="12.2XC"/><vers num="12.2XD"/><vers num="12.2XE"/><vers num="12.2XF"/><vers num="12.2XG"/><vers num="12.2XH"/><vers num="12.2XI"/><vers num="12.2XJ"/><vers num="12.2XK"/><vers num="12.2XL"/><vers num="12.2XM"/><vers num="12.2XN"/><vers num="12.2XQ"/><vers num="12.2XR"/><vers num="12.2XT"/><vers num="12.2XU"/><vers num="12.2XW"/><vers num="12.2XZ"/><vers num="12.2YA"/><vers num="12.2YB"/><vers num="12.2YC"/><vers num="12.2YD"/><vers num="12.2YE"/><vers num="12.2YF"/><vers num="12.2YG"/><vers num="12.2YH"/><vers num="12.2YJ"/><vers num="12.2YK"/><vers num="12.2YL"/><vers num="12.2YM"/><vers num="12.2YN"/><vers num="12.2YO"/><vers num="12.2YP"/><vers num="12.2YQ"/><vers num="12.2YR"/><vers num="12.2YT"/><vers num="12.2YU"/><vers num="12.2YV"/><vers num="12.2YW"/><vers num="12.2YX"/><vers num="12.2YY"/><vers num="12.2YZ"/><vers num="12.2ZA"/><vers num="12.2ZB"/><vers num="12.2ZC"/><vers num="12.2ZD"/><vers num="12.2ZE"/><vers num="12.2ZF"/><vers num="12.2ZG"/><vers num="12.2ZH"/><vers num="12.2ZJ"/><vers num="12.2ZL"/><vers num="12.2ZN"/><vers num="12.2ZO"/><vers num="12.2ZP"/><vers num="12.3"/><vers num="12.3BC"/><vers num="12.3B"/><vers num="12.3BW"/><vers num="12.3JA"/><vers num="12.2JK"/><vers num="12.3T"/><vers num="12.3XA"/><vers num="12.3XB"/><vers num="12.3XC"/><vers num="12.3XD"/><vers num="12.3XE"/><vers num="12.3XF"/><vers num="12.3XG"/><vers num="12.3XH"/><vers num="12.3XI"/><vers num="12.3XJ"/><vers num="12.3XK"/><vers num="12.3XL"/><vers num="12.3XM"/><vers num="12.3XQ"/><vers num="12.3XR"/><vers num="12.3XS"/><vers num="12.3XT"/><vers num="12.3XU"/><vers num="12.3XW"/><vers num="12.3XX"/><vers num="12.3XY"/><vers num="12.3YA"/><vers num="12.3YD"/><vers num="12.3YF"/><vers num="12.3YG"/><vers num="12.3YH"/><vers num="12.3YI"/><vers num="12.3YJ"/><vers num="12.3YK"/><vers num="12.3YQ"/><vers num="12.3YS"/><vers num="12.3YT"/><vers num="12.3YU"/><vers num="12.4"/><vers num="12.4MR"/><vers num="12.4T"/></prod><prod name="IOS XR" vendor="Cisco"><vers num="3.1.0"/><vers num="3.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-11-30" name="CVE-2005-2452" published="2005-08-03" seq="2005-2452" severity="Medium" type="CVE"><desc><descript source="cve">libtiff up to 3.7.0 allows remote attackers to cause a denial of service (application crash) via a TIFF image header with a zero &quot;YCbCr subsampling&quot; value, which causes a divide-by-zero error in (1) tif_strip.c and (2) tif_tile.c, a different vulnerability than CVE-2004-0804.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref patch="1" source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-156-1">USN-156-1</ref><ref source="MISC" url="https://bugzilla.ubuntu.com/show_bug.cgi?id=12008">https://bugzilla.ubuntu.com/show_bug.cgi?id=12008</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:142">MDKSA-2005:142</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:143">MDKSA-2005:143</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:144">MDKSA-2005:144</ref><ref source="BID" url="http://www.securityfocus.com/bid/14417">14417</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/16266">16266</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/16486">16486</ref></refs><vuln_soft><prod name="libTIFF" vendor="libTIFF"><vers num="3.6.1"/><vers num="3.5.7"/><vers num="3.5.5"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2453" published="2005-08-04" seq="2005-2453" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in NetworkActiv Web Server 1.0, 2.0.0.6, 3.0.1.1, and 3.5.13, and possibly other versions, allows remote attackers to inject arbitrary web script or HTML via the query string.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="MISC" url="http://secunia.com/secunia_research/2005-31/advisory/">http://secunia.com/secunia_research/2005-31/advisory/</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/16301">16301</ref><ref source="BID" url="http://www.securityfocus.com/bid/14473">14473</ref><ref source="OSVDB" url="http://www.osvdb.org/18525">18525</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014624">1014624</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/21696">networkactiv-xss(21696)</ref></refs><vuln_soft><prod name="NetworkActiv Web Server" vendor="NetworkActiv"><vers num="1.0"/><vers num="2.0.0.6"/><vers num="3.0.1.1"/><vers num="3.5.13"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-01-03" name="CVE-2005-2454" published="2005-12-31" seq="2005-2454" severity="Medium" type="CVE"><desc><descript source="cve">IBM Lotus Notes 6.5.4 and 6.5.5, and 7.0.0 and 7.0.1, uses insecure default permissions (Everyone/Full Control) for the &quot;Notes&quot; folder and all children, which allows local users to gain privileges and modify, add, or delete files in that folder.</descript></desc><sols><sol source="nvd">Update to version 7.0.2.</sol></sols><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><env/></vuln_types><range><local/></range><refs><ref adv="1" source="" url="http://secunia.com/secunia_research/2005-29/advisory/"></ref><ref source="" url="http://www-1.ibm.com/support/docview.wss?rs=463&amp;uid=swg21246773"></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19537">19537</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/449126/100/0/threaded">20061018 Secunia Research: IBM Lotus Notes Insecure Default FolderPermissions</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/383092">VU#383092</ref><ref source="BID" url="http://www.securityfocus.com/bid/20612">20612</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/4093">ADV-2006-4093</ref><ref source="OSVDB" url="http://www.osvdb.org/29761">29761</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1017086">1017086</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/29660">lotusnotes-directory-insecure-permission(29660)</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/27342">27342</ref></refs><vuln_soft><prod name="Lotus Notes" vendor="IBM"><vers num="6.5.4"/><vers num="6.5.5"/><vers num="7.0.0"/><vers num="7.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2455" published="2005-08-04" seq="2005-2455" severity="Medium" type="CVE"><desc><descript source="cve">Greasemonkey before 0.3.5 allows remote web servers to (1) read arbitrary files via a GET request to a file:// URL in the GM_xmlhttpRequest API function, (2) list installed scripts using GM_scripts, or obtain sensitive information via (3) GM_setValue and GM_getValue.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="MLIST" url="http://mozdev.org/pipermail/greasemonkey/2005-July/004022.html">[Greasemonkey] 20050718 greasemonkey for secure data over insecure networks / sites</ref><ref source="MLIST" url="http://mozdev.org/pipermail/greasemonkey/2005-July/004000.html">[Greasemonkey] 20050718 greasemonkey for secure data over insecure networks / sites</ref><ref patch="1" source="" url="http://greaseblog.blogspot.com/2005/07/mandatory-greasemonkey-update.html">http://greaseblog.blogspot.com/2005/07/mandatory-greasemonkey-update.html</ref><ref patch="1" source="" url="http://greasemonkey.mozdev.org/changes/0.3.5.html">http://greasemonkey.mozdev.org/changes/0.3.5.html</ref><ref patch="1" source="MISC" url="http://www.securiteam.com/securitynews/5CP0P20GBK.html">http://www.securiteam.com/securitynews/5CP0P20GBK.html</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/14336">14336</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/1147">ADV-2005-1147</ref><ref source="OSVDB" url="http://www.osvdb.org/18154">18154</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1014529">1014529</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/16128">16128</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/21453">mozilla-greasemonkey-information-disclosure(21453)</ref></refs><vuln_soft><prod name="Greasemonkey" vendor="Greasemonkey"><vers num="0.3.3"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-04-07" name="CVE-2005-2456" published="2005-08-04" seq="2005-2456" severity="Low" type="CVE"><desc><descript source="cve">Array index overflow in the xfrm_sk_policy_insert function in xfrm_user.c in Linux kernel 2.6 allows local users to cause a denial of service (oops or deadlock) and possibly execute arbitrary code via a p-&gt;dir value that is larger than XFRM_POLICY_OUT, which is used as an index in the sock-&gt;sk_policy array.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><local/></range><refs><ref patch="1" source="MISC" url="http://www.mail-archive.com/netdev@vger.kernel.org/msg00520.html">http://www.mail-archive.com/netdev@vger.kernel.org/msg00520.html</ref><ref patch="1" source="" url="http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=a4f1bac62564049ea4718c4624b0fadc9f597c84">http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=a4f1bac62564049ea4718c4624b0fadc9f597c84</ref><ref patch="1" source="" url="http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=blobdiff;h=8da3e25b2c4c1f305fd85428d3a9eb62b543bfba;hp=ecade4893a139cc35d4fe345ce70242ede5358c4;hb=a4f1bac62564049ea4718c4624b0fadc9f597c84;f=net/xfrm/xfrm_user.c">http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=blobdiff;h=8da3e25b2c4c1f305fd85428d3a9eb62b543bfba;hp=ecade4893a139cc35d4fe345ce70242ede5358c4;hb=a4f1bac62564049ea4718c4624b0fadc9f597c84;f=net/xfrm/xfrm_user.c</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-169-1">USN-169-1</ref><ref source="BID" url="http://www.securityfocus.com/bid/14477">14477</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16298">16298</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16500">16500</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/21710">linux-kernel-xfrm-dos(21710)</ref><ref source="SUSE-SA" url="http://www.novell.com/linux/security/advisories/2005_50_kernel.html">2005:050</ref><ref source="MANDRAKE" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2005:219">MDKSA-2005:219</ref><ref source="MANDRAKE" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2005:220">MDKSA-2005:220</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-922">DSA-922</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-921">DSA-921</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18056">18056</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18059">18059</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-514.html">RHSA-2005:514</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-663.html">RHSA-2005:663</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/427980/100/0/threaded">FLSA:157459-3</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17073">17073</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17826">17826</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17002">17002</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/1878">ADV-2005-1878</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:219">MDKSA-2005:219</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:220">MDKSA-2005:220</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.6"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2457" published="2005-08-23" seq="2005-2457" severity="Medium" type="CVE"><desc><descript source="cve">The driver for compressed ISO file systems (zisofs) in the Linux kernel before 2.6.12.5 allows local users and remote attackers to cause a denial of service (kernel crash) via a crafted compressed ISO file system.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="KERNEL" url="http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.12.5"></ref><ref adv="1" source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-169-1">USN-169-1</ref><ref source="BID" url="http://www.securityfocus.com/bid/14614">14614</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16355/">16355</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16500">16500</ref><ref source="SUSE-SA" url="http://www.novell.com/linux/security/advisories/2005_50_kernel.html">2005:050</ref><ref source="MANDRAKE" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2005:218">MDKSA-2005:218</ref><ref source="MANDRAKE" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2005:219">MDKSA-2005:219</ref><ref source="MANDRAKE" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2005:220">MDKSA-2005:220</ref><ref source="SUSE" url="http://www.securityfocus.com/archive/1/archive/1/419522/100/0/threaded">SUSE-SA:2005:068</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17918">17918</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1017">DSA-1017</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17826">17826</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1018">DSA-1018</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19374">19374</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19369">19369</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:218">MDKSA-2005:218</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:219">MDKSA-2005:219</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:220">MDKSA-2005:220</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.6 test9 CVS"/><vers num="2.6 test9"/><vers num="2.6 test8"/><vers num="2.6 test7"/><vers num="2.6 test6"/><vers num="2.6 test5"/><vers num="2.6 test4"/><vers num="2.6 test3"/><vers num="2.6 test2"/><vers num="2.6 test11"/><vers num="2.6 test10"/><vers num="2.6 test1"/><vers edition="2.6.20" num="2.6.9"/><vers edition="PowerPC_smp" num="2.6.8.1.5"/><vers edition="PowerPC" num="2.6.8.1.5"/><vers edition="Power4_smp" num="2.6.8.1.5"/><vers edition="Power4" num="2.6.8.1.5"/><vers edition="Power3_smp" num="2.6.8.1.5"/><vers edition="Power3" num="2.6.8.1.5"/><vers edition="K7_smp" num="2.6.8.1.5"/><vers edition="K7" num="2.6.8.1.5"/><vers edition="AMD64_Xeon" num="2.6.8.1.5"/><vers edition="AMD64_K8_smp" num="2.6.8.1.5"/><vers edition="AMD64_K8" num="2.6.8.1.5"/><vers edition="AMD64" num="2.6.8.1.5"/><vers edition="686_smp" num="2.6.8.1.5"/><vers edition="686" num="2.6.8.1.5"/><vers edition="386" num="2.6.8.1.5"/><vers num="2.6.8.1.5"/><vers num="2.6.8.1"/><vers num="2.6.8 rc3"/><vers num="2.6.8 rc2"/><vers num="2.6.8 rc1"/><vers num="2.6.8"/><vers num="2.6.7 rc1"/><vers num="2.6.7"/><vers num="2.6.6 rc1"/><vers num="2.6.6"/><vers num="2.6.5"/><vers num="2.6.4"/><vers num="2.6.3"/><vers num="2.6.2"/><vers num="2.6.12 rc4"/><vers num="2.6.12 rc1"/><vers num="2.6.11 rc4"/><vers num="2.6.11 rc3"/><vers num="2.6.11 rc2"/><vers num="2.6.11 rc1 bk6"/><vers num="2.6.11.8"/><vers num="2.6.11.7"/><vers num="2.6.11.6"/><vers num="2.6.11.5"/><vers num="2.6.11.4"/><vers num="2.6.11.3"/><vers num="2.6.11.2"/><vers num="2.6.11.1"/><vers num="2.6.11"/><vers num="2.6.10 rc2"/><vers num="2.6.10"/><vers num="2.6.1 rc2"/><vers num="2.6.1 rc1"/><vers num="2.6.1"/><vers num="2.6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2458" published="2005-08-23" seq="2005-2458" severity="Medium" type="CVE"><desc><descript source="cve">inflate.c in the zlib routines in the Linux kernel before 2.6.12.5 allows remote attackers to cause a denial of service (kernel crash) via a compressed file with &quot;improper tables&quot;.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="MLIST" url="http://sources.redhat.com/ml/bug-gnu-utils/1999-06/msg00183.html">[bug-gnu-utils] 19990625 Re: bug in gzip: segfault when doing </ref><ref source="KERNEL" url="http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.12.5">Module per-cpu alignment cannot always be met</ref><ref adv="1" source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-169-1">USN-169-1</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/16355/">16355</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16500">16500</ref><ref source="SUSE-SA" url="http://www.novell.com/linux/security/advisories/2005_50_kernel.html">2005:050</ref><ref source="MANDRAKE" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2005:219">MDKSA-2005:219</ref><ref source="MANDRAKE" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2005:220">MDKSA-2005:220</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-922">DSA-922</ref><ref source="BID" url="http://www.securityfocus.com/bid/14719">14719</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-921">DSA-921</ref><ref source="SUSE" url="http://www.securityfocus.com/archive/1/archive/1/419522/100/0/threaded">SUSE-SA:2005:068</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17918">17918</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18056">18056</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18059">18059</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0101.html">RHSA-2006:0101</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18510">18510</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0190.html">RHSA-2006:0190</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0191.html">RHSA-2006:0191</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18684">18684</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0144.html">RHSA-2006:0144</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/428028/100/0/threaded">FLSA:157459-1</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/428058/100/0/threaded">FLSA:157459-2</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/427980/100/0/threaded">FLSA:157459-3</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19252">19252</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17826">17826</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:219">MDKSA-2005:219</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:220">MDKSA-2005:220</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.6 test9 CVS"/><vers num="2.6 test9"/><vers num="2.6 test8"/><vers num="2.6 test7"/><vers num="2.6 test6"/><vers num="2.6 test5"/><vers num="2.6 test4"/><vers num="2.6 test3"/><vers num="2.6 test2"/><vers num="2.6 test11"/><vers num="2.6 test10"/><vers num="2.6 test1"/><vers edition="2.6.20" num="2.6.9"/><vers edition="PowerPC_smp" num="2.6.8.1.5"/><vers edition="PowerPC" num="2.6.8.1.5"/><vers edition="Power4_smp" num="2.6.8.1.5"/><vers edition="Power4" num="2.6.8.1.5"/><vers edition="Power3_smp" num="2.6.8.1.5"/><vers edition="Power3" num="2.6.8.1.5"/><vers edition="K7_smp" num="2.6.8.1.5"/><vers edition="K7" num="2.6.8.1.5"/><vers edition="AMD64_Xeon" num="2.6.8.1.5"/><vers edition="AMD64_K8_smp" num="2.6.8.1.5"/><vers edition="AMD64_K8" num="2.6.8.1.5"/><vers edition="AMD64" num="2.6.8.1.5"/><vers edition="686_smp" num="2.6.8.1.5"/><vers edition="686" num="2.6.8.1.5"/><vers edition="386" num="2.6.8.1.5"/><vers num="2.6.8.1.5"/><vers num="2.6.8.1"/><vers num="2.6.8 rc3"/><vers num="2.6.8 rc2"/><vers num="2.6.8 rc1"/><vers num="2.6.8"/><vers num="2.6.7 rc1"/><vers num="2.6.7"/><vers num="2.6.6 rc1"/><vers num="2.6.6"/><vers num="2.6.5"/><vers num="2.6.4"/><vers num="2.6.3"/><vers num="2.6.2"/><vers num="2.6.12 rc4"/><vers num="2.6.12 rc1"/><vers num="2.6.11 rc4"/><vers num="2.6.11 rc3"/><vers num="2.6.11 rc2"/><vers num="2.6.11 rc1 bk6"/><vers num="2.6.11.8"/><vers num="2.6.11.7"/><vers num="2.6.11.6"/><vers num="2.6.11.5"/><vers num="2.6.11.4"/><vers num="2.6.11.3"/><vers num="2.6.11.2"/><vers num="2.6.11.1"/><vers num="2.6.11"/><vers num="2.6.10 rc2"/><vers num="2.6.10"/><vers num="2.6.1 rc2"/><vers num="2.6.1 rc1"/><vers num="2.6.1"/><vers num="2.6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-25" name="CVE-2005-2459" published="2005-08-23" seq="2005-2459" severity="Medium" type="CVE"><desc><descript source="cve">The huft_build function in inflate.c in the zlib routines in the Linux kernel before 2.6.12.5 returns the wrong value, which allows remote attackers to cause a denial of service (kernel crash) via a certain compressed file that leads to a null pointer dereference, a different vulnerbility than CVE-2005-2458.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="GENTOO" url="http://bugs.gentoo.org/show_bug.cgi?id=94584">Bugzilla Bug 94584</ref><ref source="KERNEL" url="http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.12.5">Module per-cpu alignment cannot always be met</ref><ref adv="1" source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-169-1">USN-169-1</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/16355/">16355</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16500">16500</ref><ref source="SUSE-SA" url="http://www.novell.com/linux/security/advisories/2005_50_kernel.html">2005:050</ref><ref source="MANDRAKE" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2005:219">MDKSA-2005:219</ref><ref source="MANDRAKE" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2005:220">MDKSA-2005:220</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-922">DSA-922</ref><ref source="BID" url="http://www.securityfocus.com/bid/14720">14720</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-921">DSA-921</ref><ref source="SUSE" url="http://www.securityfocus.com/archive/1/archive/1/419522/100/0/threaded">SUSE-SA:2005:068</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17918">17918</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18056">18056</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18059">18059</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17826">17826</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:219">MDKSA-2005:219</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:220">MDKSA-2005:220</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.6 test9 CVS"/><vers num="2.6 test9"/><vers num="2.6 test8"/><vers num="2.6 test7"/><vers num="2.6 test6"/><vers num="2.6 test5"/><vers num="2.6 test4"/><vers num="2.6 test3"/><vers num="2.6 test2"/><vers num="2.6 test11"/><vers num="2.6 test10"/><vers num="2.6 test1"/><vers edition="2.6.20" num="2.6.9"/><vers edition="PowerPC_smp" num="2.6.8.1.5"/><vers edition="PowerPC" num="2.6.8.1.5"/><vers edition="Power4_smp" num="2.6.8.1.5"/><vers edition="Power4" num="2.6.8.1.5"/><vers edition="Power3_smp" num="2.6.8.1.5"/><vers edition="Power3" num="2.6.8.1.5"/><vers edition="K7_smp" num="2.6.8.1.5"/><vers edition="K7" num="2.6.8.1.5"/><vers edition="AMD64_Xeon" num="2.6.8.1.5"/><vers edition="AMD64_K8_smp" num="2.6.8.1.5"/><vers edition="AMD64_K8" num="2.6.8.1.5"/><vers edition="AMD64" num="2.6.8.1.5"/><vers edition="686_smp" num="2.6.8.1.5"/><vers edition="686" num="2.6.8.1.5"/><vers edition="386" num="2.6.8.1.5"/><vers num="2.6.8.1.5"/><vers num="2.6.8.1"/><vers num="2.6.8 rc3"/><vers num="2.6.8 rc2"/><vers num="2.6.8 rc1"/><vers num="2.6.8"/><vers num="2.6.7 rc1"/><vers num="2.6.7"/><vers num="2.6.6 rc1"/><vers num="2.6.6"/><vers num="2.6.5"/><vers num="2.6.4"/><vers num="2.6.3"/><vers num="2.6.2"/><vers num="2.6.12 rc4"/><vers num="2.6.12 rc1"/><vers num="2.6.11 rc4"/><vers num="2.6.11 rc3"/><vers num="2.6.11 rc2"/><vers num="2.6.11 rc1 bk6"/><vers num="2.6.11.8"/><vers num="2.6.11.7"/><vers num="2.6.11.6"/><vers num="2.6.11.5"/><vers num="2.6.11.4"/><vers num="2.6.11.3"/><vers num="2.6.11.2"/><vers num="2.6.11.1"/><vers num="2.6.11"/><vers num="2.6.10 rc2"/><vers num="2.6.10"/><vers num="2.6.1 rc2"/><vers num="2.6.1 rc1"/><vers num="2.6.1"/><vers num="2.6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="4.9" CVSS_score="5.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2005-04-01" modified="2006-06-08" name="CVE-2005-2460" published="2005-12-31" seq="2005-2460" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Kayako liveResponse 2.x allow remote attackers to inject arbitrary web script or HTML via the (1) username parameter or (2) name field when entering a session or sending a message.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112274359718863&amp;w=2">20050730 Kayako liveResponse Multiple Vulnerabilities</ref><ref source="" url="http://www.gulftech.org/?node=research&amp;article_id=00092-07302005"></ref><ref source="BID" url="http://www.securityfocus.com/bid/14425">14425</ref><ref source="OSVDB" url="http://www.osvdb.org/18395">18395</ref><ref source="OSVDB" url="http://www.osvdb.org/18397">18397</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/16286">16286</ref></refs><vuln_soft><prod name="LiveResponse" vendor="Kayako"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2005-04-01" modified="2006-06-08" name="CVE-2005-2461" published="2005-12-31" seq="2005-2461" severity="Medium" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in the calendar feature in Kayako liveResponse 2.x allow remote attackers to execute arbitrary SQL commands via the (1) year or (2) date parameter.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112274359718863&amp;w=2">20050730 Kayako liveResponse Multiple Vulnerabilities</ref><ref source="" url="http://www.gulftech.org/?node=research&amp;article_id=00092-07302005"></ref><ref source="BID" url="http://www.securityfocus.com/bid/14425">14425</ref><ref source="OSVDB" url="http://www.osvdb.org/18396">18396</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/16286">16286</ref></refs><vuln_soft><prod name="LiveResponse" vendor="Kayako"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2005-04-01" modified="2006-06-08" name="CVE-2005-2462" published="2005-12-31" seq="2005-2462" severity="Low" type="CVE"><desc><descript source="cve">Kayako liveResponse 2.x, when logging in a user, records the password in plaintext in the URL, which allows local users and possibly remote attackers to gain privileges.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112274359718863&amp;w=2">20050730 Kayako liveResponse Multiple Vulnerabilities</ref><ref source="" url="http://www.gulftech.org/?node=research&amp;article_id=00092-07302005"></ref><ref source="BID" url="http://www.securityfocus.com/bid/14425">14425</ref><ref source="OSVDB" url="http://www.osvdb.org/18398">18398</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/16286">16286</ref></refs><vuln_soft><prod name="LiveResponse" vendor="Kayako"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2005-04-01" modified="2006-06-08" name="CVE-2005-2463" published="2005-12-31" seq="2005-2463" severity="Medium" type="CVE"><desc><descript source="cve">Kayako liveResponse 2.x allows remote attackers to obtain sensitive information via a direct request to addressbook.php and other include scripts, which reveals the path in an error message.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/><design/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112274359718863&amp;w=2">20050730 Kayako liveResponse Multiple Vulnerabilities</ref><ref source="" url="http://www.gulftech.org/?node=research&amp;article_id=00092-07302005"></ref><ref source="BID" url="http://www.securityfocus.com/bid/14425">14425</ref><ref source="OSVDB" url="http://www.osvdb.org/18399">18399</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/16286">16286</ref></refs><vuln_soft><prod name="LiveResponse" vendor="Kayako"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-06-09" name="CVE-2005-2464" published="2005-12-31" seq="2005-2464" severity="High" type="CVE"><desc><descript source="cve">login.php in PCXP/TOPPE CMS allows remote attackers to bypass authentication and gain privileges by modifying the cookie to match the target userid.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112274251601106&amp;w=2">20050730 PC-EXPERIENCE/TOPPE CMS Security Advisory</ref></refs><vuln_soft><prod name="PCXP_TOPPE CMS" vendor="PCXP TOPPE CMS"><vers num="2"/><vers num="1.15"/></prod></vuln_soft></entry><entry CVSS_base_score="5.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="4.9" CVSS_score="5.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2005-07-30" modified="2006-06-08" name="CVE-2005-2465" published="2005-12-31" seq="2005-2465" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in pm.php in PCXP/TOPPE CMS allows remote attackers to inject arbitrary web script or HTML via the msg variable.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112274251601106&amp;w=2">20050730 PC-EXPERIENCE/TOPPE CMS Security Advisory</ref><ref source="BID" url="http://www.securityfocus.com/bid/14428">14428</ref><ref source="OSVDB" url="http://www.osvdb.org/18715">18715</ref></refs><vuln_soft><prod name="PC-Experience" vendor="PC-Experience"><vers num="2.0"/><vers num="1.15"/></prod><prod name="Toppe CMS" vendor="Toppe"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2005-07-30" modified="2006-06-08" name="CVE-2005-2466" published="2005-12-31" seq="2005-2466" severity="Medium" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in the auth_user function in admin.php in OpenBook 1.2.2 allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameter.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112291283419785&amp;w=2">20050730 [SVadvisory] - SQL injection in OpenBook 1.2.2</ref><ref source="BID" url="http://www.securityfocus.com/bid/14444">14444</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/1301">ADV-2005-1301</ref><ref source="OSVDB" url="http://www.osvdb.org/18475">18475</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014606">1014606</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/21643">openbook-authuser-sql-injection(21643)</ref></refs><vuln_soft><prod name="OpenBook" vendor="OpenBook"><vers num="1.2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="4.9" CVSS_score="5.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2005-07-01" modified="2006-06-08" name="CVE-2005-2467" published="2005-12-31" seq="2005-2467" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in MySQL Eventum 1.5.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to view.php, (2) release parameter to list.php, or (3) F parameter to get_jsrs_data.php.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112292193807958&amp;w=2">20050731 MySQL Eventum Multiple Vulnerabilities</ref><ref source="" url="http://www.gulftech.org/?node=research&amp;article_id=00093-07312005"></ref><ref patch="1" source="" url="http://lists.mysql.com/eventum-users/2072"></ref><ref source="BID" url="http://www.securityfocus.com/bid/14436">14436</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/1287">ADV-2005-1287</ref><ref source="OSVDB" url="http://www.osvdb.org/18400">18400</ref><ref source="OSVDB" url="http://www.osvdb.org/18401">18401</ref><ref source="OSVDB" url="http://www.osvdb.org/18402">18402</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1014603">1014603</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/16304">16304</ref></refs><vuln_soft><prod name="MySQL Eventum" vendor="MySQL Eventum"><vers num="1.5.5"/><vers num="1.5.4"/><vers num="1.4"/><vers num="1.3.1"/><vers num="1.3"/><vers num="1.2.2"/><vers num="1.2"/><vers num="1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2005-07-31" modified="2006-06-08" name="CVE-2005-2468" published="2005-12-31" seq="2005-2468" severity="Medium" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in MySQL Eventum 1.5.5 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) isCorrectPassword or (2) userExist function in class.auth.php, getCustomFieldReport function in (4) custom_fields.php, (5) custom_fields_graph.php, or (6) class.report.php, or the insert function in (7) releases.php or (8) class.release.php.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112292193807958&amp;w=2">20050731 MySQL Eventum Multiple Vulnerabilities</ref><ref source="" url="http://www.gulftech.org/?node=research&amp;article_id=00093-07312005"></ref><ref patch="1" source="" url="http://lists.mysql.com/eventum-users/2072"></ref><ref source="BID" url="http://www.securityfocus.com/bid/14437">14437</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/1287">ADV-2005-1287</ref><ref patch="1" source="OSVDB" url="http://www.osvdb.org/18403">18403</ref><ref patch="1" source="OSVDB" url="http://www.osvdb.org/18404">18404</ref><ref patch="1" source="OSVDB" url="http://www.osvdb.org/18405">18405</ref><ref patch="1" source="OSVDB" url="http://www.osvdb.org/18406">18406</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1014603">1014603</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/16304">16304</ref></refs><vuln_soft><prod name="MySQL Eventum" vendor="MySQL Eventum"><vers num="1.5.5"/><vers num="1.5.4"/><vers num="1.4"/><vers num="1.3.1"/><vers num="1.3"/><vers num="1.2.2"/><vers num="1.2"/><vers num="1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2469" published="2005-10-20" seq="2005-2469" severity="Medium" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in the NMAP Agent for Novell NetMail 3.52C and possibly earlier versions allows local users to execute arbitrary code via a long user name in the USER command.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="" url="http://secunia.com/secunia_research/2005-23/advisory/"></ref><ref patch="1" source="" url="http://support.novell.com/cgi-bin/search/searchtid.cgi?/2972340.htm"></ref><ref patch="1" source="" url="http://support.novell.com/cgi-bin/search/searchtid.cgi?/2972433.htm"></ref><ref patch="1" source="" url="http://support.novell.com/cgi-bin/search/searchtid.cgi?/2972438.htm"></ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/15925/">15925</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015048">1015048</ref><ref source="BID" url="http://www.securityfocus.com/bid/15080">15080</ref><ref source="OSVDB" url="http://www.osvdb.org/19916">19916</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/22727">netmail-nmap-user-bo(22727)</ref><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2005-10/0299.html">20051012 Secunia Research: Novell NetMail NMAP Agent &quot;USER&quot; Buffer Overflow Vulnerability</ref></refs><vuln_soft><prod name="NetMail" vendor="Novell"><vers num="3.5.2 C"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2470" published="2005-08-16" seq="2005-2470" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in a &quot;core application plug-in&quot; for Adobe Reader 5.1 through 7.0.2 and Acrobat 5.0 through 7.0.2 allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Adobe" url="http://www.adobe.com/support/techdocs/321644.html">http://www.adobe.com/support/techdocs/321644.html</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-750.html">RHSA-2005:750</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/1434">ADV-2005-1434</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/896220">VU#896220</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200508-11.xml">GLSA-200508-11</ref><ref source="BID" url="http://www.securityfocus.com/bid/14603">14603</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014712">1014712</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16466">16466</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/21860">adobe-acrobat-reader-plugin-bo(21860)</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_19_sr.html">SUSE-SR:2005:019</ref></refs><vuln_soft><prod name="Acrobat" vendor="Adobe"><vers num="7.0.1"/><vers num="7.0"/><vers num="6.0.2"/><vers num="6.0.1"/><vers num="6.0"/><vers num="5.0.5"/><vers num="5.0"/><vers num="7.0.2"/></prod><prod name="Acrobat Reader" vendor="Adobe"><vers num="7.0.2"/><vers num="7.0.1"/><vers num="7.0"/><vers num="7.0"/><vers num="6.0.3"/><vers num="6.0.2"/><vers num="6.0.1"/><vers num="6.0"/><vers num="6.0"/><vers num="5.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-08-28" name="CVE-2005-2471" published="2005-08-05" seq="2005-2471" severity="High" type="CVE"><desc><descript source="cve">pstopnm in netpbm does not properly use the &quot;-dSAFER&quot; option when calling Ghostscript to convert a PostScript file into a (1) PBM, (2) PGM, or (3) PNM file, which allows external user-assisted attackers to execute arbitrary commands.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="Debian" url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=319757">319757: netpbm: arbitrary postscript code execution (CAN-2005-2471)</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/16184">16184</ref><ref adv="1" source="TRUSTIX" url="http://www.trustix.org/errata/2005/0038/">2005-0038</ref><ref source="BID" url="http://www.securityfocus.com/bid/14379">14379</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/21500">netpbm-dsafer-command-execution(21500)</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18330">18330</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014752">1014752</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1021">DSA-1021</ref><ref source="OSVDB" url="http://www.osvdb.org/18253">18253</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19436">19436</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-743.html">RHSA-2005:743</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_19_sr.html">SUSE-SR:2005:019</ref></refs><vuln_soft><prod name="netpbm" vendor="netpbm"><vers num="2.10.0.8"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2472" published="2005-08-05" seq="2005-2472" severity="Medium" type="CVE"><desc><descript source="cve">Multiple buffer overflows in BusinessMail 4.60.00 allow remote attackers to cause a denial of service (application crash) via a long string to SMTP (1) HELO or (2) MAIL FROM commands.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref patch="1" source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-August/035647.html">20050801 Buffer overflow in BusinessMail email server system 4.60.00</ref><ref patch="1" source="MISC" url="http://reedarvin.thearvins.com/20050730-01.html">http://reedarvin.thearvins.com/20050730-01.html</ref><ref source="BID" url="http://www.securityfocus.com/bid/14434">14434</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/16306">16306</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/21636">businessmail-smtp-dos(21636)</ref><ref source="OSVDB" url="http://www.osvdb.org/18407">18407</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014602">1014602</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112291456305261&amp;w=2">20050801 Buffer overflow in BusinessMail email server system 4.60.00</ref></refs><vuln_soft><prod name="BusinessMail" vendor="NetCPlus"><vers num="4.60.00"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2473" published="2005-08-05" seq="2005-2473" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in ChurchInfo allow remote attackers to execute arbitrary SQL commands via the PersonID parameter to (1) PersonView.php, (2) MemberRoleChange.php, (3) PropertyAssign.php, (4) WhyCameEditor.php, (5) GroupPropsEditor.php, (6) Reports/PDFLabel.php, or (7) UserDelete.php, (8) DepositSlipID parameter to DepositSlipEditor.php, (9) QueryID parameter to QueryView.php, GroupID parameter to (10) GroupView.php, (11) GroupMemberList.php, (12) MemberRoleChange.php, (13) GroupDelete.php, (14) /Reports/ClassAttendance.php, or (15) /Reports/GroupReport.php, (16) PropertyID parameter to PropertyEditor.php, FamilyID parameter to (17) Canvas05Editor.php, (18) CanvasEditor.php, or (19) FamilyView.php, or (20) PledgeID parameter to PledgeDetails.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/14438">14438</ref><ref source="OSVDB" url="http://www.osvdb.org/18408">18408</ref><ref source="OSVDB" url="http://www.osvdb.org/18409">18409</ref><ref source="OSVDB" url="http://www.osvdb.org/18410">18410</ref><ref source="OSVDB" url="http://www.osvdb.org/18411">18411</ref><ref source="OSVDB" url="http://www.osvdb.org/18412">18412</ref><ref source="OSVDB" url="http://www.osvdb.org/18413">18413</ref><ref source="OSVDB" url="http://www.osvdb.org/18414">18414</ref><ref source="OSVDB" url="http://www.osvdb.org/18415">18415</ref><ref source="OSVDB" url="http://www.osvdb.org/18416">18416</ref><ref source="OSVDB" url="http://www.osvdb.org/18417">18417</ref><ref source="OSVDB" url="http://www.osvdb.org/18418">18418</ref><ref source="OSVDB" url="http://www.osvdb.org/18419">18419</ref><ref source="OSVDB" url="http://www.osvdb.org/18420">18420</ref><ref source="OSVDB" url="http://www.osvdb.org/18421">18421</ref><ref source="OSVDB" url="http://www.osvdb.org/18422">18422</ref><ref source="OSVDB" url="http://www.osvdb.org/18423">18423</ref><ref source="OSVDB" url="http://www.osvdb.org/18424">18424</ref><ref source="OSVDB" url="http://www.osvdb.org/18427">18427</ref><ref source="OSVDB" url="http://www.osvdb.org/18428">18428</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014617">1014617</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16292">16292</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/21647">churchinfo-sql-injection(21647)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112291550713546&amp;w=2">20050801 ChurchInfo Multiple Vulnerabilities</ref></refs><vuln_soft><prod name="ChurchInfo" vendor="ChurchInfo"><vers num="1.2.2"/><vers num="1.2.1"/><vers num="1.2.0"/><vers num="1.1.6"/><vers num="1.1.5"/><vers num="1.1.4"/><vers num="1.1.3"/><vers num="1.1.2"/><vers num="1.1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2474" published="2005-08-05" seq="2005-2474" severity="Medium" type="CVE"><desc><descript source="cve">ChurchInfo allows remote attackers to execute obtain sensitive information via the PersonID parameter to (1) PersonView.php, (2) MemberRoleChange.php, (3) PropertyAssign.php, (4) WhyCameEditor.php, (5) GroupPropsEditor.php, (6) Reports/PDFLabel.php, or (7) UserDelete.php, an invalid Number parameter to (8) SelectList.php or (9) SelectDelete.php, GroupID parameter to (10) GroupView.php, (11) GroupMemberList.php, (12) MemberRoleChange.php, (13) GroupDelete.php, (14) /Reports/ClassAttendance.php, or (15) /Reports/GroupReport.php, (16) PropertyID parameter to PropertyEditor.php, FamilyID parameter to (17) Canvas05Editor.php, (18) CanvasEditor.php, or (19) FamilyView.php, or (20) PledgeID parameter to PledgeDetails.php, which reveal the path in an error message.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="OSVDB" url="http://www.osvdb.org/18429">18429</ref><ref source="OSVDB" url="http://www.osvdb.org/18430">18430</ref><ref source="OSVDB" url="http://www.osvdb.org/18431">18431</ref><ref source="OSVDB" url="http://www.osvdb.org/18432">18432</ref><ref source="OSVDB" url="http://www.osvdb.org/18433">18433</ref><ref source="OSVDB" url="http://www.osvdb.org/18434">18434</ref><ref source="OSVDB" url="http://www.osvdb.org/18435">18435</ref><ref source="OSVDB" url="http://www.osvdb.org/18436">18436</ref><ref source="OSVDB" url="http://www.osvdb.org/18437">18437</ref><ref source="OSVDB" url="http://www.osvdb.org/18438">18438</ref><ref source="OSVDB" url="http://www.osvdb.org/18439">18439</ref><ref source="OSVDB" url="http://www.osvdb.org/18450">18450</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014617">1014617</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16292">16292</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/21648">churchinfo-path-disclosure(21648)</ref><ref source="OSVDB" url="http://www.osvdb.org/18425">18425</ref><ref source="OSVDB" url="http://www.osvdb.org/18426">18426</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112291550713546&amp;w=2">20050801 ChurchInfo Multiple Vulnerabilities</ref></refs><vuln_soft><prod name="ChurchInfo" vendor="ChurchInfo"><vers num="1.2.2"/><vers num="1.2.1"/><vers num="1.2.0"/><vers num="1.1.6"/><vers num="1.1.5"/><vers num="1.1.4"/><vers num="1.1.3"/><vers num="1.1.2"/><vers num="1.1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="1.2" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="2.9" CVSS_score="1.2" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2475" published="2005-08-05" seq="2005-2475" severity="Low" type="CVE"><desc><descript source="cve">Race condition in Unzip 5.52 allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by Unzip after the decompression is complete.</descript></desc><loss_types><conf/></loss_types><vuln_types><race/></vuln_types><range><local/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/14450">14450</ref><ref source="OSVDB" url="http://www.osvdb.org/18530">18530</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16309">16309</ref><ref source="SCO" url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.39/SCOSA-2005.39.txt">SCOSA-2005.39</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-191-1">USN-191-1</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-903">DSA-903</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17653">17653</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2005:197">MDKSA-2005:197</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2005/0053/">2005-0053</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17045">17045</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17342">17342</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16985">16985</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17006">17006</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112300046224117&amp;w=2">20050801 unzip TOCTOU file-permissions vulnerability</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2007-0203.html">
RHSA-2007:0203</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25098">
25098</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:197">MDKSA-2005:197</ref><ref source="SREASON" url="http://securityreason.com/securityalert/32">32</ref></refs><vuln_soft><prod name="Unzip" vendor="Info-ZIP"><vers num="5.52"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2476" published="2005-08-05" seq="2005-2476" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in lost_passowrd.php in Naxtor Shopping Cart 1.0 allows remote attackers to inject arbitrary web script or HTML via the email parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/16262">16262</ref><ref source="BID" url="http://www.securityfocus.com/bid/14454">14454</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014613">1014613</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/21676">naxtorshoppingcart-password-xss(21676)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112301600608192&amp;w=2">20050802 [NOBYTES.COM: #8] Naxtor Shopping Cart 1.0 - Information Disclosure &amp; Possible SQL Injection</ref></refs><vuln_soft><prod name="Shopping Cart" vendor="Naxtor"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2477" published="2005-08-05" seq="2005-2477" severity="Medium" type="CVE"><desc><descript source="cve">shop_display_products.php in Naxtor Shopping Cart 1.0 allows remote attackers to obtain sensitive information via a cat_id with a &quot;&apos;&quot; (single quote), which reveals the path in an error message, possibly due to an SQL injection vulnerability.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/16262">16262</ref><ref source="BID" url="http://www.securityfocus.com/bid/14456">14456</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014613">1014613</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/21677">naxtorshoppingcart-path-disclosure(21677)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112301600608192&amp;w=2">20050802 [NOBYTES.COM: #8] Naxtor Shopping Cart 1.0 - Information Disclosure &amp; Possible SQL Injection</ref></refs><vuln_soft><prod name="Shopping Cart" vendor="Naxtor"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2478" published="2005-08-05" seq="2005-2478" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in SilverNews 2.0.3 allows remote attackers to execute arbitrary SQL commands via the user field on the login page in the Admin control panel.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MISC" url="http://www.rgod.altervista.org/silvernews.html">http://www.rgod.altervista.org/silvernews.html</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/16315">16315</ref><ref source="BID" url="http://www.securityfocus.com/bid/14466">14466</ref><ref source="OSVDB" url="http://www.osvdb.org/18517">18517</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014622">1014622</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/21688">silvernews-username-sql-injection(21688)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112309780321088&amp;w=2">20050803 Silvernews 2.0.3 (possibly previous versions ) SQL Injection / Login Bypass / Remote commands execution / cross site scripting</ref></refs><vuln_soft><prod name="SilverNews" vendor="Silver-Scripts"><vers num="2.0.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2479" published="2005-08-05" seq="2005-2479" severity="Medium" type="CVE"><desc><descript source="cve">Quick &apos;n Easy FTP Server 3.0 allows remote attackers to cause a denial of service (application crash or CPU consumption) via a long USER command.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="SECTRACK" url="http://securitytracker.com/id?1014615">1014615</ref><ref source="BID" url="http://www.securityfocus.com/bid/14451">14451</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/21679">quickneasy-user-command-dos(21679)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/428812/100/0/threaded">20060325 Re: Quick &apos;n Easy FTP Server 3.0 pro / lite (buffer overflow vulnerabilities)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112300508617889&amp;w=2">20050802 Quick &apos;n Easy FTP Server 3.0 pro / lite (buffer overflow</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112309262324047&amp;w=2">20050802 Re: Quick &apos;n Easy FTP Server 3.0 pro / lite (buffer overflow</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112319110831249&amp;w=2">20050803 Re: Re: Quick &apos;n Easy FTP Server 3.0 pro / lite (buffer overflow</ref></refs><vuln_soft><prod name="Quick &apos;n Easy FTP Server" vendor="Pablo Software Solutions"><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2480" published="2005-08-05" seq="2005-2480" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in ColdFusion Fusebox 4.1.0 allows remote attackers to inject arbitrary web script or HTML via the fuseaction parameter, which is not quoted in an error page, as demonstrated using index.cfm.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/14460">14460</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/16320">16320</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/21697">fusebox-fuseaction-xss(21697)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112309656102615&amp;w=2">20050803 Coldfusion Fusebox V4.1.0 Vulnerability</ref></refs><vuln_soft><prod name="ColdFusion Fusebox" vendor="Macromedia"><vers num="4.1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2481" published="2005-08-05" seq="2005-2481" severity="Medium" type="CVE"><desc><descript source="cve">ColdFusion Fusebox 4.1.0 allows remote attackers to obtain sensitive information via an invalid fuseaction parameter, which leaks the full server path in an error message, as demonstrated using the &quot;?&quot; (question mark) character.</descript></desc><loss_types><conf/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112309656102615&amp;w=2">20050803 Coldfusion Fusebox V4.1.0 Vulnerability</ref></refs><vuln_soft><prod name="ColdFusion Fusebox" vendor="Macromedia"><vers num="4.1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2482" published="2005-08-07" seq="2005-2482" severity="Medium" type="CVE"><desc><descript source="cve">The StateToOptions function in msfweb in Metasploit Framework 2.4 and earlier, when running with the -D option (defanged mode), allows attackers to modify temporary environment variables before the &quot;_Defanged&quot; environment option is checked when processing the Exploit command.</descript></desc><loss_types><int/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref source="" url="http://metasploit.com/archive/framework/msg00469.html">http://metasploit.com/archive/framework/msg00469.html</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/16318">16318</ref><ref source="BID" url="http://www.securityfocus.com/bid/14455">14455</ref><ref source="OSVDB" url="http://www.osvdb.org/18495">18495</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/21705">metasploit-defanged-bypass-security(21705)</ref></refs><vuln_soft><prod name="Metasploit Framework" vendor="Metasploit"><vers num="2.4"/><vers num="2.3"/><vers num="2.2"/><vers num="2.1"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2483" published="2005-08-07" seq="2005-2483" severity="High" type="CVE"><desc><descript source="cve">Eval injection vulnerability in Karrigell before 2.1.8 allows remote attackers to execute arbitrary Python code via modified arguments to a Karrigell services (.ks) script, which can reference functions from libraries that are used by that script.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref patch="1" source="MLIST" url="http://sourceforge.net/mailarchive/message.php?msg_id=12539317">[karrigell-main] 20050802 Re: SECURITY: python namespace exposure</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/16319">16319</ref><ref source="BID" url="http://www.securityfocus.com/bid/14463">14463</ref><ref source="OSVDB" url="http://www.osvdb.org/18506">18506</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/21668">karrigel-dos(21668)</ref><ref source="MLIST" url="http://sourceforge.net/mailarchive/forum.php?thread_id=7863293&amp;forum_id=32318">[karrigell-main] 20050731 SECURITY: python namespace exposure</ref></refs><vuln_soft><prod name="Karrigell" vendor="Karrigell"><vers num="2.1.5"/><vers num="2.1.4"/><vers num="2.1.3"/><vers num="2.1.2"/><vers num="2.1.1"/><vers num="2.1"/><vers num="2.0.5"/><vers num="2.0.4"/><vers num="2.0.3"/><vers num="2.0.2"/><vers num="2.0.1"/><vers num="2.0"/><vers num="2.0_Beta"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2484" published="2005-08-07" seq="2005-2484" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the rdb_query function for Denora IRC Stats 1.0 might allow attackers to execute arbitrary code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://sourceforge.net/project/shownotes.php?release_id=346819">http://sourceforge.net/project/shownotes.php?release_id=346819</ref><ref patch="1" source="" url="http://denora.nomadirc.net/index.php">http://denora.nomadirc.net/index.php</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/14471">14471</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/1319">ADV-2005-1319</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/16281">16281</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/21686">denora-rdbquery-bo(21686)</ref></refs><vuln_soft><prod name="Denora IRC Stats" vendor="Denora IRC Stats"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2485" published="2005-08-07" seq="2005-2485" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in the Helpdesk in Logicampus before 1.1.1 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://sourceforge.net/project/shownotes.php?release_id=346801">http://sourceforge.net/project/shownotes.php?release_id=346801</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/14472">14472</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16297">16297</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/21687">logicampus-helpdesk-xss(21687)</ref></refs><vuln_soft><prod name="Logicampus" vendor="Logicampus"><vers num="1.1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-25" name="CVE-2005-2486" published="2005-08-07" seq="2005-2486" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in mod_forum/read_message.php in PortailPHP allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php with the affiche parameter set to &quot;Forum-read_mess&quot;, a different vulnerability than CVE-2005-1701.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://msgs.securepoint.com/cgi-bin/get/bugtraq0508/53.html">20050804 SQL IN PortailPHP</ref><ref source="BID" url="http://www.securityfocus.com/bid/14474">14474</ref><ref source="OSVDB" url="http://www.osvdb.org/18685">18685</ref></refs><vuln_soft><prod name="PortailPHP" vendor="PortailPHP"><vers num="2.4"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2487" published="2005-08-07" seq="2005-2487" severity="Low" type="CVE"><desc><descript source="cve">Unknown vulnerability in Sun McData switches and directors 4300, 4500, 6064, and 6140 before E/OS 6.0.0 may allow attackers to cause a denial of service (connectivity and array access loss) via a network broadcast storm.</descript></desc><loss_types><avail/></loss_types><range><local/></range><refs><ref adv="1" patch="1" source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101833-1">101833</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/16295">16295</ref><ref source="BID" url="http://www.securityfocus.com/bid/14475">14475</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/21706">mcdata-switch-director-dos(21706)</ref></refs><vuln_soft><prod name="Intrepid Director Switch" vendor="McDATA"><vers num="6140"/><vers num="6064"/></prod><prod name="Sphereon Fabric Switch" vendor="McDATA"><vers num="4500"/><vers num="4300"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2488" published="2005-08-07" seq="2005-2488" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Web Content Management News System allows remote attackers to inject arbitrary web script or HTML via (1) the strRootpath parameter to validsession.php or (2) the strTable parameter to Admin/News/List.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MISC" url="http://www.rgod.altervista.org/webc.html">http://www.rgod.altervista.org/webc.html</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014616">1014616</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/16317">16317</ref><ref source="BID" url="http://www.securityfocus.com/bid/14464">14464</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/21689">webcms-multiple-script-xss(21689)</ref></refs><vuln_soft><prod name="Web Content Management News System" vendor="Web Content Management"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2489" published="2005-08-07" seq="2005-2489" severity="High" type="CVE"><desc><descript source="cve">Web Content Management News System allows remote attackers to create arbitrary accounts and gain privileges via a direct request to Admin/Users/AddModifyInput.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MISC" url="http://www.rgod.altervista.org/webc.html">http://www.rgod.altervista.org/webc.html</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014616">1014616</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/16317">16317</ref><ref source="BID" url="http://www.securityfocus.com/bid/14465">14465</ref><ref source="OSVDB" url="http://www.osvdb.org/18524">18524</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/21694">webcms-addmodifyinput-create-account(21694)</ref></refs><vuln_soft><prod name="Web Content Management News System" vendor="Web Content Management"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2490" published="2005-09-14" seq="2005-2490" severity="Medium" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in the sendmsg function call in the Linux kernel 2.6 before 2.6.13.1 allows local users execute arbitrary code by calling sendmsg and modifying the message contents in another thread.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref patch="1" source="" url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=166248"></ref><ref source="" url="http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.13.1"></ref><ref adv="1" source="UBUNTU" url="http://www.ubuntu.com/usn/usn-178-1">USN-178-1</ref><ref source="BID" url="http://www.securityfocus.com/bid/14785">14785</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/16747/">16747</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/22217">kernel-sendmsg-bo(22217)</ref><ref source="MANDRAKE" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2005:219">MDKSA-2005:219</ref><ref source="MANDRAKE" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2005:220">MDKSA-2005:220</ref><ref source="SUSE" url="http://www.securityfocus.com/archive/1/archive/1/419522/100/0/threaded">SUSE-SA:2005:068</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17918">17918</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2005:235">MDKSA-2005:235</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-514.html">RHSA-2005:514</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-663.html">RHSA-2005:663</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/428028/100/0/threaded">FLSA:157459-1</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/428058/100/0/threaded">FLSA:157459-2</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/427980/100/0/threaded">FLSA:157459-3</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1017">DSA-1017</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17073">17073</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17826">17826</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19374">19374</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17002">17002</ref><ref source="TRUSTIX" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112690609622266&amp;w=2">2005-0049</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/1878">ADV-2005-1878</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:219">MDKSA-2005:219</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:220">MDKSA-2005:220</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:235">MDKSA-2005:235</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.6.12-rc4"/><vers num="2.6.12-rc1"/><vers num="2.6.11.8"/><vers num="2.6.11.7"/><vers num="2.6.11.6"/><vers num="2.6.11.5"/><vers num="2.6.11.11"/><vers num="2.6.11-rc4"/><vers num="2.6.11-rc3"/><vers num="2.6.11-rc2"/><vers num="2.6.11"/><vers num="2.6.10-rc2"/><vers edition="2.6.20" num="2.6.9"/><vers num="2.6.8-rc3"/><vers num="2.6.8-rc2"/><vers num="2.6.8-rc1"/><vers num="2.6.8"/><vers num="2.6.7 rc1"/><vers num="2.6.7"/><vers num="2.6.6-rc1"/><vers num="2.6.6"/><vers num="2.6.5"/><vers num="2.6.4"/><vers num="2.6.3"/><vers num="2.6.2"/><vers num="2.6.1-rc2"/><vers num="2.6.1-rc1"/><vers num="2.6.1"/><vers num="2.6.10"/><vers num="2.6 test 9 CVS"/><vers num="2.6-test9"/><vers num="2.6-test8"/><vers num="2.6-test7"/><vers num="2.6-test6"/><vers num="2.6-test5"/><vers num="2.6-test4"/><vers num="2.6-test3"/><vers num="2.6-test2"/><vers num="2.6-test11"/><vers num="2.6-test10"/><vers num="2.6-test1"/><vers num="2.6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-11-02" name="CVE-2005-2491" published="2005-08-23" seq="2005-2491" severity="High" type="CVE"><desc><descript source="cve">Integer overflow in pcre_compile.c in Perl Compatible Regular Expressions (PCRE) before 6.2, as used in multiple products such as Python, Ethereal, and PHP, allows attackers to execute arbitrary code via quantifier values in regular expressions, which leads to a heap-based buffer overflow.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/14620">14620</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1014744">1014744</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-800">DSA-800</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200509-02.xml">GLSA-200509-02</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-761.html">RHSA-2005:761</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200508-17.xml">GLSA-200509-08</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200509-12.xml">GLSA-200509-12</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-819">DSA-819</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-817">DSA-817</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-821">DSA-821</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200509-19.xml">GLSA-200509-19</ref><ref source="TRUSTIX" url="http://lists.trustix.org/pipermail/tsl-announce/2005-October/000354.html">TSLSA-2005-0059</ref><ref source="" url="http://www.ethereal.com/appnotes/enpa-sa-00021.html"></ref><ref source="" url="http://www.php.net/release_4_4_1.php"></ref><ref source="APPLE" url="http://docs.info.apple.com/article.html?artnum=302847">APPLE-SA-2005-11-29</ref><ref source="BID" url="http://www.securityfocus.com/bid/15647">15647</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17813">17813</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval735.html">OVAL735</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16502">16502</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16679">16679</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/1511">ADV-2005-1511</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/2659">ADV-2005-2659</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/427046/100/0/threaded">FLSA:168516</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0197.html">RHSA-2006:0197</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102198-1">102198</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0789">ADV-2006-0789</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19072">19072</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-358.html">RHSA-2005:358</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/428138/100/0/threaded">HPSBUX02074</ref><ref source="SCO" url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2006.10/SCOSA-2006.10.txt">SCOSA-2006.10</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19193">19193</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2005-216.pdf"></ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2005-223.pdf"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/17252">17252</ref><ref source="OPENPKG" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112606064317223&amp;w=2">OpenPKG-SA-2005.018</ref><ref source="SUSE" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112605112027335&amp;w=2">SUSE-SA:2005:051</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20060401-01-U">20060401-01-U</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19532">19532</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-081.htm"></ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_48_pcre.html">SUSE-SA:2005:048</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_49_php.html">SUSE-SA:2005:049</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_52_apache2.html">SUSE-SA:2005:052</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-159.htm"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/21522">21522</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:735">oval:org.mitre.oval:def:735</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1496">oval:org.mitre.oval:def:1496</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1659">oval:org.mitre.oval:def:1659</ref><ref source="HP" url="http://itrc.hp.com/service/cki/docDisplay.do?docId=c00786522">HPSBMA02159</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/4320">ADV-2006-4320</ref><ref source="SECUNIA" url="http://secunia.com/advisories/22691">22691</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/4502">ADV-2006-4502</ref><ref source="SECUNIA" url="http://secunia.com/advisories/22875">22875</ref><ref source="SREASON" url="http://securityreason.com/securityalert/604">604</ref></refs><vuln_soft><prod name="PCRE" vendor="PCRE"><vers num="6.1"/><vers num="6.0"/><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="3.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="4.9" CVSS_score="3.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2492" published="2005-09-14" seq="2005-2492" severity="Low" type="CVE"><desc><descript source="cve">The raw_sendmsg function in the Linux kernel 2.6 before 2.6.13.1 allows local users to cause a denial of service (change hardware state) or read from arbitrary memory via crafted input.</descript></desc><loss_types><avail/><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref patch="1" source="" url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=166830"></ref><ref source="" url="http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.13.1"></ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-178-1">USN-178-1</ref><ref source="BID" url="http://www.securityfocus.com/bid/14787">14787</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/16747/">16747</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/22218">kernel-rawsendmsg-obtain-information(22218)</ref><ref source="MANDRAKE" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2005:220">MDKSA-2005:220</ref><ref source="SUSE" url="http://www.securityfocus.com/archive/1/archive/1/419522/100/0/threaded">SUSE-SA:2005:068</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17918">17918</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2005:235">MDKSA-2005:235</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-514.html">RHSA-2005:514</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/427980/100/0/threaded">FLSA:157459-3</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17073">17073</ref><ref source="TRUSTIX" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112690609622266&amp;w=2">2005-0049</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:220">MDKSA-2005:220</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:235">MDKSA-2005:235</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.6.12-rc4"/><vers num="2.6.12-rc1"/><vers num="2.6.11.8"/><vers num="2.6.11.7"/><vers num="2.6.11.6"/><vers num="2.6.11.5"/><vers num="2.6.11.11"/><vers num="2.6.11-rc4"/><vers num="2.6.11-rc3"/><vers num="2.6.11-rc2"/><vers num="2.6.11"/><vers num="2.6.10-rc2"/><vers edition="2.6.20" num="2.6.9"/><vers num="2.6.8-rc3"/><vers num="2.6.8-rc2"/><vers num="2.6.8-rc1"/><vers num="2.6.8"/><vers num="2.6.7 rc1"/><vers num="2.6.7"/><vers num="2.6.6-rc1"/><vers num="2.6.6"/><vers num="2.6.5"/><vers num="2.6.4"/><vers num="2.6.3"/><vers num="2.6.2"/><vers num="2.6.1-rc2"/><vers num="2.6.1-rc1"/><vers num="2.6.1"/><vers num="2.6.10"/><vers num="2.6 test 9 CVS"/><vers num="2.6-test9"/><vers num="2.6-test8"/><vers num="2.6-test7"/><vers num="2.6-test6"/><vers num="2.6-test5"/><vers num="2.6-test4"/><vers num="2.6-test3"/><vers num="2.6-test2"/><vers num="2.6-test11"/><vers num="2.6-test10"/><vers num="2.6-test1"/><vers num="2.6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2494" published="2005-09-06" seq="2005-2494" severity="High" type="CVE"><desc><descript source="cve">kcheckpass in KDE 3.2.0 up to 3.4.2 allows local users to gain root access via a symlink attack on lock files.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="" url="http://www.kde.org/info/security/advisory-20050905-1.txt"></ref><ref patch="1" source="" url="ftp://ftp.kde.org/pub/kde/security_patches/post-3.4.2-kdebase-kcheckpass.diff"></ref><ref source="" url="http://www.suresec.org/advisories/adv6.pdf"></ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-815">DSA-815</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:160">MDKSA-2005:160</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-176-1">USN-176-1</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16692">16692</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18139">18139</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112611555928169&amp;w=2">20050907 [ Suresec Advisories ] - Kcheckpass file creation vulnerability</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112603999215453&amp;w=2">20050905 [KDE Security Advisory] kcheckpass local root vulnerability</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0582.html">RHSA-2006:0582</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21481">21481</ref><ref source="BID" url="http://www.securityfocus.com/bid/14736">14736</ref></refs><vuln_soft><prod name="KDE" vendor="KDE"><vers num="3.2.0"/><vers num="3.2.1"/><vers num="3.2.2"/><vers num="3.2.3"/><vers num="3.3.0"/><vers num="3.3.1"/><vers num="3.3.2"/><vers num="3.4.0"/><vers num="3.4.1"/><vers num="3.4.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-08-28" name="CVE-2005-2495" published="2005-09-15" seq="2005-2495" severity="Medium" type="CVE"><desc><descript source="cve">Multiple integer overflows in XFree86 before 4.3.0 allow user-assisted attackers to execute arbitrary code via a crafted pixmap image.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-501.html">RHSA-2005:501</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200509-07.xml">GLSA-200509-07</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:164">MDKSA-2005:164</ref><ref source="TRUSTIX" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112690609622266&amp;w=2">2005-0049</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_56_xserver.html">SUSE-SA:2005:056</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/102441">VU#102441</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2005-218.pdf"></ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2005-226.pdf"></ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101953-1">101953</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17044">17044</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17258">17258</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17278">17278</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/427045/100/0/threaded">FLSA:168264-2</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-329.html">RHSA-2005:329</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-396.html">RHSA-2005:396</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_23_sr.html">SUSE-SR:2005:023</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17215">17215</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20060403-01-U">20060403-01-U</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/442163/100/0/threaded">HPSBUX02137</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/3140">ADV-2006-3140</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21318">21318</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1044">oval:org.mitre.oval:def:1044</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:998">oval:org.mitre.oval:def:998</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-816">DSA-816</ref><ref source="FEDORA" url="http://www.securityfocus.com/advisories/9285">FEDORA-2005-893</ref><ref source="FEDORA" url="http://www.securityfocus.com/advisories/9286">FEDORA-2005-894</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101926-1">101926</ref><ref source="UBUNTU" url="http://www.securityfocus.com/advisories/9242">USN-182-1</ref><ref source="BID" url="http://www.securityfocus.com/bid/14807">14807</ref><ref source="OSVDB" url="http://www.osvdb.org/19352">19352</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014887">1014887</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16777">16777</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16790">16790</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/22244">xorg-pixmap-bo(22244)</ref><ref source="SCO" url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2006.22/SCOSA-2006.22.txt">
SCOSA-2006.22</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19624">
19624</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19796">
19796</ref></refs><vuln_soft><prod name="XFree86" vendor="XFree86 Project"><vers num="4.2.1"/><vers num="4.2.0"/><vers num="4.1.0"/><vers num="4.0.3"/><vers num="4.0.2"/><vers num="4.0.1"/><vers num="4.0.0"/><vers num="3.3.6"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2496" published="2005-09-02" seq="2005-2496" severity="Medium" type="CVE"><desc><descript source="cve">The xntpd ntp (ntpd) daemon before 4.2.0b, when run with the -u option and using a string to specify the group, uses the group ID of the user instead of the group, which causes xntpd to run with different privileges than intended.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><other/></vuln_types><range><local/></range><refs><ref adv="1" source="FEDORA" url="http://www.securityspace.com/smysecure/catid.html?id=55155">FEDORA-2005-812</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/1561">ADV-2005-1561</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/16602">16602</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/22035">ntp-incorrect-group-permissions(22035)</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:156">MDKSA-2005:156</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-801">DSA-801</ref><ref source="BID" url="http://www.securityfocus.com/bid/14673">14673</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0393.html">RHSA-2006:0393</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21464">21464</ref><ref source="OSVDB" url="http://www.osvdb.org/19055">19055</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1016679">1016679</ref></refs><vuln_soft><prod name="ntpd" vendor="Dave Mills"><vers num="4.2.0.a.2004-06-17_4.FC3" prev="1"/></prod></vuln_soft></entry><entry modified="2005-10-25" name="CVE-2005-2497" published="2005-10-07" reject="1" seq="2005-2497" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2005-2641.  Reason: This candidate is a duplicate of CVE-2005-2641.  Notes: All CVE users should reference CVE-2005-2641 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript></desc><refs/></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-25" name="CVE-2005-2498" published="2005-08-15" seq="2005-2498" severity="Medium" type="CVE"><desc><descript source="cve">Eval injection vulnerability in PHPXMLRPC 1.1.1 and earlier (PEAR XML-RPC for PHP), as used in multiple products including (1) Drupal, (2) phpAdsNew, (3) phpPgAds, and (4) phpgroupware, allows remote attackers to execute arbitrary PHP code via certain nested XML tags in a PHP document that should not be nested, which are injected into an eval function call, a different vulnerability than CVE-2005-1921.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="MISC" url="http://www.hardened-php.net/advisory_152005.67.html">http://www.hardened-php.net/advisory_152005.67.html</ref><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112412415822890&amp;w=2">20050815 [DRUPAL-SA-2005-004] Drupal 4.6.3 / 4.5.5 fixes critical XML-RPC issue</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-748.html">RHSA-2005:748</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-798">DSA-798</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-789">DSA-789</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200509-19.xml">GLSA-200509-19</ref><ref source="FEDORA" url="http://www.fedoralegacy.org/updates/FC2/2005-11-28-FLSA_2005_166943__Updated_php_packages_fix_security_issues.html">FLSA:166943</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16431">16431</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16432">16432</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16441">16441</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16460">16460</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16465">16465</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16468">16468</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16469">16469</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16491">16491</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16550">16550</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16558">16558</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16563">16563</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16619">16619</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16635">16635</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16693">16693</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16976">16976</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17440">17440</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-840">DSA-840</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-842">DSA-842</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17053">17053</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17066">17066</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112431497300344&amp;w=2">20050817 [PHPADSNEW-SA-2005-001] phpAdsNew and phpPgAds 2.0.6 fix multiple vulnerabilities</ref><ref source="SUSE" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112605112027335&amp;w=2">SUSE-SA:2005:051</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/408125">20050815 Advisory 15/2005: PHPXMLRPC Remote PHP Code Injection Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/14560">14560</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_49_php.html">SUSE-SA:2005:049</ref></refs><vuln_soft><prod name="PHPXMLRPC" vendor="Edd Dumbill"><vers num="1.1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2499" published="2005-08-23" seq="2005-2499" severity="Low" type="CVE"><desc><descript source="cve">slocate before 2.7 does not properly process very long paths, which allows local users to cause a denial of service (updatedb exit and incomplete slocate database) via a certain crafted directory structure.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-747.html">RHSA-2005:747</ref><ref source="BID" url="http://www.securityfocus.com/bid/14640">14640</ref><ref source="OSVDB" url="http://www.osvdb.org/19034">19034</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014751">1014751</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/22316">slocate-directory-structure-dos(22316)</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-346.html">RHSA-2005:346</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-345.html">RHSA-2005:345</ref></refs><vuln_soft><prod name="slocate" vendor="slocate"><vers num="2.1"/><vers num="2.2"/><vers num="2.3"/><vers num="2.4"/><vers num="2.5"/><vers num="2.6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2500" published="2005-08-08" seq="2005-2500" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the xdr_xcode_array2 function in xdr.c in Linux kernel 2.6.12, as used in SuSE Linux Enterprise Server 9, might allow remote attackers to cause a denial of service and possibly execute arbitrary code via crafted XDR data for the nfsacl protocol.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="MISC" url="http://lkml.org/lkml/2005/6/23/19">http://lkml.org/lkml/2005/6/23/19</ref><ref source="" url="http://lkml.org/lkml/2005/6/23/126">http://lkml.org/lkml/2005/6/23/126</ref><ref adv="1" patch="1" source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_44_kernel.html">SUSE-SA:2005:044</ref><ref source="" url="http://linux.bkbits.net:8080/linux-2.6/cset@42b9c4fdYUuaq0joRUZi8W0Q-2hA1A">http://linux.bkbits.net:8080/linux-2.6/cset@42b9c4fdYUuaq0joRUZi8W0Q-2hA1A</ref><ref source="BID" url="http://www.securityfocus.com/bid/14470">14470</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16406">16406</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/21805">kernel-xdrxcodearray-dos(21805)</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.6.5" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="10.0" CVSS_score="7.6" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-08-28" name="CVE-2005-2501" published="2005-08-19" seq="2005-2501" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in AppKit for Mac OS X 10.3.9 and 10.4.2 allows external user-assisted attackers to execute arbitrary code via a crafted Rich Text Format (RTF) file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/Aug/msg00000.html">APPLE-SA-2005-08-15</ref><ref patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2005//Aug/msg00001.html">APPLE-SA-2005-08-17</ref><ref adv="1" patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA05-229A.html">TA05-229A</ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/435188">VU#435188</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014695">1014695</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.3.9"/><vers num="10.4.2"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.3.9"/><vers num="10.4.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-08-28" name="CVE-2005-2502" published="2005-08-19" seq="2005-2502" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in AppKit for Mac OS X 10.3.9 and 10.4.2, as used in applications such as TextEdit, allows external user-assisted attackers to execute arbitrary code via a crafted Microsoft Word file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2005//Aug/msg00000.html">APPLE-SA-2005-08-15</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2005//Aug/msg00001.html">APPLE-SA-2005-08-17</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA05-229A.html">TA05-229A</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/172948">VU#172948</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014695">1014695</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/Aug/msg00000.html">APPLE-SA-2005-08-15</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.3.9"/><vers num="10.4.2"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.3.9"/><vers num="10.4.2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2503" published="2005-08-19" seq="2005-2503" severity="Medium" type="CVE"><desc><descript source="cve">AppKit for Mac OS X 10.3.9 and 10.4.2 allows attackers with physical access to create local accounts by forcing a particular error to occur at the login window.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><exception/></vuln_types><range><local/></range><refs><ref patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2005//Aug/msg00000.html">APPLE-SA-2005-08-15</ref><ref patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2005//Aug/msg00001.html">APPLE-SA-2005-08-17</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014696">1014696</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/Aug/msg00000.html">APPLE-SA-2005-08-15</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.3.9"/><vers num="10.4.2"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.3.9"/><vers num="10.4.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2504" published="2005-08-19" seq="2005-2504" severity="High" type="CVE"><desc><descript source="cve">The System Profiler in Mac OS X 10.4.2 labels a Bluetooth device with &quot;Requires Authentication: No&quot; even when the user has selected the &quot;Require pairing for security&quot; option, which could confuse users about which setting is valid.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/Aug/msg00000.html">APPLE-SA-2005-08-15</ref><ref patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2005//Aug/msg00001.html">APPLE-SA-2005-08-17</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.4.2"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.4.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2505" published="2005-08-19" seq="2005-2505" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in CoreFoundation in Mac OS X 10.3.9 allows attackers to execute arbitrary code via command line arguments to an application that uses CoreFoundation.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/Aug/msg00000.html">APPLE-SA-2005-08-15</ref><ref patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2005//Aug/msg00001.html">APPLE-SA-2005-08-17</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014697">1014697</ref></refs><vuln_soft><prod name="Mac OS X" vendor="Apple"><vers num="10.3.9"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2506" published="2005-08-19" seq="2005-2506" severity="Medium" type="CVE"><desc><descript source="cve">Algorithmic complexity vulnerability in CoreFoundation in Mac OS X 10.3.9 and 10.4.2 allows attackers to cause a denial of service (CPU consumption) via crafted Gregorian dates.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/Aug/msg00000.html">APPLE-SA-2005-08-15</ref><ref patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2005//Aug/msg00001.html">APPLE-SA-2005-08-17</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014697">1014697</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.3.9"/><vers num="10.4.2"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.3.9"/><vers num="10.4.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2507" published="2005-08-19" seq="2005-2507" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Directory Services in Mac OS X 10.3.9 and 10.4.2 allows remote attackers to execute arbitrary code during authentication.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/Aug/msg00000.html">APPLE-SA-2005-08-15</ref><ref patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2005//Aug/msg00001.html">APPLE-SA-2005-08-17</ref><ref adv="1" patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA05-229A.html">TA05-229A</ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/913820">VU#913820</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.3.9"/><vers num="10.4.2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2508" published="2005-08-19" seq="2005-2508" severity="Medium" type="CVE"><desc><descript source="cve">dsidentity in Directory Services in Mac OS X 10.4.2 allows local users to add or remove user accounts.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/Aug/msg00000.html">APPLE-SA-2005-08-15</ref><ref patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2005//Aug/msg00001.html">APPLE-SA-2005-08-17</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.4.2"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.4.2"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2509" published="2005-08-19" seq="2005-2509" severity="Low" type="CVE"><desc><descript source="cve">Unknown vulnerability in loginwindow in Mac OS X 10.4.2 and earlier, when Fast User Switching is enabled, allows attackers to log into other accounts if they know the passwords to at least two accounts.</descript></desc><loss_types><int/></loss_types><range><local/></range><refs><ref patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/Aug/msg00000.html">APPLE-SA-2005-08-15</ref><ref patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2005//Aug/msg00001.html">APPLE-SA-2005-08-17</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014704">1014704</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.3.5"/><vers num="10.3.4"/><vers num="10.2.8"/><vers num="10.4.1"/><vers num="10.4"/><vers num="10.3.9"/><vers num="10.3.8"/><vers num="10.3.7"/><vers num="10.3.6"/><vers num="10.3.5"/><vers num="10.3.4"/><vers num="10.3.3"/><vers num="10.3.2"/><vers num="10.3.1"/><vers num="10.3"/><vers num="10.2.8"/><vers num="10.2.7"/><vers num="10.2.6"/><vers num="10.2.5"/><vers num="10.2.4"/><vers num="10.2.3"/><vers num="10.2.2"/><vers num="10.2.1"/><vers num="10.2"/><vers num="10.1.5"/><vers num="10.1.4"/><vers num="10.1.3"/><vers num="10.1.2"/><vers num="10.1.1"/><vers num="10.1"/><vers num="10.0"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.3.5"/><vers num="10.3.4"/><vers num="10.2.8"/><vers num="10.4.1"/><vers num="10.4"/><vers num="10.3.9"/><vers num="10.3.8"/><vers num="10.3.7"/><vers num="10.3.6"/><vers num="10.3.5"/><vers num="10.3.4"/><vers num="10.3.3"/><vers num="10.3.2"/><vers num="10.3.1"/><vers num="10.3"/><vers num="10.2.7"/><vers num="10.2.6"/><vers num="10.2.5"/><vers num="10.2.4"/><vers num="10.2.3"/><vers num="10.2.2"/><vers num="10.2.1"/><vers num="10.2"/><vers num="10.1.5"/><vers num="10.1.4"/><vers num="10.1.3"/><vers num="10.1.2"/><vers num="10.1.1"/><vers num="10.1"/><vers num="10.0.4"/><vers num="10.0.3"/><vers num="10.0.2"/><vers num="10.0.1"/><vers num="10.0"/><vers num="10.4.9"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2510" published="2005-08-19" seq="2005-2510" severity="Medium" type="CVE"><desc><descript source="cve">The Server Admin tool in servermgr_ipfilter for Mac OS X 10.4 to 10.4.2, when using multiple subnets and Address Groups, does not always properly write firewall rules to the Active Rules when certain conditions occur, which could result in firewall policies that are less restrictive than intended by the administrator.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/Aug/msg00000.html">APPLE-SA-2005-08-15</ref><ref patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2005//Aug/msg00001.html">APPLE-SA-2005-08-17</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014708">1014708</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.4"/><vers num="10.4.1"/><vers num="10.4.2"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2511" published="2005-08-19" seq="2005-2511" severity="High" type="CVE"><desc><descript source="cve">Unknown vulnerability in Mac OS X 10.4.2 and earlier, when using Kerberos authentication with LDAP, allows attackers to gain access to a root Terminal window.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs><ref patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/Aug/msg00000.html">APPLE-SA-2005-08-15</ref><ref patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2005//Aug/msg00001.html">APPLE-SA-2005-08-17</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.4.2"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.4.2"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-03-02" name="CVE-2005-2512" published="2005-08-19" seq="2005-2512" severity="Low" type="CVE"><desc><descript source="cve">Mail.app in Mac OS 10.4.2 and earlier, when printing or forwarding an HTML message, loads remote images even when the user&apos;s preferences state otherwise, which could result in a privacy leak.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/Aug/msg00000.html">APPLE-SA-2005-08-15</ref><ref adv="1" patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2005//Aug/msg00001.html">APPLE-SA-2005-08-17</ref></refs><vuln_soft><prod name="Mac OS X" vendor="Apple"><vers num="10.4.2"/><vers num="10.4.1"/><vers num="10.4"/></prod><prod name="Mail" vendor="Apple"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2513" published="2005-08-19" seq="2005-2513" severity="Medium" type="CVE"><desc><descript source="cve">Unknown vulnerability in HItoolbox for Mac OS X 10.4.2 allows VoiceOver services to read secure input fields.</descript></desc><loss_types><conf/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/Aug/msg00000.html">APPLE-SA-2005-08-15</ref><ref adv="1" patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2005//Aug/msg00001.html">APPLE-SA-2005-08-17</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014699">1014699</ref></refs><vuln_soft><prod name="Mac OS X" vendor="Apple"><vers num="10.4.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2514" published="2005-08-19" seq="2005-2514" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in ping in Mac OS X 10.3.9 allows local users to execute arbitrary code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/Aug/msg00000.html">APPLE-SA-2005-08-15</ref><ref adv="1" patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2005//Aug/msg00001.html">APPLE-SA-2005-08-17</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014701">1014701</ref></refs><vuln_soft><prod name="Mac OS X" vendor="Apple"><vers num="10.3.9"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2515" published="2005-08-19" seq="2005-2515" severity="Medium" type="CVE"><desc><descript source="cve">Quartz Composer Screen Saver in Mac OS X 10.4.2 allows local users to access links from the RSS Visualizer even when a password is required.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><env/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/Aug/msg00000.html">APPLE-SA-2005-08-15</ref><ref adv="1" patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2005//Aug/msg00001.html">APPLE-SA-2005-08-17</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014705">1014705</ref></refs><vuln_soft><prod name="Mac OS X" vendor="Apple"><vers num="10.4.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2516" published="2005-08-19" seq="2005-2516" severity="High" type="CVE"><desc><descript source="cve">Safari in Mac OS X 10.3.9 and 10.4.2, when rendering Rich Text Format (RTF) files, can directly access URLs without performing the normal security checks, which allows remote attackers to execute arbitrary commands.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/Aug/msg00000.html">APPLE-SA-2005-08-15</ref><ref adv="1" patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2005//Aug/msg00001.html">APPLE-SA-2005-08-17</ref><ref adv="1" patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA05-229A.html">TA05-229A</ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/709220">VU#709220</ref></refs><vuln_soft><prod name="Mac OS X" vendor="Apple"><vers num="10.3.9"/><vers num="10.4.2"/></prod><prod name="Safari" vendor="Apple"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2517" published="2005-08-19" seq="2005-2517" severity="Low" type="CVE"><desc><descript source="cve">Safari in Mac OS X 10.3.9 and 10.4.2 submits forms from an XSL formatted page to the next page that is browsed by the user, which causes form data to be sent to the wrong site.</descript></desc><loss_types><conf/></loss_types><vuln_types><other/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/Aug/msg00000.html">APPLE-SA-2005-08-15</ref><ref adv="1" patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2005//Aug/msg00001.html">APPLE-SA-2005-08-17</ref></refs><vuln_soft><prod name="Mac OS X" vendor="Apple"><vers num="10.3.9"/><vers num="10.4.2"/></prod><prod name="Safari" vendor="Apple"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2518" published="2005-08-19" seq="2005-2518" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in servermgrd in Mac OS X 10.3.9 and 10.4.2 allows remote attackers to execute arbitrary code during authentication.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/Aug/msg00000.html">APPLE-SA-2005-08-15</ref><ref adv="1" patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2005//Aug/msg00001.html">APPLE-SA-2005-08-17</ref><ref adv="1" patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA05-229A.html">TA05-229A</ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/461412">VU#461412</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014709">1014709</ref></refs><vuln_soft><prod name="Mac OS X" vendor="Apple"><vers num="10.3.9"/><vers num="10.4.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2519" published="2005-08-19" seq="2005-2519" severity="High" type="CVE"><desc><descript source="cve">slpd in Directory Services in Mac OS X 10.3.9 creates insecure temporary files as root, which allows local users to gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><other/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/Aug/msg00000.html">APPLE-SA-2005-08-15</ref><ref adv="1" patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2005//Aug/msg00001.html">APPLE-SA-2005-08-17</ref></refs><vuln_soft><prod name="Mac OS X" vendor="Apple"><vers num="10.3.9"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2520" published="2005-08-19" seq="2005-2520" severity="Low" type="CVE"><desc><descript source="cve">The password assistant in Mac OS X 10.4 to 10.4.2, when used to create multiple accounts from the same process, does not reset the suggested password list when the assistant is displayed, which allows attackers to view recently used passwords.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/Aug/msg00000.html">APPLE-SA-2005-08-15</ref><ref adv="1" patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2005//Aug/msg00001.html">APPLE-SA-2005-08-17</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014707">1014707</ref></refs><vuln_soft><prod name="Mac OS X" vendor="Apple"><vers num="10.4"/><vers num="10.4.1"/><vers num="10.4.2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2521" published="2005-08-19" seq="2005-2521" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in traceroute in Mac OS X 10.3.9 allows local users to execute arbitrary code via unknown vectors.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/Aug/msg00000.html">APPLE-SA-2005-08-15</ref><ref adv="1" patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2005//Aug/msg00001.html">APPLE-SA-2005-08-17</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014702">1014702</ref></refs><vuln_soft><prod name="Mac OS X" vendor="Apple"><vers num="10.3.9"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2522" published="2005-08-19" seq="2005-2522" severity="Medium" type="CVE"><desc><descript source="cve">Safari in WebKit in Mac OS X 10.4 to 10.4.2 directly accesses URLs within PDF files without the normal security checks, which allows remote attackers to execute arbitrary code via links in a PDF file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><design/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/Aug/msg00000.html">APPLE-SA-2005-08-15</ref><ref adv="1" patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2005//Aug/msg00001.html">APPLE-SA-2005-08-17</ref><ref adv="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA05-229A.html">TA05-229A</ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/420316">VU#420316</ref></refs><vuln_soft><prod name="Mac OS X" vendor="Apple"><vers num="10.4"/><vers num="10.4.1"/><vers num="10.4.2"/></prod><prod name="Safari" vendor="Apple"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2523" published="2005-08-19" seq="2005-2523" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Weblog Server in Mac OS X 10.4 to 10.4.2 allow remote attackers to inject arbitrary web script or HTML via unknown vectors.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/Aug/msg00000.html">APPLE-SA-2005-08-15</ref><ref adv="1" patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2005//Aug/msg00001.html">APPLE-SA-2005-08-17</ref></refs><vuln_soft><prod name="Weblog Server" vendor="Apple"><vers num=""/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.4"/><vers num="10.4.1"/><vers num="10.4.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-31" name="CVE-2005-2524" published="2005-10-25" seq="2005-2524" severity="Medium" type="CVE"><desc><descript source="cve">Safari after 2.0 in Apple Mac OS X 10.3.9 allows remote attackers to bypass domain restrictions via crafted web archives that cause Safari to render them as if they came from a different site.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/Sep/msg00002.html">APPLE-SA-2005-09-22</ref><ref adv="1" patch="1" source="AUSCERT" url="http://www.auscert.org.au/5509">ESB-2005.0732</ref><ref adv="1" source="CIAC" url="http://www.ciac.org/ciac/bulletins/p-312.shtml">P-312</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/16920/">16920</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.3.9"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.3.9"/></prod><prod name="Safari" vendor="Apple"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-08-31" name="CVE-2005-2525" published="2005-08-19" seq="2005-2525" severity="Medium" type="CVE"><desc><descript source="cve">CUPS in Mac OS X 10.3.9 and 10.4.2 does not properly close file descriptors when handling multiple simultaneous print jobs, which allows remote attackers to cause a denial of service (printing halt).</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/Aug/msg00000.html">APPLE-SA-2005-08-15</ref><ref adv="1" patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2005//Aug/msg00001.html">APPLE-SA-2005-08-17</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014698">1014698</ref></refs><vuln_soft><prod name="Mac OS X" vendor="Apple"><vers num="10.3.9"/><vers num="10.4.2"/></prod><prod name="CUPS" vendor="Easy Software Products"><vers num="1.2.10"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-08-31" name="CVE-2005-2526" published="2005-08-19" seq="2005-2526" severity="Medium" type="CVE"><desc><descript source="cve">CUPS in Mac OS X 10.3.9 and 10.4.2 allows remote attackers to cause a denial of service (CPU consumption) by sending a partial IPP request and closing the connection.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/Aug/msg00000.html">APPLE-SA-2005-08-15</ref><ref adv="1" patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2005//Aug/msg00001.html">APPLE-SA-2005-08-17</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014698">1014698</ref></refs><vuln_soft><prod name="Mac OS X" vendor="Apple"><vers num="10.3.9"/><vers num="10.4.2"/></prod><prod name="CUPS" vendor="Easy Software Products"><vers num="1.2.10"/></prod></vuln_soft></entry><entry CVSS_base_score="1.2" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="2.9" CVSS_score="1.2" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-08-08" name="CVE-2005-2527" published="2005-12-31" seq="2005-2527" severity="Low" type="CVE"><desc><descript source="cve">Race condition in Java 1.4.2 before 1.4.2 Release 2 on Apple Mac OS X allows local users to corrupt files or create arbitrary files via unspecified attack vectors related to a temporary directory, possibly due a symlink attack.</descript></desc><loss_types><int/></loss_types><vuln_types><race/></vuln_types><range><local/></range><refs><ref source="" url="http://docs.info.apple.com/article.html?artnum=302266"></ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/Sep/msg00001.html">APPLE-SA-2005-09-13</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/p-306.shtml">P-306</ref></refs><vuln_soft><prod name="Java" vendor="Sun"><vers num="1.4.2 Release1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-08-08" name="CVE-2005-2529" published="2005-12-31" seq="2005-2529" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Java 1.4.2 before 1.4.2 Release 2 on Apple Mac OS X allows local users to gain privileges via unspecified attack vectors relating to &quot;the utility used to update Java shared archives.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><env/></vuln_types><range><network/></range><refs><ref source="" url="http://docs.info.apple.com/article.html?artnum=302266"></ref><ref source="APPLE" url="http://lists.apple.com/archives/Security-announce/2005/Sep/msg00000.html">APPLE-SA-2005-09-13</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/p-306.shtml">P-306</ref></refs><vuln_soft><prod name="Java" vendor="Sun"><vers num="1.4.2"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-08-08" name="CVE-2005-2530" published="2005-12-31" seq="2005-2530" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Java 1.3.1 before 1.3.1_16 on Apple Mac OS X allows an untrusted applet to gain privileges, related to &quot;Mac OS X specific extensions.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><env/></vuln_types><range><network/></range><refs><ref source="" url="http://docs.info.apple.com/article.html?artnum=302265"></ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/Sep/msg00001.html">APPLE-SA-2005-09-13</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/p-306.shtml">P-306</ref></refs><vuln_soft><prod name="Java" vendor="Sun"><vers num="1.3.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2531" published="2005-08-24" seq="2005-2531" severity="Medium" type="CVE"><desc><descript source="cve">OpenVPN before 2.0.1, when running with &quot;verb 0&quot; and without TLS authentication, does not properly flush the OpenSSL error queue when a client fails certificate authentication to the server and causes the error to be processed by the wrong client, which allows remote attackers to cause a denial of service (client disconnection) via a large number of failed authentication attempts.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:145">MDKSA-2005:145</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-851">DSA-851</ref><ref source="" url="http://openvpn.net/changelog.html"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/16463">16463</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17103">17103</ref><ref source="BID" url="http://www.securityfocus.com/bid/14605">14605</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_20_sr.html">SUSE-SR:2005:020</ref></refs><vuln_soft><prod name="OpenVPN" vendor="OpenVPN"><vers num="2.0.1 rc7"/><vers num="2.0.1 rc6"/><vers num="2.0.1 rc5"/><vers num="2.0.1 rc4"/><vers num="2.0.1 rc3"/><vers num="2.0.1 rc2"/><vers num="2.0.1 rc1"/><vers num="2.0"/><vers num="2.0 rc21"/><vers num="2.0 rc20"/><vers num="2.0 rc19"/><vers num="2.0 rc18"/><vers num="2.0 rc17"/><vers num="2.0 rc16"/><vers num="2.0 rc15"/><vers num="2.0 rc14"/><vers num="2.0 rc13"/><vers num="2.0 rc12"/><vers num="2.0 rc11"/><vers num="2.0 rc10"/><vers num="2.0 rc9"/><vers num="2.0 rc8"/><vers num="2.0 rc7"/><vers num="2.0 rc6"/><vers num="2.0 rc5"/><vers num="2.0 rc4"/><vers num="2.0 rc3"/><vers num="2.0 rc2"/><vers num="2.0 rc1"/><vers num="2.0 Beta20"/><vers num="2.0 Beta19"/><vers num="2.0 Beta18"/><vers num="2.0 Beta17"/><vers num="2.0 Beta16"/><vers num="2.0 Beta15"/><vers num="2.0 Beta1"/><vers num="2.0 Beta13"/><vers num="2.0 Beta12"/><vers num="2.0 Beta11"/><vers num="2.0 Beta10"/><vers num="2.0 Beta9"/><vers num="2.0 Beta8"/><vers num="2.0 Beta7"/><vers num="2.0 Beta6"/><vers num="2.0 Beta5"/><vers num="2.0 Beta4"/><vers num="2.0 Beta3"/><vers num="2.0 Beta2"/><vers num="2.0 test29"/><vers num="2.0 Beta28"/><vers num="2.0 test27"/><vers num="2.0 test26"/><vers num="2.0 test24"/><vers num="2.0 test23"/><vers num="2.0 test22"/><vers num="2.0 test21"/><vers num="2.0 test20"/><vers num="2.0 test19"/><vers num="2.0 test18"/><vers num="2.0 test17"/><vers num="2.0 test16"/><vers num="2.0 test15"/><vers num="2.0 test14"/><vers num="2.0 test12"/><vers num="2.0 test11"/><vers num="2.0 test10"/><vers num="2.0 test9"/><vers num="2.0 test8"/><vers num="2.0 test7"/><vers num="2.0 test6"/><vers num="2.0 test5"/><vers num="2.0 test3"/><vers num="2.0 test2"/><vers num="2.0 test1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2532" published="2005-08-24" seq="2005-2532" severity="Medium" type="CVE"><desc><descript source="cve">OpenVPN before 2.0.1 does not properly flush the OpenSSL error queue when a packet can not be decrypted by the server, which allows remote authenticated attackers to cause a denial of service (client disconnection) via a large number of packets that can not be decrypted.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:145">MDKSA-2005:145</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-851">DSA-851</ref><ref source="" url="http://openvpn.net/changelog.html"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/16463">16463</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17103">17103</ref><ref source="BID" url="http://www.securityfocus.com/bid/14607">14607</ref></refs><vuln_soft><prod name="OpenVPN" vendor="OpenVPN"><vers num="2.0.1 rc7"/><vers num="2.0.1 rc6"/><vers num="2.0.1 rc5"/><vers num="2.0.1 rc4"/><vers num="2.0.1 rc3"/><vers num="2.0.1 rc2"/><vers num="2.0.1 rc1"/><vers num="2.0"/><vers num="2.0 rc21"/><vers num="2.0 rc20"/><vers num="2.0 rc19"/><vers num="2.0 rc18"/><vers num="2.0 rc17"/><vers num="2.0 rc16"/><vers num="2.0 rc15"/><vers num="2.0 rc14"/><vers num="2.0 rc13"/><vers num="2.0 rc12"/><vers num="2.0 rc11"/><vers num="2.0 rc10"/><vers num="2.0 rc9"/><vers num="2.0 rc8"/><vers num="2.0 rc7"/><vers num="2.0 rc6"/><vers num="2.0 rc5"/><vers num="2.0 rc4"/><vers num="2.0 rc3"/><vers num="2.0 rc2"/><vers num="2.0 rc1"/><vers num="2.0 Beta20"/><vers num="2.0 Beta19"/><vers num="2.0 Beta18"/><vers num="2.0 Beta17"/><vers num="2.0 Beta16"/><vers num="2.0 Beta15"/><vers num="2.0 Beta1"/><vers num="2.0 Beta13"/><vers num="2.0 Beta12"/><vers num="2.0 Beta11"/><vers num="2.0 Beta10"/><vers num="2.0 Beta9"/><vers num="2.0 Beta8"/><vers num="2.0 Beta7"/><vers num="2.0 Beta6"/><vers num="2.0 Beta5"/><vers num="2.0 Beta4"/><vers num="2.0 Beta3"/><vers num="2.0 Beta2"/><vers num="2.0 test29"/><vers num="2.0 Beta28"/><vers num="2.0 test27"/><vers num="2.0 test26"/><vers num="2.0 test24"/><vers num="2.0 test23"/><vers num="2.0 test22"/><vers num="2.0 test21"/><vers num="2.0 test20"/><vers num="2.0 test19"/><vers num="2.0 test18"/><vers num="2.0 test17"/><vers num="2.0 test16"/><vers num="2.0 test15"/><vers num="2.0 test14"/><vers num="2.0 test12"/><vers num="2.0 test11"/><vers num="2.0 test10"/><vers num="2.0 test9"/><vers num="2.0 test8"/><vers num="2.0 test7"/><vers num="2.0 test6"/><vers num="2.0 test5"/><vers num="2.0 test3"/><vers num="2.0 test2"/><vers num="2.0 test1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2533" published="2005-08-24" seq="2005-2533" severity="Low" type="CVE"><desc><descript source="cve">OpenVPN before 2.0.1, when running in &quot;dev tap&quot; Ethernet bridging mode, allows remote authenticated clients to cause a denial of service (memory exhaustion) via a flood of packets with a large number of spoofed MAC addresses.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:145">MDKSA-2005:145</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-851">DSA-851</ref><ref source="" url="http://openvpn.net/changelog.html"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/16463">16463</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17103">17103</ref></refs><vuln_soft><prod name="OpenVPN" vendor="OpenVPN"><vers num="2.0.1 rc7"/><vers num="2.0.1 rc6"/><vers num="2.0.1 rc5"/><vers num="2.0.1 rc4"/><vers num="2.0.1 rc3"/><vers num="2.0.1 rc2"/><vers num="2.0.1 rc1"/><vers num="2.0"/><vers num="2.0 rc21"/><vers num="2.0 rc20"/><vers num="2.0 rc19"/><vers num="2.0 rc18"/><vers num="2.0 rc17"/><vers num="2.0 rc16"/><vers num="2.0 rc15"/><vers num="2.0 rc14"/><vers num="2.0 rc13"/><vers num="2.0 rc12"/><vers num="2.0 rc11"/><vers num="2.0 rc10"/><vers num="2.0 rc9"/><vers num="2.0 rc8"/><vers num="2.0 rc7"/><vers num="2.0 rc6"/><vers num="2.0 rc5"/><vers num="2.0 rc4"/><vers num="2.0 rc3"/><vers num="2.0 rc2"/><vers num="2.0 rc1"/><vers num="2.0 Beta20"/><vers num="2.0 Beta19"/><vers num="2.0 Beta18"/><vers num="2.0 Beta17"/><vers num="2.0 Beta16"/><vers num="2.0 Beta15"/><vers num="2.0 Beta1"/><vers num="2.0 Beta13"/><vers num="2.0 Beta12"/><vers num="2.0 Beta11"/><vers num="2.0 Beta10"/><vers num="2.0 Beta9"/><vers num="2.0 Beta8"/><vers num="2.0 Beta7"/><vers num="2.0 Beta6"/><vers num="2.0 Beta5"/><vers num="2.0 Beta4"/><vers num="2.0 Beta3"/><vers num="2.0 Beta2"/><vers num="2.0 test29"/><vers num="2.0 Beta28"/><vers num="2.0 test27"/><vers num="2.0 test26"/><vers num="2.0 test24"/><vers num="2.0 test23"/><vers num="2.0 test22"/><vers num="2.0 test21"/><vers num="2.0 test20"/><vers num="2.0 test19"/><vers num="2.0 test18"/><vers num="2.0 test17"/><vers num="2.0 test16"/><vers num="2.0 test15"/><vers num="2.0 test14"/><vers num="2.0 test12"/><vers num="2.0 test11"/><vers num="2.0 test10"/><vers num="2.0 test9"/><vers num="2.0 test8"/><vers num="2.0 test7"/><vers num="2.0 test6"/><vers num="2.0 test5"/><vers num="2.0 test3"/><vers num="2.0 test2"/><vers num="2.0 test1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2534" published="2005-08-24" seq="2005-2534" severity="Low" type="CVE"><desc><descript source="cve">Race condition in OpenVPN before 2.0.1, when --duplicate-cn is not enabled, allows remote attackers to cause a denial of service (server crash) via simultaneous TCP connections from multiple clients that use the same client certificate.</descript></desc><loss_types><avail/></loss_types><vuln_types><race/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:145">MDKSA-2005:145</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-851">DSA-851</ref><ref source="" url="http://openvpn.net/changelog.html"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/16463">16463</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17103">17103</ref><ref source="BID" url="http://www.securityfocus.com/bid/14610">14610</ref></refs><vuln_soft><prod name="OpenVPN" vendor="OpenVPN"><vers num="2.0.1 rc7"/><vers num="2.0.1 rc6"/><vers num="2.0.1 rc5"/><vers num="2.0.1 rc4"/><vers num="2.0.1 rc3"/><vers num="2.0.1 rc2"/><vers num="2.0.1 rc1"/><vers num="2.0"/><vers num="2.0 rc21"/><vers num="2.0 rc20"/><vers num="2.0 rc19"/><vers num="2.0 rc18"/><vers num="2.0 rc17"/><vers num="2.0 rc16"/><vers num="2.0 rc15"/><vers num="2.0 rc14"/><vers num="2.0 rc13"/><vers num="2.0 rc12"/><vers num="2.0 rc11"/><vers num="2.0 rc10"/><vers num="2.0 rc9"/><vers num="2.0 rc8"/><vers num="2.0 rc7"/><vers num="2.0 rc6"/><vers num="2.0 rc5"/><vers num="2.0 rc4"/><vers num="2.0 rc3"/><vers num="2.0 rc2"/><vers num="2.0 rc1"/><vers num="2.0 Beta20"/><vers num="2.0 Beta19"/><vers num="2.0 Beta18"/><vers num="2.0 Beta17"/><vers num="2.0 Beta16"/><vers num="2.0 Beta15"/><vers num="2.0 Beta1"/><vers num="2.0 Beta13"/><vers num="2.0 Beta12"/><vers num="2.0 Beta11"/><vers num="2.0 Beta10"/><vers num="2.0 Beta9"/><vers num="2.0 Beta8"/><vers num="2.0 Beta7"/><vers num="2.0 Beta6"/><vers num="2.0 Beta5"/><vers num="2.0 Beta4"/><vers num="2.0 Beta3"/><vers num="2.0 Beta2"/><vers num="2.0 test29"/><vers num="2.0 Beta28"/><vers num="2.0 test27"/><vers num="2.0 test26"/><vers num="2.0 test24"/><vers num="2.0 test23"/><vers num="2.0 test22"/><vers num="2.0 test21"/><vers num="2.0 test20"/><vers num="2.0 test19"/><vers num="2.0 test18"/><vers num="2.0 test17"/><vers num="2.0 test16"/><vers num="2.0 test15"/><vers num="2.0 test14"/><vers num="2.0 test12"/><vers num="2.0 test11"/><vers num="2.0 test10"/><vers num="2.0 test9"/><vers num="2.0 test8"/><vers num="2.0 test7"/><vers num="2.0 test6"/><vers num="2.0 test5"/><vers num="2.0 test3"/><vers num="2.0 test2"/><vers num="2.0 test1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-25" name="CVE-2005-2535" published="2005-08-10" seq="2005-2535" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the Discovery Service in BrightStor ARCserve Backup 9.0 through 11.1 allows remote attackers to execute arbitrary commands via a large packet to TCP port 41523, a different vulnerability than CVE-2005-0260.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2005-02/0123.html">20050211 BrightStor ARCserve Backup buffer overflow PoC</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2005-02/0141.html">20050211 Re: BrightStor ARCserve Backup buffer overflow PoC</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2005-02/0201.html">20050215 Re: BrightStor ARCserve Backup buffer overflow PoC</ref><ref patch="1" source="" url="http://www3.ca.com/securityadvisor/vulninfo/vuln.aspx?ID=32478">http://www3.ca.com/securityadvisor/vulninfo/vuln.aspx?ID=32478</ref><ref patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/966880">VU#966880</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/12536">12536</ref><ref source="OSVDB" url="http://www.osvdb.org/13814">13814</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14293">14293</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19320">brightstor-discovery-servicepc-bo(19320)</ref></refs><vuln_soft><prod name="BrightStor Enterprise Backup Mainframe Linux" vendor="Computer Associates"><vers num="10.0"/></prod><prod name="BrightStor Enterprise Backup AIX" vendor="Computer Associates"><vers num="10.5"/><vers num="10.0"/></prod><prod name="BrightStor Enterprise Backup Tru64" vendor="Computer Associates"><vers num="10.5"/></prod><prod name="BrightStor Enterprise Backup HPUX" vendor="Computer Associates"><vers num="10.0"/></prod><prod name="BrightStor ARCServe Backup AIX" vendor="Computer Associates"><vers num="11.1"/></prod><prod name="BrightStor Enterprise Backup" vendor="Computer Associates"><vers num="10.5"/><vers num="10.0"/></prod><prod name="BrightStor ARCServe Backup NetWare" vendor="Computer Associates"><vers num="11.1"/><vers num="9.0"/></prod><prod name="BrightStor ARCServe Backup Solaris" vendor="Computer Associates"><vers num="11.1"/></prod><prod name="BrightStor ARCServe Backup Linux" vendor="Computer Associates"><vers num="11.1"/><vers num="9.0"/><vers num="7.0"/></prod><prod name="BrightStor Enterprise Backup Solaris" vendor="Computer Associates"><vers num="10.5"/><vers num="10.0"/></prod><prod name="BrightStor ARCServe Backup Tru64" vendor="Computer Associates"><vers num="11.1"/></prod><prod name="BrightStor ARCServe Backup HP" vendor="Computer Associates"><vers num="11.1"/></prod><prod name="BrightStor ARCServe Backup Macintosh" vendor="Computer Associates"><vers num="11.1"/></prod><prod name="BrightStor ARCServe Backup Mainframe Linux" vendor="Computer Associates"><vers num="11.1"/></prod><prod name="BrightStor ARCServe Backup Linux Japanese" vendor="Computer Associates"><vers num="9.0"/></prod><prod name="BrightStor ARCServe Backup Windows" vendor="Computer Associates"><vers num="11.1"/><vers num="11.0"/><vers num="9.0.1"/></prod><prod name="BrightStor Enterprise Backup HP" vendor="Computer Associates"><vers num="10.5"/></prod><prod name="BrightStor ARCserve 2000 Backup Windows Japanese" vendor="Computer Associates"><vers num=""/></prod><prod name="BrightStor Enterprise Backup Windows" vendor="Computer Associates"><vers num="10.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2536" published="2005-08-10" seq="2005-2536" severity="High" type="CVE"><desc><descript source="cve">pstotext before 1.8g does not properly use the &quot;-dSAFER&quot; option when calling Ghostscript to extract plain text from PostScript and PDF files, which allows remote attackers to execute arbitrary commands via a malicious PostScript file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200507-29.xml">GLSA-200507-29</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/16183/">16183</ref><ref source="BID" url="http://www.securityfocus.com/bid/14378">14378</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/21498">pstotext-dsafer-command-execution(21498)</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-792">DSA-792</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16305">16305</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16624">16624</ref></refs><vuln_soft><prod name="pstotext" vendor="pstotext"><vers num="1.9.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2537" published="2005-08-10" seq="2005-2537" severity="Medium" type="CVE"><desc><descript source="cve">FlatNuke 2.5.5 and possibly earlier versions allows remote attackers to obtain sensitive information via a direct request to structure.php.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112327238030127&amp;w=2">20050804 FlatNuke 2.5.5 (possibly prior versions) remote commands</ref><ref source="MISC" url="http://www.rgod.altervista.org/flatnuke.html">http://www.rgod.altervista.org/flatnuke.html</ref><ref source="OSVDB" url="http://www.osvdb.org/18549">18549</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16330">16330</ref></refs><vuln_soft><prod name="FlatNuke" vendor="FlatNuke"><vers num="2.5.5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2538" published="2005-08-10" seq="2005-2538" severity="Medium" type="CVE"><desc><descript source="cve">FlatNuke 2.5.5 and possibly earlier versions allows remote attackers to obtain sensitive information via (1) a null byte or (2) an MS-DOS device name such as AUX, CON, PRN, COM1, or LPT1 in the mod parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112327238030127&amp;w=2">20050804 FlatNuke 2.5.5 (possibly prior versions) remote commands</ref><ref source="MISC" url="http://www.rgod.altervista.org/flatnuke.html">http://www.rgod.altervista.org/flatnuke.html</ref><ref source="OSVDB" url="http://www.osvdb.org/18550">18550</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16330">16330</ref></refs><vuln_soft><prod name="FlatNuke" vendor="FlatNuke"><vers num="2.5.5"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2539" published="2005-08-10" seq="2005-2539" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in FlatNuke 2.5.5 and possibly earlier versions allow remote attackers to inject arbitrary web script or HTML via the (1) bodycolor, (2) backimage, (3) theme, or (4) logo parameter to structure.php, (5) admin, (6) admin_mail, or (7) back parameter to footer.php, or (8) the message body in a news post.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112327238030127&amp;w=2">20050804 FlatNuke 2.5.5 (possibly prior versions) remote commands</ref><ref source="MISC" url="http://www.rgod.altervista.org/flatnuke.html">http://www.rgod.altervista.org/flatnuke.html</ref><ref source="BID" url="http://www.securityfocus.com/bid/14483">14483</ref><ref source="OSVDB" url="http://www.osvdb.org/18551">18551</ref><ref source="OSVDB" url="http://www.osvdb.org/18552">18552</ref><ref source="OSVDB" url="http://www.osvdb.org/18553">18553</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16330">16330</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/21708">flatnuke-news-articles-xss(21708)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/21707">flatnuke-structure-xss(21707)</ref></refs><vuln_soft><prod name="FlatNuke" vendor="FlatNuke"><vers num="2.5.5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2540" published="2005-08-10" seq="2005-2540" severity="Medium" type="CVE"><desc><descript source="cve">CRLF injection vulnerability in FlatNuke 2.5.5 and possibly earlier versions allows remote attackers to execute arbitrary PHP commands via an ASCII char 13 (carriage return) in the signature field, which is injected into a PHP script without a preceding comment character, which can then be executed by a direct request.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112327238030127&amp;w=2">20050804 FlatNuke 2.5.5 (possibly prior versions) remote commands</ref><ref source="MISC" url="http://www.rgod.altervista.org/flatnuke.html">http://www.rgod.altervista.org/flatnuke.html</ref><ref source="BID" url="http://www.securityfocus.com/bid/14485">14485</ref><ref source="OSVDB" url="http://www.osvdb.org/18554">18554</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16330">16330</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/21709">flatNuke-firma-execute-commands(21709)</ref></refs><vuln_soft><prod name="FlatNuke" vendor="FlatNuke"><vers num="2.5.5"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-02-24" name="CVE-2005-2541" published="2005-08-10" seq="2005-2541" severity="High" type="CVE"><desc><descript source="cve">Tar 1.15.1 does not properly warn the user when extracting setuid or setgid files, which may allow local users or remote attackers to gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112327628230258&amp;w=2">20050804 tar preserves setuid bit</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112327628230258&amp;w=2">20050804 tar preserves setuid bit</ref></refs><vuln_soft><prod name="tar" vendor="GNU"><vers num="1.15.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2542" published="2005-08-10" seq="2005-2542" severity="Medium" type="CVE"><desc><descript source="cve">Invision Power Board (IPB) 1.0.3 allows remote attackers to inject arbitrary web script or HTML via an attachment, which is automatically downloaded and processed as HTML.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112327712614854&amp;w=2">20050805 ipb Css bug(now public)</ref><ref source="BID" url="http://www.securityfocus.com/bid/14492">14492</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16348">16348</ref></refs><vuln_soft><prod name="Invision Board" vendor="Invision Power Services"><vers num="2.1 Alpha2"/><vers num="2.0.4"/><vers num="2.0.3"/><vers num="2.0.2"/><vers num="2.0.1"/><vers num="2.0 PF2"/><vers num="2.0 PF1"/><vers num="2.0 PDR3"/><vers num="2.0 Alpha 3"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2543" published="2005-08-10" seq="2005-2543" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in wce.download.php in Comdev eCommerce 3.0 allows remote attackers to download arbitrary files via a .. (dot dot) in the download parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112327874920062&amp;w=2">20050805 Comdev eCommerce wce.download.php Download Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/14479">14479</ref></refs><vuln_soft><prod name="Comdev eCommerce" vendor="Comdev"><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2544" published="2005-08-10" seq="2005-2544" severity="Medium" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in config.php in Comdev eCommerce 3.0 allows remote attackers to execute arbitrary PHP code via the path[docroot] parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112327556202520&amp;w=2">20050805 Comdev eCommerce config.php Vulnerability</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/16346">16346</ref><ref source="BID" url="http://www.securityfocus.com/bid/14478">14478</ref><ref source="OSVDB" url="http://www.osvdb.org/18601">18601</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/21733">ecommerce-pathdocroot-file-include(21733)</ref></refs><vuln_soft><prod name="Comdev eCommerce" vendor="Comdev"><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2545" published="2005-08-10" seq="2005-2545" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in PHPOpenChat 3.0.2 allow remote attackers to inject arbitrary web script or HTML via the (1) title or (2) content parameter to profile.php and profile_misc.php, (3) the profile fields in userpage.php, (4) subject or (5) body in mail.php, or (8) disinvited_chatter or (7) invited_chatter parameter to invite.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112327181704137&amp;w=2">20050805 [HSC Security Group] Multiple XSS in phpopenchat 3.0.2</ref><ref source="BID" url="http://www.securityfocus.com/bid/14484">14484</ref><ref source="OSVDB" url="http://www.osvdb.org/18674">18674</ref><ref source="OSVDB" url="http://www.osvdb.org/18675">18675</ref><ref source="OSVDB" url="http://www.osvdb.org/18676">18676</ref><ref source="OSVDB" url="http://www.osvdb.org/18677">18677</ref><ref source="OSVDB" url="http://www.osvdb.org/18678">18678</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014634">1014634</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16350">16350</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/21761">phpopenchat-multiple-scripts-xss(21761)</ref></refs><vuln_soft><prod name="PHPOpenChat" vendor="PHPOpenChat"><vers num="3.0.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2546" published="2005-08-10" seq="2005-2546" severity="Medium" type="CVE"><desc><descript source="cve">Arab Portal 2.0 allows remote attackers to obtain sensitive information via a long (1) username or (2) password, which reveals the path in an error message when the undefined &quot;errmsg&quot; function is called.</descript></desc><loss_types><conf/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112300301707175&amp;w=2">20050801 Arab Portal</ref></refs><vuln_soft><prod name="Arab Portal" vendor="Arab Portal"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2547" published="2005-08-12" seq="2005-2547" severity="High" type="CVE"><desc><descript source="cve">security.c in hcid for BlueZ 2.16, 2.17, and 2.18 allows remote attackers to execute arbitrary commands via shell metacharacters in the Bluetooth device name when invoking the PIN helper.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="MLIST" url="http://sourceforge.net/mailarchive/forum.php?thread_id=7893206&amp;forum_id=1881">[bluez-devel] 20050804 Possible security vulnerability in hcid when calling pin helper</ref><ref adv="1" patch="1" source="" url="https://bugs.gentoo.org/show_bug.cgi?id=101557">https://bugs.gentoo.org/show_bug.cgi?id=101557</ref><ref patch="1" source="" url="http://cvs.sourceforge.net/viewcvs.py/bluez/utils/hcid/security.c?r1=1.31&amp;r2=1.34">http://cvs.sourceforge.net/viewcvs.py/bluez/utils/hcid/security.c?r1=1.31&amp;r2=1.34</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200508-09.xml">GLSA-200508-09</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16453">16453</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16476">16476</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-782">DSA-782</ref><ref source="BID" url="http://www.securityfocus.com/bid/14572">14572</ref></refs><vuln_soft><prod name="BlueZ" vendor="BlueZ Project"><vers num="2.18"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-06-14" name="CVE-2005-2548" published="2005-08-12" seq="2005-2548" severity="Medium" type="CVE"><desc><descript source="cve">vlan_dev.c in the VLAN code for Linux kernel 2.6.8 allows remote attackers to cause a denial of service (kernel oops from null dereference) via certain UDP packets that lead to a function call with the wrong argument, as demonstrated using snmpwalk on snmpd.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=309308">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=309308</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-169-1">USN-169-1</ref><ref source="" url="http://lists.osdl.org/pipermail/bridge/2004-September/000638.html"></ref><ref source="MANDRAKE" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2005:219">MDKSA-2005:219</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-922">DSA-922</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18056">18056</ref><ref source="BID" url="http://www.securityfocus.com/bid/14611">14611</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17826">17826</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:219">MDKSA-2005:219</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.6.8"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2549" published="2005-08-12" seq="2005-2549" severity="High" type="CVE"><desc><descript source="cve">Multiple format string vulnerabilities in Evolution 1.5 through 2.3.6.1 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via (1) full vCard data, (2) contact data from remote LDAP servers, or (3) task list data from remote servers.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=112368237712032&amp;w=2">20050810 Evolution multiple remote format string bugs</ref><ref source="MISC" url="http://www.sitic.se/eng/advisories_and_recommendations/sa05-001.html">http://www.sitic.se/eng/advisories_and_recommendations/sa05-001.html</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-166-1">USN-166-1</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16394">16394</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-announce-list/2005-August/msg00031.html">FEDORA-2005-743</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:141">MDKSA-2005:141</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-267.html">RHSA-2005:267</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_54_evolution.html">SUSE-SA:2005:054</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/407789">20050810 Evolution multiple remote format string bugs</ref><ref source="BID" url="http://www.securityfocus.com/bid/14532">14532</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1016">DSA-1016</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19380">19380</ref></refs><vuln_soft><prod name="Evolution" vendor="Gnome"><vers num="1.5"/><vers num="2.0"/><vers num="2.1"/><vers num="2.2"/><vers num="2.3.1"/><vers num="2.3.2"/><vers num="2.3.3"/><vers num="2.3.4"/><vers num="2.3.5"/><vers num="2.3.6.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2550" published="2005-08-12" seq="2005-2550" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in Evolution 1.4 through 2.3.6.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the calendar entries such as task lists, which are not properly handled when the user selects the Calendars tab.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=112368237712032&amp;w=2">20050810 Evolution multiple remote format string bugs</ref><ref source="MISC" url="http://www.sitic.se/eng/advisories_and_recommendations/sa05-001.html">http://www.sitic.se/eng/advisories_and_recommendations/sa05-001.html</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-166-1">USN-166-1</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16394">16394</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-announce-list/2005-August/msg00031.html">FEDORA-2005-743</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:141">MDKSA-2005:141</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-267.html">RHSA-2005:267</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_54_evolution.html">SUSE-SA:2005:054</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/407789">20050810 Evolution multiple remote format string bugs</ref><ref source="BID" url="http://www.securityfocus.com/bid/14532">14532</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1016">DSA-1016</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19380">19380</ref></refs><vuln_soft><prod name="Evolution" vendor="Gnome"><vers num="1.4"/><vers num="1.5"/><vers num="2.0"/><vers num="2.1"/><vers num="2.2"/><vers num="2.3.1"/><vers num="2.3.2"/><vers num="2.3.3"/><vers num="2.3.4"/><vers num="2.3.5"/><vers num="2.3.6.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2551" published="2005-08-12" seq="2005-2551" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in dhost.exe in iMonitor for Novell eDirectory 8.7.3 on Windows allows attackers to cause a denial of service (crash) and obtain access to files via unknown vectors.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://support.novell.com/cgi-bin/search/searchtid.cgi?/10098568.htm">http://support.novell.com/cgi-bin/search/searchtid.cgi?/10098568.htm</ref><ref patch="1" source="" url="http://support.novell.com/cgi-bin/search/searchtid.cgi?/2972038.htm">http://support.novell.com/cgi-bin/search/searchtid.cgi?/2972038.htm</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/213165">VU#213165</ref><ref source="BID" url="http://www.securityfocus.com/bid/14548">14548</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014661">1014661</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16393">16393</ref></refs><vuln_soft><prod name="eDirectory" vendor="Novell"><vers num="8.7.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2552" published="2005-08-12" seq="2005-2552" severity="High" type="CVE"><desc><descript source="cve">Unknown vulnerability in HP ProLiant DL585 servers running Integrated Lights Out (ILO) firmware before 1.81 allows attackers to access server controls when the server is &quot;powered down.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/14540">14540</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014658">1014658</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16402">16402</ref><ref source="HP" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112369495001738&amp;w=2">HPSBMA01220</ref></refs><vuln_soft><prod name="ProLiant DL585" vendor="HP"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2553" published="2005-08-12" seq="2005-2553" severity="Low" type="CVE"><desc><descript source="cve">The find_target function in ptrace32.c in the Linux kernel 2.4.x before 2.4.29 does not properly handle a NULL return value from another function, which allows local users to cause a denial of service (kernel crash/oops) by running a 32-bit ltrace program with the -i option on a 64-bit executable program.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><local/></range><refs><ref adv="1" source="" url="http://lkml.org/lkml/2005/1/5/245">http://lkml.org/lkml/2005/1/5/245</ref><ref adv="1" source="" url="http://linux.bkbits.net:8080/linux-2.4/cset@41dd3455GwQPufrGvBJjcUOXQa3WXA">http://linux.bkbits.net:8080/linux-2.4/cset@41dd3455GwQPufrGvBJjcUOXQa3WXA</ref><ref source="BID" url="http://www.securityfocus.com/bid/14965">14965</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-921">DSA-921</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18059">18059</ref><ref source="MANDRIVA" url="http://wwwnew.mandriva.com/security/advisories?name=MDKSA-2006:044">MDKSA-2006:044</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18977">18977</ref><ref source="SUSE" url="http://lists.suse.de/archive/suse-security-announce/2006-Feb/0010.html">SUSE-SA:2006:012</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19038">19038</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-663.html">RHSA-2005:663</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/428058/100/0/threaded">FLSA:157459-2</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17002">17002</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/1878">ADV-2005-1878</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.4.9"/><vers num="2.4.8"/><vers num="2.4.7"/><vers num="2.4.6"/><vers num="2.4.5"/><vers num="2.4.4"/><vers num="2.4.3-pre3"/><vers num="2.4.3"/><vers num="2.4.29-rc2"/><vers num="2.4.29-rc1"/><vers num="2.4.29 -rc2"/><vers num="2.4.29 -rc1"/><vers num="2.4.29"/><vers num="2.4.28"/><vers num="2.4.27-pre5"/><vers num="2.4.27-pre4"/><vers num="2.4.27-pre3"/><vers num="2.4.27-pre2"/><vers num="2.4.27-pre1"/><vers num="2.4.27 -pre5"/><vers num="2.4.27 -pre4"/><vers num="2.4.27 -pre3"/><vers num="2.4.27 -pre2"/><vers num="2.4.27 -pre1"/><vers num="2.4.27"/><vers num="2.4.26"/><vers num="2.4.25"/><vers num="2.4.24-ow1"/><vers num="2.4.24 ow1"/><vers num="2.4.24"/><vers num="2.4.23-pre9"/><vers num="2.4.23-ow2"/><vers num="2.4.23 -pre9"/><vers num="2.4.23 -ow2"/><vers num="2.4.23"/><vers num="2.4.22-pre10"/><vers num="2.4.22 -pre10"/><vers num="2.4.22"/><vers num="2.4.21-pre7"/><vers num="2.4.21-pre4"/><vers num="2.4.21-pre1"/><vers num="2.4.21 pre7"/><vers num="2.4.21 pre4"/><vers num="2.4.21 pre1"/><vers num="2.4.21"/><vers num="2.4.20"/><vers num="2.4.2"/><vers num="2.4.19-pre6"/><vers num="2.4.19-pre5"/><vers num="2.4.19-pre4"/><vers num="2.4.19-pre3"/><vers num="2.4.19-pre2"/><vers num="2.4.19-pre1"/><vers num="2.4.19 -pre6"/><vers num="2.4.19 -pre5"/><vers num="2.4.19 -pre4"/><vers num="2.4.19 -pre3"/><vers num="2.4.19 -pre2"/><vers num="2.4.19 -pre1"/><vers num="2.4.19"/><vers num="2.4.18-x86"/><vers num="2.4.18-pre-8"/><vers num="2.4.18-pre-7"/><vers num="2.4.18-pre-6"/><vers num="2.4.18-pre-5"/><vers num="2.4.18-pre-4"/><vers num="2.4.18-pre-3"/><vers num="2.4.18-pre-2"/><vers num="2.4.18-pre-1"/><vers edition="x86" num="2.4.18"/><vers num="2.4.18 pre-8"/><vers num="2.4.18 pre-7"/><vers num="2.4.18 pre-6"/><vers num="2.4.18 pre5"/><vers num="2.4.18 pre4"/><vers num="2.4.18 pre3"/><vers num="2.4.18 pre2"/><vers num="2.4.18 pre1"/><vers num="2.4.18"/><vers num="2.4.17"/><vers num="2.4.16"/><vers num="2.4.15"/><vers num="2.4.14"/><vers num="2.4.13"/><vers num="2.4.12"/><vers num="2.4.11"/><vers num="2.4.10"/><vers num="2.4.1"/><vers num="2.4.0 test9"/><vers num="2.4.0 test8"/><vers num="2.4.0 test7"/><vers num="2.4.0 test6"/><vers num="2.4.0 test5"/><vers num="2.4.0 test4"/><vers num="2.4.0 test3"/><vers num="2.4.0 test2"/><vers num="2.4.0 test12"/><vers num="2.4.0 test11"/><vers num="2.4.0 test10"/><vers num="2.4.0 test1"/><vers num="2.4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2554" published="2005-08-12" seq="2005-2554" severity="Low" type="CVE"><desc><descript source="cve">The web server for Network Associates ePolicy Orchestrator Agent 3.5.0 (patch 3) uses insecure permissions for the &quot;Common Framework\Db&quot; folder, which allows local users to read arbitrary files by creating a subfolder in the EPO agent web root directory.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" source="FULLDISC" url="http://lists.virus.org/full-disclosure-0508/msg00376.html">20050811 Privilege escalation in Network Associates ePolicy Orchestrator Agent 3.5.0 (patch 3)</ref><ref source="MISC" url="http://reedarvin.thearvins.com/20050811-01.html">http://reedarvin.thearvins.com/20050811-01.html</ref><ref source="BID" url="http://www.securityfocus.com/bid/14549">14549</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/1402">ADV-2005-1402</ref><ref source="OSVDB" url="http://www.osvdb.org/18735">18735</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16410">16410</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/21839">epolicy-orchestrator-gain-privileges(21839)</ref><ref source="" url="http://knowledgemap.nai.com/KanisaSupportSite/search.do?cmd=displayKC&amp;docType=kc&amp;externalId=KBkb42216xml"></ref></refs><vuln_soft><prod name="ePolicy Orchestrator Agent" vendor="Network Associates"><vers num="3.5.0 (patch 3)"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2555" published="2005-08-16" seq="2005-2555" severity="Medium" type="CVE"><desc><descript source="cve">Linux kernel 2.6.x does not properly restrict socket policy access to users with the CAP_NET_ADMIN capability, which could allow local users to conduct unauthorized activities via (1) ipv4/ip_sockglue.c and (2) ipv6/ipv6_sockglue.c.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref source="" url="http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=6fc0b4a7a73a81e74d0004732df358f4f9975be2">http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=6fc0b4a7a73a81e74d0004732df358f4f9975be2</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-169-1">USN-169-1</ref><ref source="SUSE-SA" url="http://www.novell.com/linux/security/advisories/2005_50_kernel.html">2005:050</ref><ref source="MANDRAKE" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2005:218">MDKSA-2005:218</ref><ref source="MANDRAKE" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2005:219">MDKSA-2005:219</ref><ref source="BID" url="http://www.securityfocus.com/bid/14609">14609</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-514.html">RHSA-2005:514</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-663.html">RHSA-2005:663</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/427980/100/0/threaded">FLSA:157459-3</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1017">DSA-1017</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17073">17073</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17826">17826</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1018">DSA-1018</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19374">19374</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19369">19369</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17002">17002</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/1878">ADV-2005-1878</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:218">MDKSA-2005:218</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:219">MDKSA-2005:219</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.6 test9 CVS"/><vers num="2.6 test9"/><vers num="2.6 test8"/><vers num="2.6 test7"/><vers num="2.6 test6"/><vers num="2.6 test5"/><vers num="2.6 test4"/><vers num="2.6 test3"/><vers num="2.6 test2"/><vers num="2.6 test11"/><vers num="2.6 test10"/><vers num="2.6 test1"/><vers edition="2.6.20" num="2.6.9"/><vers num="2.6.8 rc3"/><vers num="2.6.8 rc2"/><vers num="2.6.8 rc1"/><vers edition="PowerPC_smp" num="2.6.8.1.5"/><vers edition="PowerPC" num="2.6.8.1.5"/><vers edition="Power4_smp" num="2.6.8.1.5"/><vers edition="Power4" num="2.6.8.1.5"/><vers edition="Power3_smp" num="2.6.8.1.5"/><vers edition="Power3" num="2.6.8.1.5"/><vers edition="K7_smp" num="2.6.8.1.5"/><vers edition="K7" num="2.6.8.1.5"/><vers edition="AMD64_Xeon" num="2.6.8.1.5"/><vers edition="AMD64_K8_smp" num="2.6.8.1.5"/><vers edition="AMD64_K8" num="2.6.8.1.5"/><vers edition="AMD64" num="2.6.8.1.5"/><vers edition="686_smp" num="2.6.8.1.5"/><vers edition="686" num="2.6.8.1.5"/><vers edition="386" num="2.6.8.1.5"/><vers num="2.6.8.1.5"/><vers num="2.6.8.1"/><vers num="2.6.8"/><vers num="2.6.7 rc1"/><vers num="2.6.7"/><vers num="2.6.6 rc1"/><vers num="2.6.6"/><vers num="2.6.5"/><vers num="2.6.4"/><vers num="2.6.3"/><vers num="2.6.2"/><vers num="2.6.1 rc2"/><vers num="2.6.1 rc1"/><vers num="2.6.12 rc4"/><vers num="2.6.12 rc1"/><vers num="2.6.11 rc4"/><vers num="2.6.11 rc3"/><vers num="2.6.11 rc2"/><vers num="2.6.11 rc1 bk6"/><vers num="2.6.11.8"/><vers num="2.6.11.7"/><vers num="2.6.11.6"/><vers num="2.6.11.5"/><vers num="2.6.11.4"/><vers num="2.6.11.3"/><vers num="2.6.11.2"/><vers num="2.6.11.1"/><vers num="2.6.11 rc1"/><vers num="2.6.11"/><vers num="2.6.10 rc2"/><vers num="2.6.10"/><vers num="2.6.1"/><vers num="2.6.0"/><vers num="2.6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2556" published="2005-08-24" seq="2005-2556" severity="High" type="CVE"><desc><descript source="cve">core/database_api.php in Mantis 0.19.0a1 through 1.0.0a3, with register_globals enabled, allows remote attackers to connect to internal databases by modifying the g_db_type variable and monitoring the speed of responses, as identified by bug#0005956.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-778">DSA-778</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/14604">14604</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/16506/">16506</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112786017426276&amp;w=2">20050926 Mantis Bugtracker - Remote Database Scanner and XSS Vulnerabilities</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200509-16.xml">GLSA-200509-16</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16506">16506</ref></refs><vuln_soft><prod name="Mantis" vendor="Mantis"><vers num="1.0.0a3"/><vers num="1.0.0a2"/><vers num="1.0.0a1"/><vers num="0.19.2"/><vers num="0.19.1"/><vers num="0.19.0"/><vers num="0.19.0 rc1"/><vers num="0.19.0a2"/><vers num="0.19.0a1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-25" name="CVE-2005-2557" published="2005-09-28" seq="2005-2557" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in view_all_set.php in Mantis 0.19.0a1 through 1.0.0a3 allows remote attackers to inject arbitrary web script or HTML via the dir parameter, as identified by bug#0005959, and a different vulnerability than CVE-2005-3090.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.mantisbt.org/changelog.php"></ref><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-778">DSA-778</ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200509-16.xml">GLSA-200509-16</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/14604">14604</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/16506/">16506</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/21958">mantis-bug-report-xss(21958)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112786017426276&amp;w=2">20050926 Mantis Bugtracker - Remote Database Scanner and XSS Vulnerabilities</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16506">16506</ref></refs><vuln_soft><prod name="Linux" vendor="Gentoo"><vers num=""/></prod><prod name="Mantis" vendor="Mantis"><vers num="1.0.0a3"/><vers num="1.0.0a2"/><vers num="1.0.0a1"/><vers num="0.19.2"/><vers num="0.19.1"/><vers num="0.19.0"/><vers num="0.19.0 rc1"/><vers num="0.19.0a2"/><vers num="0.19.0a1"/></prod><prod name="Debian Linux" vendor="Debian"><vers num="3.1 sparc"/><vers num="3.1 s_390"/><vers num="3.1 ppc"/><vers num="3.1 mipsel"/><vers num="3.1 mips"/><vers num="3.1 m68k"/><vers num="3.1 ia-64"/><vers num="3.1 ia-32"/><vers num="3.1 hppa"/><vers num="3.1 arm"/><vers num="3.1 amd64"/><vers num="3.1 alpha"/><vers num="3.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-03-28" name="CVE-2005-2558" published="2005-08-16" seq="2005-2558" severity="Medium" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in the init_syms function in MySQL 4.0 before 4.0.25, 4.1 before 4.1.13, and 5.0 before 5.0.7-beta allows remote authenticated users who can create user-defined functions to execute arbitrary code via a long function_name field.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112354450412427&amp;w=2">20050808 [AppSecInc Advisory MYSQL05-V0002] Buffer Overflow in MySQL User Defined Functions</ref><ref adv="1" patch="1" source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-August/035845.html">20050808 [AppSecInc Advisory MYSQL05-V0002] Buffer Overflow in MySQL User Defined Functions</ref><ref adv="1" patch="1" source="MISC" url="http://www.appsecinc.com/resources/alerts/mysql/2005-002.html">http://www.appsecinc.com/resources/alerts/mysql/2005-002.html</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/14509">14509</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/21737">mysql-user-defined-function-bo(21737)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112354450412427&amp;w=2">20050808 [AppSecInc Advisory MYSQL05-V0002] Buffer Overflow in MySQL User Defined Functions</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:163">MDKSA-2005:163</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-829">DSA-829</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-831">DSA-831</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-833">DSA-833</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/usn/usn-180-1/document_view">USN-180-1</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-180-2">USN-180-2</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00005.html">FLSA-2006:167803</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_21_sr.html">SUSE-SR:2005:021</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17027">17027</ref><ref source="SCO" url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2006.18.1/SCOSA-2006.18.1.txt">SCOSA-2006.18</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20381">20381</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-236703-1">236703</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/1326/references">ADV-2008-1326</ref><ref source="SECUNIA" url="http://secunia.com/advisories/29847">29847</ref></refs><vuln_soft><prod name="MySQL" vendor="MySQL"><vers num="5.0.4"/><vers num="5.0.3"/><vers num="5.0.2"/><vers num="5.0.1"/><vers num="5.0.0 alpha"/><vers num="5.0.0.0"/><vers num="4.1.5"/><vers num="4.1.4"/><vers num="4.1.3 beta"/><vers num="4.1.3.0"/><vers num="4.1.2 alpha"/><vers num="4.1.10a"/><vers num="4.1.0 alpha"/><vers num="4.1.0.0"/><vers num="4.0.24"/><vers num="4.0.21"/><vers num="4.0.20"/><vers num="4.0.18"/><vers num="4.0.15"/><vers num="4.0.14"/><vers num="4.0.13"/><vers num="4.0.12"/><vers num="4.0.11 gamma"/><vers num="4.0.11"/><vers num="4.0.10"/><vers num="4.0.9 gamma"/><vers num="4.0.9"/><vers num="4.0.8 gamma"/><vers num="4.0.8"/><vers num="4.0.7 gamma"/><vers num="4.0.7"/><vers num="4.0.6"/><vers num="4.0.5a"/><vers num="4.0.5"/><vers num="4.0.4"/><vers num="4.0.3"/><vers num="4.0.2"/><vers num="4.0.1"/><vers num="4.0.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-04-07" name="CVE-2005-2559" published="2005-08-16" seq="2005-2559" severity="High" type="CVE"><desc><descript source="cve">doping.php in ePing plugin 1.02 and earlier for e107 portal allows remote attackers to execute arbitrary code or overwrite files via (1) shell metacharacters in the eping_count parameter or (2) restricted shell metacharacters such as &quot;&gt;&quot; and &quot;&amp;&quot; in the eping_host parameter, which is not handled by the validation function.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://e107plugins.co.uk/news.php">http://e107plugins.co.uk/news.php</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112328161319148&amp;w=2">20050805 Vulnerability in ePing and eTrace plugins of e107</ref></refs><vuln_soft><prod name="e107" vendor="e107"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2560" published="2005-08-16" seq="2005-2560" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in index.cfm in CFBB 1.1.0 allows remote attackers to inject arbitrary web script or HTML via the page parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/14440">14440</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16311">16311</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112352059715868&amp;w=2">20050805 XSS in forums CFBB v1.1.0</ref></refs><vuln_soft><prod name="CFBB" vendor="ADER Software"><vers num="1.1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2561" published="2005-08-16" seq="2005-2561" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in MYFAQ 1.0 allow remote attackers to execute arbitrary SQL commands via the Theme parameter to (1) affichagefaq.php3, (2) choixsoustheme.php3, (3) consultation.php3, (4) insfaq.php3, (5) inssoustheme.php3, (6) instheme.php3, (7) saisiefaqtotale.php3, (8) saisiesoustheme.php3, or (9) voirfaq.php3, the SousTheme parameter to (10) affichagefaq.php3, (11) consultation.php3, (12) insfaq.php3, (13) inssoustheme.php3, (14) saisiefaq.php3, (15) saisiefaqtotale.php3, or (16) voirfaq.php3, the Faq parameter to (17) saisiefaq.php3, (18) voirfaq.php3, or (19) inssolution.php3, or (20) question parameter to affichagefaq.php3.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112352204602309&amp;w=2">20050806 [SVadvisory#13] - SQL injection in MYFAQ 1.0</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/16366/">MyFAQ Multiple Scripts SQL Injection Vulnerability</ref><ref source="" url="http://svt.nukleon.us/lab/svadvisory13.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/14503">14503</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16366">16366</ref></refs><vuln_soft><prod name="MYFAQ" vendor="MYFAQ"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2562" published="2005-08-16" seq="2005-2562" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in Gravity Board X (GBX) 1.1 allows remote attackers to execute arbitrary SQL commands and bypass authentication via the login field.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/14497">14497</ref><ref source="SECTRACK" url="http://securitytracker.com/alerts/2005/Aug/1014631.html">1014631</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/21740">gravityboardx-login-bypass-authentication(21740)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112351740803443&amp;w=2">20050807 Gravity Board X v1.1 multiple vulnerabilities</ref></refs><vuln_soft><prod name="Gravity Board X" vendor="Gravity Board X Development Team"><vers num="1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2563" published="2005-08-16" seq="2005-2563" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Gravity Board X (GBX) 1.1 allow remote attackers to inject arbitrary web script or HTML via (1) the board_id parameter to deletethread.php or (2) the template.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/14497">14497</ref><ref source="SECTRACK" url="http://securitytracker.com/alerts/2005/Aug/1014631.html">1014631</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112351740803443&amp;w=2">20050807 Gravity Board X v1.1 multiple vulnerabilities</ref></refs><vuln_soft><prod name="Gravity Board X" vendor="Gravity Board X Development Team"><vers num="1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2564" published="2005-08-16" seq="2005-2564" severity="High" type="CVE"><desc><descript source="cve">Direct static code injection vulnerability in editcss.php in Gravity Board X (GBX) 1.1 allows remote attackers to execute arbitrary PHP code, HTML, and script via the csscontent parameter, which is directly inserted into the gbxfinal.css file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112351740803443&amp;w=2">20050807 Gravity Board X v1.1 multiple vulnerabilities</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/21742">gravityboardx-template-xss(21742)</ref></refs><vuln_soft><prod name="Gravity Board X" vendor="Gravity Board X Development Team"><vers num="1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2565" published="2005-08-16" seq="2005-2565" severity="Medium" type="CVE"><desc><descript source="cve">Gravity Board X (GBX) 1.1 allows remote attackers to obtain sensitive information via (1) a 1 in the perm parameter to deletethread.php or a direct request to (2) ban.php, (3) addnews.php, (4) banned.php, (5) boardstats.php, (6) adminform.php, (7) /forms/admininfo.php, (8) /forms/announcements.php, (9) forms/banform.php, or (10) other pages in the /forms directory, which reveal the path in an error message.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112351740803443&amp;w=2">20050807 Gravity Board X v1.1 multiple vulnerabilities</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/21746">gravityboardx-multiple-path-disclosure(21746)</ref></refs><vuln_soft><prod name="Gravity Board X" vendor="Gravity Board X Development Team"><vers num="1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2566" published="2005-08-16" seq="2005-2566" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in Open Bulletin Board (OpenBB) allow remote attackers to execute arbitrary SQL commands via the (1) FID parameter to board.php or (2) UID parameter to member.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112351834624072&amp;w=2">20050808 SQL IN Open Bulletin Board</ref></refs><vuln_soft><prod name="OpenBB" vendor="OpenBB"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-22" name="CVE-2005-2567" published="2005-08-16" seq="2005-2567" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in SysCP 1.2.10 and earlier allows remote attackers to execute arbitrary PHP code via the language parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="MISC" url="http://www.hardened-php.net/advisory_132005.64.html">http://www.hardened-php.net/advisory_132005.64.html</ref><ref patch="1" source="" url="http://www.syscp.de/forum/viewtopic.php?t=1772">http://www.syscp.de/forum/viewtopic.php?t=1772</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112352095923614&amp;w=2">20050808 Advisory 13/2005: Remote code execution in SysCP</ref></refs><vuln_soft><prod name="SysCP" vendor="SysCP Team"><vers num="1.2.10" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2568" published="2005-08-16" seq="2005-2568" severity="High" type="CVE"><desc><descript source="cve">Eval injection vulnerability in the template engine for SysCP 1.2.10 and earlier allows remote attackers to execute arbitrary PHP code via a string containing the code within &quot;{&quot; and &quot;}&quot; (curly bracket) characters, which are processed by the PHP eval function.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112352095923614&amp;w=2">20050808 Advisory 13/2005: Remote code execution in SysCP</ref><ref adv="1" source="MISC" url="http://www.hardened-php.net/advisory_132005.64.html">http://www.hardened-php.net/advisory_132005.64.html</ref><ref patch="1" source="" url="http://www.syscp.de/forum/viewtopic.php?t=1772">http://www.syscp.de/forum/viewtopic.php?t=1772</ref></refs><vuln_soft><prod name="SysCP" vendor="SysCP Team"><vers num="1.2.10"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2569" published="2005-08-16" seq="2005-2569" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in FunkBoard 0.66CF, and possibly earlier versions, allow remote attackers to inject arbitrary web script or HTML via the fbusername or fbpassword parameter to (1) editpost.php, (2) prefs.php, (3) newtopic.php, (4) reply.php, or (5) profile.php, the (6) fbusername, (7) fmail, (8) www, (9) icq, (10) yim, (11) location, (12) sex, (13) interebbies, (14) sig or (15) aim parameter to register.php, or (16) subject parameter to newtopic.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112360702307424&amp;w=2">20050808 FunkBoard V0.66CF (possibly prior versions) cross site scripting, possible database username/password disclosure &amp; board takeover, possible remote code execution</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112413891603018&amp;w=2">20050813 Re: FunkBoard V0.66CF (possibly prior versions) cross site scripting, possible database username/password disclosure &amp; board takeover, possible remote code execution</ref></refs><vuln_soft><prod name="Funkboard" vendor="Funkboard"><vers num="0.66F" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-05" name="CVE-2005-2570" published="2005-08-16" seq="2005-2570" severity="Medium" type="CVE"><desc><descript source="cve">FunkBoard 0.66CF, and possibly earlier versions, allows remote attackers to obtain sensitive information via a direct request to forums.php, which reveals the path in an error message.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref patch="1" source="FunkBoard" url="http://www.funkboard.co.uk/downloads.php">FunkBoard</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112360702307424&amp;w=2">20050808 FunkBoard V0.66CF (possibly prior versions) cross site scripting, possible database username/password disclosure &amp; board takeover, possible remote code execution</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112413891603018&amp;w=2">20050813 Re: FunkBoard V0.66CF (possibly prior versions) cross site scripting, possible database username/password disclosure &amp; board takeover, possible remote code execution</ref></refs><vuln_soft><prod name="FunkBoard" vendor="FunkBoard"><vers num="0.66CF"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2571" published="2005-08-16" seq="2005-2571" severity="Medium" type="CVE"><desc><descript source="cve">FunkBoard 0.66CF, and possibly earlier versions, does not properly restrict access to the (1) admin/mysql_install.php and (2) admin/pg_install.php scripts, which allows attackers to obtain the database username and password or inject arbitrary PHP code into info.php.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112360702307424&amp;w=2">20050808 FunkBoard V0.66CF (possibly prior versions) cross site scripting, possible database username/password disclosure &amp; board takeover, possible remote code execution</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112413891603018&amp;w=2">20050813 Re: FunkBoard V0.66CF (possibly prior versions) cross site scripting, possible database username/password disclosure &amp; board takeover, possible remote code execution</ref><ref source="" url="http://www.funkboard.co.uk/forum/thread.php?id=265"></ref></refs><vuln_soft><prod name="Funkboard" vendor="Funkboard"><vers num="0.66F" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-03-28" name="CVE-2005-2572" published="2005-08-16" seq="2005-2572" severity="Medium" type="CVE"><desc><descript source="cve">MySQL, when running on Windows, allows remote authenticated users with insert privileges on the mysql.func table to cause a denial of service (server hang) and possibly execute arbitrary code via (1) a request for a non-library file, which causes the Windows LoadLibraryEx function to block, or (2) a request for a function in a library that has the XXX_deinit or XXX_init functions defined but is not tailored for mySQL, such as jpeg1x32.dll and jpeg2x32.dll.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112360818900941&amp;w=2">20050808 [AppSecInc Advisory MYSQL05-V0003] Multiple Issues with MySQL User Defined Functions</ref><ref adv="1" source="MISC" url="http://www.appsecinc.com/resources/alerts/mysql/2005-003.html">http://www.appsecinc.com/resources/alerts/mysql/2005-003.html</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/21756">mysql-loadlibraryex-dos(21756)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112360818900941&amp;w=2">20050808 [AppSecInc Advisory MYSQL05-V0003] Multiple Issues with MySQL User Defined Functions</ref></refs><vuln_soft><prod name="MySQL" vendor="MySQL"><vers num="5.0.33"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-03-28" name="CVE-2005-2573" published="2005-08-16" seq="2005-2573" severity="Medium" type="CVE"><desc><descript source="cve">The mysql_create_function function in sql_udf.cc for MySQL 4.0 before 4.0.25, 4.1 before 4.1.13, and 5.0 before 5.0.7-beta, when running on Windows, uses an incomplete blacklist in a directory traversal check, which allows attackers to include arbitrary files via the backslash (\) character.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-August/035847.html">20050808 [AppSecInc Advisory MYSQL05-V0001] Improper Filtering of Directory Traversal Characters in MySQL User Defined Functions</ref><ref adv="1" patch="1" source="MISC" url="http://www.appsecinc.com/resources/alerts/mysql/2005-001.html">http://www.appsecinc.com/resources/alerts/mysql/2005-001.html</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/21738">mysql-udf-directory-traversal(21738)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112360618320729&amp;w=2">20050808 [AppSecInc Advisory MYSQL05-V0001] Improper Filtering of Directory Traversal Characters in MySQL User Defined Functions</ref><ref source="" url="http://mysql.bkbits.net:8080/mysql-4.0/cset@428b981bg2iwh3CbGANDaF-W6DbttA"></ref><ref source="" url="http://mysql.bkbits.net:8080/mysql-4.0/gnupatch@428b981bg2iwh3CbGANDaF-W6DbttA"></ref></refs><vuln_soft><prod name="MySQL" vendor="MySQL"><vers num="5.0.4"/><vers num="5.0.3"/><vers num="5.0.2"/><vers num="5.0.1"/><vers num="5.0.0 alpha"/><vers num="5.0.0.0"/><vers num="4.1.5"/><vers num="4.1.4"/><vers num="4.1.3 beta"/><vers num="4.1.3.0"/><vers num="4.1.2 alpha"/><vers num="4.1.10a"/><vers num="4.1.0 alpha"/><vers num="4.1.0.0"/><vers num="4.0.24"/><vers num="4.0.21"/><vers num="4.0.20"/><vers num="4.0.18"/><vers num="4.0.15"/><vers num="4.0.14"/><vers num="4.0.13"/><vers num="4.0.12"/><vers num="4.0.11 gamma"/><vers num="4.0.11"/><vers num="4.0.10"/><vers num="4.0.9 gamma"/><vers num="4.0.9"/><vers num="4.0.8 gamma"/><vers num="4.0.8"/><vers num="4.0.7 gamma"/><vers num="4.0.7"/><vers num="4.0.6"/><vers num="4.0.5a"/><vers num="4.0.5"/><vers num="4.0.4"/><vers num="4.0.3"/><vers num="4.0.2"/><vers num="4.0.1"/><vers num="4.0.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2574" published="2005-08-16" seq="2005-2574" severity="Medium" type="CVE"><desc><descript source="cve">xmb.php in XMB Forum 1.9.1 extracts and defines all provided variables, which allows remote attackers to modify arbitrary server variables such as _SERVER[REMOTE_ADDR].</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="MISC" url="http://forums.xmbforum.com/viewthread.php?tid=754523">http://forums.xmbforum.com/viewthread.php?tid=754523</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112361545228809&amp;w=2">20050809 Sql injection and global variables poisoning in XMB Forum 1.9.1</ref></refs><vuln_soft><prod name="XMB" vendor="XMB Forum"><vers num="1.9.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2575" published="2005-08-16" seq="2005-2575" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in u2u.inc.php in XMB Forum 1.9.1 allows remote attackers to execute arbitrary SQL commands via certain values that are inserted into the $in variable.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/14523">14523</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112361545228809&amp;w=2">20050809 Sql injection and global variables poisoning in XMB Forum 1.9.1</ref></refs><vuln_soft><prod name="XMB" vendor="XMB Forum"><vers num="1.9.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2576" published="2005-08-16" seq="2005-2576" severity="Medium" type="CVE"><desc><descript source="cve">CaLogic 1.22, and possibly earlier versions, allows remote attackers to obtain sensitive information via a direct request to (1) doclsqlres.php, (2) clmcpreload.php, (3) viewhistlog.php, (4) mcconfig.php, (5) doclsqlbak.php, (6) defcalsel.php, or (7) cl_minical.php, which reveals the path in an error message.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112369871827743&amp;w=2">20050810 Full path disclosure in CaLogic 1.22 and possible in older versions.</ref></refs><vuln_soft><prod name="CaLogic" vendor="CaLogic"><vers num="1.22"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2577" published="2005-08-16" seq="2005-2577" severity="Medium" type="CVE"><desc><descript source="cve">Wyse Winterm 1125SE running firmware 4.2.09f or 4.4.061f allows remote attackers to cause a denial of service (device crash) via a packet with a zero in the IP option length field.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><design/><exception/></vuln_types><range><network/></range><refs><ref source="SECTRACK" url="http://securitytracker.com/id?1014659">1014659</ref><ref source="BID" url="http://www.securityfocus.com/bid/14536">14536</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16409">16409</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112379283900586&amp;w=2">20050810 remote DOS on Wyse thin client 1125SE</ref></refs><vuln_soft><prod name="Winterm" vendor="Wyse"><vers num="1125SE"/></prod></vuln_soft></entry><entry modified="2005-10-25" name="CVE-2005-2578" published="2005-08-16" reject="1" seq="2005-2578" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2005-2552.  Reason: This candidate is a duplicate of CVE-2005-2552.  Notes: All CVE users should reference CVE-2005-2552 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><refs/></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-08-30" name="CVE-2005-2579" published="2005-08-16" seq="2005-2579" severity="High" type="CVE"><desc><descript source="cve">Nortel Contivity VPN Client V05_01.030, when configuring a certificate to be used as authentication, does not properly drop system privileges, which allows local users to gain privileges by opening a program with the File Open dialog box.</descript></desc><sols><sol source="nvd">Patch released by vendor.</sol></sols><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112370730131219&amp;w=2">20050810 Privilege escalation in Nortel Contivity VPN Client V05_01.030</ref></refs><vuln_soft><prod name="Contivity" vendor="Nortel Networks"><vers num="V05_01.030"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2580" published="2005-08-16" seq="2005-2580" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in MyBulletinBoard (MyBB) 1.00 RC4 with Security Patch allow remote attackers to execute arbitrary SQL commands via the Username field in (1) index.php or (2) member.php, action parameter to (3) search.php or (4) member.php, or (5) polloptions parameter to polls.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/14553">14553</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112387501519835&amp;w=2">20050812 My Bulletin Board RC 4 Vulnerabilities</ref></refs><vuln_soft><prod name="MyBulletinBoard" vendor="MyBulletinBoard"><vers num="1.00 RC4 Security Patch"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2581" published="2005-08-16" seq="2005-2581" severity="Medium" type="CVE"><desc><descript source="cve">Grandstream BudgeTone 101 and 102 running firmware 1.0.6.7 and possibly earlier versions, allows remote attackers to cause a denial of service (device hang or reboot) via a large UDP packet to port 5060.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="SECTRACK" url="http://securitytracker.com/id?1014665">1014665</ref><ref source="BID" url="http://www.securityfocus.com/bid/14539">14539</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16438">16438</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112388062328906&amp;w=2">20050812 Grandstream Budge Tone 101/102 DoS Vulnerability</ref></refs><vuln_soft><prod name="BudgeTone 102" vendor="Grandstream"><vers num="1.0.6.7" prev="1"/></prod><prod name="BudgeTone 101" vendor="Grandstream"><vers num="1.0.6.7" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="3.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="4.9" CVSS_score="3.6" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-03-08" name="CVE-2005-2582" published="2005-08-16" seq="2005-2582" severity="Low" type="CVE"><desc><descript source="cve">Kaspersky Anti-Virus for Unix/Linux File Servers 5.0-5 uses world-writable permissions for the (1) log and (2) license directory, which allows local users to delete log files, append to arbitrary files via a symlink attack on kavmonitor.log, or delete license keys and prevent keepup2date from properly executing.</descript></desc><loss_types><avail/><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="AERAsec" url="ftp://ftp.aerasec.de/pub/advisories/kav4unix/kav4unix-local-root-exploit.txt">ftp://ftp.aerasec.de/pub/advisories/kav4unix/kav4unix-local-root-exploit.txt</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112387573811339&amp;w=2">20050812 Insecure directory permissions of default installation of Kaspersky</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112387573811339&amp;w=2">20050812 Insecure directory permissions of default installation of Kaspersky</ref></refs><vuln_soft><prod name="Kaspersky Anti-Virus" vendor="Kaspersky Lab"><vers edition="Linux Servers" num="5.0.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2583" published="2005-08-16" seq="2005-2583" severity="High" type="CVE"><desc><descript source="cve">Mentor ADSL-FR4II router running firmware 2.00.0111 has an undocumented web server running on TCP port 5678, which allows local users to gain access.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112394620905095&amp;w=2">20050813 Low security hole affecting Mentor&apos;s ADSLFR4II router</ref></refs><vuln_soft><prod name="ADSLFR4II" vendor="Mentor"><vers num="2.00.0111"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2584" published="2005-08-16" seq="2005-2584" severity="High" type="CVE"><desc><descript source="cve">The web administration interface in Mentor ADSL-FR4II router running firmware 2.00.0111 does not set a default password, which allows local users to gain access.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112394620905095&amp;w=2">20050813 Low security hole affecting Mentor&apos;s ADSLFR4II router</ref></refs><vuln_soft><prod name="ADSLFR4II" vendor="Mentor"><vers num="2.00.0111"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2585" published="2005-08-16" seq="2005-2585" severity="Medium" type="CVE"><desc><descript source="cve">Mentor ADSL-FR4II router running firmware 2.00.0111 allows remote attackers to cause a denial of service (active TCP connections state table consumption) via a large number of connections, such as a port scan.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/14557">14557</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112394620905095&amp;w=2">20050813 Low security hole affecting Mentor&apos;s ADSLFR4II router</ref></refs><vuln_soft><prod name="ADSLFR4II" vendor="Mentor"><vers num="2.00.0111"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2586" published="2005-08-16" seq="2005-2586" severity="Low" type="CVE"><desc><descript source="cve">Mentor ADSL-FR4II router running firmware 2.00.0111 stores the web administration password in cleartext in the backup configuration file, which allows local users to obtain sensitive information.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="SECUNIA" url="http://secunia.com/advisories/16445">16445</ref><ref source="BID" url="http://www.securityfocus.com/bid/14557">14557</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112394620905095&amp;w=2">20050813 Low security hole affecting Mentor&apos;s ADSLFR4II router</ref></refs><vuln_soft><prod name="ADSLFR4II" vendor="Mentor"><vers num="2.00.0111"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2587" published="2005-08-16" seq="2005-2587" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in emailvalidate.php in PHPTB Topic Boards 2.0 allows remote attackers to execute arbitrary SQL commands via the mid parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/14535">14535</ref><ref source="OSVDB" url="http://www.osvdb.org/18736">18736</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16443">16443</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/21813">phptb-mid-sql-injection(21813)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112395837127707&amp;w=2">20050813 SQL in PHPTB Topic Boards 2.0</ref></refs><vuln_soft><prod name="Topic Boards" vendor="PHPTB"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2588" published="2005-08-17" seq="2005-2588" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in DVBBS 7.1 SP2 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the page parameter to dispbbs.asp, (2) name parameter to dispuser.asp, or the (3) title, (4) view, or (5) act parameter to boardhelp.asp.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://lostmon.blogspot.com/2005/08/dvbbs-multiple-variable-cross-site.html">http://lostmon.blogspot.com/2005/08/dvbbs-multiple-variable-cross-site.html</ref><ref source="OSVDB" url="http://www.osvdb.org/18512">18512</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014632">1014632</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/16131">16131</ref><ref source="BID" url="http://www.securityfocus.com/bid/14498">14498</ref></refs><vuln_soft><prod name="Dvbbs" vendor="Dvbbs"><vers num="7.1 SP2"/><vers num="7.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2589" published="2005-08-17" seq="2005-2589" severity="High" type="CVE"><desc><descript source="cve">Unknown vulnerability in Linksys WRT54GS wireless router with firmware 4.50.6, with WPA Personal/TKIP authentication enabled, allows remote clients to bypass authentication by connecting without using encryption.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/408161">20050815 Serious flaw in Linksys wireless AP password security</ref><ref source="BID" url="http://www.securityfocus.com/bid/14566">14566</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014721">1014721</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16457">16457</ref></refs><vuln_soft><prod name="WRT54GS" vendor="Linksys"><vers num="4.50.6"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2590" published="2005-08-17" seq="2005-2590" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Parlano MindAlign 5.0 and later versions allows remote attackers to inject arbitrary web script or HTML via unknown vectors.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://www.niscc.gov.uk/niscc/docs/br-20050812-00673.html?lang=en">http://www.niscc.gov.uk/niscc/docs/br-20050812-00673.html?lang=en</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/16408">16408</ref><ref source="BID" url="http://www.securityfocus.com/bid/14562">14562</ref><ref source="OSVDB" url="http://www.osvdb.org/18755">18755</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/21837">mindalign-xss(21837)</ref></refs><vuln_soft><prod name="MindAlign" vendor="Parlano"><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2591" published="2005-08-17" seq="2005-2591" severity="Medium" type="CVE"><desc><descript source="cve">Parlano MindAlign 5.0 and later versions allows remote attackers to list valid users via unknown vectors, aka the &quot;User Enumeration&quot; vulnerability.</descript></desc><loss_types><conf/></loss_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://www.niscc.gov.uk/niscc/docs/br-20050812-00673.html?lang=en">http://www.niscc.gov.uk/niscc/docs/br-20050812-00673.html?lang=en</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/16408">16408</ref><ref source="BID" url="http://www.securityfocus.com/bid/14562">14562</ref><ref source="OSVDB" url="http://www.osvdb.org/18754">18754</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/21821">mindalign-user-enumeration(21821)</ref></refs><vuln_soft><prod name="MindAlign" vendor="Parlano"><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2592" published="2005-08-17" seq="2005-2592" severity="High" type="CVE"><desc><descript source="cve">Unknown vulnerability in Parlano MindAlign 5.0 and later versions allows remote attackers to bypass authentication via unknown vectors.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://www.niscc.gov.uk/niscc/docs/br-20050812-00673.html?lang=en">http://www.niscc.gov.uk/niscc/docs/br-20050812-00673.html?lang=en</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/16408">16408</ref><ref source="BID" url="http://www.securityfocus.com/bid/14562">14562</ref><ref source="OSVDB" url="http://www.osvdb.org/18756">18756</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/21838">mindalign-bypass-authentication(21838)</ref></refs><vuln_soft><prod name="MindAlign" vendor="Parlano"><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2593" published="2005-08-17" seq="2005-2593" severity="High" type="CVE"><desc><descript source="cve">Parlano MindAlign 5.0 and later versions uses weak encryption, with unknown impact and attack vectors.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://www.niscc.gov.uk/niscc/docs/br-20050812-00673.html?lang=en">http://www.niscc.gov.uk/niscc/docs/br-20050812-00673.html?lang=en</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/16408">16408</ref><ref source="BID" url="http://www.securityfocus.com/bid/14562">14562</ref><ref source="OSVDB" url="http://www.osvdb.org/18757">18757</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/21840">mindalign-weak-encryption(21840)</ref></refs><vuln_soft><prod name="MindAlign" vendor="Parlano"><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2594" published="2005-08-17" seq="2005-2594" severity="Medium" type="CVE"><desc><descript source="cve">Apple Safari 1.3 (132) on Mac OS X 1.3.9 allows remote attackers to cause a denial of service (crash) via certain Javascript, possibly involving a function that defines a handler for itself within the function body.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/407702">20050809 Apple Safari &amp; Javascript - KERN_INVALID_ADDRESS (0x0001)</ref><ref source="BID" url="http://www.securityfocus.com/bid/14528">14528</ref></refs><vuln_soft><prod name="Safari" vendor="Apple"><vers num="1.3"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2595" published="2005-08-17" seq="2005-2595" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Dada Mail before 2.10 Alpha 1 allows remote attackers to execute arbitrary Javascript via archived messages.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="SKAZAT" url="http://mojo.skazat.com/download/testing_2_10_0_alpha1.html">http://mojo.skazat.com/download/testing_2_10_0_alpha1.html</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/16435">16435</ref><ref source="BID" url="http://www.securityfocus.com/bid/14573">14573</ref></refs><vuln_soft><prod name="Dada Mail" vendor="Dada Mail"><vers num="2.9.2"/><vers num="2.9.1"/><vers num="2.9.0"/><vers num="2.9.0 rc1"/><vers num="2.9.0 Beta2"/><vers num="2.9.0 Beta1"/><vers num="2.8.16 alpha4"/><vers num="2.8.16 alpha3"/><vers num="2.8.16 alpha2"/><vers num="2.8.16 alpha1"/><vers num="2.8.15"/><vers num="2.8.15 rc1"/><vers num="2.8.15 Beta1"/><vers num="2.8.15 alpha1"/><vers num="2.8.14 rc2"/><vers num="2.8.14 rc1"/><vers num="2.8.14 Beta1"/><vers num="2.8.14 alpha1"/><vers num="2.8.13"/><vers num="2.8.13 alpha2"/><vers num="2.8.13 alpha1"/><vers num="2.8.12"/><vers num="2.8.12 beta"/><vers num="2.8.11"/><vers num="2.8.10"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2596" published="2005-08-17" seq="2005-2596" severity="Medium" type="CVE"><desc><descript source="cve">User.php in Gallery, as used in Postnuke, allows users with any Admin privileges to gain access to all galleries.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/16389">16389</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-879">DSA-879</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17367">17367</ref><ref source="BID" url="http://www.securityfocus.com/bid/14547">14547</ref><ref source="" url="http://gallery.menalto.com/index.php?name=PNphpBB2&amp;file=viewtopic&amp;t=7048"></ref></refs><vuln_soft><prod name="Gallery" vendor="Gallery Project"><vers num="1.3.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2597" published="2005-08-17" seq="2005-2597" severity="High" type="CVE"><desc><descript source="cve">AOL Client Software 9.0 uses insecure permissions for its installation path, which allows local users to execute arbitrary code with SYSTEM privileges by replacing ACSD.exe with a malicious program.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref source="NTBUGTRAQ" url="http://archives.neohapsis.com/archives/ntbugtraq/2005-08/0009.html">20050807 Eh? Oh well....Flaws in AOL software, and accountability. Patch available for one of the two.</ref><ref source="BID" url="http://www.securityfocus.com/bid/14530">14530</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24324">aol-subfolder-weak-security(24324)</ref></refs><vuln_soft><prod name="AOL Client Software" vendor="AOL"><vers num="9.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-06-14" name="CVE-2005-2598" published="2005-08-17" seq="2005-2598" severity="Medium" type="CVE"><desc><descript source="cve">Multiple directory traversal vulnerabilities in Dokeos 1.6 and earlier, and possibly Claroline, allow remote attackers to (1) delete arbitrary files or directories via the delete parameter to claroline/scorm/scormdocument.php, (2) move arbitrary files via the move_to and move_file parameters to claroline/document/document.php, or determine the existence of arbitrary files via the file parameter to (3) claroline/scorm/showinframes.php or (4) claroline/scorm/contents.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/16407">16407</ref><ref source="FULLDISC" url="http://seclists.org/lists/fulldisclosure/2005/Aug/0394.html">20050812 Multiple directory traversal vulnerabilities in Claroline</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-August/036345.html">20050819 Re: Erroneous Informations - Multiple directory traversal vulnerabilities in Claroline</ref></refs><vuln_soft><prod name="Dokeos" vendor="Dokeos"><vers num="1.6" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2599" published="2005-08-17" seq="2005-2599" severity="High" type="CVE"><desc><descript source="cve">Hummingbird FTP for Connectivity 10.0 uses weak encryption (trivial encoding) to store the user&apos;s password in the FTP profile, which allows attackers to gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2005-08/0219.html">20050814 Hummingbird FTP Weak Password Encryption</ref><ref source="OSVDB" url="http://www.osvdb.org/18734">18734</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/16430">16430</ref><ref source="BID" url="http://www.securityfocus.com/bid/14559">14559</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/21811">humnmingbird-ftp-weak-encryption(21811)</ref></refs><vuln_soft><prod name="Connectivity" vendor="Hummingbird"><vers num="10.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-05" name="CVE-2005-2600" published="2005-08-17" seq="2005-2600" severity="Medium" type="CVE"><desc><descript source="cve">FUDForum 2.6.15 with &quot;Tree View&quot; enabled, as used in other products such as phpgroupware and egroupware, allows remote attackers to read private posts via a modified mid parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2005-08/0383.html">20050811 Fudforum: incompletely check of user rights in tree view gaining access to all messages</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/16414">16414</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-798">DSA-798</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-899">DSA-899</ref><ref source="BID" url="http://www.securityfocus.com/bid/14556">14556</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17643">17643</ref></refs><vuln_soft><prod name="FUDForum" vendor="Ilia Alshanetsky"><vers num="2.6.15"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2601" published="2005-08-17" seq="2005-2601" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in MidiCart allows remote attackers to execute arbitrary SQL commands via the code_no parameter to (1) Item_Show.asp or (2) search_list.asp.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://systemsecure.org/ssforum/viewtopic.php?t=30">http://systemsecure.org/ssforum/viewtopic.php?t=30</ref><ref adv="1" source="SECTRACK" url="http://securitytracker.com/id?1014660">1014660</ref><ref source="BID" url="http://www.securityfocus.com/bid/14544">14544</ref></refs><vuln_soft><prod name="MidiCart PHP Shopping Cart" vendor="Midicart Software"><vers num="a"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2602" published="2005-08-17" seq="2005-2602" severity="Low" type="CVE"><desc><descript source="cve">Mozilla Thunderbird 1.0 and Firefox 1.0.6 allows remote attackers to obfuscate URIs via a long URI, which causes the address bar to go blank and could facilitate phishing attacks.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/407704">20050809 Mozilla Firefox up to 1.0.6 and Mozilla Thunderbird up to 1.0 url string obfuscation</ref><ref source="MISC" url="http://www.scip.ch/cgi-bin/smss/showadvf.pl?id=1682">http://www.scip.ch/cgi-bin/smss/showadvf.pl?id=1682</ref><ref source="BID" url="http://www.securityfocus.com/bid/14526">14526</ref></refs><vuln_soft><prod name="Firefox" vendor="Mozilla"><vers num="1.0.6"/></prod><prod name="Thunderbird" vendor="Mozilla"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2603" published="2005-08-17" seq="2005-2603" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in index.php for My Image Gallery (Mig ) 1.4.1 allows remote attackers to inject arbitrary web script or HTML via the (1) currDir or (2) image parameters.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="MISC" url="http://secwatch.org/advisories/secwatch/20050813_Mig.txt">http://secwatch.org/advisories/secwatch/20050813_Mig.txt</ref><ref patch="1" source="" url="http://sourceforge.net/project/shownotes.php?release_id=349348">http://sourceforge.net/project/shownotes.php?release_id=349348</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/14570">14570</ref><ref patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/1432">ADV-2005-1432</ref><ref patch="1" source="OSVDB" url="http://www.osvdb.org/18741">18741</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/16405">16405</ref></refs><vuln_soft><prod name="My Image Gallery" vendor="My Image Gallery"><vers num="1.4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2604" published="2005-08-17" seq="2005-2604" severity="Medium" type="CVE"><desc><descript source="cve">index.php for My Image Gallery (Mig ) 1.4.1 allows remote attackers to obtain the web server path via certain currDir and image arguments, which leaks the path in an error message.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="MISC" url="http://secwatch.org/advisories/secwatch/20050813_Mig.txt">http://secwatch.org/advisories/secwatch/20050813_Mig.txt</ref><ref patch="1" source="" url="http://sourceforge.net/project/shownotes.php?release_id=349348">http://sourceforge.net/project/shownotes.php?release_id=349348</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/14570">14570</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/1432">ADV-2005-1432</ref><ref patch="1" source="OSVDB" url="http://www.osvdb.org/18742">18742</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/16405">16405</ref></refs><vuln_soft><prod name="My Image Gallery" vendor="My Image Gallery"><vers num="1.4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2605" published="2005-08-17" seq="2005-2605" severity="Medium" type="CVE"><desc><descript source="cve">Unknown vulnerability in Lasso Professional Server8.0.4 and 8.0.5 allows attackers to bypass authentication, related to [Auth] tags.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://www.omnipilot.com/Software%20Updates.1747.8901.lasso">http://www.omnipilot.com/Software%20Updates.1747.8901.lasso</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/14543">14543</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16364">16364</ref></refs><vuln_soft><prod name="Lasso Professional Server" vendor="OmniPilot Software"><vers num="8.0.5"/><vers num="8.0.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2606" published="2005-08-17" seq="2005-2606" severity="High" type="CVE"><desc><descript source="cve">Unknown vulnerability in the &quot;frontend authentication&quot; in PHlyMail 3.02.00 has unknown impact and attack vectors.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://phlymail.de/forum/viewtopic.php?t=698">http://phlymail.de/forum/viewtopic.php?t=698</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/14537">14537</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/1365">ADV-2005-1365</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/16388">16388</ref></refs><vuln_soft><prod name="PHlyMail" vendor="PHlyMail"><vers num="3.02.00"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2607" published="2005-08-17" seq="2005-2607" severity="Medium" type="CVE"><desc><descript source="cve">PHP file include vulnerability in download.php in PHPSimplicity Simplicity oF Upload before 1.3.1 allows remote attackers to include arbitrary local and remote files via the language parameter and a terminating null (&quot;%00&quot;) characters.</descript></desc><sols><sol source="nvd">Download new version of program at http://www.phpsimplicity.com/scripts.php?id=3.</sol></sols><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MISC" url="http://rgod.altervista.org/simply.html">http://rgod.altervista.org/simply.html</ref><ref patch="1" source="" url="http://www.phpsimplicity.com/scripts.php?id=3">http://www.phpsimplicity.com/scripts.php?id=3</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/14424">14424</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014591">1014591</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16273">16273</ref></refs><vuln_soft><prod name="Simplicity oF Upload" vendor="PHPSimplicity"><vers num="1.3"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2608" published="2005-08-17" seq="2005-2608" severity="Medium" type="CVE"><desc><descript source="cve">SafeHTML before 1.3.5 does not properly filter script in UTF-7 and CSS comments, which allows remote attackers to conduct cross-site scripting (XSS) attacks in vulnerable applications that use SafeHTML.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/14574">14574</ref><ref source="SECUNIA" url="http://secunia.com/advisories/16427">16427</ref></refs><vuln_soft><prod name="SafeHTML" vendor="SafeHTML"><vers num="1.3.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2609" published="2005-08-17" seq="2005-2609" severity="Medium" type="CVE"><desc><descript source="cve">index.php in VegaDNS 0.8.1, 0.9.8, and possibly other versions, allows remote attackers to obtain the full server path via an invalid VDNS_Sessid parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MISC" url="http://www.packetstormsecurity.org/0508-exploits/vegadns-dyn0.txt">http://www.packetstormsecurity.org/0508-exploits/vegadns-dyn0.txt</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/16370">16370</ref><ref source="" url="http://vegadns.org/src/current/CHANGELOG"></ref></refs><vuln_soft><prod name="VegaDNS" vendor="VegaDNS"><vers num="0.8.1"/><vers num="0.9.8"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2610" published="2005-08-17" seq="2005-2610" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in VegaDNS 0.8.1, 0.9.8, and possibly other versions, allows remote attackers to inject arbitrary web script or HTML via the message parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MISC" url="http://www.packetstormsecurity.org/0508-exploits/vegadns-dyn0.txt">http://www.packetstormsecurity.org/0508-exploits/vegadns-dyn0.txt</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/16370">16370</ref><ref source="" url="http://vegadns.org/src/current/CHANGELOG"></ref><ref source="BID" url="http://www.securityfocus.com/bid/14538">14538</ref></refs><vuln_soft><prod name="VegaDNS" vendor="VegaDNS"><vers num="0.8.1"/><vers num="0.9.8"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-08-20" name="CVE-2005-2611" published="2005-08-17" seq="2005-2611" severity="High" type="CVE"><desc><descript source="cve">VERITAS Backup Exec for Windows Servers 8.6 through 10.0, Backup Exec for NetWare Servers 9.0 and 9.1, and NetBackup for NetWare Media Server Option 4.5 through 5.1 uses a static password during authentication from the NDMP agent to the server, which allows remote attackers to read and write arbitrary files with the backup server.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="SYMANTEC" url="http://securityresponse.symantec.com/avcenter/security/Content/2005.08.12b.html">http://securityresponse.symantec.com/avcenter/security/Content/2005.08.12b.html</ref><ref adv="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA05-224A.html">TA05-224A</ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/378957">VU#378957</ref><ref source="BID" url="http://www.securityfocus.com/bid/14551">14551</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/1387">ADV-2005-1387</ref><ref adv="1" patch="1" source="SECTRACK" url="http://securitytracker.com/id?1014662">1014662</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/16403">16403</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/21793">backupexec-ndmp-gain-access(21793)</ref></refs><vuln_soft><prod name="NetBackup" vendor="Symantec Veritas"><vers num="NetWare Media Servers 5.1 MP3"/><vers num="NetWare Media Servers 5.1 MP2"/><vers num="NetWare Media Servers 5.1 MP1"/><vers num="NetWare Media Servers 5.1"/><vers num="NetWare Media Servers 5.0 MP5"/><vers num="NetWare Media Servers 5.0 MP4"/><vers num="NetWare Media Servers 5.0 MP3"/><vers num="NetWare Media Servers 5.0 MP2"/><vers num="NetWare Media Servers 5.0 MP1"/><vers num="NetWare Media Servers 5.0"/><vers num="NetWare Media Servers 4.5 MP8"/><vers num="NetWare Media Servers 4.5 MP7"/><vers num="NetWare Media Servers 4.5 MP6"/><vers num="NetWare Media Servers 4.5 MP5"/><vers num="NetWare Media Servers 4.5 MP4"/><vers num="NetWare Media Servers 4.5 MP3"/><vers num="NetWare Media Servers 4.5 MP2"/><vers num="NetWare Media Servers 4.5 MP1"/><vers num="NetWare Media Servers 4.5 FP8"/><vers num="NetWare Media Servers 4.5 FP7"/><vers num="NetWare Media Servers 4.5 FP6"/><vers num="NetWare Media Servers 4.5 FP5"/><vers num="NetWare Media Servers 4.5 FP4"/><vers num="NetWare Media Servers 4.5 FP3"/><vers num="NetWare Media Servers 4.5 FP2"/><vers num="NetWare Media Servers 4.5 FP1"/><vers num="NetWare Media Servers 4.5"/></prod><prod name="Backup Exec" vendor="Symantec Veritas"><vers num="Windows Servers 10.0 rev. 5520"/><vers num="Windows Servers 10.0 rev. 5484 SP1"/><vers num="Windows Servers 10.0 rev. 5484"/><vers num="Windows Servers 9.1 rev. 4691 SP2"/><vers num="Windows Servers 9.1 rev. 4691"/><vers num="Windows Servers 9.1"/><vers num="Windows Servers 9.0 rev. 4454 SP1"/><vers num="Windows Servers 9.0 rev. 4454"/><vers num="Windows Servers 9.0 rev. 4367 SP1"/><vers num="Windows Servers 9.0 rev. 4367"/><vers num="Windows Servers 9.0"/><vers num="Windows Servers 8.6"/><vers num="NetWare Servers 9.1.1156"/><vers num="NetWare Servers 9.1.1154"/><vers num="NetWare Servers 9.1.1152 .4"/><vers num="NetWare Servers 9.1.1152"/><vers num="NetWare Servers 9.1.1151 .1"/><vers num="NetWare Servers 9.1.1127 .1"/><vers num="NetWare Servers 9.1.1067 .3"/><vers num="NetWare Servers 9.1.1067 .2"/><vers num="NetWare Servers 9.1.307"/><vers num="NetWare Servers 9.1.306"/><vers num="NetWare Servers 9.0.4202"/><vers num="NetWare Servers 9.0.4174"/><vers num="NetWare Servers 9.0.4172"/><vers num="NetWare Servers 9.0.4170"/><vers num="NetWare Servers 9.0.4019"/></prod><prod name="Backup Exec Remote Agent" vendor="Symantec Veritas"><vers num="Windows Server"/><vers num="Unix/Linux Server"/><vers num="NetWare Server"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2612" published="2005-08-17" seq="2005-2612" severity="High" type="CVE"><desc><descript source="cve">Direct code injection vulnerability in WordPress 1.5.1.3 and earlier allows remote attackers to execute arbitrary PHP code via the cache_lastpostdate[server] cookie.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2005-08/0234.html">20050809 (no subject)</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/16386">16386</ref></refs><vuln_soft><prod name="WordPress" vendor="WordPress"><vers num="1.5.1.3"/><vers num="1.5.1.2"/><vers num="1.5.1"/><vers num="1.5"/><vers num="1.2"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-2613" published="2005-08-17" seq="2005-2613" severity="Medium" type="CVE"><desc><descript source="cve">Unknown vulnerability in CPAINT Ajax Toolkit before 1.3-SP allows attackers to execute arbitrary PHP or ASP code or read files via unknown vectors.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/408130">20050815 Vulnerability found in CPAINT Ajax Toolkit</ref><ref patch="1" source="" url="http://sourceforge.net/forum/forum.php?forum_id=488784">http://sourceforge.net/forum/forum.php?forum_id=488784</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/14565">14565
