<?xml version="1.0" encoding="UTF-8"?>
<nvd nvd_xml_version="1.2" pub_date="2008-09-05" xmlns="http://nvd.nist.gov/feeds/cve/1.2" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://nvd.nist.gov/feeds/cve/1.2 http://nvd.nist.gov/schema/nvdcve.xsd"><!--This XML file has been upgraded to support CVSS version 2.  The following new attributes have been added to CVS entries:
* CVSS_version - Indicates the version of the CVSS data
* CVSS_base_score - The CVSSv2 base score
* CVSS_impact_subscore - The CVSSv2 impact sub-score
* CVSS_exploit_subscore - the CVSSv2 exploit sub-score

The following attributes have been mapped to new content in CVS entries:
* CVSS_score - This attribute is the same as the CVSS_base_score and is now deprecated.
* CVSS_vector - Contains the new CVSSv2 vector string--><entry CVSS_base_score="6.9" CVSS_exploit_subscore="3.4" CVSS_impact_subscore="10.0" CVSS_score="6.9" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2007-02-07" name="CVE-2005-0001" published="2005-05-02" seq="2005-0001" severity="Medium" type="CVE"><desc><descript source="cve">Race condition in the page fault handler (fault.c) for Linux kernel 2.2.x to 2.2.7, 2.4 to 2.4.29, and 2.6 to 2.6.10, when running on multiprocessor machines, allows local users to execute arbitrary code via concurrent threads that share the same virtual memory space and simultaneously request stack expansion.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><race/></vuln_types><range><local/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110554694522719&amp;w=2">20050112 Linux kernel i386 SMP page fault handler privilege escalation</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-January/030826.html">20050112 Linux kernel i386 SMP page fault handler privilege escalation</ref><ref source="MISC" url="http://isec.pl/vulnerabilities/isec-0022-pagefault.txt">http://isec.pl/vulnerabilities/isec-0022-pagefault.txt</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/index.php?id=a&amp;anuncio=000930">CLA-2005:930</ref><ref source="FEDORA" url="https://bugzilla.fedora.us/show_bug.cgi?id=2336">FLSA:2336</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:022">MDKSA-2005:022</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-043.html">RHSA-2005:043</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-092.html">RHSA-2005:092</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2005/0001/">2005-0001</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110581146702951&amp;w=2">20050114 [USN-60-0] Linux kernel vulnerabilities</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18849">linux-fault-handler-gain-privileges(18849)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1012862">1012862</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13822">13822</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-016.html">RHSA-2005:016</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1070">DSA-1070</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1067">DSA-1067</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1069">DSA-1069</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-017.html">RHSA-2005:017</ref><ref source="BID" url="http://www.securityfocus.com/bid/12244">12244</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20163">20163</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20202">20202</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1082">DSA-1082</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20338">20338</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:022">MDKSA-2005:022</ref></refs><vuln_soft><prod name="Secure Linux" vendor="Trustix"><vers num="2.1"/><vers num="2.2"/></prod><prod name="Desktop" vendor="Red Hat"><vers num="3.0"/><vers num="4.0"/></prod><prod name="Kernel" vendor="Linux"><vers num="2.2.7"/><vers num="2.4.0"/><vers num="2.4.1"/><vers num="2.4.2"/><vers num="2.4.3"/><vers num="2.4.4"/><vers num="2.4.5"/><vers num="2.4.6"/><vers num="2.4.7"/><vers num="2.4.8"/><vers num="2.4.9"/><vers num="2.4.10"/><vers num="2.4.11"/><vers num="2.4.12"/><vers num="2.4.13"/><vers num="2.4.14"/><vers num="2.4.15"/><vers num="2.4.16"/><vers num="2.4.17"/><vers num="2.4.18"/><vers num="2.4.19"/><vers num="2.4.20"/><vers num="2.4.21"/><vers num="2.4.22"/><vers num="2.4.23"/><vers num="2.4.24"/><vers num="2.4.25"/><vers num="2.4.26"/><vers num="2.4.27"/><vers num="2.4.28"/><vers num="2.4.29"/><vers num="2.6.0"/><vers num="2.6.1"/><vers num="2.6.2"/><vers num="2.6.3"/><vers num="2.6.4"/><vers num="2.6.5"/><vers num="2.6.6"/><vers num="2.6.7"/><vers num="2.6.8"/><vers edition="2.6.20" num="2.6.9"/><vers num="2.6.10"/></prod><prod name="Trustix Enterprise Server" vendor="Trustix"><vers num="2"/></prod><prod name="Enterprise Linux" vendor="Red Hat"><vers edition="Advanced Server" num="3.0"/><vers edition="Enterprise Server" num="3.0"/><vers edition="Workstation Server" num="3.0"/><vers edition="Advanced Server" num="4.0"/><vers edition="Enterprise Server" num="4.0"/><vers edition="Workstation" num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0002" published="2005-05-02" seq="2005-0002" severity="High" type="CVE"><desc><descript source="cve">poppassd_pam 1.0 and earlier, when changing a user password, does not verify that the user entered the old password correctly, which allows remote attackers to change passwords for arbitrary users.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200501-22.xml">GLSA-200501-22</ref><ref source="Secunia" url="http://secunia.com/advisories/13865/">Gentoo update for poppassd_pam </ref><ref source="SECTRACK" url="http://securitytracker.com/id?1012840">1012840</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13865">13865</ref></refs><vuln_soft><prod name="poppassd_pam" vendor="Gentoo"><vers num="1.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-11-30" name="CVE-2005-0003" published="2005-04-14" seq="2005-0003" severity="Low" type="CVE"><desc><descript source="cve">The 64 bit ELF support in Linux kernel 2.6 before 2.6.10, on 64-bit architectures, does not properly check for overlapping VMA (virtual memory address) allocations, which allows local users to cause a denial of service (system crash) or execute arbitrary code via a crafted ELF or a.out file.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2005-043.html">Updated kernel packages fix security vulnerabilities</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/12261">bid 12261</ref><ref source="CONFIRM" url="http://linux.bkbits.net:8080/linux-2.4/cset@41c36fb6q1Z68WUzKQFjJR-40Ev3tw">http://linux.bkbits.net:8080/linux-2.4/cset@41c36fb6q1Z68WUzKQFjJR-40Ev3tw</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:022">MDKSA-2005:022</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_18_kernel.html">SUSE-SA:2005:018</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2005/0001/">2005-0001</ref><ref source="MISC" url="http://linux.bkbits.net:8080/linux-2.6/cset@41a6721cce-LoPqkzKXudYby_3TUmg">http://linux.bkbits.net:8080/linux-2.6/cset@41a6721cce-LoPqkzKXudYby_3TUmg</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18886">linux-vma-gain-privileges(18886)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1012885">1012885</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1070">DSA-1070</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1067">DSA-1067</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1069">DSA-1069</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-017.html">RHSA-2005:017</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20163">20163</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20202">20202</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1082">DSA-1082</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20338">20338</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:022">MDKSA-2005:022</ref></refs><vuln_soft><prod name="S8300" vendor="Avaya"><vers num="R2.0.1"/><vers num="R2.0.0"/></prod><prod name="Mandrake Linux" vendor="MandrakeSoft"><vers edition="amd64" num="9.2"/><vers num="9.2"/><vers edition="AMD64" num="10.0"/><vers num="10.0"/><vers edition="x86_64" num="10.1"/><vers num="10.1"/></prod><prod name="Enterprise Linux AS" vendor="Red Hat"><vers edition="Advanced Servers" num="3.0"/></prod><prod name="Intuity" vendor="Avaya"><vers num="LX"/></prod><prod name="S8710" vendor="Avaya"><vers num="R2.0.1"/><vers num="R2.0.0"/></prod><prod name="Enterprise Linux WS" vendor="Red Hat"><vers edition="Workstation" num="3.0"/></prod><prod name="Mandrake Multi Network Firewall" vendor="MandrakeSoft"><vers num="8.2"/></prod><prod name="Desktop" vendor="Red Hat"><vers num="3.0"/></prod><prod name="Mandrake Corporate Server" vendor="MandrakeSoft"><vers edition="x86_64" num="2.1"/><vers num="2.1"/><vers num="3.0"/></prod><prod name="Modular Messaging Message Storage Server" vendor="Avaya"><vers num="1.1"/><vers num="2.0"/></prod><prod name="Converged Communications Server" vendor="Avaya"><vers num="2.0"/></prod><prod name="Kernel" vendor="Linux"><vers num="2.4.0 test9"/><vers num="2.4.0 test8"/><vers num="2.4.0 test7"/><vers num="2.4.0 test6"/><vers num="2.4.0 test5"/><vers num="2.4.0 test4"/><vers num="2.4.0 test3"/><vers num="2.4.0 test2"/><vers num="2.4.0 test12"/><vers num="2.4.0 test11"/><vers num="2.4.0 test10"/><vers num="2.4.0 test1"/><vers num="2.4.0"/><vers num="2.4.1"/><vers num="2.4.2"/><vers num="2.4.3"/><vers num="2.4.4"/><vers num="2.4.5"/><vers num="2.4.6"/><vers num="2.4.7"/><vers num="2.4.8"/><vers num="2.4.9"/><vers num="2.4.10"/><vers num="2.4.11"/><vers num="2.4.12"/><vers num="2.4.13"/><vers num="2.4.14"/><vers num="2.4.15"/><vers num="2.4.16"/><vers num="2.4.17"/><vers num="2.4.18 pre8"/><vers num="2.4.18 pre7"/><vers num="2.4.18 pre6"/><vers num="2.4.18 pre5"/><vers num="2.4.18 pre4"/><vers num="2.4.18 pre3"/><vers num="2.4.18 pre2"/><vers num="2.4.18 pre1"/><vers edition="x86" num="2.4.18"/><vers num="2.4.18"/><vers num="2.4.19 pre6"/><vers num="2.4.19 pre5"/><vers num="2.4.19 pre4"/><vers num="2.4.19 pre3"/><vers num="2.4.19 pre2"/><vers num="2.4.19 pre1"/><vers num="2.4.19"/><vers num="2.4.20"/><vers num="2.4.21 pre7"/><vers num="2.4.21 pre4"/><vers num="2.4.21 pre1"/><vers num="2.4.21"/><vers num="2.4.22"/><vers num="2.4.23 pre9"/><vers num="2.4.23 ow2"/><vers num="2.4.23"/><vers num="2.4.24 ow1"/><vers num="2.4.24"/><vers num="2.4.25"/><vers num="2.4.26"/><vers num="2.4.27 pre5"/><vers num="2.4.27 pre4"/><vers num="2.4.27 pre3"/><vers num="2.4.27 pre2"/><vers num="2.4.27 pre1"/><vers num="2.4.27"/><vers num="2.4.28"/><vers num="2.4.29 rc2"/><vers num="2.4.29 rc1"/></prod><prod name="S8500" vendor="Avaya"><vers num="R2.0.1"/><vers num="R2.0.0"/></prod><prod name="Enterprise Linux ES" vendor="Red Hat"><vers edition="Enterprise Server" num="3.0"/></prod><prod name="Network Routing" vendor="Avaya"><vers num=""/></prod><prod name="S8700 Series" vendor="Avaya"><vers num="R2.0.1"/><vers num="R2.0.0"/></prod><prod name="MN100" vendor="Avaya"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-03-28" name="CVE-2005-0004" published="2005-04-14" seq="2005-0004" severity="Medium" type="CVE"><desc><descript source="cve">The mysqlaccess script in MySQL 4.0.23 and earlier, 4.1.x before 4.1.10, 5.0.x before 5.0.3, and other versions including 3.x, allows local users to overwrite arbitrary files or read temporary files via a symlink attack on temporary files.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2005/dsa-647">mysql -- insecure temporary files</ref><ref adv="1" patch="1" source="Secunia.com" url="http://secunia.com/advisories/13867">MySQL mysqlaccess Script Insecure Temporary File Creation</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/12277">bid 12277</ref><ref source="CONFIRM" url="http://lists.mysql.com/internals/20600">http://lists.mysql.com/internals/20600</ref><ref source="CONFIRM" url="http://mysql.osuosl.org/doc/mysql/en/News-4.1.10.html">http://mysql.osuosl.org/doc/mysql/en/News-4.1.10.html</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000947">CLA-2005:947</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:036">MDKSA-2005:036</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110608297217224&amp;w=2">20050118 [USN-63-1] MySQL client vulnerability</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18922">mysql-mysqlaccess-symlink(18922)</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101864-1">101864</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:036">MDKSA-2005:036</ref></refs><vuln_soft><prod name="Linux" vendor="Gentoo"><vers num=""/></prod><prod name="MySQL" vendor="MySQL"><vers num="4.0.0"/><vers num="4.0.1"/><vers num="4.0.2"/><vers num="4.0.3"/><vers num="4.0.4"/><vers num="4.0.5a"/><vers num="4.0.5"/><vers num="4.0.6"/><vers num="4.0.7 gamma"/><vers num="4.0.7"/><vers num="4.0.8 gamma"/><vers num="4.0.8"/><vers num="4.0.9 gamma"/><vers num="4.0.9"/><vers num="4.0.10"/><vers num="4.0.11 gamma"/><vers num="4.0.11"/><vers num="4.0.12"/><vers num="4.0.13"/><vers num="4.0.14"/><vers num="4.0.15"/><vers num="4.0.18"/><vers num="4.0.20"/><vers num="4.0.21"/><vers num="4.1.0 alpha"/><vers num="4.1.0.0"/><vers num="4.1.2 alpha"/><vers num="4.1.3 beta"/><vers num="4.1.3.0"/><vers num="4.1.4"/><vers num="4.1.5"/></prod><prod name="Linux" vendor="Red Hat"><vers edition="i386" num="7.3"/><vers edition="i386" num="9.0"/></prod><prod name="Fedora" vendor="Red Hat"><vers num="Core 1.0"/></prod><prod name="Debian Linux" vendor="Debian"><vers num="3.0 sparc"/><vers num="3.0 s_390"/><vers num="3.0 ppc"/><vers num="3.0 mipsel"/><vers num="3.0 mips"/><vers num="3.0 m68k"/><vers num="3.0 ia-64"/><vers num="3.0 ia-32"/><vers num="3.0 hppa"/><vers num="3.0 arm"/><vers num="3.0 alpha"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0005" published="2005-05-02" seq="2005-0005" severity="High" type="CVE"><desc><descript source="cve">Heap-based buffer overflow in psd.c for ImageMagick 6.1.0, 6.1.7, and possibly earlier versions allows remote attackers to execute arbitrary code via a .PSD image file with a large number of layers.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=184&amp;type=vulnerabilities">20050117 Multiple Vendor ImageMagick .psd Image File Decode Heap Overflow Vulnerability</ref><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-646">DSA-646</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200501-37.xml">GLSA-200501-37</ref><ref patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-071.html">RHSA-2005:071</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110608222117215&amp;w=2">20050118 [USN-62-1] imagemagick vulnerability</ref><ref patch="1" source="bid" url="http://www.securityfocus.com/bid/12287">12287</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-070.html">RHSA-2005:070</ref></refs><vuln_soft><prod name="Linux" vendor="Gentoo"><vers num="0.5"/><vers num="0.7"/><vers num="1.1a"/><vers num="1.2"/><vers num="1.4 rc3"/><vers num="1.4 rc2"/><vers num="1.4 rc1"/><vers num="1.4"/></prod><prod name="SuSE Linux" vendor="SuSE"><vers edition="i386" num="8.0"/><vers num="8.0"/><vers num="8.1"/><vers num="8.2"/><vers edition="x86_64" num="9.0"/><vers num="9.0"/><vers num="9.1"/><vers num="9.2"/></prod><prod name="GraphicsMagick" vendor="GraphicsMagick"><vers num="1.0"/><vers num="1.0.6"/><vers num="1.1"/><vers num="1.1.3"/><vers num="1.1.4"/></prod><prod name="ProPack" vendor="SGI"><vers num="3.0"/></prod><prod name="Debian Linux" vendor="Debian"><vers num="3.0 sparc"/><vers num="3.0 s_390"/><vers num="3.0 ppc"/><vers num="3.0 mipsel"/><vers num="3.0 mips"/><vers num="3.0 m68k"/><vers num="3.0 ia-64"/><vers num="3.0 ia-32"/><vers num="3.0 hppa"/><vers num="3.0 arm"/><vers num="3.0 alpha"/></prod><prod name="ImageMagick" vendor="ImageMagick"><vers num="5.3.3"/><vers num="5.4.3"/><vers num="5.4.7"/><vers num="6.0"/><vers num="6.0.1"/><vers num="6.0.2.5"/><vers num="6.0.2"/><vers num="6.0.3"/><vers num="6.0.4"/><vers num="6.0.5"/><vers num="6.0.6"/><vers num="6.0.7"/><vers num="6.0.8"/><vers num="6.1"/><vers num="6.1.1.6"/><vers num="6.1.2"/><vers num="6.1.3"/><vers num="6.1.4"/><vers num="6.1.5"/><vers num="6.1.6"/><vers num="6.1.7"/><vers num="6.2.0.7"/><vers num="6.2.0.4"/><vers num="6.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0006" published="2005-05-02" seq="2005-0006" severity="Medium" type="CVE"><desc><descript source="cve">The COPS dissector in Ethereal 0.10.6 through 0.10.8 allows remote attackers to cause a denial of service (infinite loop).</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="CONFIRM" url="http://www.ethereal.com/appnotes/enpa-sa-00017.html">http://www.ethereal.com/appnotes/enpa-sa-00017.html</ref><ref adv="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200501-27.xml">GLSA-200501-27</ref><ref adv="1" source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:013">MDKSA-2005:013</ref><ref adv="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-037.html">RHSA-2005:037</ref><ref adv="1" source="CIAC" url="http://www.ciac.org/ciac/bulletins/p-106.shtml">P-106</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/13946/">13946</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18999">ethereal-cops-dos(18999)</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00003.html">FLSA-2006:152922</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-011.html">RHSA-2005:011</ref><ref source="BID" url="http://www.securityfocus.com/bid/12326">12326</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:013">MDKSA-2005:013</ref></refs><vuln_soft><prod name="Ethereal" vendor="Ethereal Group"><vers num="0.10.6"/><vers num="0.10.7"/><vers num="0.10.8"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0007" published="2005-05-02" seq="2005-0007" severity="Medium" type="CVE"><desc><descript source="cve">Unknown vulnerability in the DLSw dissector in Ethereal 0.10.6 through 0.10.8 allows remote attackers to cause a denial of service (application crash from assertion).</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="CONFIRM" url="http://www.ethereal.com/appnotes/enpa-sa-00017.html">http://www.ethereal.com/appnotes/enpa-sa-00017.html</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200501-27.xml">GLSA-200501-27</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:013">MDKSA-2005:013</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-037.html">RHSA-2005:037</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/p-106.shtml">P-106</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/13946/">13946</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19000">ethereal-dlsw-dos(19000)</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00003.html">FLSA-2006:152922</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-011.html">RHSA-2005:011</ref><ref source="BID" url="http://www.securityfocus.com/bid/12326">12326</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:013">MDKSA-2005:013</ref></refs><vuln_soft><prod name="Ethereal" vendor="Ethereal Group"><vers num="0.10.6"/><vers num="0.10.7"/><vers num="0.10.8"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0008" published="2005-05-02" seq="2005-0008" severity="Medium" type="CVE"><desc><descript source="cve">Unknown vulnerability in the DNP dissector in Ethereal 0.10.5 through 0.10.8 allows remote attackers to cause &quot;memory corruption.&quot;</descript></desc><loss_types><int/></loss_types><range><network/></range><refs><ref patch="1" source="CONFIRM" url="http://www.ethereal.com/appnotes/enpa-sa-00017.html">http://www.ethereal.com/appnotes/enpa-sa-00017.html</ref><ref adv="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200501-27.xml">GLSA-200501-27</ref><ref adv="1" source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:013">MDKSA-2005:013</ref><ref adv="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-037.html">RHSA-2005:037</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/p-106.shtml">P-106</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13946/">13946</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19001">ethereal-dnp-memory-corruption(19001)</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00003.html">FLSA-2006:152922</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-011.html">RHSA-2005:011</ref><ref source="BID" url="http://www.securityfocus.com/bid/12326">12326</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:013">MDKSA-2005:013</ref></refs><vuln_soft><prod name="Ethereal" vendor="Ethereal Group"><vers num="0.10.5"/><vers num="0.10.6"/><vers num="0.10.7"/><vers num="0.10.8"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0009" published="2005-05-02" seq="2005-0009" severity="Medium" type="CVE"><desc><descript source="cve">Unknown vulnerability in the Gnutella dissector in Ethereal 0.10.6 through 0.10.8 allows remote attackers to cause a denial of service (application crash).</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref source="CONFIRM" url="http://www.ethereal.com/appnotes/enpa-sa-00017.html">http://www.ethereal.com/appnotes/enpa-sa-00017.html</ref><ref patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200501-27.xml">GLSA-200501-27</ref><ref adv="1" source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:013">MDKSA-2005:013</ref><ref adv="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-037.html">RHSA-2005:037</ref><ref adv="1" source="CIAC" url="http://www.ciac.org/ciac/bulletins/p-106.shtml">P-106</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/13946/">13946</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19002">ethereal-gnutella-dos(19002)</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00003.html">FLSA-2006:152922</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-011.html">RHSA-2005:011</ref><ref source="BID" url="http://www.securityfocus.com/bid/12326">12326</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:013">MDKSA-2005:013</ref></refs><vuln_soft><prod name="Ethereal" vendor="Ethereal Group"><vers num="0.10.6"/><vers num="0.10.7"/><vers num="0.10.8"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0010" published="2005-05-02" seq="2005-0010" severity="Medium" type="CVE"><desc><descript source="cve">Unknown vulnerability in the MMSE dissector in Ethereal 0.10.4 through 0.10.8 allows remote attackers to cause a denial of service by triggering a free of statically allocated memory.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/><other/></vuln_types><range><network/></range><refs><ref source="CONFIRM" url="http://www.ethereal.com/appnotes/enpa-sa-00017.html">http://www.ethereal.com/appnotes/enpa-sa-00017.html</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200501-27.xml">GLSA-200501-27</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:013">MDKSA-2005:013</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-037.html">RHSA-2005:037</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/p-106.shtml">P-106</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/13946/">13946</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19003">ethereal-mmse-free-memory(19003)</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00003.html">FLSA-2006:152922</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-011.html">RHSA-2005:011</ref><ref source="BID" url="http://www.securityfocus.com/bid/12326">12326</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:013">MDKSA-2005:013</ref></refs><vuln_soft><prod name="Ethereal" vendor="Ethereal Group"><vers num="0.10.4"/><vers num="0.10.5"/><vers num="0.10.6"/><vers num="0.10.7"/><vers num="0.10.8"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0011" published="2005-05-02" seq="2005-0011" severity="High" type="CVE"><desc><descript source="cve">Multiple vulnerabilities in fliccd, when installed setuid root as part of the kdeedu Kstars support for Instrument Neutral Distributed Interface (INDI) in KDE 3.3 to 3.3.2, allow local users and remote attackers to execute arbitrary code via stack-based buffer overflows.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CONFIRM" url="http://www.kde.org/info/security/advisory-20050215-1.txt">http://www.kde.org/info/security/advisory-20050215-1.txt</ref><ref adv="1" source="FEDORA" url="http://www.redhat.com/archives/fedora-announce-list/2005-February/msg00044.html">FEDORA-2005-148</ref><ref adv="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200502-23.xml">GLSA-200502-23</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/14306">14306</ref></refs><vuln_soft><prod name="KDE" vendor="KDE"><vers num="3.3"/><vers num="3.3.1"/><vers num="3.3.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0012" published="2005-05-02" seq="2005-0012" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in the a_Interface_msg function in Dillo before 0.8.3-r4 allows remote attackers to execute arbitrary code via format string specifiers in a web page.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200501-11.xml">GLSA-200501-11</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/12203">12203</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/13760/">13760</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18807">dillo-capi-format-string(18807)</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13764">13764</ref></refs><vuln_soft><prod name="Dillo Web Browser" vendor="Dillo"><vers num="0.2"/><vers num="0.2.1"/><vers num="0.2.2"/><vers num="0.2.3"/><vers num="0.2.4"/><vers num="0.3"/><vers num="0.3.1"/><vers num="0.4"/><vers num="0.5.1"/><vers num="0.6"/><vers num="0.6.1"/><vers num="0.6.2"/><vers num="0.6.3"/><vers num="0.6.4"/><vers num="0.6.5"/><vers num="0.6.6"/><vers num="0.7"/><vers num="0.7.1.2"/><vers num="0.7.1"/><vers num="0.7.2"/><vers num="0.7.3"/><vers num="0.8"/><vers num="0.8.1"/><vers num="0.8.2"/><vers num="0.8.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0013" published="2005-05-02" seq="2005-0013" severity="High" type="CVE"><desc><descript source="cve">nwclient.c in ncpfs before 2.2.6 does not drop root privileges before executing utilities using the NetWare client functions, which allows local users to gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref source="CONFIRM" url="ftp://platan.vc.cvut.cz/pub/linux/ncpfs/Changes-2.2.6">ftp://platan.vc.cvut.cz/pub/linux/ncpfs/Changes-2.2.6</ref><ref patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-665">DSA-665</ref><ref adv="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200501-44.xml">GLSA-200501-44</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:028">MDKSA-2005:028</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-371.html">RHSA-2005:371</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/433927/100/0/threaded">FLSA:152904</ref><ref source="BID" url="http://www.securityfocus.com/bid/12400">12400</ref><ref source="OSVDB" url="http://www.osvdb.org/13297">13297</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013019">1013019</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:028">MDKSA-2005:028</ref></refs><vuln_soft><prod name="ncpfs" vendor="ncpfs"><vers num="2.2.1"/><vers num="2.2.2"/><vers num="2.2.3"/><vers num="2.2.4"/><vers num="2.2.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0014" published="2005-05-02" seq="2005-0014" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in ncplogin in ncpfs before 2.2.6 allows remote malicious NetWare servers to execute arbitrary code on the NetWare client.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref source="CONFIRM" url="ftp://platan.vc.cvut.cz/pub/linux/ncpfs/Changes-2.2.6">ftp://platan.vc.cvut.cz/pub/linux/ncpfs/Changes-2.2.6</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200501-44.xml">GLSA-200501-44</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:028">MDKSA-2005:028</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/433927/100/0/threaded">FLSA:152904</ref><ref source="BID" url="http://www.securityfocus.com/bid/12400">12400</ref><ref source="OSVDB" url="http://www.osvdb.org/13298">13298</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013019">1013019</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:028">MDKSA-2005:028</ref></refs><vuln_soft><prod name="ncpfs" vendor="ncpfs"><vers num="2.2.5" prev="1"/><vers num="2.2.1"/><vers num="2.2.2"/><vers num="2.2.3"/><vers num="2.2.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0015" published="2005-05-02" seq="2005-0015" severity="High" type="CVE"><desc><descript source="cve">diatheke.pl in Sword 1.5.7a allows remote attackers to execute arbitrary commands via shell metacharacters in a URL.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-650">DSA-650</ref><ref source="MISC" url="http://www.securitytracker.com/alerts/2005/Jan/1012955.html">http://www.securitytracker.com/alerts/2005/Jan/1012955.html</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13897">13897</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18997">sword-diatheke-command-execution(18997)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1012955">1012955</ref><ref source="BID" url="http://www.securityfocus.com/bid/12320">12320</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13941">13941</ref></refs><vuln_soft><prod name="SWORD" vendor="CrossWire Bible Society"><vers num="1.5.7a"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0016" published="2005-04-14" seq="2005-0016" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the exported_display function in xatitv in gatos before 0.0.5 allows local users to execute arbitrary code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2005/dsa-640">gatos -- buffer overflow</ref><ref adv="1" patch="1" source="Secunia.com" url="http://secunia.com/advisories/13884/">Debian GATOS xatitv &quot;exported_display()&quot; Buffer Overflow</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/18930">GATOS xatitv buffer overflow</ref></refs><vuln_soft><prod name="gatos" vendor="gatos"><vers num="0.0.5"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0017" published="2005-05-02" seq="2005-0017" severity="Low" type="CVE"><desc><descript source="cve">The f2c translator in the f2c package 3.1 allows local users to read arbitrary files via a symlink attack on temporary files.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-661">DSA-661</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200501-43.xml">GLSA-200501-43</ref><ref source="BID" url="http://www.securityfocus.com/bid/12380">12380</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013028">1013028</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14041">14041</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14052">14052</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14067">14067</ref></refs><vuln_soft><prod name="f2c translator" vendor="f2c Open Source Project"><vers num="3.1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0018" published="2005-05-02" seq="2005-0018" severity="Low" type="CVE"><desc><descript source="cve">The f2 shell script in the f2c package 3.1 allows local users to read arbitrary files via a symlink attack on temporary files.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-661">DSA-661</ref><ref patch="1" source="" url="http://www.securityfocus.com/bid/12380"></ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013028">1013028</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14041">14041</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14052">14052</ref></refs><vuln_soft><prod name="f2c translator" vendor="f2c Open Source Project"><vers num="3.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0019" published="2005-04-27" seq="2005-0019" severity="Medium" type="CVE"><desc><descript source="cve">Unknown vulnerability in hztty 2.0 and earlier allows local users to execute arbitrary commands.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><other/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Debian.org" url="http://www.debian.org/security/2005/dsa-675">hztty -- privilege escalation</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/12518">bid 12518</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/19297">hztty command execution</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013154">1013154</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14236">14236</ref></refs><vuln_soft><prod name="hztty" vendor="Yongguang Zhang"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0020" published="2005-04-14" seq="2005-0020" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in playmidi before 2.4 allows local users to execute arbitrary code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2005/dsa-641">playmidi -- buffer overflow</ref><ref adv="1" patch="1" source="Mandrakesoft.com" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:010">playmidi</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/18933">Playmidi buffer overflow</ref><ref source="BID" url="http://www.securityfocus.com/bid/12274">12274</ref><ref source="OSVDB" url="http://www.osvdb.org/13049">13049</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1012957">1012957</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13828">13828</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13890">13890</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13898">13898</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:010">MDKSA-2005:010</ref></refs><vuln_soft><prod name="Mandrake Corporate Server" vendor="MandrakeSoft"><vers num="3.0"/></prod><prod name="Mandrake Linux" vendor="MandrakeSoft"><vers edition="AMD64" num="10.0"/><vers num="10.0"/><vers edition="x86_64" num="10.1"/><vers num="10.1"/></prod><prod name="Playmidi" vendor="Playmidi"><vers num="2.3.26"/><vers num="2.3.25.1"/><vers num="2.3.25"/><vers num="2.3.24"/><vers num="2.3.23"/><vers num="2.3.22"/><vers num="2.3.21"/><vers num="2.3.20"/><vers num="2.3.19"/><vers num="2.3.18"/><vers num="2.3.17"/><vers num="2.3.16"/><vers num="2.3.15"/><vers num="2.3.14"/><vers num="2.3.13"/><vers num="2.3.12"/><vers num="2.3.11"/><vers num="2.3.10"/><vers num="2.3.9"/><vers num="2.3.8"/><vers num="2.3.7"/><vers num="2.3.6"/><vers num="2.3.5"/><vers num="2.3.4"/><vers num="2.3.3"/><vers num="2.3.2"/><vers num="2.3.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0021" published="2005-05-02" seq="2005-0021" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in Exim before 4.43 may allow attackers to execute arbitrary code via (1) an IPv6 address with more than 8 components, as demonstrated using the -be command line option, which triggers an overflow in the host_aton function, or (2) the -bh command line option or dnsdb PTR lookup, which triggers an overflow in the dns_build_reverse function.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=179&amp;type=vulnerabilities">20050107 Exim host_aton() Buffer Overflow Vulnerability</ref><ref adv="1" source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=183&amp;type=vulnerabilities">20050114 Exim dns_buld_reverse() Buffer Overflow Vulnerability</ref><ref source="MLIST" url="http://www.exim.org/mail-archives/exim-users/Week-of-Mon-20050103/msg00028.html">[exim] 20050104 2 smallish security issues</ref><ref source="CONFIRM" url="http://ftp6.us.freebsd.org/pub/mail/exim/ChangeLogs/ChangeLog-4.44">http://ftp6.us.freebsd.org/pub/mail/exim/ChangeLogs/ChangeLog-4.44</ref><ref adv="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-635">DSA-635</ref><ref adv="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-637">DSA-637</ref><ref adv="1" source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200501-23.xml">GLSA-200501-23</ref><ref patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-025.html">RHSA-2005:025</ref><ref patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/132992">VU#132992</ref></refs><vuln_soft><prod name="Exim" vendor="University of Cambridge"><vers num="4.42"/><vers num="4.41"/><vers num="4.40" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0022" published="2005-05-02" seq="2005-0022" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in the spa_base64_to_bits function in Exim before 4.43, as originally obtained from Samba code, and as called by the auth_spa_client function, may allow attackers to execute arbitrary code during SPA authentication.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=178&amp;type=vulnerabilities">20050107 Exim auth_spa_server() Buffer Overflow Vulnerability</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110824870908614&amp;w=2">20050212 exim auth_spa_server() PoC exploit</ref><ref patch="1" source="MLIST" url="http://www.exim.org/mail-archives/exim-users/Week-of-Mon-20050103/msg00028.html">[exim] 20050104 2 smallish security issues</ref><ref source="CONFIRM" url="http://ftp6.us.freebsd.org/pub/mail/exim/ChangeLogs/ChangeLog-4.44">http://ftp6.us.freebsd.org/pub/mail/exim/ChangeLogs/ChangeLog-4.44</ref><ref adv="1" source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200501-23.xml">GLSA-200501-23</ref><ref patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-025.html">RHSA-2005:025</ref><ref source="BID" url="http://www.securityfocus.com/bid/12188">12188</ref></refs><vuln_soft><prod name="Exim" vendor="University of Cambridge"><vers num="4.42"/><vers num="4.41"/><vers num="4.40" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0023" published="2005-10-05" seq="2005-0023" severity="Low" type="CVE"><desc><descript source="cve">gnome-pty-helper in GNOME libzvt2 and libvte4 allows local users to spoof the logon hostname via a modified DISPLAY environment variable. NOTE: the severity of this issue has been disputed.</descript></desc><loss_types><int/></loss_types><vuln_types><input/><env/></vuln_types><range><local/></range><refs><ref source="" url="http://bugzilla.gnome.org/show_bug.cgi?id=317312"></ref><ref source="" url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=330907"></ref><ref source="BID" url="http://www.securityfocus.com/bid/15004">15004</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/1931">ADV-2005-1931</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/17023">17023</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/22496">libzvt-gnomeptyhelper-spoof(22496)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112879572407250&amp;w=2">20051007 gnome-pty-helper writes arbitrary utmp records</ref></refs><vuln_soft><prod name="libzvt2" vendor="GNOME"><vers num="1.4.2.19"/></prod><prod name="libvte4" vendor="GNOME"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0033" published="2005-05-02" seq="2005-0033" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in the code for recursion and glue fetching in BIND 8.4.4 and 8.4.5 allows remote attackers to cause a denial of service (crash) via queries that trigger the overflow in the q_usedns array that tracks nameservers and addresses.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref patch="1" source="MISC" url="http://www.uniras.gov.uk/niscc/docs/al-20050125-00059.html">http://www.uniras.gov.uk/niscc/docs/al-20050125-00059.html</ref><ref patch="1" source="CONFIRM" url="http://www.isc.org/index.pl?/sw/bind/bind-security.php">http://www.isc.org/index.pl?/sw/bind/bind-security.php</ref><ref patch="1" source="CONFIRM" url="http://www.isc.org/index.pl?/sw/bind/bind8.php">http://www.isc.org/index.pl?/sw/bind/bind8.php</ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/327633">VU#327633</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19063">bind-qusedns-bo(19063)</ref><ref source="BID" url="http://www.securityfocus.com/bid/12364">12364</ref><ref source="SCO" url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2006.1/SCOSA-2006.1.txt">SCOSA-2006.1</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14009">14009</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18291">18291</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1012996">1012996</ref></refs><vuln_soft><prod name="BIND" vendor="ISC"><vers num="8.4.4"/><vers num="8.4.5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0034" published="2005-05-02" seq="2005-0034" severity="Medium" type="CVE"><desc><descript source="cve">An &quot;incorrect assumption&quot; in the authvalidated validator function in BIND 9.3.0, when DNSSEC is enabled, allows remote attackers to cause a denial of service (named server exit) via crafted DNS packets that cause an internal consistency test (self-check) to fail.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref patch="1" source="MISC" url="http://www.uniras.gov.uk/niscc/docs/al-20050125-00060.html">http://www.uniras.gov.uk/niscc/docs/al-20050125-00060.html</ref><ref patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/938617">VU#938617</ref><ref patch="1" source="CONFIRM" url="http://www.isc.org/index.pl?/sw/bind/bind-security.php">http://www.isc.org/index.pl?/sw/bind/bind-security.php</ref><ref source="CONFIRM" url="http://www.isc.org/index.pl?/sw/bind/bind9.php">http://www.isc.org/index.pl?/sw/bind/bind9.php</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2005/0003/">2005-0003</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19062">bind-named-dns-dos(19062)</ref><ref source="BID" url="http://www.securityfocus.com/bid/12365">12365</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1012995">1012995</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14008">14008</ref></refs><vuln_soft><prod name="BIND" vendor="ISC"><vers num="9.3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0035" published="2005-05-02" seq="2005-0035" severity="Medium" type="CVE"><desc><descript source="cve">The Acrobat web control in Adobe Acrobat and Acrobat Reader 7.0 and earlier, when used with Internet Explorer, allows remote attackers to determine the existence of arbitrary files via the LoadFile ActiveX method.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><env/></vuln_types><range><network/><user_init/></range><refs><ref source="CONFIRM" url="http://www.adobe.com/support/techdocs/331465.html">http://www.adobe.com/support/techdocs/331465.html</ref><ref source="MISC" url="http://www.niscc.gov.uk/niscc/docs/re-20050401-00264.pdf">http://www.niscc.gov.uk/niscc/docs/re-20050401-00264.pdf</ref><ref source="MISC" url="http://www.frsirt.com/english/advisories/2005/0310">http://www.frsirt.com/english/advisories/2005/0310</ref><ref source="MISC" url="http://www.hyperdose.com/advisories/H2005-06.txt">http://www.hyperdose.com/advisories/H2005-06.txt</ref><ref source="BID" url="http://www.securityfocus.com/bid/12989">12989</ref><ref source="OSVDB" url="http://www.osvdb.org/15242">15242</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14813">14813</ref></refs><vuln_soft><prod name="Acrobat Reader" vendor="Adobe"><vers num="7.0"/><vers num="6.0.3"/><vers num="6.0.2"/><vers num="6.0.1"/><vers num="6.0"/><vers num="5.1"/><vers num="5.0.5"/><vers num="5.0"/><vers num="4.5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-28" name="CVE-2005-0036" published="2005-12-31" seq="2005-0036" severity="Medium" type="CVE"><desc><descript source="cve">The DNS implementation in DeleGate 8.10.2 and earlier allows remote attackers to cause a denial of service via a compressed DNS packet with a label length byte with an incorrect offset, which could trigger an infinite loop.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="NISCC" url="http://www.niscc.gov.uk/niscc/docs/re-20050524-00432.pdf?lang=en">NISCC Vulnerability Advisory 589088</ref><ref patch="1" source="NISCC" url="http://www.niscc.gov.uk/niscc/docs/al-20050524-00433.html">Id: 20050524-00433</ref><ref source="BID" url="http://www.securityfocus.com/bid/13729">13729</ref><ref source="OSVDB" url="http://www.osvdb.org/25291">25291</ref></refs><vuln_soft><prod name="DeleGate" vendor="DeleGate"><vers num="8.10.2" prev="1"/><vers num="8.10.1"/><vers num="8.10"/><vers num="8.9.6"/><vers num="8.9.5"/><vers num="8.9.4"/><vers num="8.9.3"/><vers num="8.9.2"/><vers num="8.9.1"/><vers num="8.9"/><vers num="8.5.0"/><vers num="8.4.0"/><vers num="8.3.4"/><vers num="8.3.3"/><vers num="7.9.11"/><vers num="7.8.2"/><vers num="7.8.1"/><vers num="7.8.0"/><vers num="7.7.1"/><vers num="7.7.0"/><vers num="5.9.3"/></prod><prod name="Delegate" vendor="ETL"><vers num="6.0"/><vers num="5.9"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-28" name="CVE-2005-0037" published="2005-12-31" seq="2005-0037" severity="Medium" type="CVE"><desc><descript source="cve">The DNS implementation of DNRD before 2.10 allows remote attackers to cause a denial of service via a compressed DNS packet with a label length byte with an incorrect offset, which could trigger an infinite loop.</descript></desc><sols><sol source="nvd">This vulnerability is addressed in the following product release:
dnrd, dnrd, 2.10 </sol></sols><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref patch="1" source="NISCC" url="http://www.niscc.gov.uk/niscc/docs/al-20050524-00433.html">Id: 20050524-00433</ref><ref source="" url="http://www.niscc.gov.uk/niscc/docs/re-20050524-00432.pdf?lang=en"></ref><ref source="BID" url="http://www.securityfocus.com/bid/13729">13729</ref><ref source="OSVDB" url="http://www.osvdb.org/25291">25291</ref></refs><vuln_soft><prod name="dnrd" vendor="dnrd"><vers num="2.9"/><vers num="2.8"/><vers num="2.7"/><vers num="2.6"/><vers num="2.5"/><vers num="2.4"/><vers num="2.3"/><vers num="2.2"/><vers num="2.1"/><vers num="2.0"/><vers num="1.4"/><vers num="1.3"/><vers num="1.2"/><vers num="1.1"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-28" name="CVE-2005-0038" published="2005-12-31" seq="2005-0038" severity="Medium" type="CVE"><desc><descript source="cve">The DNS implementation of PowerDNS 2.9.16 and earlier allows remote attackers to cause a denial of service via a compressed DNS packet with a label length byte with an incorrect offset, which could trigger an infinite loop.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="NISCC" url="http://www.niscc.gov.uk/niscc/docs/al-20050524-00433.html">Id: 20050524-00433</ref><ref source="" url="http://www.niscc.gov.uk/niscc/docs/re-20050524-00432.pdf?lang=en"></ref><ref source="BID" url="http://www.securityfocus.com/bid/13729">13729</ref><ref source="OSVDB" url="http://www.osvdb.org/25291">25291</ref></refs><vuln_soft><prod name="PowerDNS" vendor="PowerDNS"><vers num="2.9.16" prev="1"/><vers num="2.9.15"/><vers num="2.9.14"/><vers num="2.9.13"/><vers num="2.9.12"/><vers num="2.9.11"/><vers num="2.9.10"/><vers num="2.9.8"/><vers num="2.9.7"/><vers num="2.9.6"/><vers num="2.9.5"/><vers num="2.9.4"/><vers num="2.9.3a"/><vers num="2.9.2"/><vers num="2.9.1"/><vers num="2.9.0"/><vers num="2.8"/><vers num="2.0 RC1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0039" published="2005-05-10" seq="2005-0039" severity="Medium" type="CVE"><desc><descript source="cve">Certain configurations of IPsec, when using Encapsulating Security Payload (ESP) in tunnel mode, integrity protection at a higher layer, or Authentication Header (AH), allow remote attackers to decrypt IPSec communications by modifying the outer packet in ways that cause plaintext data from the inner packet to be returned in ICMP messages, as demonstrated using bit-flipping attacks and (1) Destination Address Rewriting, (2) a modified header length that causes portions of the packet to be interpreted as IP Options, or (3) a modified protocol field and source address.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref source="MISC" url="http://www.niscc.gov.uk/niscc/docs/al-20050509-00386.html?lang=en">http://www.niscc.gov.uk/niscc/docs/al-20050509-00386.html?lang=en</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/407774">HPSBTU01217</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/302220">VU#302220</ref><ref source="BID" url="http://www.securityfocus.com/bid/13562">13562</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/0507">ADV-2005-0507</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/2806">ADV-2005-2806</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015320">1015320</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17938">17938</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111566201610350&amp;w=2">20050509 NISCC Vulnerability Advisory IPSEC - 004033</ref></refs><vuln_soft><prod name="IPsec" vendor="NISSC"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0040" published="2005-05-19" seq="2005-0040" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in DotNetNuke before 3.0.12 allow remote attackers to inject arbitrary web script or HTML via the (1) register a new user page, (2) User-Agent, or (3) Username, which is not properly quoted before sending to the error log.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111627180518591&amp;w=2">20050516 DotNetNuke (Multiple XSS)</ref><ref adv="1" source="MISC" url="http://www.woany.co.uk/advisories/dotnetnukexss.txt">http://www.woany.co.uk/advisories/dotnetnukexss.txt</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15397">15397</ref><ref source="BID" url="http://www.securityfocus.com/bid/13644">13644</ref><ref source="BID" url="http://www.securityfocus.com/bid/13646">13646</ref><ref source="BID" url="http://www.securityfocus.com/bid/13647">13647</ref></refs><vuln_soft><prod name="DotNetNuke" vendor="DotNetNuke"><vers num="3.0.11" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0043" published="2005-05-02" seq="2005-0043" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Apple iTunes 4.7 allows remote attackers to execute arbitrary code via a long URL in (1) .m3u or (2) .pls playlist files.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref patch="1" source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=180&amp;type=vulnerabilities">20050113 Apple iTunes Playlist Parsing Buffer Overflow Vulnerability</ref><ref patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/Jan/msg00000.html">APPLE-SA-2005-01-11</ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/377368">VU#377368</ref><ref source="BID" url="http://www.securityfocus.com/bid/12238">12238</ref><ref source="OSVDB" url="http://www.osvdb.org/12833">12833</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1012839">1012839</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13804">13804</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18851">itunes-m3u-pls-bo(18851)</ref></refs><vuln_soft><prod name="iTunes" vendor="Apple"><vers num="4.7"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-01" name="CVE-2005-0044" published="2005-05-02" seq="2005-0044" severity="High" type="CVE"><desc><descript source="cve">The OLE component in Windows 98, 2000, XP, and Server 2003, and Exchange Server 5.0 through 2003, does not properly validate the lengths of messages for certain OLE data, which allows remote attackers to execute arbitrary code, aka the &quot;Input Validation Vulnerability.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms05-012.mspx">MS05-012</ref><ref patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/927889">VU#927889</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1180.html">OVAL1180</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval2917.html">OVAL2917</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval3568.html">OVAL3568</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval4499.html">OVAL4499</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19109">win-ole-code-execution(19109)</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA05-039A.html">TA05-039A</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1180">oval:org.mitre.oval:def:1180</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2917">oval:org.mitre.oval:def:2917</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3568">oval:org.mitre.oval:def:3568</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4499">oval:org.mitre.oval:def:4499</ref></refs><vuln_soft><prod name="Windows 98" vendor="Microsoft"><vers num="Gold"/><vers num="SE"/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers edition="64-bit" num="R2"/><vers edition="Datacenter 64-bit" num="R2"/><vers edition="64-bit" num="Enterprise"/><vers num="Enterprise 64-bit"/><vers edition="64-bit" num="Standard"/><vers num="Web"/></prod><prod name="Windows XP" vendor="Microsoft"><vers edition="SP1" num="64-bit"/><vers num="64-bit"/><vers num="64-bit Version 2003"/><vers edition="SP2" num="Home"/><vers edition="SP1" num="Home"/><vers num="Home"/><vers edition="Gold" num="Professional"/><vers edition="Gold" num="Professional"/><vers edition="Gold" num="Professional"/><vers edition="SP2" num="Media Center"/><vers edition="SP1" num="Media Center"/><vers num="Media Center"/><vers edition="SP2" num="Tablet PC"/><vers edition="SP2" num="Tablet PC"/><vers edition="SP2" num="Tablet PC"/></prod><prod name="exchange srv" vendor="Microsoft"><vers num="5.0"/></prod><prod name="Windows ME" vendor="Microsoft"><vers num=""/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num="Advanced Server SP4"/><vers num="Advanced Server SP3"/><vers num="Advanced Server SP2"/><vers num="Advanced Server SP1"/><vers num="Advanced Server"/><vers num="Datacenter Server SP4"/><vers num="Datacenter Server SP3"/><vers num="Datacenter Server SP2"/><vers num="Datacenter Server SP1"/><vers num="Datacenter Server"/><vers num="Professional SP4"/><vers num="Professional SP3"/><vers num="Professional SP2"/><vers num="Professional SP1"/><vers num="Professional"/><vers num="Server SP4"/><vers num="Server SP3"/><vers num="Server SP2"/><vers num="Server SP1"/><vers num="Server"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0045" published="2005-05-02" seq="2005-0045" severity="High" type="CVE"><desc><descript source="cve">The Server Message Block (SMB) implementation for Windows NT 4.0, 2000, XP, and Server 2003 does not properly validate certain SMB packets, which allows remote attackers to execute arbitrary code via Transaction responses containing (1) Trans or (2) Trans2 commands, aka the &quot;Server Message Block Vulnerability,&quot; and as demonstrated using Trans2 FIND_FIRST2 responses with large file name length fields.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110792638401852&amp;w=2">20050209 EEYE: Windows SMB Client Transaction Response Handling Vulnerability</ref><ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=110795643831169&amp;w=2">20050209 EEYE: Windows SMB Client Transaction Response Handling Vulnerability</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111040962600205&amp;w=2">20050309 Update: MS05-011 EEYE: Windows SMB Client Transaction Response Handling Vulnerability</ref><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms05-011.mspx">MS05-011</ref><ref adv="1" patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA05-039A.html">TA05-039A</ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/652537">VU#652537</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1606.html">OVAL1606</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1847.html">OVAL1847</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1889.html">OVAL1889</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval4043.html">OVAL4043</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19089">win-smb-code-execution(19089)</ref><ref source="BID" url="http://www.securityfocus.com/bid/12484">12484</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1606">oval:org.mitre.oval:def:1606</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1847">oval:org.mitre.oval:def:1847</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1889">oval:org.mitre.oval:def:1889</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4043">oval:org.mitre.oval:def:4043</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num="Enterprise Server 4.0 SP6a"/><vers num="Enterprise Server 4.0 SP5"/><vers num="Enterprise Server 4.0 SP4"/><vers num="Enterprise Server 4.0 SP3"/><vers num="Enterprise Server 4.0 SP2"/><vers num="Enterprise Server 4.0 SP1"/><vers num="Enterprise Server 4.0"/><vers num="Server 4.0 SP6a"/><vers num="Server 4.0 SP5"/><vers num="Server 4.0 SP4"/><vers num="Server 4.0 SP3"/><vers num="Server 4.0 SP2"/><vers num="Server 4.0 SP1"/><vers num="Server 4.0"/><vers num="Terminal Server 4.0 SP6a"/><vers num="Terminal Server 4.0 SP5"/><vers num="Terminal Server 4.0 SP4"/><vers num="Terminal Server 4.0 SP3"/><vers num="Terminal Server 4.0 SP2"/><vers num="Terminal Server 4.0 SP1"/><vers num="Terminal Server 4.0"/><vers num="Workstation 4.0 SP6a"/><vers num="Workstation 4.0 SP5"/><vers num="Workstation 4.0 SP4"/><vers num="Workstation 4.0 SP3"/><vers num="Workstation 4.0 SP2"/><vers num="Workstation 4.0 SP1"/><vers num="Workstation 4.0"/></prod><prod name="Windows XP" vendor="Microsoft"><vers edition="SP1" num="64-bit"/><vers num="64-bit"/><vers edition="SP1" num="64-bit Version 2003"/><vers num="64-bit Version 2003"/><vers edition="SP2" num="Home"/><vers edition="SP1" num="Home"/><vers num="Home"/><vers edition="Gold" num="Professional"/><vers edition="Gold" num="Professional"/><vers edition="Gold" num="Professional"/><vers edition="SP2" num="Media Center"/><vers edition="SP1" num="Media Center"/><vers num="Media Center"/><vers edition="SP2" num="Tablet PC"/><vers edition="SP2" num="Tablet PC"/><vers edition="SP2" num="Tablet PC"/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers edition="64-bit" num="R2"/><vers edition="Datacenter 64-bit" num="R2"/><vers edition="64-bit" num="Enterprise"/><vers num="Enterprise 64-bit"/><vers edition="64-bit" num="Standard"/><vers num="Web"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num="Advanced Server SP4"/><vers num="Advanced Server SP3"/><vers num="Advanced Server SP2"/><vers num="Advanced Server SP1"/><vers num="Advanced Server"/><vers num="Professional SP4"/><vers num="Professional SP3"/><vers num="Professional SP2"/><vers num="Professional SP1"/><vers num="Professional"/><vers num="Server SP4"/><vers num="Server SP3"/><vers num="Server SP2"/><vers num="Server SP1"/><vers num="Server"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0047" published="2005-05-02" seq="2005-0047" severity="High" type="CVE"><desc><descript source="cve">Windows 2000, XP, and Server 2003 does not properly &quot;validate the use of memory regions&quot; for COM structured storage files, which allows attackers to execute arbitrary code, aka the &quot;COM Structured Storage Vulnerability.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/><design/></vuln_types><range><local/></range><refs><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms05-012.mspx">MS05-012</ref><ref patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA05-039A.html">TA05-039A</ref><ref patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/597889">VU#597889</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1159.html">OVAL1159</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval2351.html">OVAL2351</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval2892.html">OVAL2892</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval901.html">OVAL901</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19105">win-com-gain-privileges(19105)</ref><ref source="MISC" url="http://www.argeniss.com/research/SSExploit.c">http://www.argeniss.com/research/SSExploit.c</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111755870828817&amp;w=2">20050530 [Argeniss] MS05-012 Exploit</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1159">oval:org.mitre.oval:def:1159</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2351">oval:org.mitre.oval:def:2351</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2892">oval:org.mitre.oval:def:2892</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:901">oval:org.mitre.oval:def:901</ref></refs><vuln_soft><prod name="Windows XP" vendor="Microsoft"><vers edition="SP1" num="64-bit"/><vers num="64-bit"/><vers num="64-bit Version 2003"/><vers edition="SP2" num="Home"/><vers edition="SP1" num="Home"/><vers num="Home"/><vers edition="Gold" num="Professional"/><vers edition="Gold" num="Professional"/><vers edition="Gold" num="Professional"/><vers edition="SP2" num="Media Center"/><vers edition="SP1" num="Media Center"/><vers num="Media Center"/><vers edition="SP2" num="Tablet PC"/><vers edition="SP2" num="Tablet PC"/><vers edition="SP2" num="Tablet PC"/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers edition="64-bit" num="R2"/><vers edition="Datacenter 64-bit" num="R2"/><vers edition="64-bit" num="Enterprise"/><vers num="Enterprise 64-bit"/><vers edition="64-bit" num="Standard"/><vers num="Web"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num="Advanced Server SP4"/><vers num="Advanced Server SP3"/><vers num="Advanced Server SP2"/><vers num="Advanced Server SP1"/><vers num="Advanced Server"/><vers num="Datacenter Server SP4"/><vers num="Datacenter Server SP3"/><vers num="Datacenter Server SP2"/><vers num="Datacenter Server SP1"/><vers num="Datacenter Server"/><vers num="Professional SP4"/><vers num="Professional SP3"/><vers num="Professional SP2"/><vers num="Professional SP1"/><vers num="Professional"/><vers num="Server SP4"/><vers num="Server SP3"/><vers num="Server SP2"/><vers num="Server SP1"/><vers num="Server"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0048" published="2005-05-02" seq="2005-0048" severity="High" type="CVE"><desc><descript source="cve">Microsoft Windows XP SP2 and earlier, 2000 SP3 and SP4, Server 2003, and older operating systems allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted IP packets with malformed options, aka the &quot;IP Validation Vulnerability.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms05-019.mspx">MS05-019</ref><ref adv="1" source="ISS" url="http://xforce.iss.net/xforce/alerts/id/192">20050412 Windows IP Options Remote Compromise</ref><ref patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA05-102A.html">TA05-102A</ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/233754">VU#233754</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval3824.html">OVAL3824</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1744.html">OVAL1744</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval4549.html">OVAL4549</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3824">oval:org.mitre.oval:def:3824</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1744">oval:org.mitre.oval:def:1744</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4549">oval:org.mitre.oval:def:4549</ref></refs><vuln_soft><prod name="Windows XP" vendor="Microsoft"><vers edition="SP1" num="64-bit"/><vers num="64-bit"/><vers edition="SP1" num="64-bit Version 2003"/><vers num="64-bit Version 2003"/><vers edition="SP1" num="Embedded"/><vers num="Embedded"/><vers edition="SP1" num="Home"/><vers num="Home"/><vers edition="Gold" num="Professional"/><vers edition="Gold" num="Professional"/><vers edition="SP1" num="Media Center"/><vers num="Media Center"/><vers edition="SP2" num="Tablet PC"/><vers edition="SP2" num="Tablet PC"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num="Advanced Server SP4"/><vers num="Advanced Server SP3"/><vers num="Advanced Server SP2"/><vers num="Advanced Server SP1"/><vers num="Advanced Server"/><vers num="Datacenter Server SP4"/><vers num="Datacenter Server SP3"/><vers num="Datacenter Server SP2"/><vers num="Datacenter Server SP1"/><vers num="Datacenter Server"/><vers num="Professional SP4"/><vers num="Professional SP3"/><vers num="Professional SP2"/><vers num="Professional SP1"/><vers num="Professional"/><vers num="Server SP4"/><vers num="Server SP3"/><vers num="Server SP2"/><vers num="Server SP1"/><vers num="Server"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0049" published="2005-05-02" seq="2005-0049" severity="Medium" type="CVE"><desc><descript source="cve">Windows SharePoint Services and SharePoint Team Services for Windows Server 2003 does not properly validate an HTTP redirection query, which allows remote attackers to inject arbitrary HTML and web script via a cross-site scripting (XSS) attack, or to spoof the web cache.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms05-006.mspx">MS05-006</ref><ref patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA05-039A.html">TA05-039A</ref><ref patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/340409">VU#340409</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19091">win-sharepoint-services-xss(19091)</ref></refs><vuln_soft><prod name="Windows SharePoint Services" vendor="Microsoft"><vers num="Windows Server 2003 SP1"/><vers num="Windows Server 2003"/></prod><prod name="SharePoint Team Services" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0050" published="2005-05-02" seq="2005-0050" severity="High" type="CVE"><desc><descript source="cve">The License Logging service for Windows NT Server, Windows 2000 Server, and Windows Server 2003 does not properly validate the length of messages, which leads to an &quot;unchecked buffer&quot; and allows remote attackers to cause a denial of service (crash) and possibly execute arbtirary code, aka the &quot;License Logging Service Vulnerability.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms05-010.mspx">MS05-010</ref><ref patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA05-039A.html">TA05-039A</ref><ref patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/130433">VU#130433</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval2568.html">OVAL2568</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval3582.html">OVAL3582</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval4786.html">OVAL4786</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval644.html">OVAL644</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19101">win-license-code-execution(19101)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2568">oval:org.mitre.oval:def:2568</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3582">oval:org.mitre.oval:def:3582</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4786">oval:org.mitre.oval:def:4786</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:644">oval:org.mitre.oval:def:644</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num="Enterprise Server 4.0 SP6a"/><vers num="Enterprise Server 4.0 SP6"/><vers num="Enterprise Server 4.0 SP5"/><vers num="Enterprise Server 4.0 SP4"/><vers num="Enterprise Server 4.0 SP3"/><vers num="Enterprise Server 4.0 SP2"/><vers num="Enterprise Server 4.0 SP1"/><vers num="Enterprise Server 4.0"/><vers num="Server 4.0 SP6a"/><vers num="Server 4.0 SP6"/><vers num="Server 4.0 SP5"/><vers num="Server 4.0 SP4"/><vers num="Server 4.0 SP3"/><vers num="Server 4.0 SP2"/><vers num="Server 4.0 SP1"/><vers num="Server 4.0"/><vers num="Terminal Server 4.0 SP6a"/><vers num="Terminal Server 4.0 SP6"/><vers num="Terminal Server 4.0 SP5"/><vers num="Terminal Server 4.0 SP4"/><vers num="Terminal Server 4.0 SP3"/><vers num="Terminal Server 4.0 SP2"/><vers num="Terminal Server 4.0 SP1"/><vers num="Terminal Server 4.0"/></prod><prod name="Small Business Server" vendor="Microsoft"><vers num="2000"/><vers num="2003"/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers edition="64-bit" num="R2"/><vers edition="Datacenter 64-bit" num="R2"/><vers edition="64-bit" num="Enterprise"/><vers num="Enterprise 64-bit"/><vers edition="64-bit" num="Standard"/><vers num="Web"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num="Advanced Server SP4"/><vers num="Advanced Server SP3"/><vers num="Advanced Server SP2"/><vers num="Advanced Server SP1"/><vers num="Advanced Server"/><vers num="Datacenter Server SP4"/><vers num="Datacenter Server SP3"/><vers num="Datacenter Server SP2"/><vers num="Datacenter Server SP1"/><vers num="Datacenter Server"/><vers num="Server SP4"/><vers num="Server SP3"/><vers num="Server SP2"/><vers num="Server SP1"/><vers num="Server"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0051" published="2005-05-02" seq="2005-0051" severity="High" type="CVE"><desc><descript source="cve">The Server service (srvsvc.dll) in Windows XP SP1 and SP2 allows remote attackers to obtain sensitive information (users who are accessing resources) via an anonymous logon using a named pipe, which is not properly authenticated, aka the &quot;Named Pipe Vulnerability.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms05-007.mspx">MS05-007</ref><ref adv="1" patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA05-039A.html">TA05-039A</ref><ref patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/939074">VU#939074</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval2292.html">OVAL2292</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval3055.html">OVAL3055</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19093">win-named-pipe-information-disclosure (19093)</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14189">14189</ref><ref source="BID" url="http://www.securityfocus.com/bid/12486">12486</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013112">1013112</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2292">oval:org.mitre.oval:def:2292</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3055">oval:org.mitre.oval:def:3055</ref></refs><vuln_soft><prod name="Windows XP" vendor="Microsoft"><vers edition="Tablet PC" num="SP1"/><vers edition="Tablet PC" num="SP2"/><vers edition="SP1" num="64-bit"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0053" published="2005-05-02" seq="2005-0053" severity="High" type="CVE"><desc><descript source="cve">Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via drag and drop events, aka the &quot;Drag-and-Drop Vulnerability.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms05-014.mspx">MS05-014</ref><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms05-008.mspx">MS05-008</ref><ref patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA05-039A.html">TA05-039A</ref><ref patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/698835">VU#698835</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1334.html">OVAL1334</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval2046.html">OVAL2046</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval2953.html">OVAL2953</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval3006.html">OVAL3006</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval4726.html">OVAL4726</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval4864.html">OVAL4864</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19117">ie-dragdrop-gain-privileges(19117)</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/11466">11466</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1015.html">OVAL1015</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1334">oval:org.mitre.oval:def:1334</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2046">oval:org.mitre.oval:def:2046</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2953">oval:org.mitre.oval:def:2953</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3006">oval:org.mitre.oval:def:3006</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4726">oval:org.mitre.oval:def:4726</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4864">oval:org.mitre.oval:def:4864</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1015">oval:org.mitre.oval:def:1015</ref></refs><vuln_soft><prod name="Windows 98" vendor="Microsoft"><vers num="Gold"/><vers num="SE"/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers edition="64-bit" num="R2"/><vers edition="Datacenter 64-bit" num="R2"/><vers edition="64-bit" num="Enterprise"/><vers num="Enterprise 64-bit"/><vers edition="64-bit" num="Standard"/><vers num="Web"/></prod><prod name="Windows XP" vendor="Microsoft"><vers edition="SP1" num="64-bit"/><vers num="64-bit"/><vers num="64-bit Version 2003"/><vers edition="SP2" num="Home"/><vers edition="SP1" num="Home"/><vers num="Home"/><vers edition="Gold" num="Professional"/><vers edition="Gold" num="Professional"/><vers edition="Gold" num="Professional"/><vers edition="SP2" num="Media Center"/><vers edition="SP1" num="Media Center"/><vers num="Media Center"/><vers edition="SP2" num="Tablet PC"/><vers edition="SP2" num="Tablet PC"/><vers edition="SP2" num="Tablet PC"/></prod><prod name="Internet Explorer" vendor="Microsoft"><vers num="5.0.1 SP4"/><vers num="5.0.1 SP3"/><vers num="5.0.1 SP2"/><vers num="5.0.1 SP1"/><vers num="5.0.1"/><vers num="5.5 SP2"/><vers num="5.5 SP1"/><vers num="5.5"/><vers num="6.0 SP2"/><vers num="6.0 SP1"/><vers num="6.0"/></prod><prod name="Windows ME" vendor="Microsoft"><vers num=""/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num="Advanced Server SP4"/><vers num="Advanced Server SP3"/><vers num="Advanced Server SP2"/><vers num="Advanced Server SP1"/><vers num="Advanced Server"/><vers num="Datacenter Server SP4"/><vers num="Datacenter Server SP3"/><vers num="Datacenter Server SP2"/><vers num="Datacenter Server SP1"/><vers num="Datacenter Server"/><vers num="Professional SP4"/><vers num="Professional SP3"/><vers num="Professional SP2"/><vers num="Professional SP1"/><vers num="Professional"/><vers num="Server SP4"/><vers num="Server SP3"/><vers num="Server SP2"/><vers num="Server SP1"/><vers num="Server"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0054" published="2005-05-02" seq="2005-0054" severity="Medium" type="CVE"><desc><descript source="cve">Internet Explorer 5.01, 5.5, and 6 allows remote attackers to spoof a less restrictive security zone and execute arbitrary code via an HTML page containing URLs that contain hostnames that have been double hex encoded, which are decoded twice to generate a malicious hostname, aka the &quot;URL Decoding Zone Spoofing Vulnerability.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><exception/></vuln_types><range><network/><user_init/></range><refs><ref patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110796851002781&amp;w=2">20050209 Internet Explorer zone spoofing with encoded URLs</ref><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms05-014.mspx">MS05-014</ref><ref patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA05-039A.html">TA05-039A</ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/580299">VU#580299</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1308.html">OVAL1308</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1736.html">OVAL1736</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval3060.html">OVAL3060</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval3196.html">OVAL3196</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval3586.html">OVAL3586</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19214">ie-file-url-encode(19214)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1308">oval:org.mitre.oval:def:1308</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1736">oval:org.mitre.oval:def:1736</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3060">oval:org.mitre.oval:def:3060</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3196">oval:org.mitre.oval:def:3196</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3586">oval:org.mitre.oval:def:3586</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="5.01"/><vers num="5.5"/><vers edition="Windows Server 2003 SP1" num="6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0055" published="2005-05-02" seq="2005-0055" severity="High" type="CVE"><desc><descript source="cve">Internet Explorer 5.01, 5.5, and 6 does not properly validate buffers when handling certain DHTML methods including the createControlRange Javascript function, which allows remote attackers to execute arbitrary code, aka the &quot;DHTML Method Heap Memory Corruption Vulnerability.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms05-014.mspx">MS05-014</ref><ref patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA05-039A.html">TA05-039A</ref><ref patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/843771">VU#843771</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/12427">12427</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1005.html">OVAL1005</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval2692.html">OVAL2692</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval3137.html">OVAL3137</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval3910.html">OVAL3910</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval710.html">OVAL710</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19137">ie-cdf-execute-code(19137)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013125">1013125</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1005">oval:org.mitre.oval:def:1005</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2692">oval:org.mitre.oval:def:2692</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3137">oval:org.mitre.oval:def:3137</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3910">oval:org.mitre.oval:def:3910</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:710">oval:org.mitre.oval:def:710</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="5.0.1 SP4"/><vers num="5.0.1 SP3"/><vers num="5.0.1 SP2"/><vers num="5.0.1 SP1"/><vers num="5.0.1"/><vers num="5.5 SP2"/><vers num="5.5 SP1"/><vers num="5.5"/><vers num="6.0 SP2"/><vers num="6.0 SP1"/><vers num="6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0056" published="2005-05-02" seq="2005-0056" severity="Medium" type="CVE"><desc><descript source="cve">Internet Explorer 5.01, 5.5, and 6 does not properly validate certain URLs in Channel Definition Format (CDF) files, which allows remote attackers to obtain sensitive information or execute arbitrary code, aka the &quot;Channel Definition Format (CDF) Cross Domain Vulnerability.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><design/></vuln_types><range><network/><user_init/></range><refs><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms05-014.mspx">MS05-014</ref><ref patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA05-039A.html">TA05-039A</ref><ref patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/823971">VU#823971</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval2385.html">OVAL2385</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval2817.html">OVAL2817</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval3318.html">OVAL3318</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval4085.html">OVAL4085</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval4947.html">OVAL4947</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19137">ie-cdf-execute-code(19137)</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/12427">12427</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013126">1013126</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2385">oval:org.mitre.oval:def:2385</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2817">oval:org.mitre.oval:def:2817</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3318">oval:org.mitre.oval:def:3318</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4085">oval:org.mitre.oval:def:4085</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4947">oval:org.mitre.oval:def:4947</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="5.01"/><vers num="5.5"/><vers edition="Windows Server 2003 SP1" num="6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0057" published="2005-05-02" seq="2005-0057" severity="High" type="CVE"><desc><descript source="cve">The Hyperlink Object Library for Windows 98, 2000, XP, and Server 2003 allows remote attackers to execute arbitrary code via a crafted link that triggers an &quot;unchecked buffer&quot; in the library, possibly due to a buffer overflow.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms05-015.mspx">MS05-015</ref><ref patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA05-039A.html">TA05-039A</ref><ref patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/820427">VU#820427</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval2570.html">OVAL2570</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval3203.html">OVAL3203</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval713.html">OVAL713</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19110">win-hyperlink-code-execution(19110)</ref><ref source="BID" url="http://www.securityfocus.com/bid/12479">12479</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013119">1013119</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14195">14195</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2570">oval:org.mitre.oval:def:2570</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3203">oval:org.mitre.oval:def:3203</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:713">oval:org.mitre.oval:def:713</ref></refs><vuln_soft><prod name="Windows 98" vendor="Microsoft"><vers num="Gold"/><vers num="SE"/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers edition="64-bit" num="R2"/><vers edition="Datacenter 64-bit" num="R2"/><vers edition="64-bit" num="Enterprise"/><vers num="Enterprise 64-bit"/><vers edition="64-bit" num="Standard"/><vers num="Web"/></prod><prod name="Windows XP" vendor="Microsoft"><vers edition="SP1" num="64-bit"/><vers num="64-bit"/><vers num="64-bit Version 2003"/><vers edition="SP2" num="Home"/><vers edition="SP1" num="Home"/><vers num="Home"/><vers edition="Gold" num="Professional"/><vers edition="Gold" num="Professional"/><vers edition="Gold" num="Professional"/><vers edition="SP2" num="Media Center"/><vers edition="SP1" num="Media Center"/><vers num="Media Center"/><vers edition="SP2" num="Tablet PC"/><vers edition="SP2" num="Tablet PC"/><vers edition="SP2" num="Tablet PC"/></prod><prod name="Windows ME" vendor="Microsoft"><vers num=""/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num="Advanced Server SP4"/><vers num="Advanced Server SP3"/><vers num="Advanced Server SP2"/><vers num="Advanced Server SP1"/><vers num="Advanced Server"/><vers num="Datacenter Server SP4"/><vers num="Datacenter Server SP3"/><vers num="Datacenter Server SP2"/><vers num="Datacenter Server SP1"/><vers num="Datacenter Server"/><vers num="Professional SP4"/><vers num="Professional SP3"/><vers num="Professional SP2"/><vers num="Professional SP1"/><vers num="Professional"/><vers num="Server SP4"/><vers num="Server SP3"/><vers num="Server SP2"/><vers num="Server SP1"/><vers num="Server"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0058" published="2005-08-10" seq="2005-0058" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the Telephony Application Programming Interface (TAPI) for Microsoft Windows 98, Windows 98 SE, Windows ME, Windows 2000, Windows XP, and Windows Server 2003 allows attackers elevate privileges or execute arbitrary code via a crafted message.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref patch="1" source="MS" url="http://www.microsoft.com/technet/Security/bulletin/ms05-040.mspx">MS05-040</ref><ref patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA05-221A.html">TA05-221A</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/16354/">16354</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval100084.html">OVAL100084</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval100085.html">OVAL100085</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval100086.html">OVAL100086</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval100088.html">OVAL100088</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1075.html">OVAL1075</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1213.html">OVAL1213</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1297.html">OVAL1297</ref><ref source="BID" url="http://www.securityfocus.com/bid/14518">14518</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014639">1014639</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100084">oval:org.mitre.oval:def:100084</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100085">oval:org.mitre.oval:def:100085</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100086">oval:org.mitre.oval:def:100086</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100088">oval:org.mitre.oval:def:100088</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1075">oval:org.mitre.oval:def:1075</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1213">oval:org.mitre.oval:def:1213</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1297">oval:org.mitre.oval:def:1297</ref></refs><vuln_soft><prod name="Windows 98" vendor="Microsoft"><vers num="Gold"/><vers num="SE"/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers num="R2"/></prod><prod name="Windows XP" vendor="Microsoft"><vers num="Gold"/></prod><prod name="Windows ME" vendor="Microsoft"><vers num=""/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0059" published="2005-05-02" seq="2005-0059" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the Message Queuing component of Microsoft Windows 2000 and Windows XP SP1 allows remote attackers to execute arbitrary code via a crafted message.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms05-017.mspx">MS05-017</ref><ref patch="1" source="bid" url="http://www.securityfocus.com/bid/13112">13112</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval4384.html">OVAL4384</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval4988.html">OVAL4988</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4384">oval:org.mitre.oval:def:4384</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4988">oval:org.mitre.oval:def:4988</ref></refs><vuln_soft><prod name="Windows 98" vendor="Microsoft"><vers num="Gold"/><vers num="SE"/></prod><prod name="Windows XP" vendor="Microsoft"><vers edition="SP1" num="64-bit"/><vers num="64-bit"/><vers edition="SP1" num="Embedded"/><vers num="Embedded"/><vers edition="SP1" num="Home"/><vers num="Home"/><vers edition="Gold" num="Professional"/><vers edition="Gold" num="Professional"/><vers edition="SP1" num="Media Center"/><vers num="Media Center"/><vers edition="SP2" num="Tablet PC"/><vers edition="SP2" num="Tablet PC"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num="Advanced Server SP4"/><vers num="Advanced Server SP3"/><vers num="Advanced Server SP2"/><vers num="Advanced Server SP1"/><vers num="Advanced Server"/><vers num="Datacenter Server SP4"/><vers num="Datacenter Server SP3"/><vers num="Datacenter Server SP2"/><vers num="Datacenter Server SP1"/><vers num="Datacenter Server"/><vers num="Professional SP4"/><vers num="Professional SP3"/><vers num="Professional SP2"/><vers num="Professional SP1"/><vers num="Professional"/><vers num="Server SP4"/><vers num="Server SP3"/><vers num="Server SP2"/><vers num="Server SP1"/><vers num="Server"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0060" published="2005-05-02" seq="2005-0060" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the font processing component of Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2003 allows local users to gain privileges via a specially-designed application.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><local/></range><refs><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms05-018.mspx">MS05-018</ref><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111343529426926&amp;w=2">20050413 Windows kernel overflow fixed</ref><ref adv="1" source="MISC" url="http://www.ngssoftware.com/advisories/ms-01.txt">http://www.ngssoftware.com/advisories/ms-01.txt</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval2562.html">OVAL2562</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval2731.html">OVAL2731</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval3941.html">OVAL3941</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval4797.html">OVAL4797</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2562">oval:org.mitre.oval:def:2562</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2731">oval:org.mitre.oval:def:2731</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3941">oval:org.mitre.oval:def:3941</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4797">oval:org.mitre.oval:def:4797</ref></refs><vuln_soft><prod name="Windows 98" vendor="Microsoft"><vers num="Gold"/><vers num="SE"/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers edition="64-bit" num="R2"/><vers edition="Datacenter 64-bit" num="R2"/><vers edition="64-bit" num="Enterprise"/><vers num="Enterprise 64-bit"/><vers edition="64-bit" num="Standard"/><vers num="Web"/></prod><prod name="Windows XP" vendor="Microsoft"><vers edition="SP1" num="64-bit"/><vers num="64-bit"/><vers num="64-bit Version 2003"/><vers edition="SP2" num="Home"/><vers edition="SP1" num="Home"/><vers num="Home"/><vers edition="Gold" num="Professional"/><vers edition="Gold" num="Professional"/><vers edition="Gold" num="Professional"/><vers edition="SP2" num="Media Center"/><vers edition="SP1" num="Media Center"/><vers num="Media Center"/><vers edition="SP2" num="Tablet PC"/><vers edition="SP2" num="Tablet PC"/><vers edition="SP2" num="Tablet PC"/></prod><prod name="Windows ME" vendor="Microsoft"><vers num=""/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num="Advanced Server SP4"/><vers num="Advanced Server SP3"/><vers num="Advanced Server SP2"/><vers num="Advanced Server SP1"/><vers num="Advanced Server"/><vers num="Datacenter Server SP4"/><vers num="Datacenter Server SP3"/><vers num="Datacenter Server SP2"/><vers num="Datacenter Server SP1"/><vers num="Datacenter Server"/><vers num="Professional SP4"/><vers num="Professional SP3"/><vers num="Professional SP2"/><vers num="Professional SP1"/><vers num="Professional"/><vers num="Server SP4"/><vers num="Server SP3"/><vers num="Server SP2"/><vers num="Server SP1"/><vers num="Server"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0061" published="2005-05-02" seq="2005-0061" severity="High" type="CVE"><desc><descript source="cve">The kernel of Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2003 allows local users to gain privileges via certain access requests.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><local/></range><refs><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms05-018.mspx">MS05-018</ref><ref patch="1" source="bid" url="http://www.securityfocus.com/bid/13121">13121</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1656.html">OVAL1656</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1761.html">OVAL1761</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval3994.html">OVAL3994</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval4593.html">OVAL4593</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1656">oval:org.mitre.oval:def:1656</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1761">oval:org.mitre.oval:def:1761</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3994">oval:org.mitre.oval:def:3994</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4593">oval:org.mitre.oval:def:4593</ref></refs><vuln_soft><prod name="Windows 98" vendor="Microsoft"><vers num="Gold"/><vers num="SE"/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers edition="64-bit" num="R2"/><vers edition="Datacenter 64-bit" num="R2"/><vers edition="64-bit" num="Enterprise"/><vers num="Enterprise 64-bit"/><vers edition="64-bit" num="Standard"/><vers num="Web"/></prod><prod name="Windows XP" vendor="Microsoft"><vers edition="SP1" num="64-bit"/><vers num="64-bit"/><vers num="64-bit Version 2003"/><vers edition="SP2" num="Home"/><vers edition="SP1" num="Home"/><vers num="Home"/><vers edition="Gold" num="Professional"/><vers edition="Gold" num="Professional"/><vers edition="Gold" num="Professional"/><vers edition="SP2" num="Media Center"/><vers edition="SP1" num="Media Center"/><vers num="Media Center"/></prod><prod name="Windows ME" vendor="Microsoft"><vers num=""/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num="Advanced Server SP4"/><vers num="Advanced Server SP3"/><vers num="Advanced Server SP2"/><vers num="Advanced Server SP1"/><vers num="Advanced Server"/><vers num="Datacenter Server SP4"/><vers num="Datacenter Server SP3"/><vers num="Datacenter Server SP2"/><vers num="Datacenter Server SP1"/><vers num="Datacenter Server"/><vers num="Professional SP4"/><vers num="Professional SP3"/><vers num="Professional SP2"/><vers num="Professional SP1"/><vers num="Professional"/><vers num="Server SP4"/><vers num="Server SP3"/><vers num="Server SP2"/><vers num="Server SP1"/><vers num="Server"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0063" published="2005-05-02" seq="2005-0063" severity="High" type="CVE"><desc><descript source="cve">The document processing application used by the Windows Shell in Microsoft Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code by modifying the CLSID stored in a file so that it is processed by HTML Application Host (MSHTA), as demonstrated using a Microsoft Word document.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms05-016.mspx">MS05-016</ref><ref patch="1" source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=231&amp;type=vulnerabilities">20050412 Microsoft MSHTA Script Execution Vulnerability</ref><ref source="MISC" url="http://www.securiteam.com/exploits/5YP0T0AFFW.html">http://www.securiteam.com/exploits/5YP0T0AFFW.html</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/0335">ADV-2005-0335</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval2184.html">OVAL2184</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval3456.html">OVAL3456</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval407.html">OVAL407</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval4710.html">OVAL4710</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval573.html">OVAL573</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval587.html">OVAL587</ref><ref source="BID" url="http://www.securityfocus.com/bid/13132">13132</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111755356016155&amp;w=2">20050529 Spam exploiting MS05-016</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2184">oval:org.mitre.oval:def:2184</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3456">oval:org.mitre.oval:def:3456</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:407">oval:org.mitre.oval:def:407</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4710">oval:org.mitre.oval:def:4710</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:573">oval:org.mitre.oval:def:573</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:587">oval:org.mitre.oval:def:587</ref></refs><vuln_soft><prod name="Windows 98" vendor="Microsoft"><vers num="Gold"/><vers num="SE"/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers edition="64-bit" num="R2"/><vers edition="64-bit" num="Enterprise"/><vers edition="64-bit" num="Standard"/><vers num="Web"/></prod><prod name="Windows XP" vendor="Microsoft"><vers edition="SP1" num="64-bit"/><vers edition="SP1" num="64-bit Version 2003"/><vers edition="SP2" num="Home"/><vers edition="SP1" num="Home"/><vers num="Home"/><vers edition="Gold" num="Professional"/><vers edition="Gold" num="Professional"/><vers edition="Gold" num="Professional"/><vers edition="SP2" num="Media Center"/><vers edition="SP1" num="Media Center"/><vers num="Media Center"/><vers edition="SP2" num="Tablet PC"/><vers edition="SP2" num="Tablet PC"/><vers edition="SP2" num="Tablet PC"/></prod><prod name="Windows ME" vendor="Microsoft"><vers num=""/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num="Advanced Server SP4"/><vers num="Advanced Server SP3"/><vers num="Advanced Server SP2"/><vers num="Advanced Server SP1"/><vers num="Advanced Server"/><vers num="Datacenter Server SP4"/><vers num="Datacenter Server SP3"/><vers num="Datacenter Server SP2"/><vers num="Datacenter Server SP1"/><vers num="Datacenter Server"/><vers num="Professional SP4"/><vers num="Professional SP3"/><vers num="Professional SP2"/><vers num="Professional SP1"/><vers num="Professional"/><vers num="Server SP4"/><vers num="Server SP3"/><vers num="Server SP2"/><vers num="Server SP1"/><vers num="Server"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2007-02-07" name="CVE-2005-0064" published="2005-05-02" seq="2005-0064" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the Decrypt::makeFileKey2 function in Decrypt.cc for xpdf 3.00 and earlier allows remote attackers to execute arbitrary code via a PDF file with a large /Encrypt /Length keyLength value.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=186&amp;type=vulnerabilities">20050118 Multiple Unix/Linux Vendor Xpdf makeFileKey2 Stack Overflow</ref><ref patch="1" source="CONFIRM" url="ftp://ftp.foolabs.com/pub/xpdf/xpdf-3.00pl3.patch">ftp://ftp.foolabs.com/pub/xpdf/xpdf-3.00pl3.patch</ref><ref adv="1" patch="1" source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000921">CLA-2005:921</ref><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-645">DSA-645</ref><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-648">DSA-648</ref><ref adv="1" patch="1" source="FEDORA" url="https://bugzilla.fedora.us/show_bug.cgi?id=2352">FLSA:2352</ref><ref adv="1" patch="1" source="FEDORA" url="https://bugzilla.fedora.us/show_bug.cgi?id=2353">FLSA:2353</ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200501-28.xml">GLSA-200502-10</ref><ref adv="1" patch="1" source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:016">MDKSA-2005:016</ref><ref adv="1" patch="1" source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:017">MDKSA-2005:017</ref><ref adv="1" patch="1" source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:018">MDKSA-2005:018</ref><ref adv="1" patch="1" source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:019">MDKSA-2005:019</ref><ref adv="1" patch="1" source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:020">MDKSA-2005:020</ref><ref adv="1" patch="1" source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:021">MDKSA-2005:021</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-034.html">RHSA-2005:034</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-053.html">RHSA-2005:053</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-057.html">RHSA-2005:057</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-059.html">RHSA-2005:059</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-066.html">RHSA-2005:066</ref><ref adv="1" patch="1" source="TRUSTIX" url="http://www.trustix.org/errata/2005/0003/">2005-0003</ref><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110625368019554&amp;w=2">20050119 [USN-64-1] xpdf, CUPS vulnerabilities</ref><ref source="SCO" url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.42/SCOSA-2005.42.txt">SCOSA-2005.42</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17277">17277</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-026.html">RHSA-2005:026</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:016">MDKSA-2005:016</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:017">MDKSA-2005:017</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:018">MDKSA-2005:018</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:019">MDKSA-2005:019</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:020">MDKSA-2005:020</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:021">MDKSA-2005:021</ref></refs><vuln_soft><prod name="Xpdf" vendor="Xpdf"><vers num="3.0"/><vers num="2.3"/><vers num="2.2"/><vers num="2.1"/><vers num="2.0"/><vers num="1.1"/><vers num="1.0a"/><vers num="1.0"/><vers num="0.93c"/><vers num="0.93b"/><vers num="0.93a"/><vers num="0.93"/><vers num="0.92e"/><vers num="0.92d"/><vers num="0.92c"/><vers num="0.92b"/><vers num="0.92a"/><vers num="0.92"/><vers num="0.91c"/><vers num="0.91b"/><vers num="0.91a"/><vers num="0.91"/><vers num="0.90"/><vers num="0.80"/><vers num="0.7a"/><vers num="0.7"/><vers num="0.6"/><vers num="0.5a"/><vers num="0.5"/><vers num="0.4"/><vers num="0.3"/><vers num="0.2"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-25" name="CVE-2005-0065" published="2005-05-02" seq="2005-0065" severity="High" type="CVE"><desc><descript source="cve">The original design of TCP does not check that the TCP sequence number in an ICMP error message is within the range of sequence numbers for data that has been sent but not acknowledged (aka &quot;TCP sequence number checking&quot;), which makes it easier for attackers to forge ICMP error messages for specific TCP connections and cause a denial of service, as demonstrated using (1) blind connection-reset attacks with forged &quot;Destination Unreachable&quot; messages, (2) blind throughput-reduction attacks with forged &quot;Source Quench&quot; messages, or (3) blind throughput-reduction attacks with forged ICMP messages that cause the Path MTU to be reduced.  NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability.  While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref source="MISC" url="http://www.gont.com.ar/drafts/icmp-attacks-against-tcp.html">http://www.gont.com.ar/drafts/icmp-attacks-against-tcp.html</ref><ref source="BID" url="http://www.securityfocus.com/bid/13124">13124</ref></refs><vuln_soft><prod name="TCP" vendor="TCP"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-25" name="CVE-2005-0066" published="2004-12-22" seq="2005-0066" severity="Medium" type="CVE"><desc><descript source="cve">The original design of TCP does not check that the TCP Acknowledgement number in an ICMP error message generated by an intermediate router is within the range of possible values for data that has already been acknowledged (aka &quot;TCP acknowledgement number checking&quot;), which makes it easier for attackers to forge ICMP error messages for specific TCP connections and cause a denial of service, as demonstrated using (1) blind connection-reset attacks with forged &quot;Destination Unreachable&quot; messages, (2) blind throughput-reduction attacks with forged &quot;Source Quench&quot; messages, or (3) blind throughput-reduction attacks with forged ICMP messages that cause the Path MTU to be reduced.  NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability.  While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://www.gont.com.ar/drafts/icmp-attacks-against-tcp.html">http://www.gont.com.ar/drafts/icmp-attacks-against-tcp.html</ref><ref source="BID" url="http://www.securityfocus.com/bid/13124">13124</ref></refs><vuln_soft><prod name="TCP" vendor="TCP"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-25" name="CVE-2005-0067" published="2004-12-22" seq="2005-0067" severity="Medium" type="CVE"><desc><descript source="cve">The original design of TCP does not require that port numbers be assigned randomly (aka &quot;Port randomization&quot;), which makes it easier for attackers to forge ICMP error messages for specific TCP connections and cause a denial of service, as demonstrated using (1) blind connection-reset attacks with forged &quot;Destination Unreachable&quot; messages, (2) blind throughput-reduction attacks with forged &quot;Source Quench&quot; messages, or (3) blind throughput-reduction attacks with forged ICMP messages that cause the Path MTU to be reduced.  NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability.  While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://www.gont.com.ar/drafts/icmp-attacks-against-tcp.html">http://www.gont.com.ar/drafts/icmp-attacks-against-tcp.html</ref><ref source="BID" url="http://www.securityfocus.com/bid/13124">13124</ref></refs><vuln_soft><prod name="TCP" vendor="TCP"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-25" name="CVE-2005-0068" published="2004-12-22" seq="2005-0068" severity="Medium" type="CVE"><desc><descript source="cve">The original design of ICMP does not require authentication for host-generated ICMP error messages, which makes it easier for attackers to forge ICMP error messages for specific TCP connections and cause a denial of service, as demonstrated using (1) blind connection-reset attacks with forged &quot;Destination Unreachable&quot; messages, (2) blind throughput-reduction attacks with forged &quot;Source Quench&quot; messages, or (3) blind throughput-reduction attacks with forged ICMP messages that cause the Path MTU to be reduced.  NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability.  While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://www.gont.com.ar/drafts/icmp-attacks-against-tcp.html">http://www.gont.com.ar/drafts/icmp-attacks-against-tcp.html</ref><ref source="BID" url="http://www.securityfocus.com/bid/13124">13124</ref></refs><vuln_soft><prod name="TCP" vendor="TCP"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0069" published="2005-01-13" seq="2005-0069" severity="Medium" type="CVE"><desc><descript source="cve">The (1) tcltags or (2) vimspell.sh scripts in vim 6.3 allow local users to overwrite or create arbitrary files via a symlink attack on temporary files.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="FEDORA" url="https://bugzilla.fedora.us/show_bug.cgi?id=2343">FLSA:2343</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-036.html">RHSA-2005:036</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-122.html">RHSA-2005:122</ref><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110608387001863&amp;w=2">20050118 [USN-61-1] vim vulnerabilities</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/13841/">13841</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18870">vim-symlink(18870)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1012938">1012938</ref></refs><vuln_soft><prod name="VIM" vendor="VIM Development Group"><vers num="6.3.044"/><vers num="6.3.030"/><vers num="6.3.025"/><vers num="6.3.011"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0070" published="2005-05-02" seq="2005-0070" severity="High" type="CVE"><desc><descript source="cve">Synaesthesia 2.1 and earlier, and possibly other versions, when installed setuid root, does not drop privileges before processing configuration and mixer files, which allows local users to read arbitrary files.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-681">DSA-681</ref><ref source="BID" url="http://www.securityfocus.com/bid/12546">12546</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013206">1013206</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14300">14300</ref></refs><vuln_soft><prod name="Synaesthesia" vendor="Synaesthesia"><vers num="2.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0071" published="2005-05-02" seq="2005-0071" severity="Medium" type="CVE"><desc><descript source="cve">vdr before 1.2.6 does not securely create files, which allows attackers to overwrite arbitrary files.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-656">DSA-656</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200501-42.xml">GLSA-200501-42</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19066">vdr-dvdapi-file-overwrite(19066)</ref><ref source="BID" url="http://www.securityfocus.com/bid/12356">12356</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13930">13930</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13995">13995</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14066">14066</ref></refs><vuln_soft><prod name="vdr" vendor="VDR"><vers num="1.2.5"/><vers num="1.2.2"/><vers num="1.2.1"/><vers num="1.2.0"/><vers num="1.0.4"/><vers num="1.0.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0072" published="2005-01-24" seq="2005-0072" severity="Low" type="CVE"><desc><descript source="cve">zhcon before 0.2 does not drop privileges before reading a user configuration file, which allows local users to read arbitrary files.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-655">DSA-655</ref><ref adv="1" patch="1" source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:012">MDKSA-2005:012</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19045">zhcon-information-disclosure(19045)</ref><ref source="BID" url="http://www.securityfocus.com/bid/12343">12343</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1012977">1012977</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13977">13977</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13982">13982</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13987">13987</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:012">MDKSA-2005:012</ref></refs><vuln_soft><prod name="zhcon" vendor="ejoy and Hu Yong"><vers num="0.2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0073" published="2005-05-02" seq="2005-0073" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in queue.c in a support script for sympa 3.3.3, when running setuid, allows local users to execute arbitrary code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-677">DSA-677</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013163">1013163</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14217">14217</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14224">14224</ref></refs><vuln_soft><prod name="sympa" vendor="Debian"><vers num="3.3.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0074" published="2005-02-11" seq="2005-0074" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in pcdsvgaview in xpcd 2.08 allows local users to execute arbitrary code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-676">DSA-676</ref><ref source="BID" url="http://www.securityfocus.com/bid/12523">12523</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013162">1013162</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14248">14248</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14250">14250</ref></refs><vuln_soft><prod name="xpcd" vendor="xpcd"><vers num="2.08"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0075" published="2005-01-29" seq="2005-0075" severity="Medium" type="CVE"><desc><descript source="cve">prefs.php in SquirrelMail before 1.4.4, with register_globals enabled, allows remote attackers to inject local code into the SquirrelMail code via custom preference handlers.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110702772714662&amp;w=2">20050129 SquirrelMail Security Advisory</ref><ref adv="1" patch="1" source="CONFIRM" url="http://www.squirrelmail.org/security/issue/2005-01-14">http://www.squirrelmail.org/security/issue/2005-01-14</ref><ref patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/Mar/msg00000.html">APPLE-SA-2005-03-21</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-099.html">RHSA-2005:099</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-135.html">RHSA-2005:135</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/13962/">13962</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200501-39.xml">GLSA-200501-39</ref></refs><vuln_soft><prod name="SquirrelMail" vendor="SquirrelMail"><vers num="1.4.3a"/><vers num="1.4.3"/><vers num="1.4.2"/><vers num="1.4.1"/><vers num="1.4.0"/><vers num="1.4"/><vers num="1.2.9"/><vers num="1.2.8"/><vers num="1.2.7"/><vers num="1.2.6"/><vers num="1.2.5"/><vers num="1.2.4"/><vers num="1.2.3"/><vers num="1.2.2"/><vers num="1.2.11"/><vers num="1.2.10"/><vers num="1.2.1"/><vers num="1.2.0"/><vers num="1.0.5"/><vers num="1.0.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0076" published="2005-05-02" seq="2005-0076" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in the XView library 3.2 may allow local users to execute arbitrary code via setuid applications that use the library.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-672">DSA-672</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19271">xview-xvparseone-bo(19271)</ref></refs><vuln_soft><prod name="Debian Linux" vendor="Debian"><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0077" published="2005-05-02" seq="2005-0077" severity="Low" type="CVE"><desc><descript source="cve">The DBI library (libdbi-perl) for Perl allows local users to overwrite arbitrary files via a symlink attack on a temporary PID file.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-658">DSA-658</ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200501-38.xml">GLSA-200501-38</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-072.html">RHSA-2005:072</ref><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110667936707597&amp;w=2">20050125 [USN-70-1] Perl DBI module vulnerability</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19068">dbi-library-file-overwrite(19068)</ref><ref source="MANDRAKE" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2005:030">MDKSA-2005:030</ref><ref source="BID" url="http://www.securityfocus.com/bid/12360">12360</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013007">1013007</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14015">14015</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14050">14050</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/426530/30/6600/threaded">
FLSA-2006:178989</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:030">MDKSA-2005:030</ref></refs><vuln_soft><prod name="Linux" vendor="Gentoo"><vers num=""/></prod><prod name="Desktop" vendor="Red Hat"><vers num="4.0"/></prod><prod name="Enterprise Linux WS" vendor="Red Hat"><vers edition="Workstation" num="4.0"/></prod><prod name="Enterprise Linux ES" vendor="Red Hat"><vers edition="Enterprise Server" num="4.0"/></prod><prod name="Ubuntu Linux" vendor="Ubuntu"><vers num="4.10"/></prod><prod name="Enterprise Linux AS" vendor="Red Hat"><vers edition="Advanced Server" num="4.0"/></prod><prod name="Debian Linux" vendor="Debian"><vers edition="woody" num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0078" published="2005-05-02" seq="2005-0078" severity="Medium" type="CVE"><desc><descript source="cve">The KDE screen saver in KDE before 3.0.5 does not properly check the return value from a certain function call, which allows attackers with physical access to cause a crash and access the desktop session.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><exception/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-660">DSA-660</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-009.html">RHSA-2005:009</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19084">kdebase-screensaver-security-bypass(19084)</ref></refs><vuln_soft><prod name="Linux Advanced Workstation" vendor="Red Hat"><vers num="2.1"/></prod><prod name="Desktop" vendor="Red Hat"><vers num="3.0"/></prod><prod name="Enterprise Linux WS" vendor="Red Hat"><vers edition="Workstation" num="2.1"/><vers edition="Workstation" num="3.0"/></prod><prod name="Enterprise Linux ES" vendor="Red Hat"><vers edition="Enterprise Server" num="2.1"/><vers edition="Enterprise Server" num="3.0"/></prod><prod name="KDE" vendor="KDE"><vers num="3.0.4"/><vers num="3.0.3"/><vers num="3.0.2"/><vers num="3.0.1"/><vers num="3.0"/><vers num="3.0 Beta 2"/><vers num="3.0 Beta 1"/><vers num="2.2.1"/><vers num="2.2"/><vers num="2.2 Beta1"/><vers num="2.1"/><vers num="2.1 beta2"/><vers num="2.1 beta1"/><vers num="2.0.1"/><vers num="2.0"/><vers num="1.1.2"/><vers num="1.1.1"/><vers num="1.1"/><vers num="1.0"/></prod><prod name="Enterprise Linux AS" vendor="Red Hat"><vers edition="Advanced Server" num="2.1"/><vers edition="Advanced Servers" num="3.0"/></prod><prod name="Debian Linux" vendor="Debian"><vers edition="woody" num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0079" published="2005-05-02" seq="2005-0079" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in xtrlock 2.0 allows local users to cause a denial of service (application crash) and hijack the desktop session.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-649">DSA-649</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18991">xtrlock-screen-lock-bypass(18991)</ref><ref source="" url="http://www.securitytracker.com/alerts/2005/Jan/1012909.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/12316">12316</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13938">13938</ref></refs><vuln_soft><prod name="xtrlock" vendor="xtrlock"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0080" published="2005-05-02" seq="2005-0080" severity="Medium" type="CVE"><desc><descript source="cve">The 55_options_traceback.dpatch patch for mailman 2.1.5 in Ubuntu 4.10 displays a different error message depending on whether the e-mail address is subscribed to a private list, which allows remote attackers to determine the list membership for a given e-mail address.</descript></desc><loss_types><conf/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110549296126351&amp;w=2">20050110 [USN-59-1] mailman vulnerabilities</ref><ref source="CONFIRM" url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=285839">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=285839</ref><ref source="MISC" url="http://qa.debian.org/bts-security.html">http://qa.debian.org/bts-security.html</ref></refs><vuln_soft><prod name="Mailman" vendor="GNU"><vers num="2.1.5"/></prod><prod name="Ubuntu Linux" vendor="Ubuntu"><vers edition="ia640" num="4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-03-28" name="CVE-2005-0081" published="2005-04-14" seq="2005-0081" severity="Medium" type="CVE"><desc><descript source="cve">MySQL MaxDB 7.5.0.0, and other versions before 7.5.0.21, allows remote attackers to cause a denial of service (crash) via an HTTP request with invalid headers.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="iDefense" url="http://www.idefense.com/application/poi/display?id=187&amp;type=vulnerabilities">MySQL MaxDB Web Agent Multiple Denial of Service Vulnerabilities</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/12313">bid 12313</ref><ref source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=187&amp;type=vulnerabilities">20050119 MySQL MaxDB Web Agent Multiple Denial of Service Vulnerabilities</ref></refs><vuln_soft><prod name="MaxDB" vendor="MySQL"><vers num="7.5.00.19"/><vers num="7.5.00.18"/><vers num="7.5.00.16"/><vers num="7.5.00.15"/><vers num="7.5.00.14"/><vers num="7.5.00.12"/><vers num="7.5.00.11"/><vers num="7.5.00.08"/><vers num="7.5.00"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2007-08-14" name="CVE-2005-0082" published="2005-04-14" seq="2005-0082" severity="Medium" type="CVE"><desc><descript source="cve">The sapdbwa_GetUserData function in MySQL MaxDB 7.5.0.0, and other versions before 7.5.0.21, allows remote attackers to cause a denial of service (crash) via invalid parameters to the WebDAV handler code, which triggers a null dereference that causes the SAP DB Web Agent to crash.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="iDefense" url="http://www.idefense.com/application/poi/display?id=187&amp;type=vulnerabilities">MySQL MaxDB Web Agent Multiple Denial of Service Vulnerabilities</ref><ref adv="1" source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=187&amp;type=vulnerabilities">20050119 MySQL MaxDB Web Agent Multiple Denial of Service Vulnerabilities</ref></refs><vuln_soft><prod name="MaxDB" vendor="MySQL"><vers num="7.5.00.19"/><vers num="7.5.00.18"/><vers num="7.5.00.16"/><vers num="7.5.00.15"/><vers num="7.5.00.14"/><vers num="7.5.00.12"/><vers num="7.5.00.11"/><vers num="7.5.00.08"/><vers num="7.5.00"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-03-28" name="CVE-2005-0083" published="2005-05-02" seq="2005-0083" severity="Medium" type="CVE"><desc><descript source="cve">MySQL MaxDB 7.5.00 for Windows, and possibly earlier versions and other platforms, allows remote attackers to cause a denial of service (application crash) via invalid parameters to the (1) DBMCli_String::ReallocString, (2) DBMCli_String::operator, (3) DBMCli_Buffer::ForceResize, (4) DBMCli_Wizard::InstallDatabase, (5) DBMCli_Devspaces::Complete, (6) DBMWeb_TemplateWizard::askForWriteCountStep5, or (7) DBMWeb_DBMWeb::wizardDB functions, which triggers a null dereference.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=218&amp;type=vulnerabilities">20050314 MySQL MaxDB Web Agent Multiple Denial of Service Vulnerabilities</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19687">maxdb-null-pointer-dos(19687)</ref><ref source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=218&amp;type=vulnerabilities">20050314 MySQL MaxDB Web Agent Multiple Denial of Service Vulnerabilities</ref></refs><vuln_soft><prod name="MaxDB" vendor="MySQL"><vers num="7.5.00"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0084" published="2005-05-02" seq="2005-0084" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the X11 dissector in Ethereal 0.8.10 through 0.10.8 allows remote attackers to execute arbitrary code via a crafted packet.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="CONFIRM" url="http://www.ethereal.com/appnotes/enpa-sa-00017.html">http://www.ethereal.com/appnotes/enpa-sa-00017.html</ref><ref patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-653">DSA-653</ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200501-27.xml">GLSA-200501-27</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:013">MDKSA-2005:013</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-037.html">RHSA-2005:037</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/p-106.shtml">P-106</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/13946/">13946</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19004">ethereal-x11-bo(19004)</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00003.html">FLSA-2006:152922</ref><ref source="BID" url="http://www.securityfocus.com/bid/12326">12326</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:013">MDKSA-2005:013</ref></refs><vuln_soft><prod name="Ethereal" vendor="Ethereal Group"><vers num="0.8"/><vers num="0.9.9"/><vers num="0.9.8"/><vers num="0.9.7"/><vers num="0.9.6"/><vers num="0.9.5"/><vers num="0.9.4"/><vers num="0.9.3"/><vers num="0.9.2"/><vers num="0.9.16"/><vers num="0.9.15"/><vers num="0.9.14"/><vers num="0.9.13"/><vers num="0.9.12"/><vers num="0.9.11"/><vers num="0.9.10"/><vers num="0.9.1"/><vers num="0.9.0"/><vers num="0.9"/><vers num="0.8.20"/><vers num="0.8.19"/><vers num="0.8.18"/><vers num="0.8.17a"/><vers num="0.8.16"/><vers num="0.8.15"/><vers num="0.8.14"/><vers num="0.8.13"/><vers num="0.10.8"/><vers num="0.10.7"/><vers num="0.10.6"/><vers num="0.10.5"/><vers num="0.10.4"/><vers num="0.10.3"/><vers num="0.10.2"/><vers num="0.10.1"/><vers num="0.10.0a"/><vers num="0.10.0"/><vers num="0.10"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0085" published="2005-04-27" seq="2005-0085" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in ht://dig (htdig) before 3.1.6-r7 allows remote attackers to execute arbitrary web script or HTML via the config parameter, which is not properly sanitized before it is displayed in an error message.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Debian.org" url="http://www.debian.org/security/2005/dsa-680">htdig -- unsanitised input</ref><ref adv="1" source="SecurityTracker" url="http://securitytracker.com/alerts/2005/Feb/1013078.html">ht://dig Input Validation Hole in &apos;config&apos; Parameter Permits Cross-Site Scripting Attacks</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/12442">bid 12442</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200502-16.xml">GLSA-200502-16</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:063">MDKSA-2005:063</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-073.html">RHSA-2005:073</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013078">1013078</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19223">htdig-config-xss(19223)</ref><ref source="SCO" url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.46/SCOSA-2005.46.txt">SCOSA-2005.46</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14255">14255</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17414">17414</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17415">17415</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00002.html">FLSA-2006:152907</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14276">14276</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14303">14303</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14795">14795</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15007">15007</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-090.html">RHSA-2005:090</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:063">MDKSA-2005:063</ref></refs><vuln_soft><prod name="Mandrake Corporate Server" vendor="MandrakeSoft"><vers edition="x86_64" num="2.1"/><vers num="2.1"/><vers edition="x86_64" num="3.0"/><vers num="3.0"/></prod><prod name="Fedora" vendor="Red Hat"><vers num="Core 3.0"/></prod><prod name="Mandrake Linux" vendor="MandrakeSoft"><vers edition="AMD64" num="10.0"/><vers num="10.0"/><vers edition="x86_64" num="10.1"/><vers num="10.1"/></prod><prod name="SuSE Linux" vendor="SuSE"><vers edition="i386" num="8.0"/><vers num="8.0"/><vers num="8.1"/><vers num="8.2"/><vers edition="x86_64" num="9.0"/><vers num="9.0"/><vers num="9.1"/><vers num="9.2"/></prod><prod name="htDig" vendor="htDig"><vers num="3.1.5_8"/><vers num="3.1.5_7"/><vers num="3.1.5"/><vers num="3.1.6"/><vers num="3.2.0b6"/><vers num="3.2.0b5"/><vers num="3.2.0b4"/><vers num="3.2.0b3"/><vers num="3.2.0b2"/><vers num="3.2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0086" published="2005-05-02" seq="2005-0086" severity="High" type="CVE"><desc><descript source="cve">Heap-based buffer overflow in less in Red Hat Enterprise Linux 3 allows attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted file, as demonstrated using the UTF-8 locale.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="FEDORA" url="https://bugzilla.fedora.us/show_bug.cgi?id=2404">FLSA:2404</ref><ref adv="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-068.html">RHSA-2005:068</ref><ref source="CONFIRM" url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=145527">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=145527</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19131">less-file-bo(19131)</ref></refs><vuln_soft><prod name="Desktop" vendor="Red Hat"><vers num="3.0"/></prod><prod name="Enterprise Linux WS" vendor="Red Hat"><vers edition="Workstation" num="3.0"/></prod><prod name="Enterprise Linux ES" vendor="Red Hat"><vers edition="Enterprise Server" num="3.0"/></prod><prod name="Enterprise Linux AS" vendor="Red Hat"><vers edition="Advanced Servers" num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0087" published="2005-04-27" seq="2005-0087" severity="Medium" type="CVE"><desc><descript source="cve">The alsa-lib package in Red Hat Linux 4 disables stack protection for the libasound.so library, which makes it easier for attackers to execute arbitrary code if there are other vulnerabilities in the library.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><other/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="RedHat" url="http://www.redhat.com/support/errata/RHSA-2005-033.html">alsa-lib security update</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/12575">bid 12575</ref></refs><vuln_soft><prod name="Enterprise Linux WS" vendor="Red Hat"><vers edition="Workstation" num="4.0"/></prod><prod name="Enterprise Linux ES" vendor="Red Hat"><vers edition="Enterprise Server" num="4.0"/></prod><prod name="alsa-lib" vendor="ALSA"><vers num="1.0.6"/></prod><prod name="Enterprise Linux AS" vendor="Red Hat"><vers edition="Advanced Server" num="4.0"/></prod><prod name="Enterprise Linux Desktop" vendor="Red Hat"><vers edition="Desktop" num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-21" name="CVE-2005-0088" published="2005-05-02" seq="2005-0088" severity="High" type="CVE"><desc><descript source="cve">The publisher handler for mod_python 2.7.8 and earlier allows remote attackers to obtain access to restricted objects via a crafted URL.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/><input/></vuln_types><range><network/></range><refs><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000926">CLA-2005:926</ref><ref patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-689">DSA-689</ref><ref patch="1" source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200502-14.xml">GLSA-200502-14</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-100.html">RHSA-2005:100</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-104.html">RHSA-2005:104</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2005/0003/">2005-0003</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110815313218389&amp;w=2">20050211 [USN-80-1] mod_python vulnerability</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/356409">VU#356409</ref><ref source="BID" url="http://www.securityfocus.com/bid/12519">12519</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013156">1013156</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/430286/100/0/threaded">FLSA:152896</ref></refs><vuln_soft><prod name="mod_python" vendor="Apache Software Foundation"><vers num="2.7.8" prev="1"/><vers num="2.7.7"/><vers num="2.7.6"/><vers num="2.7.5"/><vers num="2.7.4"/><vers num="2.7.3"/><vers num="2.7.2"/><vers num="2.7.1"/><vers num="2.7"/><vers num="2.6.4"/><vers num="2.6.3"/><vers num="2.6.2"/><vers num="2.6.1"/><vers num="2.6"/><vers num="2.5"/><vers num="2.4.1"/><vers num="2.4"/><vers num="2.3"/><vers num="2.2"/><vers num="2.1"/><vers num="2.0"/><vers num="1.9a"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0089" published="2005-05-02" seq="2005-0089" severity="High" type="CVE"><desc><descript source="cve">The SimpleXMLRPCServer library module in Python 2.2, 2.3 before 2.3.5, and 2.4, when used by XML-RPC servers that use the register_instance method to register an object without a _dispatch method, allows remote attackers to read or modify globals of the associated module, and possibly execute arbitrary code, via dotted attributes.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/><env/></vuln_types><range><network/></range><refs><ref patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110746469728728&amp;w=2">20050203 Python Security Advisory PSF-2005-001 - SimpleXMLRPCServer.py</ref><ref patch="1" source="CONFIRM" url="http://www.python.org/security/PSF-2005-001/">http://www.python.org/security/PSF-2005-001/</ref><ref patch="1" source="CONFIRM" url="http://python.org/security/PSF-2005-001/patch-2.2.txt">http://python.org/security/PSF-2005-001/patch-2.2.txt</ref><ref patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-666">DSA-666</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:035">MDKSA-2005:035</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-108.html">RHSA-2005:108</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2005/0003/">2005-0003</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19217">python-simplexmlrpcserver-bypass(19217)</ref><ref source="BID" url="http://www.securityfocus.com/bid/12437">12437</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013083">1013083</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14128">14128</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:035">MDKSA-2005:035</ref></refs><vuln_soft><prod name="Python" vendor="Python Software Foundation"><vers num="2.2"/><vers num="2.3"/><vers num="2.3.1"/><vers num="2.3.2"/><vers num="2.3.3"/><vers num="2.3.4"/><vers num="2.4"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0090" published="2005-05-02" seq="2005-0090" severity="Low" type="CVE"><desc><descript source="cve">A regression error in the Red Hat Enterprise Linux 4 kernel 4GB/4GB split patch omits an &quot;access check,&quot; which allows local users to cause a denial of service (crash).</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/12599">12599</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-092.html">RHSA-2005:092</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20618">red-hat-regression-dos(20618)</ref></refs><vuln_soft><prod name="Desktop" vendor="Red Hat"><vers num="4.0"/></prod><prod name="Enterprise Linux WS" vendor="Red Hat"><vers edition="Workstation" num="4.0"/></prod><prod name="Enterprise Linux ES" vendor="Red Hat"><vers edition="Enterprise Server" num="4.0"/></prod><prod name="Enterprise Linux AS" vendor="Red Hat"><vers edition="Advanced Server" num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0091" published="2005-05-02" seq="2005-0091" severity="High" type="CVE"><desc><descript source="cve">Unknown vulnerability in the Red Hat Enterprise Linux 4 kernel 4GB/4GB split patch, when using the hugemem kernel, allows local users to read and write to arbitrary kernel memory and gain privileges via certain syscalls.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/12599">12599</ref><ref adv="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-092.html">RHSA-2005:092</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20619">red-hat-patch-gain-privileges(20619)</ref></refs><vuln_soft><prod name="Desktop" vendor="Red Hat"><vers num="4.0"/></prod><prod name="Enterprise Linux WS" vendor="Red Hat"><vers edition="Workstation" num="4.0"/></prod><prod name="Enterprise Linux ES" vendor="Red Hat"><vers edition="Enterprise Server" num="4.0"/></prod><prod name="Enterprise Linux AS" vendor="Red Hat"><vers edition="Advanced Server" num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0092" published="2005-02-19" seq="2005-0092" severity="Low" type="CVE"><desc><descript source="cve">Unknown vulnerability in the Red Hat Enterprise Linux 4 kernel 4GB/4GB split patch, when running on x86 with the hugemem kernel, allows local users to cause a denial of service (crash).</descript></desc><loss_types><avail/></loss_types><range><local/></range><refs><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/12599">12599</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-092.html">RHSA-2005:092</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/20620">red-hat-patch-dos(20620)</ref></refs><vuln_soft><prod name="Desktop" vendor="Red Hat"><vers num="4.0"/></prod><prod name="Enterprise Linux" vendor="Red Hat"><vers edition="Workstation" num="4.0"/><vers edition="Enterprise Server" num="4.0"/><vers edition="Advanced Server" num="4.0"/></prod></vuln_soft></entry><entry modified="2005-10-20" name="CVE-2005-0093" published="2005-05-02" reject="1" seq="2005-0093" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: none.  Reason: This candidate was withdrawn by its CNA.  Further investigation showed that it was not a security issue.  Notes: none.</descript></desc><refs/></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0094" published="2005-01-15" seq="2005-0094" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in the gopherToHTML function in the Gopher reply parser for Squid 2.5.STABLE7 and earlier allows remote malicious Gopher servers to cause a denial of service (crash) via crafted responses.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="CONFIRM" url="http://www.squid-cache.org/Advisories/SQUID-2005_1.txt">http://www.squid-cache.org/Advisories/SQUID-2005_1.txt</ref><ref adv="1" source="CONFIRM" url="http://www.squid-cache.org/Versions/v2/2.5/bugs/squid-2.5.STABLE7-gopher_html_parsing.patch">http://www.squid-cache.org/Versions/v2/2.5/bugs/squid-2.5.STABLE7-gopher_html_parsing.patch</ref><ref adv="1" source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000923">CLA-2005:923</ref><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-651">DSA-651</ref><ref adv="1" patch="1" source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200501-25.xml">GLSA-200501-25</ref><ref adv="1" patch="1" source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:014">MDKSA-2005:014</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-060.html">RHSA-2005:060</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-061.html">RHSA-2005:061</ref><ref adv="1" source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_06_squid.html">SUSE-SA:2005:006</ref><ref adv="1" source="TRUSTIX" url="http://www.trustix.org/errata/2005/0003/">2005-0003</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/13825">13825</ref><ref source="FEDORA" url="http://fedoranews.org/updates/FEDORA--.shtml">FLSA-2006:152809</ref><ref source="BID" url="http://www.securityfocus.com/bid/12276">12276</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:014">MDKSA-2005:014</ref></refs><vuln_soft><prod name="Squid" vendor="Squid"><vers num="2.5.STABLE7"/><vers num="2.5.STABLE6"/><vers num="2.5.STABLE5"/><vers num="2.5.STABLE4"/><vers num="2.5.STABLE3"/><vers num="2.5.STABLE2"/><vers num="2.5.STABLE1"/><vers num="2.5.6"/><vers num="2.5 Stable9"/><vers num="2.5 STABLE4"/><vers num="2.5 STABLE3"/><vers num="2.5 .STABLE6"/><vers num="2.5 .STABLE5"/><vers num="2.5 .STABLE4"/><vers num="2.5 .STABLE3"/><vers num="2.5 .STABLE1"/><vers num="2.4 STABLE7"/><vers num="2.4 .STABLE7"/><vers num="2.4 .STABLE6"/><vers num="2.4 .STABLE2"/><vers num="2.4"/><vers num="2.3 STABLE5"/><vers num="2.3 .STABLE5"/><vers num="2.3 .STABLE4"/><vers num="2.1 PATCH2"/><vers num="2.0 PATCH2"/><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0095" published="2005-01-15" seq="2005-0095" severity="Medium" type="CVE"><desc><descript source="cve">The WCCP message parsing code in Squid 2.5.STABLE7 and earlier allows remote attackers to cause a denial of service (crash) via malformed WCCP messages with source addresses that are spoofed to reference Squid&apos;s home router and invalid WCCP_I_SEE_YOU cache numbers.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CONFIRM" url="http://www.squid-cache.org/Advisories/SQUID-2005_2.txt">http://www.squid-cache.org/Advisories/SQUID-2005_2.txt</ref><ref adv="1" source="CONFIRM" url="http://www.squid-cache.org/Versions/v2/2.5/bugs/squid-2.5.STABLE7-wccp_denial_of_service.patch">http://www.squid-cache.org/Versions/v2/2.5/bugs/squid-2.5.STABLE7-wccp_denial_of_service.patch</ref><ref adv="1" patch="1" source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000923">CLA-2005:923</ref><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-651">DSA-651</ref><ref adv="1" patch="1" source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200501-25.xml">GLSA-200501-25</ref><ref adv="1" patch="1" source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:014">MDKSA-2005:014</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-060.html">RHSA-2005:060</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-061.html">RHSA-2005:061</ref><ref adv="1" patch="1" source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_06_squid.html">SUSE-SA:2005:006</ref><ref adv="1" patch="1" source="TRUSTIX" url="http://www.trustix.org/errata/2005/0003/">2005-0003</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/13825">13825</ref><ref source="OSVDB" url="http://www.osvdb.org/12886">12886</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1012882">1012882</ref><ref source="FEDORA" url="http://fedoranews.org/updates/FEDORA--.shtml">FLSA-2006:152809</ref><ref source="BID" url="http://www.securityfocus.com/bid/12275">12275</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:014">MDKSA-2005:014</ref></refs><vuln_soft><prod name="Squid" vendor="Squid"><vers num="2.5.STABLE7"/><vers num="2.5.STABLE6"/><vers num="2.5.STABLE5"/><vers num="2.5.STABLE4"/><vers num="2.5.STABLE3"/><vers num="2.5.STABLE2"/><vers num="2.5.STABLE1"/><vers num="2.5.6"/><vers num="2.5 Stable9"/><vers num="2.5 STABLE4"/><vers num="2.5 STABLE3"/><vers num="2.5 .STABLE6"/><vers num="2.5 .STABLE5"/><vers num="2.5 .STABLE4"/><vers num="2.5 .STABLE3"/><vers num="2.5 .STABLE1"/><vers num="2.4 STABLE7"/><vers num="2.4 .STABLE7"/><vers num="2.4 .STABLE6"/><vers num="2.4 .STABLE2"/><vers num="2.4"/><vers num="2.3 STABLE5"/><vers num="2.3 .STABLE5"/><vers num="2.3 .STABLE4"/><vers num="2.1 PATCH2"/><vers num="2.0 PATCH2"/><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0096" published="2005-01-25" seq="2005-0096" severity="Medium" type="CVE"><desc><descript source="cve">Memory leak in the NTLM fakeauth_auth helper for Squid 2.5.STABLE7 and earlier allows remote attackers to cause a denial of service (memory consumption).</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CONFIRM" url="http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE7-fakeauth_auth">http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE7-fakeauth_auth</ref><ref adv="1" patch="1" source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000923">CLA-2005:923</ref><ref adv="1" patch="1" source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200501-25.xml">GLSA-200501-25</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-060.html">RHSA-2005:060</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-061.html">RHSA-2005:061</ref><ref adv="1" source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_06_squid.html">SUSE-SA:2005:006</ref><ref adv="1" source="TRUSTIX" url="http://www.trustix.org/errata/2005/0003/">2005-0003</ref><ref source="BID" url="http://www.securityfocus.com/bid/12324">12324</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1012818">1012818</ref><ref source="FEDORA" url="http://fedoranews.org/updates/FEDORA--.shtml">FLSA-2006:152809</ref></refs><vuln_soft><prod name="Squid" vendor="Squid"><vers num="2.5.STABLE7"/><vers num="2.5.STABLE6"/><vers num="2.5.STABLE5"/><vers num="2.5.STABLE4"/><vers num="2.5.STABLE3"/><vers num="2.5.STABLE2"/><vers num="2.5.STABLE1"/><vers num="2.5.6"/><vers num="2.5 Stable9"/><vers num="2.5 STABLE4"/><vers num="2.5 STABLE3"/><vers num="2.5 .STABLE6"/><vers num="2.5 .STABLE5"/><vers num="2.5 .STABLE4"/><vers num="2.5 .STABLE3"/><vers num="2.5 .STABLE1"/><vers num="2.4 STABLE7"/><vers num="2.4 .STABLE7"/><vers num="2.4 .STABLE6"/><vers num="2.4 .STABLE2"/><vers num="2.4"/><vers num="2.3 STABLE5"/><vers num="2.3 .STABLE5"/><vers num="2.3 .STABLE4"/><vers num="2.1 PATCH2"/><vers num="2.0 PATCH2"/><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0097" published="2005-01-11" seq="2005-0097" severity="Medium" type="CVE"><desc><descript source="cve">The NTLM component in Squid 2.5.STABLE7 and earlier allows remote attackers to cause a denial of service (crash) via a malformed NTLM type 3 message that triggers a NULL dereference.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CONFIRM" url="http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE7-fakeauth_auth">http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE7-fakeauth_auth</ref><ref adv="1" patch="1" source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200501-25.xml">GLSA-200501-25</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-060.html">RHSA-2005:060</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-061.html">RHSA-2005:061</ref><ref adv="1" patch="1" source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_06_squid.html">SUSE-SA:2005:006</ref><ref adv="1" patch="1" source="TRUSTIX" url="http://www.trustix.org/errata/2005/0003/">2005-0003</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/13789">13789</ref><ref source="BID" url="http://www.securityfocus.com/bid/12220">12220</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1012818">1012818</ref><ref source="FEDORA" url="http://fedoranews.org/updates/FEDORA--.shtml">FLSA-2006:152809</ref></refs><vuln_soft><prod name="Squid" vendor="Squid"><vers num="2.5.STABLE7"/><vers num="2.5.STABLE6"/><vers num="2.5.STABLE5"/><vers num="2.5.STABLE4"/><vers num="2.5.STABLE3"/><vers num="2.5.STABLE2"/><vers num="2.5.STABLE1"/><vers num="2.5.6"/><vers num="2.5 Stable9"/><vers num="2.5 STABLE4"/><vers num="2.5 STABLE3"/><vers num="2.5 .STABLE6"/><vers num="2.5 .STABLE5"/><vers num="2.5 .STABLE4"/><vers num="2.5 .STABLE3"/><vers num="2.5 .STABLE1"/><vers num="2.4 STABLE7"/><vers num="2.4 .STABLE7"/><vers num="2.4 .STABLE6"/><vers num="2.4 .STABLE2"/><vers num="2.4"/><vers num="2.3 STABLE5"/><vers num="2.3 .STABLE5"/><vers num="2.3 .STABLE4"/><vers num="2.1 PATCH2"/><vers num="2.0 PATCH2"/><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-08-03" name="CVE-2005-0098" published="2005-03-08" seq="2005-0098" severity="Medium" type="CVE"><desc><descript source="cve">Multiple buffer overflows in the SDL port of abuse (abuse-SDL) before 2.00 allow local users to execute arbitrary code via the command line.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-691">DSA-691</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/14495">14495</ref></refs><vuln_soft><prod name="Abuse-SDL" vendor="Abuse"><vers num="2.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-08-03" name="CVE-2005-0099" published="2005-03-08" seq="2005-0099" severity="Low" type="CVE"><desc><descript source="cve">The SDL port of abuse (abuse-SDL) before 2.00 does not properly drop privileges before creating certain files, which allows local users to create or overwrite arbitrary files.</descript></desc><loss_types><int/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-691">DSA-691</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14495">14495</ref><ref source="OSVDB" url="http://www.osvdb.org/14610">14610</ref></refs><vuln_soft><prod name="Abuse-SDL" vendor="Abuse"><vers num="2.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0100" published="2005-02-07" seq="2005-0100" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in the movemail utility in (1) Emacs 20.x, 21.3, and possibly other versions, and (2) XEmacs 21.4 and earlier, allows remote malicious POP3 servers to execute arbitrary code via crafted packets.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-670">DSA-670</ref><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-671">DSA-671</ref><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-685">DSA-685</ref><ref adv="1" patch="1" source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:038">MDKSA-2005:038</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-110.html">RHSA-2005:110</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-112.html">RHSA-2005:112</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-133.html">RHSA-2005:133</ref><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110780416112719&amp;w=2">20050207 [USN-76-1] Emacs vulnerability</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19246">xemacs-movemail-format-string(19246)</ref><ref source="BID" url="http://www.securityfocus.com/bid/12462">12462</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/433928/30/5010/threaded">
FLSA-2006:152898</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:038">MDKSA-2005:038</ref></refs><vuln_soft><prod name="XEmacs" vendor="GNU"><vers num="21.4" prev="1"/></prod><prod name="Emacs" vendor="GNU"><vers num="20.0" prev="1"/><vers num="21.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0101" published="2005-02-01" seq="2005-0101" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the socket_getline function in Newspost 2.1.1 and earlier allows remote malicious NNTP servers to execute arbitrary code via a long string without a newline character.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110746336728781&amp;w=2">20050202 RE: SECURITEY.NNOV.RU NewsPost buffer overflow [EXPLOIT]</ref><ref adv="1" source="MISC" url="http://people.freebsd.org/~niels/issues/newspost-20050114.txt">http://people.freebsd.org/~niels/issues/newspost-20050114.txt</ref><ref adv="1" source="CONFIRM" url="http://www.vuxml.org/freebsd/7f13607b-6948-11d9-8937-00065be4b5b6.html">http://www.vuxml.org/freebsd/7f13607b-6948-11d9-8937-00065be4b5b6.html</ref><ref adv="1" patch="1" source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200502-05.xml">GLSA-200502-05</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/14092/">14092</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19178">newspost-socketgetline-bo(19178)</ref><ref source="BID" url="http://www.securityfocus.com/bid/12418">12418</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013056">1013056</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14098">14098</ref></refs><vuln_soft><prod name="Newspost" vendor="Newspost"><vers num="2.1.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0102" published="2005-01-24" seq="2005-0102" severity="High" type="CVE"><desc><descript source="cve">Integer overflow in camel-lock-helper in Evolution 2.0.2 and earlier allows local users or remote malicious POP3 servers to execute arbitrary code via a length value of -1, which leads to a zero byte memory allocation and a buffer overflow.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110667319720599&amp;w=2">20050124 [USN-69-1] Evolution vulnerability</ref><ref adv="1" patch="1" source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000925">CLA-2005:925</ref><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-673">DSA-673</ref><ref adv="1" patch="1" source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200501-35.xml">GLSA-200501-35</ref><ref adv="1" patch="1" source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:024">MDKSA-2005:024</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/12354">12354</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19031">evolution-camellockhelper-bo(19031)</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-397.html">RHSA-2005:397</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-238.html">RHSA-2005:238</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-69-1">USN-69-1</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1012981">1012981</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13830">13830</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:024">MDKSA-2005:024</ref></refs><vuln_soft><prod name="Evolution" vendor="Ximian"><vers num="1.3.2 beta"/><vers num="1.2.4"/><vers num="1.2.3"/><vers num="1.2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-28" name="CVE-2005-0103" published="2005-01-24" seq="2005-0103" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in webmail.php in SquirrelMail before 1.4.4 allows remote attackers to execute arbitrary PHP code by modifying a URL parameter to reference a URL on a remote web server that contains the code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110702772714662&amp;w=2">20050129 SquirrelMail Security Advisory</ref><ref adv="1" patch="1" source="CONFIRM" url="http://www.squirrelmail.org/security/issue/2005-01-19?PHPSESSID=8af117822fb1ca3aa966a64248b5d223">http://www.squirrelmail.org/security/issue/2005-01-19?PHPSESSID=8af117822fb1ca3aa966a64248b5d223</ref><ref adv="1" patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/Mar/msg00000.html">APPLE-SA-2005-03-21</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-099.html">RHSA-2005:099</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-135.html">RHSA-2005:135</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/13962/">13962</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200501-39.xml">GLSA-200501-39</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19037">squirrelmail-frame-file-include(19037)</ref></refs><vuln_soft><prod name="SquirrelMail" vendor="SquirrelMail"><vers num="1.4.3 RC1"/><vers num="1.4.3a"/><vers num="1.4.3"/><vers num="1.4.2"/><vers num="1.4.1"/><vers num="1.4.0"/><vers num="1.4"/><vers num="1.2.9"/><vers num="1.2.8"/><vers num="1.2.7"/><vers num="1.2.6"/><vers num="1.2.5"/><vers num="1.2.4"/><vers num="1.2.3"/><vers num="1.2.2"/><vers num="1.2.11"/><vers num="1.2.10"/><vers num="1.2.1"/><vers num="1.2.0"/><vers num="1.0.5"/><vers num="1.0.4"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0104" published="2005-01-29" seq="2005-0104" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in webmail.php in SquirrelMail before 1.4.4 allows remote attackers to inject arbitrary web script or HTML via certain integer variables.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110702772714662&amp;w=2">20050129 SquirrelMail Security Advisory</ref><ref adv="1" patch="1" source="CONFIRM" url="http://www.squirrelmail.org/security/issue/2005-01-20">http://www.squirrelmail.org/security/issue/2005-01-20</ref><ref adv="1" patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/Mar/msg00000.html">APPLE-SA-2005-03-21</ref><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-662">DSA-662</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-099.html">RHSA-2005:099</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-135.html">RHSA-2005:135</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/13962/">13962</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14096">14096</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200501-39.xml">GLSA-200501-39</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19036">squirrelmail-webmailphp-xss(19036)</ref></refs><vuln_soft><prod name="SquirrelMail" vendor="SquirrelMail"><vers num="1.44"/><vers num="1.4.3 RC1"/><vers num="1.4.3a"/><vers num="1.4.3"/><vers num="1.4.2"/><vers num="1.4.1"/><vers num="1.4.0"/><vers num="1.4"/><vers num="1.2.9"/><vers num="1.2.8"/><vers num="1.2.7"/><vers num="1.2.6"/><vers num="1.2.5"/><vers num="1.2.4"/><vers num="1.2.3"/><vers num="1.2.2"/><vers num="1.2.11"/><vers num="1.2.10"/><vers num="1.2.1"/><vers num="1.2.0"/><vers num="1.0.5"/><vers num="1.0.4"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-22" name="CVE-2005-0105" published="2005-02-16" seq="2005-0105" severity="Medium" type="CVE"><desc><descript source="cve">Unknown vulnerability in typespeed 0.4.1 and earlier allows local users to gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-684">DSA-684</ref></refs><vuln_soft><prod name="typespeed" vendor="typespeed"><vers num="0.4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0106" published="2005-05-03" seq="2005-0106" severity="Medium" type="CVE"><desc><descript source="cve">SSLeay.pm in libnet-ssleay-perl before 1.25 uses the /tmp/entropy file for entropy if a source is not set in the EGD_PATH variable, which allows local users to reduce the cryptographic strength of certain operations by modifying the file.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref patch="1" source="CONFIRM" url="http://www.ubuntulinux.org/support/documentation/usn/usn-113-1">http://www.ubuntulinux.org/support/documentation/usn/usn-113-1</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:023">MDKSA-2006:023</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18639">18639</ref><ref source="BID" url="http://www.securityfocus.com/bid/13471">13471</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:023">MDKSA-2006:023</ref></refs><vuln_soft><prod name="Ubuntu Linux" vendor="Ubuntu"><vers num="5.04"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0107" published="2005-02-25" seq="2005-0107" severity="High" type="CVE"><desc><descript source="cve">bsmtpd 2.3 and earlier does not properly sanitize e-mail addresses, which allows remote attackers to execute arbitrary commands.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-690">DSA-690</ref></refs><vuln_soft><prod name="bsmtpd" vendor="Debian"><vers num="2.3" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0108" published="2005-01-11" seq="2005-0108" severity="Medium" type="CVE"><desc><descript source="cve">Apache mod_auth_radius 1.5.4 and libpam-radius-auth allow remote malicious RADIUS servers to cause a denial of service (crash) via a RADIUS_REPLY_MESSAGE with a RADIUS attribute length of 1, which leads to a memcpy operation with a -1 length argument.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110548193312050&amp;w=2">20050111 Apache mod_auth_radius remote integer overflow</ref><ref adv="1" source="MISC" url="http://security.lss.hr/en/index.php?page=details&amp;ID=LSS-2005-01-02">http://security.lss.hr/en/index.php?page=details&amp;ID=LSS-2005-01-02</ref><ref adv="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-659">DSA-659</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18841">modauthradius-dos(18841)</ref><ref source="BID" url="http://www.securityfocus.com/bid/12217">12217</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1012829">1012829</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13773">13773</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14046">14046</ref></refs><vuln_soft><prod name="mod_auth_radius" vendor="Apache Software Foundation"><vers num="1.5.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-05-11" name="CVE-2005-0109" published="2005-03-05" seq="2005-0109" severity="High" type="CVE"><desc><descript source="cve">Hyper-Threading technology, as used in FreeBSD and other operating systems that are run on Intel Pentium and other processors, allows local users to use a malicious thread to create covert channels, monitor the execution of other threads, and obtain sensitive information such as cryptographic keys, via a timing attack on memory cache misses.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/12724">12724</ref><ref source="MISC" url="http://www.daemonology.net/papers/htt.pdf">http://www.daemonology.net/papers/htt.pdf</ref><ref source="MISC" url="http://www.daemonology.net/hyperthreading-considered-harmful/">http://www.daemonology.net/hyperthreading-considered-harmful/</ref><ref source="SCO" url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.24/SCOSA-2005.24.txt">SCOSA-2005.24</ref><ref adv="1" source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101739-1">101739</ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/911878">VU#911878</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/0540">ADV-2005-0540</ref><ref adv="1" patch="1" source="SECTRACK" url="http://securitytracker.com/id?1013967">1013967</ref><ref source="" url="http://www-1.ibm.com/support/docview.wss?uid=isg1SSRVHMCHMC_C081516_754"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/3002">ADV-2005-3002</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15348">15348</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18165">18165</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-476.html">RHSA-2005:476</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-800.html">RHSA-2005:800</ref><ref source="MLIST" url="http://marc.theaimsgroup.com/?l=openbsd-misc&amp;m=110995101417256&amp;w=2">[openbsd-misc] 20050304 Re: FreeBSD hiding security stuff</ref><ref source="MLIST" url="http://marc.theaimsgroup.com/?l=freebsd-security&amp;m=110994370429609&amp;w=2">[freebsd-security] 20050304 [Fwd: Re: FW:FreeBSD hiding security stuff]</ref><ref source="MLIST" url="http://marc.theaimsgroup.com/?l=freebsd-hackers&amp;m=110994026421858&amp;w=2">[freebsd-hackers] 20050304 Re: FW:FreeBSD hiding security stuff</ref></refs><vuln_soft><prod name="Enterprise Linux" vendor="Red Hat"><vers edition="Workstation" num="4.0"/><vers edition="Workstation Server" num="3.0"/><vers edition="Workstation" num="2.1"/><vers edition="Workstation" num="2.1"/><vers edition="Enterprise Server" num="4.0"/><vers edition="Enterprise Server" num="3.0"/><vers edition="Enterprise Server" num="2.1"/><vers edition="Enterprise Server" num="2.1"/><vers edition="Advanced Server" num="4.0"/><vers edition="Advanced Server" num="3.0"/><vers edition="Advanced Server" num="2.1"/><vers edition="Advanced Server" num="2.1"/></prod><prod name="Desktop" vendor="Red Hat"><vers num="4.0"/><vers num="3.0"/></prod><prod name="OpenServer" vendor="SCO"><vers num="5.0.7"/></prod><prod name="Solaris" vendor="Sun"><vers edition="SPARC" num="10.0"/><vers edition="x86 Update 2" num="9.0"/><vers edition="x86" num="9.0"/><vers edition="x86" num="8.0"/><vers edition="x86" num="7.0"/></prod><prod name="Unixware" vendor="SCO"><vers num="7.1.4"/><vers num="7.1.3 up"/><vers num="7.1.3"/></prod><prod name="Fedora" vendor="Red Hat"><vers num="Core 3.0"/></prod><prod name="Ubuntu Linux" vendor="Ubuntu"><vers edition="powerpc" num="5.04"/><vers edition="i386" num="5.04"/><vers edition="amd64" num="5.04"/><vers edition="ppc" num="4.1"/><vers edition="ia64" num="4.1"/><vers edition="ia64" num="4.1"/></prod><prod name="FreeBSD" vendor="FreeBSD"><vers num="5.4 pre"/><vers num="5.3 Stable"/><vers num="5.3 Releng"/><vers num="5.3 Release"/><vers num="5.3"/><vers num="5.2.1 Release"/><vers num="5.2 Releng"/><vers num="5.2 Release"/><vers num="5.2"/><vers num="5.1 Releng"/><vers num="5.1 Release Alpha"/><vers num="5.1 p5 Release"/><vers num="5.1 Release"/><vers num="5.1"/><vers num="5.0 Releng"/><vers num="5.0 p14 Release"/><vers num="5.0 alpha"/><vers num="5.0"/><vers num="4.11 Stable"/><vers num="4.11 Releng"/><vers num="4.11 p3 Release"/><vers num="4.10 Releng"/><vers num="4.10 p8 Release"/><vers num="4.10 Release"/><vers num="4.10"/><vers num="4.9 Releng"/><vers num="4.9 pre"/><vers num="4.9"/><vers num="4.8 Releng"/><vers num="4.8 p6 Release"/><vers num="4.8 pre"/><vers num="4.8"/><vers num="4.7 Stable"/><vers num="4.7 Releng"/><vers num="4.7 p17 Release"/><vers num="4.7 Release"/><vers num="4.7"/><vers num="4.6.2"/><vers num="4.6 Stable"/><vers num="4.6 Releng"/><vers num="4.6 p20 Release"/><vers num="4.6 Release"/><vers num="4.6"/><vers num="4.5 Stable pre 2002-03-07"/><vers num="4.5 Stable"/><vers num="4.5 Releng"/><vers num="4.5 p32 Release"/><vers num="4.5 Release"/><vers num="4.5"/><vers num="4.4 Stable"/><vers num="4.4 Releng"/><vers num="4.4 p42 Release"/><vers num="4.4"/><vers num="4.3 Stable"/><vers num="4.3 Releng"/><vers num="4.3 p38 Release"/><vers num="4.3 Release"/><vers num="4.3"/><vers num="4.2 Stable pre 2000-12-23"/><vers num="4.2 Stable pre 2001-05-02"/><vers num="4.2 Stable"/><vers num="4.2 Release"/><vers num="4.2"/><vers num="4.1.1 Stable"/><vers num="4.1.1 Release"/><vers num="4.1.1"/><vers num="4.1"/><vers num="4.0 Releng"/><vers num="4.0 alpha"/><vers num="4.0"/><vers num="3.5.1 Stable pre 2001-07-20"/><vers num="3.5.1 Stable"/><vers num="3.5.1 Release"/><vers num="3.5.1"/><vers num="3.5 Stable pre 2000-12-23"/><vers num="3.5 Stable pre 2001-05-02"/><vers num="3.5 Stable"/><vers num="3.5"/><vers num="3.4"/><vers num="3.3"/><vers num="3.2"/><vers num="3.1"/><vers num="3.0 Releng"/><vers num="3.0"/><vers num="2.2.8"/><vers num="2.2.6"/><vers num="2.2.5"/><vers num="2.2.4"/><vers num="2.2.3"/><vers num="2.2.2"/><vers num="2.2"/><vers num="2.1.7.1"/><vers num="2.1.6.1"/><vers num="2.1.6"/><vers num="2.1.5"/><vers num="2.1.0"/><vers num="2.0.5"/><vers num="2.0"/><vers num="1.1.5.1"/><vers num="4.10 pre"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0110" published="2005-01-14" seq="2005-0110" severity="Low" type="CVE"><desc><descript source="cve">Internet Explorer 6 on Windows XP SP2 allows remote attackers to bypass the file download warning dialog and possibly trick an unknowledgeable user into executing arbitrary code via a web page with a body element containing an onclick tag, as demonstrated using the createElement function.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=110569119106172&amp;w=2">20050114 Internet Explorer (SP2) - Remote File Download</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers edition="for Microsoft Windows Server 2003 SP1.0 SP2" num="6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-03-28" name="CVE-2005-0111" published="2005-01-13" seq="2005-0111" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in the websql CGI program in MySQL MaxDB 7.5.00 allows remote attackers to execute arbitrary code via a long password parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=181&amp;type=vulnerabilities">20050113 MySQL MaxDB WebAgent websql logon Buffer Overflow Vulnerability</ref><ref source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=181&amp;type=vulnerabilities">20050113 MySQL MaxDB WebAgent websql logon Buffer Overflow Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/12265">12265</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1012893">1012893</ref></refs><vuln_soft><prod name="MaxDB" vendor="MySQL"><vers num="7.5.00"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0112" published="2005-04-14" seq="2005-0112" severity="Medium" type="CVE"><desc><descript source="cve">The web-based administrative interface for 3Com OfficeConnect Wireless 11g Access Point (AP) 1.00.08, and possibly earlier versions before 1.03.07A, allows remote attackers to bypass authentication and obtain sensitive information by directly accessing the (1) config.bin (2) profile.wlp?PN=ggg or (3) event.logs URLs.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="iDefense" url="http://www.idefense.com/application/poi/display?id=188&amp;type=vulnerabilities">3Com OfficeConnect Wireless 11g AP Information Disclosure Vulnerability</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/18994">OfficeConnect Wireless information disclosure</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/12322">bid 12322</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1012958">1012958</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13942">13942</ref></refs><vuln_soft><prod name="3Com OfficeConnect Wireless11g Access Point" vendor="3Com"><vers num="3CRWE454G72 1.0.3.5"/><vers num="3CRWE454G72 1.0.2.11"/><vers num="3CRWE454G72 1.0.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0113" published="2005-01-14" seq="2005-0113" severity="High" type="CVE"><desc><descript source="cve">inpview in SGI IRIX allows local users to execute arbitrary commands via the SUN_TTSESSION_CMD environment variable, which is executed by inpview without dropping privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=182&amp;type=vulnerabilities">20050113 SGI IRIX inpview Design Error Vulnerability</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/13858">13858</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18894">irix-inpview-gain-privileges(18894)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1012894">1012894</ref><ref source="BID" url="http://www.securityfocus.com/bid/12259">12259</ref><ref source="OSVDB" url="http://www.osvdb.org/12915">12915</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num="6.5"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0114" published="2005-02-11" seq="2005-0114" severity="Low" type="CVE"><desc><descript source="cve">vsdatant.sys in Zone Lab ZoneAlarm before 5.5.062.011, ZoneAlarm Wireless before 5.5.080.000, Check Point Integrity Client 4.x before 4.5.122.000 and 5.x before 5.1.556.166 do not properly verify that the ServerPortName argument to the NtConnectPort function is a valid memory address, which allows local users to cause a denial of service (system crash) when ZoneAlarm attempts to dereference an invalid pointer.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=199&amp;type=vulnerabilities">20050211 ZoneAlarm 5.1 Invalid Pointer Dereference Vulnerability</ref><ref adv="1" patch="1" source="CONFIRM" url="http://download.zonelabs.com/bin/free/securityAlert/19.html">http://download.zonelabs.com/bin/free/securityAlert/19.html</ref><ref source="BID" url="http://www.securityfocus.com/bid/12531">12531</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14256">14256</ref></refs><vuln_soft><prod name="ZoneAlarm" vendor="Zone Labs"><vers num="5.5.062.011"/></prod><prod name="ZoneAlarm Wireless" vendor="Zone Labs"><vers num="5.5.080.000" prev="1"/></prod><prod name="Check Point Integrity Client" vendor="Zone Labs"><vers num="4.5.122.000"/><vers num="5.1.556.166" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0115" published="2005-01-24" seq="2005-0115" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in DataRescue Interactive Disassembler (IDA) Pro 4.7 allows attackers to execute arbitrary code via a PE file with an Import Address Table containing a long import library name.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=189&amp;type=vulnerabilities">20050124 DataRescue Interactive Disassembler Pro Buffer Overflow Vulnerability</ref><ref adv="1" patch="1" source="CONFIRM" url="http://www.datarescue.com/ubb/ultimatebb.php?/topic/2/146.html">http://www.datarescue.com/ubb/ultimatebb.php?/topic/2/146.html</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19042">database-ida-portable-executable-bo(19042)</ref><ref source="BID" url="http://www.securityfocus.com/bid/12353">12353</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1012975">1012975</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13980">13980</ref></refs><vuln_soft><prod name="IDA" vendor="DataRescue"><vers num="4.7"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-02-26" name="CVE-2005-0116" published="2005-01-18" seq="2005-0116" severity="High" type="CVE"><desc><descript source="cve">AWStats 6.1, and other versions before 6.3, allows remote attackers to execute arbitrary commands via shell metacharacters in the configdir parameter to aswtats.pl.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=185&amp;type=vulnerabilities&amp;flashstatus=false">20050117 AWStats Remote Command Execution Vulnerability</ref><ref adv="1" patch="1" source="CONFIRM" url="http://awstats.sourceforge.net/docs/awstats_changelog.txt">http://awstats.sourceforge.net/docs/awstats_changelog.txt</ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/272296">VU#272296</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/13893/">13893</ref><ref source="OSVDB" url="http://www.osvdb.org/13002">13002</ref><ref source="" url="http://packetstormsecurity.org/0501-exploits/AWStatsVulnAnalysis.pdf"></ref><ref source="BID" url="http://www.securityfocus.com/bid/12298">12298</ref></refs><vuln_soft><prod name="AWStats" vendor="AWStats"><vers num="6.3" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0117" published="2005-01-11" seq="2005-0117" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in XShisen before 1.36 allows local users to execute arbitrary code via a long GECOS field.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="Debian" url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=289784">289784: xshisen: buffer overflow when handling GECOS field</ref><ref adv="1" source="CONFIRM" url="http://www.vuxml.org/freebsd/56971fa6-641c-11d9-a097-000854d03344.html">http://www.vuxml.org/freebsd/56971fa6-641c-11d9-a097-000854d03344.html</ref></refs><vuln_soft><prod name="XShisen" vendor="XShisen"><vers num="1.36" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0118" published="2005-05-02" seq="2005-0118" severity="Low" type="CVE"><desc><descript source="cve">helvis 1.8h2_1 and earlier stores recovery files in world readable directories with world readable permissions, which allows local users to read the recovered files of other users.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/><design/></vuln_types><range><local/></range><refs><ref adv="1" source="CONFIRM" url="http://www.vuxml.org/freebsd/bb99f803-5fde-11d9-b721-00065be4b5b6.html">http://www.vuxml.org/freebsd/bb99f803-5fde-11d9-b721-00065be4b5b6.html</ref></refs><vuln_soft><prod name="helvis" vendor="Helvis"><vers num="1.8h2_1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0119" published="2005-05-02" seq="2005-0119" severity="Low" type="CVE"><desc><descript source="cve">helvis 1.8h2_1 and earlier allows local users to recover and read the files of other users via the elvrec setuid program.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref source="CONFIRM" url="http://www.vuxml.org/freebsd/bb99f803-5fde-11d9-b721-00065be4b5b6.html">http://www.vuxml.org/freebsd/bb99f803-5fde-11d9-b721-00065be4b5b6.html</ref></refs><vuln_soft><prod name="helvis" vendor="Helvis"><vers num="1.8h2_1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0120" published="2005-05-02" seq="2005-0120" severity="Low" type="CVE"><desc><descript source="cve">helvis 1.8h2_1 and earlier allows local users to delete arbitrary files via the elvprsv setuid program.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="MISC" url="http://people.freebsd.org/~niels/ports/korean/helvis/issues.txt">http://people.freebsd.org/~niels/ports/korean/helvis/issues.txt</ref></refs><vuln_soft><prod name="helvis" vendor="Helvis"><vers num="1.8h2_1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0121" published="2005-05-02" seq="2005-0121" severity="Medium" type="CVE"><desc><descript source="cve">Multiple buffer overflows in golddig 2.0 and earlier allow local users to execute arbitrary code via (1) a long map name command line argument or (2) a long username as recorded in the USER environment variable.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="CONFIRM" url="http://www.vuxml.org/freebsd/949c470e-528f-11d9-ac20-00065be4b5b6.html">http://www.vuxml.org/freebsd/949c470e-528f-11d9-ac20-00065be4b5b6.html</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19039">golddig-long-mapname-bo(19039)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19040">golddig-long-username-bo(19040)</ref></refs><vuln_soft><prod name="golddig" vendor="Alexander Siegel"><vers num="2.0"/></prod></vuln_soft></entry><entry modified="2005-10-25" name="CVE-2005-0122" published="2005-04-14" reject="1" seq="2005-0122" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2005-0975.  Reason: This candidate is a duplicate of CVE-2005-0975.  Notes: All CVE users should reference CVE-2005-0975 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><refs/></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0124" published="2005-04-14" seq="2005-0124" severity="Low" type="CVE"><desc><descript source="cve">The coda_pioctl function in the coda functionality (pioctl.c) for Linux kernel 2.6.9 and 2.4.x before 2.4.29 may allow local users to cause a denial of service (crash) or execute arbitrary code via negative vi.in_size or vi.out_size values, which may trigger a buffer overflow.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="Seclists.org" url="http://seclists.org/lists/linux-kernel/2005/Jan/2018.html">Re: Make pipe data structure be a circular list of pages, rather than</ref><ref source="MLIST" url="http://seclists.org/lists/linux-kernel/2004/Dec/3914.html">[linux-kernel] 20041216 [Coverity] Untrusted user data in kernel</ref><ref source="MLIST" url="http://seclists.org/lists/linux-kernel/2005/Jan/1089.html">[linux-kernel] 20050105 Re: [Coverity] Untrusted user data in kernel</ref><ref source="MLIST" url="http://seclists.org/lists/linux-kernel/2005/Jan/2020.html">[linux-kernel] 20050107 [PATCH 2.6.10-mm2] fs/coda Re: [Coverity] Untrusted user data in kernel</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013018">1013018</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0191.html">RHSA-2006:0191</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18684">18684</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-663.html">RHSA-2005:663</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/428028/100/0/threaded">FLSA:157459-1</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1017">DSA-1017</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19374">19374</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17002">17002</ref><ref source="BID" url="http://www.securityfocus.com/bid/14967">14967</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1070">DSA-1070</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1067">DSA-1067</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1069">DSA-1069</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20163">20163</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20202">20202</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1082">DSA-1082</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/1878">ADV-2005-1878</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20338">20338</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers edition="2.6.20" num="2.6.9"/><vers num="2.4.9"/><vers num="2.4.8"/><vers num="2.4.7"/><vers num="2.4.6"/><vers num="2.4.5"/><vers num="2.4.4"/><vers num="2.4.3-pre3"/><vers num="2.4.3"/><vers num="2.4.29-rc2"/><vers num="2.4.29-rc1"/><vers num="2.4.29"/><vers num="2.4.28"/><vers num="2.4.27-pre5"/><vers num="2.4.27-pre4"/><vers num="2.4.27-pre3"/><vers num="2.4.27-pre2"/><vers num="2.4.27-pre1"/><vers num="2.4.27"/><vers num="2.4.26"/><vers num="2.4.25"/><vers num="2.4.24-ow1"/><vers num="2.4.24"/><vers num="2.4.23-pre9"/><vers num="2.4.23-ow2"/><vers num="2.4.23"/><vers num="2.4.22-pre10"/><vers num="2.4.22"/><vers num="2.4.21-pre7"/><vers num="2.4.21-pre4"/><vers num="2.4.21-pre1"/><vers num="2.4.21"/><vers num="2.4.20"/><vers num="2.4.2"/><vers num="2.4.19-pre6"/><vers num="2.4.19-pre5"/><vers num="2.4.19-pre4"/><vers num="2.4.19-pre3"/><vers num="2.4.19-pre2"/><vers num="2.4.19-pre1"/><vers num="2.4.19"/><vers num="2.4.18-x86"/><vers num="2.4.18-pre-8"/><vers num="2.4.18-pre-7"/><vers num="2.4.18-pre-6"/><vers num="2.4.18-pre-5"/><vers num="2.4.18-pre-4"/><vers num="2.4.18-pre-3"/><vers num="2.4.18-pre-2"/><vers num="2.4.18-pre-1"/><vers num="2.4.18"/><vers num="2.4.17"/><vers num="2.4.16"/><vers num="2.4.15"/><vers num="2.4.14"/><vers num="2.4.13"/><vers num="2.4.12"/><vers num="2.4.11"/><vers num="2.4.10"/><vers num="2.4.1"/><vers num="2.4.0-test9"/><vers num="2.4.0-test8"/><vers num="2.4.0-test7"/><vers num="2.4.0-test6"/><vers num="2.4.0-test5"/><vers num="2.4.0-test4"/><vers num="2.4.0-test3"/><vers num="2.4.0-test2"/><vers num="2.4.0-test12"/><vers num="2.4.0-test11"/><vers num="2.4.0-test10"/><vers num="2.4.0 test1"/><vers num="2.4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0125" published="2005-05-02" seq="2005-0125" severity="High" type="CVE"><desc><descript source="cve">The &quot;at&quot; commands on Mac OS X 10.3.7 and earlier do not properly drop privileges, which allows local users to (1) delete arbitrary files via atrm, (2) execute arbitrary programs via the -f argument to batch, or (3) read arbitrary files via the -f argument to batch, which generates a job file that is readable by the local user.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110685027017411&amp;w=2">20050127 DMA[2005-0127a] - &apos;Apple OSX batch family poor use of setuid&apos;</ref><ref adv="1" source="MISC" url="http://www.digitalmunition.com/DMA%5B2005-0127a%5D.txt">http://www.digitalmunition.com/DMA[2005-0127a].txt</ref><ref adv="1" patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/Jan/msg00001.html">APPLE-SA-2005-01-25</ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/678150">VU#678150</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18981">macos-at-gain-privileges(18981)</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.3.7"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.3.4"/><vers num="10.3.7"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0126" published="2005-05-02" seq="2005-0126" severity="High" type="CVE"><desc><descript source="cve">ColorSync on Mac OS X 10.3.7 and 10.3.8 allows attackers to execute arbitrary code via malformed ICC color profiles that modify the heap.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/Jan/msg00001.html">APPLE-SA-2005-01-25</ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/980078">VU#980078</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19083">macos-icc-profile-bo(19083)</ref><ref source="BID" url="http://www.securityfocus.com/bid/12367">12367</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013000">1013000</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.2.8"/><vers num="10.3.7"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.2.8"/><vers num="10.3.7"/><vers num="10.3.8"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0127" published="2005-05-02" seq="2005-0127" severity="Medium" type="CVE"><desc><descript source="cve">Mail in Mac OS X 10.3.7, when generating a Message-ID header, generates a GUUID that includes information that identifies the Ethernet hardware being used, which allows remote attackers to link mail messages to a particular machine.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/Jan/msg00001.html">APPLE-SA-2005-01-25</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19085">macos-ethernet-address-disclosure(19085)</ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/464662">VU#464662</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14005">14005</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013001">1013001</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.3.7"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.3.7"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0129" published="2005-04-14" seq="2005-0129" severity="High" type="CVE"><desc><descript source="cve">The Quick Buttons feature in Konversation 0.15 allows remote attackers to execute certain IRC commands via a channel name containing &quot;%&quot; variables, which are recursively expanded by the Server::parseWildcards function when the Part Button is selected.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110626383310742&amp;w=2">Multiple vulnerabilities in Konversation</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/19025">Konversation expansion execute code</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-January/031033.html">20050119 Multiple vulnerabilities in Konversation</ref><ref source="" url="http://www.kde.org/info/security/advisory-20050121-1.txt"></ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200501-34.xml">GLSA-200501-34</ref><ref source="BID" url="http://www.securityfocus.com/bid/12312">12312</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1012972">1012972</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13919">13919</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13989">13989</ref></refs><vuln_soft><prod name="Konversation" vendor="Berlios"><vers num="0.15"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0130" published="2005-04-14" seq="2005-0130" severity="High" type="CVE"><desc><descript source="cve">Certain Perl scripts in Konversation 0.15 allow remote attackers to execute arbitrary commands via shell metacharacters in (1) channel names or (2) song names that are not properly quoted when the user runs IRC sripts.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110626383310742&amp;w=2">Multiple vulnerabilities in Konversation</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/19008">Konversation Perl script may allow execution of code</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-January/031033.html">20050119 Multiple vulnerabilities in Konversation</ref><ref source="" url="http://www.kde.org/info/security/advisory-20050121-1.txt"></ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200501-34.xml">GLSA-200501-34</ref><ref source="BID" url="http://www.securityfocus.com/bid/12312">12312</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1012972">1012972</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13919">13919</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13989">13989</ref></refs><vuln_soft><prod name="Konversation" vendor="Berlios"><vers num="0.15"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0131" published="2005-04-14" seq="2005-0131" severity="Medium" type="CVE"><desc><descript source="cve">The Quick Connection dialog in Konversation 0.15 inadvertently uses the user-provided password as the nickname instead of the user-provided nickname when connecting to the IRC server, which could leak the password to other users.</descript></desc><loss_types><conf/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110626383310742&amp;w=2">Multiple vulnerabilities in Konversation</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-January/031033.html">20050119 Multiple vulnerabilities in Konversation</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19038">konversation-nick-password-information-disclosure(19038)</ref><ref source="" url="http://www.kde.org/info/security/advisory-20050121-1.txt"></ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200501-34.xml">GLSA-200501-34</ref><ref source="BID" url="http://www.securityfocus.com/bid/12312">12312</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1012972">1012972</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13919">13919</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13989">13989</ref></refs><vuln_soft><prod name="Konversation" vendor="Berlios"><vers num="0.15"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0133" published="2005-05-02" seq="2005-0133" severity="Medium" type="CVE"><desc><descript source="cve">ClamAV 0.80 and earlier allows remote attackers to cause a denial of service (clamd daemon crash) via a ZIP file with malformed headers.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref patch="1" source="CONFIRM" url="http://sourceforge.net/project/shownotes.php?release_id=300116">http://sourceforge.net/project/shownotes.php?release_id=300116</ref><ref adv="1" patch="1" source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000928">CLA-2005:928</ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200501-46.xml">GLSA-200501-46</ref><ref patch="1" source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:025">MDKSA-2005:025</ref><ref adv="1" patch="1" source="TRUSTIX" url="http://www.trustix.org/errata/2005/0003/">2005-0003</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:025">MDKSA-2005:025</ref></refs><vuln_soft><prod name="ClamAV" vendor="Clam Anti-Virus"><vers num="0.80"/><vers num="0.68.1"/><vers num="0.68"/><vers num="0.67"/><vers num="0.65"/><vers num="0.60"/><vers num="0.54"/><vers num="0.53"/><vers num="0.52"/><vers num="0.51"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0134" published="2005-05-18" seq="2005-0134" severity="Medium" type="CVE"><desc><descript source="cve">The X server in SCO UnixWare 7.1.1, 7.1.3, and 7.1.4 does not properly create socket directories in /tmp, which could allow attackers to hijack local sockets.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/0077">ADV-2005-0077</ref><ref patch="1" source="SCO" url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.8/SCOSA-2005.8.txt">SCOSA-2005.8</ref><ref patch="1" source="Secunia" url="http://secunia.com/advisories/14039/">UnixWare x.org Local Socket Hijacking Vulnerability</ref></refs><vuln_soft><prod name="Unixware" vendor="SCO"><vers num="7.1.1"/><vers num="7.1.3"/><vers num="7.1.4"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0135" published="2005-05-02" seq="2005-0135" severity="Low" type="CVE"><desc><descript source="cve">The unw_unwind_to_user function in unwind.c on Itanium (ia64) architectures in Linux kernel 2.6 allows local users to cause a denial of service (system crash).</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-366.html">RHSA-2005:366</ref><ref patch="1" source="CONFIRM" url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=148868">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=148868</ref><ref source="CONFIRM" url="http://linux.bkbits.net:8080/linux-2.6/cset@41f2beablXVnAs_6fznhhITh1j5hZg">http://linux.bkbits.net:8080/linux-2.6/cset@41f2beablXVnAs_6fznhhITh1j5hZg</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/15019">15019</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-284.html">RHSA-2005:284</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-293.html">RHSA-2005:293</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1070">DSA-1070</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1067">DSA-1067</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1069">DSA-1069</ref><ref source="BID" url="http://www.securityfocus.com/bid/13266">13266</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20163">20163</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20202">20202</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1082">DSA-1082</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20338">20338</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.6"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2005-09-29" modified="2006-06-01" name="CVE-2005-0136" published="2005-12-31" seq="2005-0136" severity="Low" type="CVE"><desc><descript source="cve">The Linux kernel before 2.6.11 on the Itanium IA64 platform has certain &quot;ptrace corner cases&quot; that allow local users to cause a denial of service (crash) via crafted syscalls, possibly related to MCA/INIT, a different vulnerability than CVE-2005-1761.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-420.html">RHSA-2005:420</ref><ref patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-663.html">RHSA-2005:663</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/17002">17002</ref><ref source="MLIST" url="http://lists.alioth.debian.org/pipermail/kernel-svn-changes/2005-August/002597.html">[kernel-svn-changes] 20050816 r3920 - in branches/dist/sarge-security: . kernel kernel/i386 kernel/source kernel/source/kernel-source-2.6.8-2.6.8/debian</ref><ref patch="1" source="MLIST" url="http://www.gelato.unsw.edu.au/archives/linux-ia64/0409/11073.html">[linux-ia64] 20040916 Re: [Patch] Per CPU MCA/INIT data save areas</ref><ref patch="1" source="" url="http://openvz.org/news/updates/kernel-022stab045.1-released"></ref><ref patch="1" source="" url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=148862"></ref><ref patch="1" source="" url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=155283"></ref><ref patch="1" source="" url="http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.11"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/1878">ADV-2005-1878</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.6.10 rc3"/><vers num="2.6.10 rc2"/><vers num="2.6.10 rc1"/><vers num="2.6.10"/><vers num="2.6.9 rc4"/><vers num="2.6.9 rc3"/><vers num="2.6.9 rc2"/><vers num="2.6.9 rc1"/><vers num="2.6.9 final"/><vers edition="2.6.20" num="2.6.9"/><vers num="2.6.8 rc4"/><vers num="2.6.8 rc3"/><vers num="2.6.8 rc2"/><vers num="2.6.8 rc1"/><vers edition="PowerPC_smp" num="2.6.8.1.5"/><vers edition="PowerPC" num="2.6.8.1.5"/><vers edition="Power4_smp" num="2.6.8.1.5"/><vers edition="Power4" num="2.6.8.1.5"/><vers edition="Power3_smp" num="2.6.8.1.5"/><vers edition="Power3" num="2.6.8.1.5"/><vers edition="K7_smp" num="2.6.8.1.5"/><vers edition="K7" num="2.6.8.1.5"/><vers edition="AMD64_Xeon" num="2.6.8.1.5"/><vers edition="AMD64_K8_smp" num="2.6.8.1.5"/><vers edition="AMD64_K8" num="2.6.8.1.5"/><vers edition="AMD64" num="2.6.8.1.5"/><vers edition="686_smp" num="2.6.8.1.5"/><vers edition="686" num="2.6.8.1.5"/><vers edition="386" num="2.6.8.1.5"/><vers num="2.6.8.1.5"/><vers num="2.6.8.1"/><vers num="2.6.8"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0137" published="2005-05-02" seq="2005-0137" severity="Low" type="CVE"><desc><descript source="cve">Linux kernel 2.6 on Itanium (ia64) architectures allows local users to cause a denial of service via a &quot;missing Itanium syscall table entry.&quot;</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-293.html">RHSA-2005:293</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-284.html">RHSA-2005:284</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0138" published="2005-09-21" seq="2005-0138" severity="High" type="CVE"><desc><descript source="cve">rpc.mountd in SGI IRIX 6.5.25, 6.5.26, and 6.5.27 does not correctly allow access to anonymous clients that connect from a system whose hostname can not be determined.  NOTE: while this issue occurs in a security mechanism, there is no apparent attacker role and probably does not satisfy the CVE definition of a vulnerability.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="CIAC" url="http://www.ciac.org/ciac/bulletins/p-214.shtml">P-214</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/0702">ADV-2005-0702</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15619">15619</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num="6.5.25"/><vers num="6.5.26"/><vers num="6.5.27"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0139" published="2005-09-21" seq="2005-0139" severity="High" type="CVE"><desc><descript source="cve">Unknown vulnerability in rpc.mountd in SGI IRIX 6.5.25, 6.5.26, and 6.5.27 does not sufficiently restrict access rights for read-mostly exports, which allows attackers to conduct unauthorized activities.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="CIAC" url="http://www.ciac.org/ciac/bulletins/p-214.shtml">P-214</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/0702">ADV-2005-0702</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15619">15619</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num="6.5.25"/><vers num="6.5.26"/><vers num="6.5.27"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0140" published="2005-05-02" seq="2005-0140" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in PeID allows attackers to execute arbitrary code via a PE file with an Import Address Table containing a long import library name.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=189&amp;type=vulnerabilities">20050124 DataRescue Interactive Disassembler Pro Buffer Overflow Vulnerability</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19042">database-ida-portable-executable-bo(19042)</ref><ref source="BID" url="http://www.securityfocus.com/bid/12355">12355</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13984">13984</ref></refs><vuln_soft><prod name="PeID" vendor="PeID"><vers num="0.92"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0141" published="2005-05-02" seq="2005-0141" severity="Low" type="CVE"><desc><descript source="cve">Firefox before 1.0 and Mozilla before 1.7.5 allow remote attackers to load local files via links &quot;with a custom getter and toString method&quot; that are middle-clicked by the user to be opened in a new tab.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="CONFIRM" url="http://www.mozilla.org/security/announce/mfsa2005-01.html">http://www.mozilla.org/security/announce/mfsa2005-01.html</ref><ref adv="1" source="CONFIRM" url="https://bugzilla.mozilla.org/show_bug.cgi?id=249332">https://bugzilla.mozilla.org/show_bug.cgi?id=249332</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-323.html">RHSA-2005:323</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-335.html">RHSA-2005:335</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19168">mozilla-firefox-file-upload(19168)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval100057.html">OVAL100057</ref><ref source="BID" url="http://www.securityfocus.com/bid/12407">12407</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100057">oval:org.mitre.oval:def:100057</ref></refs><vuln_soft><prod name="Mozilla Browser" vendor="Mozilla"><vers num="1.7 rc3"/><vers num="1.7"/><vers num="1.7.1"/><vers num="1.7.2"/><vers num="1.7.3"/></prod><prod name="Firefox" vendor="Mozilla"><vers num="0.8"/><vers num="0.9"/><vers num="0.9.1"/><vers num="0.9.2"/><vers num="0.9.3"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0142" published="2005-05-02" seq="2005-0142" severity="Low" type="CVE"><desc><descript source="cve">Firefox 0.9, Thunderbird 0.6 and other versions before 0.9, and Mozilla 1.7 before 1.7.5 save temporary files with world-readable permissions, which allows local users to read certain web content or attachments that belong to other users, e.g. content that is managed by helper applications such as PDF.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="CONFIRM" url="http://www.mozilla.org/security/announce/mfsa2005-02.html">http://www.mozilla.org/security/announce/mfsa2005-02.html</ref><ref source="CONFIRM" url="https://bugzilla.mozilla.org/show_bug.cgi?id=251297">https://bugzilla.mozilla.org/show_bug.cgi?id=251297</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-335.html">RHSA-2005:335</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17832">mozilla-world-readable(17832)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval100056.html">OVAL100056</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-384.html">RHSA-2005:384</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_04_25.html">SUSE-SA:2006:022</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19823">19823</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100056">oval:org.mitre.oval:def:100056</ref></refs><vuln_soft><prod name="Thunderbird" vendor="Mozilla"><vers num="0.6"/><vers num="0.7"/><vers num="0.8"/></prod><prod name="Mozilla Browser" vendor="Mozilla"><vers num="1.7 rc3"/><vers num="1.7"/><vers num="1.7.1"/><vers num="1.7.2"/><vers num="1.7.3"/></prod><prod name="Firefox" vendor="Mozilla"><vers num="0.9"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0143" published="2005-03-23" seq="2005-0143" severity="Low" type="CVE"><desc><descript source="cve">Firefox before 1.0 and Mozilla before 1.7.5 display the SSL lock icon when an insecure page loads a binary file from a trusted site, which could facilitate phishing attacks.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="CONFIRM" url="http://www.mozilla.org/security/announce/mfsa2005-03.html">http://www.mozilla.org/security/announce/mfsa2005-03.html</ref><ref adv="1" patch="1" source="CONFIRM" url="https://bugzilla.mozilla.org/show_bug.cgi?id=257308">https://bugzilla.mozilla.org/show_bug.cgi?id=257308</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-335.html">RHSA-2005:335</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19166">mozilla-ssl-spoofing(19166)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval100055.html">OVAL100055</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-384.html">RHSA-2005:384</ref><ref source="BID" url="http://www.securityfocus.com/bid/12407">12407</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100055">oval:org.mitre.oval:def:100055</ref></refs><vuln_soft><prod name="Mozilla" vendor="Mozilla"><vers num="1.7.5"/><vers num="1.7.3"/><vers num="1.7.2"/><vers num="1.7.1"/><vers num="1.7 rc3"/><vers num="1.7 rc2"/><vers num="1.7 rc1"/><vers num="1.7 beta"/><vers num="1.7 alpha"/><vers num="1.7"/><vers num="1.6 beta"/><vers num="1.6 alpha"/><vers num="1.6"/><vers num="1.5.1"/><vers num="1.5 rc2"/><vers num="1.5 rc1"/><vers num="1.5 alpha"/><vers num="1.5"/><vers num="1.4a"/><vers num="1.4.1"/><vers num="1.4"/><vers num="1.3"/><vers num=""/></prod><prod name="Mozilla Browser" vendor="Mozilla"><vers num="1.8 Alpha2"/><vers num="1.7.3"/><vers num="1.7.2"/><vers num="1.7.1"/><vers num="1.7 rc3"/><vers num="1.7 rc2"/><vers num="1.7 rc1"/><vers num="1.7 beta"/><vers num="1.7 alpha"/><vers num="1.7"/><vers num="1.6"/><vers num="1.5.1"/><vers num="1.5"/><vers num="1.4.4"/><vers num="1.4.2"/><vers num="1.4.1"/><vers num="1.4b"/><vers num="1.4a"/><vers num="1.4"/><vers num="1.3.1"/><vers num="1.3"/><vers num="1.2.1"/><vers num="1.2 Beta"/><vers num="1.2 Alpha"/><vers num="1.2"/><vers num="1.1 Beta"/><vers num="1.1 Alpha"/><vers num="1.1"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0 RC2"/><vers num="1.0 RC1"/><vers num="1.0"/><vers num="0.9.9"/><vers num="0.9.8"/><vers num="0.9.7"/><vers num="0.9.6"/><vers num="0.9.5"/><vers num="0.9.48"/><vers num="0.9.4.1"/><vers num="0.9.4"/><vers num="0.9.35"/><vers num="0.9.3"/><vers num="0.9.2.1"/><vers num="0.9.2"/><vers num="0.8"/></prod><prod name="Firefox" vendor="Mozilla"><vers num="1.0"/><vers num="0.9.3"/><vers num="0.9.2"/><vers num="0.9.1"/><vers edition="rc" num="0.9"/><vers num="0.9"/><vers num="0.8"/><vers num="0.10.1"/><vers num="0.10"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0144" published="2005-05-02" seq="2005-0144" severity="Low" type="CVE"><desc><descript source="cve">Firefox before 1.0 and Mozilla before 1.7.5 display the secure site lock icon when a view-source: URL references a secure SSL site while an insecure page is being loaded, which could facilitate phishing attacks.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="CONFIRM" url="http://www.mozilla.org/security/announce/mfsa2005-04.html">http://www.mozilla.org/security/announce/mfsa2005-04.html</ref><ref adv="1" source="CONFIRM" url="https://bugzilla.mozilla.org/show_bug.cgi?id=262689">https://bugzilla.mozilla.org/show_bug.cgi?id=262689</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-323.html">RHSA-2005:323</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-335.html">RHSA-2005:335</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19169">mozilla-ssl-view-source-spoofing(19169)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval100054.html">OVAL100054</ref><ref source="BID" url="http://www.securityfocus.com/bid/12407">12407</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100054">oval:org.mitre.oval:def:100054</ref></refs><vuln_soft><prod name="Mozilla Browser" vendor="Mozilla"><vers num="1.7 rc3"/><vers num="1.7"/><vers num="1.7.1"/><vers num="1.7.2"/><vers num="1.7.3"/></prod><prod name="Firefox" vendor="Mozilla"><vers num="0.8"/><vers num="0.9"/><vers num="0.9.1"/><vers num="0.9.2"/><vers num="0.9.3"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0145" published="2005-01-24" seq="2005-0145" severity="Low" type="CVE"><desc><descript source="cve">Firefox before 1.0 does not properly distinguish between user-generated and synthetic click events, which allows remote attackers to use Javascript to bypass the file download prompt when the user uses the Alt-click feature.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="CONFIRM" url="http://www.mozilla.org/security/announce/mfsa2005-07.html">http://www.mozilla.org/security/announce/mfsa2005-07.html</ref><ref adv="1" patch="1" source="CONFIRM" url="https://bugzilla.mozilla.org/show_bug.cgi?id=265176">https://bugzilla.mozilla.org/show_bug.cgi?id=265176</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19170">mozilla-script-click-event-bypass(19170)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval100051.html">OVAL100051</ref><ref source="BID" url="http://www.securityfocus.com/bid/12407">12407</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100051">oval:org.mitre.oval:def:100051</ref></refs><vuln_soft><prod name="Firefox" vendor="Mozilla"><vers num="1.0"/><vers num="0.9.3"/><vers num="0.9.2"/><vers num="0.9.1"/><vers edition="rc" num="0.9"/><vers num="0.9"/><vers num="0.8"/><vers num="0.10.1"/><vers num="0.10"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0146" published="2005-05-02" seq="2005-0146" severity="Medium" type="CVE"><desc><descript source="cve">Firefox before 1.0 and Mozilla before 1.7.5 allow remote attackers to obtain sensitive data from the clipboard via Javascript that generates a middle-click event on systems for which a middle-click performs a paste operation.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="CONFIRM" url="http://www.mozilla.org/security/announce/mfsa2005-08.html">http://www.mozilla.org/security/announce/mfsa2005-08.html</ref><ref adv="1" source="CONFIRM" url="https://bugzilla.mozilla.org/show_bug.cgi?id=265728">https://bugzilla.mozilla.org/show_bug.cgi?id=265728</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-335.html">RHSA-2005:335</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19171">mozilla-middle-click-information-disclosure(19171)</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-384.html">RHSA-2005:384</ref><ref source="BID" url="http://www.securityfocus.com/bid/12407">12407</ref></refs><vuln_soft><prod name="Mozilla Browser" vendor="Mozilla"><vers num="1.7 rc3"/><vers num="1.7"/><vers num="1.7.1"/><vers num="1.7.2"/><vers num="1.7.3"/></prod><prod name="Firefox" vendor="Mozilla"><vers num="0.8"/><vers num="0.9"/><vers num="0.9.1"/><vers num="0.9.2"/><vers num="0.9.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0147" published="2005-05-02" seq="2005-0147" severity="High" type="CVE"><desc><descript source="cve">Firefox before 1.0 and Mozilla before 1.7.5, when configured to use a proxy, respond to 407 proxy auth requests from arbitrary servers, which allows remote attackers to steal NTLM or SPNEGO credentials.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/><config/></vuln_types><range><network/></range><refs><ref adv="1" source="CONFIRM" url="http://www.mozilla.org/security/announce/mfsa2005-09.html">http://www.mozilla.org/security/announce/mfsa2005-09.html</ref><ref adv="1" source="CONFIRM" url="https://bugzilla.mozilla.org/show_bug.cgi?id=267263">https://bugzilla.mozilla.org/show_bug.cgi?id=267263</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-323.html">RHSA-2005:323</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19174">mozilla-407-proxy-obtain-information(19174)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval100049.html">OVAL100049</ref><ref source="BID" url="http://www.securityfocus.com/bid/12407">12407</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100049">oval:org.mitre.oval:def:100049</ref></refs><vuln_soft><prod name="Mozilla Browser" vendor="Mozilla"><vers num="1.7 rc3"/><vers num="1.7"/><vers num="1.7.1"/><vers num="1.7.2"/><vers num="1.7.3"/></prod><prod name="Firefox" vendor="Mozilla"><vers num="0.8"/><vers num="0.9"/><vers num="0.9.1"/><vers num="0.9.2"/><vers num="0.9.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0148" published="2005-05-02" seq="2005-0148" severity="Medium" type="CVE"><desc><descript source="cve">Thunderbird before 0.9, when running on Windows systems, uses the default handler when processing javascript: links, which invokes Internet Explorer and may expose the Thunderbird user to vulnerabilities in the version of Internet Explorer that is installed on the user&apos;s system.  NOTE: since the invocation between multiple products is a common practice, and the vulnerabilities inherent in multi-product interactions are not easily enumerable, this issue might be REJECTED in the future.</descript></desc><loss_types><int/></loss_types><vuln_types><env/></vuln_types><range><network/></range><refs><ref adv="1" source="CONFIRM" url="http://www.mozilla.org/security/announce/mfsa2005-10.html">http://www.mozilla.org/security/announce/mfsa2005-10.html</ref><ref adv="1" source="CONFIRM" url="https://bugzilla.mozilla.org/show_bug.cgi?id=263546">https://bugzilla.mozilla.org/show_bug.cgi?id=263546</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19173">thunderbird-javascript-handler-launch(19173)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval100048.html">OVAL100048</ref><ref source="BID" url="http://www.securityfocus.com/bid/12407">12407</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100048">oval:org.mitre.oval:def:100048</ref></refs><vuln_soft><prod name="Thunderbird" vendor="Mozilla"><vers num="0.6"/><vers num="0.7"/><vers num="0.8"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0149" published="2005-02-15" seq="2005-0149" severity="Medium" type="CVE"><desc><descript source="cve">Thunderbird 0.6 through 0.9 and Mozilla 1.7 through 1.7.3 does not obey the network.cookie.disableCookieForMailNews preference, which could allow remote attackers bypass the user&apos;s intended privacy and security policy by using cookies in e-mail messages.</descript></desc><loss_types><int/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CONFIRM" url="http://www.mozilla.org/security/announce/mfsa2005-11.html">http://www.mozilla.org/security/announce/mfsa2005-11.html</ref><ref adv="1" patch="1" source="CONFIRM" url="https://bugzilla.mozilla.org/show_bug.cgi?id=268107">https://bugzilla.mozilla.org/show_bug.cgi?id=268107</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-094.html">RHSA-2005:094</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-323.html">RHSA-2005:323</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-335.html">RHSA-2005:335</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19172">mozilla-cookie-policy-bypass(19172)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval100047.html">OVAL100047</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_04_25.html">SUSE-SA:2006:022</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19823">19823</ref><ref source="BID" url="http://www.securityfocus.com/bid/12407">12407</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100047">oval:org.mitre.oval:def:100047</ref></refs><vuln_soft><prod name="Mozilla" vendor="Mozilla"><vers num="1.7.3"/><vers num="1.7.2"/><vers num="1.7.1"/><vers num="1.7 rc3"/><vers num="1.7 rc2"/><vers num="1.7 rc1"/><vers num="1.7 beta"/><vers num="1.7 alpha"/><vers num="1.7"/></prod><prod name="Thunderbird" vendor="Mozilla"><vers num="0.9"/><vers num="0.7.3"/><vers num="0.7.2"/><vers num="0.7.1"/><vers num="0.7"/><vers num="0.6"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0150" published="2005-05-26" seq="2005-0150" severity="Medium" type="CVE"><desc><descript source="cve">Firefox before 1.0 allows the user to store a (1) javascript: or (2) data: URLs as a Livefeed bookmark, then executes it in the security context of the currently loaded page when the user later accesses the bookmark, which could allow remote attackers to execute arbitrary code.</descript></desc><loss_types><int/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CONFIRM" url="http://www.mozilla.org/security/announce/mfsa2005-12.html">http://www.mozilla.org/security/announce/mfsa2005-12.html</ref><ref adv="1" patch="1" source="CONFIRM" url="https://bugzilla.mozilla.org/show_bug.cgi?id=265668">https://bugzilla.mozilla.org/show_bug.cgi?id=265668</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19187">mozilla-firefox-livefeed-xss(19187)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval100046.html">OVAL100046</ref><ref source="BID" url="http://www.securityfocus.com/bid/12407">12407</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100046">oval:org.mitre.oval:def:100046</ref></refs><vuln_soft><prod name="Firefox" vendor="Mozilla"><vers num="1.0"/><vers num="0.9.3"/><vers num="0.9.2"/><vers num="0.9.1"/><vers edition="rc" num="0.9"/><vers num="0.9"/><vers num="0.8"/><vers num="0.10.1"/><vers num="0.10"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0151" published="2005-06-13" seq="2005-0151" severity="High" type="CVE"><desc><descript source="cve">Unknown vulnerability in the installation of Adobe License Management Service, as used in Adobe Photoshop CS, Adobe Creative Suite 1.0, and Adobe Premiere Pro 1.5, allows attackers to gain administrator privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CONFIRM" url="http://www.adobe.com/support/techdocs/331688.html">http://www.adobe.com/support/techdocs/331688.html</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014168">1014168</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014169">1014169</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1014170">1014170</ref></refs><vuln_soft><prod name="Premiere Pro" vendor="Adobe"><vers num="1.5"/></prod><prod name="Photoshop" vendor="Adobe"><vers num="CS"/></prod><prod name="Creative Suite" vendor="Adobe"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-28" name="CVE-2005-0152" published="2005-02-02" seq="2005-0152" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in Squirrelmail 1.2.6 allows remote attackers to execute arbitrary code via &quot;URL manipulation.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-662">DSA-662</ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/203214">VU#203214</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14096">14096</ref></refs><vuln_soft><prod name="SquirrelMail" vendor="SquirrelMail"><vers num="1.2.6"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0155" published="2005-05-02" seq="2005-0155" severity="Medium" type="CVE"><desc><descript source="cve">The PerlIO implementation in Perl 5.8.0, when installed with setuid support (sperl), allows local users to create arbitrary files via the PERLIO_DEBUG variable.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/><config/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=110779723332339&amp;w=2">20050207 DMA[2005-0131a] - &apos;Setuid Perl PERLIO_DEBUG root owned file creation&apos;</ref><ref adv="1" source="MISC" url="http://www.digitalmunition.com/DMA%5B2005-0131a%5D.txt">http://www.digitalmunition.com/DMA[2005-0131a].txt</ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200502-13.xml">GLSA-200502-13</ref><ref patch="1" source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:031">MDKSA-2005:031</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-103.html">RHSA-2005:103</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-105.html">RHSA-2005:105</ref><ref patch="1" source="TRUSTIX" url="http://www.trustix.org/errata/2005/0003/">2005-0003</ref><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110737149402683&amp;w=2">20050202 [USN-72-1] Perl vulnerabilities</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/12426">12426</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19207">perl-perliodebug-file-overwrite(19207)</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14120">14120</ref><ref source="FEDORA" url="http://fedoranews.org/updates/FEDORA--.shtml">FLSA-2006:152845</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=001056">CLSA-2006:1056</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-163.htm"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/21646">21646</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:031">MDKSA-2005:031</ref></refs><vuln_soft><prod name="Perl" vendor="Larry Wall"><vers num="5.8.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0156" published="2005-02-07" seq="2005-0156" severity="Low" type="CVE"><desc><descript source="cve">Buffer overflow in the PerlIO implementation in Perl 5.8.0, when installed with setuid support (sperl), allows local users to execute arbitrary code by setting the PERLIO_DEBUG variable and executing a Perl script whose full pathname contains a long directory tree.</descript></desc><loss_types><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=110779721503111&amp;w=2">20050207 DMA[2005-0131b] - &apos;Setuid Perl PERLIO_DEBUG</ref><ref adv="1" source="MISC" url="http://www.digitalmunition.com/DMA%5B2005-0131b%5D.txt">http://www.digitalmunition.com/DMA[2005-0131b].txt</ref><ref adv="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200502-13.xml">GLSA-200502-13</ref><ref adv="1" patch="1" source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:031">MDKSA-2005:031</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-103.html">RHSA-2005:103</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-105.html">RHSA-2005:105</ref><ref adv="1" patch="1" source="TRUSTIX" url="http://www.trustix.org/errata/2005/0003/">2005-0003</ref><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110737149402683&amp;w=2">20050202 [USN-72-1] Perl vulnerabilities</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/12426">12426</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19208">perl-perliodebug-bo(19208)</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14120">14120</ref><ref source="FEDORA" url="http://fedoranews.org/updates/FEDORA--.shtml">FLSA-2006:152845</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=001056">CLSA-2006:1056</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:031">MDKSA-2005:031</ref></refs><vuln_soft><prod name="Enterprise Linux" vendor="Red Hat"><vers edition="Workstation Server" num="3.0"/><vers edition="Enterprise Server" num="3.0"/><vers edition="Advanced Server" num="3.0"/></prod><prod name="SuSE Linux" vendor="SuSE"><vers num="9.2"/><vers num="9.1"/><vers edition="x86_64" num="9.0"/><vers num="9.0"/><vers num="8.2"/><vers num="8.1"/><vers edition="i386" num="8.0"/><vers num="8.0"/></prod><prod name="Perl" vendor="Larry Wall"><vers num="5.8.4.5"/><vers num="5.8.4.4"/><vers num="5.8.4.3"/><vers num="5.8.4.2.3"/><vers num="5.8.4.2"/><vers num="5.8.4.1"/><vers num="5.8.4"/><vers num="5.8.3"/><vers num="5.8.1"/><vers num="5.8.0"/></prod><prod name="Secure Enterprise Linux" vendor="Trustix"><vers num="2.0"/></prod><prod name="Fedora" vendor="Red Hat"><vers num="Core 3.0"/></prod><prod name="Desktop" vendor="Red Hat"><vers num="3.0"/></prod><prod name="Secure Linux" vendor="Trustix"><vers num="2.2"/><vers num="2.1"/><vers num="1.5"/></prod><prod name="Ubuntu Linux" vendor="Ubuntu"><vers edition="ppc" num="4.1"/><vers edition="ia64" num="4.1"/><vers edition="ia64" num="4.1"/></prod><prod name="AIX" vendor="IBM"><vers num="5.3"/><vers num="5.2"/></prod><prod name="ProPack" vendor="SGI"><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0157" published="2005-05-03" seq="2005-0157" severity="High" type="CVE"><desc><descript source="cve">The confirm add-on in SmartList 3.15 and earlier allows attackers to subscribe arbitrary e-mail addresses by using a valid cookie that specifies an address other than the address for which the cookie was assigned.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-720">DSA-720</ref><ref source="Security Focus" url="http://www.securityfocus.org/bid/13474">SmartList ListManager Arbitrary List Addition Vulnerability</ref></refs><vuln_soft><prod name="Smartlist" vendor="Smartlist"><vers num="3.15" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0158" published="2005-05-02" seq="2005-0158" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in bidwatcher before 1.3.17 allows remote malicious web servers from eBay, or a spoofed eBay server, to cause a denial of service and possibly execute arbitrary code via certain responses.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-687">DSA-687</ref><ref patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200503-06.xml">GLSA-200503-06</ref></refs><vuln_soft><prod name="bidwatcher" vendor="Bidwatcher"><vers num="1.3.16"/><vers num="1.3.15"/><vers num="1.3.14"/><vers num="1.3.13"/><vers num="1.3.12"/><vers num="1.3.11"/><vers num="1.3.10"/><vers num="1.3.9"/><vers num="1.3.8"/><vers num="1.3.7"/><vers num="1.3.6"/><vers num="1.3.5"/><vers num="1.3.4"/><vers num="1.3.3"/><vers num="1.3.2"/><vers num="1.3.1"/><vers num="1.3.0 beta"/><vers num="1.2.0"/><vers num="1.1.9.2"/><vers num="1.1.9.1"/><vers num="1.1.9"/><vers num="1.1.8"/><vers num="1.1.7"/><vers num="1.1.2"/><vers num="1.0.5"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0159" published="2005-04-27" seq="2005-0159" severity="Medium" type="CVE"><desc><descript source="cve">The tpkg-* scripts in the toolchain-source 3.0.4 package on Debian GNU/Linux 3.0 allow local users to overwrite arbitrary files via a symlink attack on temporary files.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2005/dsa-679">toolchain-source -- insecure temporary files</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/12540">bid 12540</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19317">toolchain-source-symlink(19317)</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14277">14277</ref></refs><vuln_soft><prod name="Debian Linux" vendor="Debian"><vers num="3.0 sparc"/><vers num="3.0 s_390"/><vers num="3.0 ppc"/><vers num="3.0 mipsel"/><vers num="3.0 mips"/><vers num="3.0 m68k"/><vers num="3.0 ia-64"/><vers num="3.0 ia-32"/><vers num="3.0 hppa"/><vers num="3.0 arm"/><vers num="3.0 alpha"/><vers num="3.0"/></prod><prod name="toolchain-source" vendor="Debian"><vers num="3.0.3.3"/><vers num="3.0.3.2"/><vers num="3.0.3.1"/><vers num="3.0.4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0160" published="2005-02-22" seq="2005-0160" severity="Medium" type="CVE"><desc><descript source="cve">Multiple buffer overflows in unace 1.2b allow attackers to execute arbitrary code via (1) 2 overflows in ACE archives, (2) a long command line argument, or (3) certain &quot;Ready for next volume&quot; messages.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-February/031908.html">20050222 unace-1.2b multiple buffer overflows and directory traversal bugs</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/14359">14359</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_16_sr.html">SUSE-SR:2005:016</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/215006">VU#215006</ref><ref source="BID" url="http://www.securityfocus.com/bid/12630">12630</ref></refs><vuln_soft><prod name="unace" vendor="e-merge"><vers num="1.2b"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0161" published="2005-02-22" seq="2005-0161" severity="Low" type="CVE"><desc><descript source="cve">Multiple directory traversal vulnerabilities in unace 1.2b allow attackers to overwrite arbitrary files via an ACE archive containing (1) ../ sequences or (2) absolute pathnames.</descript></desc><loss_types><int/></loss_types><vuln_types><access/><input/></vuln_types><range><local/></range><refs><ref adv="1" source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-February/031908.html">20050222 unace-1.2b multiple buffer overflows and directory traversal bugs</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/14359">14359</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_16_sr.html">SUSE-SR:2005:016</ref><ref source="BID" url="http://www.securityfocus.com/bid/12628">12628</ref></refs><vuln_soft><prod name="unace" vendor="e-merge"><vers num="1.2b"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0162" published="2005-01-26" seq="2005-0162" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in the get_internal_addresses function in the pluto application for Openswan 1.x before 1.0.9, and Openswan 2.x before 2.3.0, when compiled with XAUTH and PAM enabled, allows remote authenticated attackers to execute arbitrary code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=190&amp;type=vulnerabilities">20050126 Openswan XAUTH/PAM Buffer Overflow Vulnerability</ref><ref adv="1" patch="1" source="CONFIRM" url="http://www.openswan.org/support/vuln/IDEF0785/">http://www.openswan.org/support/vuln/IDEF0785/</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19078">openswan-xauth-pam-bo(19078)</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-announce-list/2005-January/msg00103.html">FEDORA-2005-082</ref><ref source="BID" url="http://www.securityfocus.com/bid/12377">12377</ref><ref source="OSVDB" url="http://www.osvdb.org/13195">13195</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013014">1013014</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14038">14038</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14062">14062</ref></refs><vuln_soft><prod name="openswan" vendor="Openswan"><vers num="1.0.9" prev="1"/><vers num="2.3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0173" published="2005-05-02" seq="2005-0173" severity="High" type="CVE"><desc><descript source="cve">squid_ldap_auth in Squid 2.5 and earlier allows remote authenticated users to bypass username-based Access Control Lists (ACLs) via a username with a space at the beginning or end, which is ignored by the LDAP server.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/><input/></vuln_types><range><network/></range><refs><ref patch="1" source="CONFIRM" url="http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE7-ldap_spaces">http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE7-ldap_spaces</ref><ref source="CONFIRM" url="http://www.squid-cache.org/bugs/show_bug.cgi?id=1187">http://www.squid-cache.org/bugs/show_bug.cgi?id=1187</ref><ref patch="1" source="CONFIRM" url="http://www.squid-cache.org/Versions/v2/2.5/bugs/squid-2.5.STABLE7-ldap_spaces.patch">http://www.squid-cache.org/Versions/v2/2.5/bugs/squid-2.5.STABLE7-ldap_spaces.patch</ref><ref patch="1" source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000923">CLA-2005:923</ref><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-667">DSA-667</ref><ref patch="1" source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:034">MDKSA-2005:034</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-060.html">RHSA-2005:060</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-061.html">RHSA-2005:061</ref><ref adv="1" patch="1" source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_06_squid.html">SUSE-SA:2005:006</ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/924198">VU#924198</ref><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110780531820947&amp;w=2">20050207 [USN-77-1] Squid vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/12431">12431</ref><ref source="FEDORA" url="http://fedoranews.org/updates/FEDORA--.shtml">FLSA-2006:152809</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:034">MDKSA-2005:034</ref></refs><vuln_soft><prod name="Squid" vendor="Squid"><vers num="2.5.STABLE6"/><vers num="2.5.STABLE5"/><vers num="2.5.STABLE4"/><vers num="2.5.STABLE3"/><vers num="2.5.STABLE2"/><vers num="2.5.STABLE1"/><vers num="2.4.STABLE7"/><vers num="2.4.STABLE6"/><vers num="2.4.STABLE4"/><vers num="2.4.STABLE3"/><vers num="2.4.STABLE2"/><vers num="2.4.STABLE1"/><vers num="2.3.DEVEL2"/><vers num="2.3.DEVEL3"/><vers num="2.3.STABLE1"/><vers num="2.3.STABLE2"/><vers num="2.3.STABLE3"/><vers num="2.3.STABLE4"/><vers num="2.3.STABLE5"/><vers num="2.2.PRE1"/><vers num="2.2.PRE2"/><vers num="2.2.DEVEL3"/><vers num="2.2.DEVEL4"/><vers num="2.2.STABLE1"/><vers num="2.2.STABLE2"/><vers num="2.2.STABLE3"/><vers num="2.2.STABLE4"/><vers num="2.2.STABLE5"/><vers num="2.1.PRE1"/><vers num="2.1.PRE3"/><vers num="2.1.PRE4"/><vers num="2.1.RELEASE"/><vers num="2.1.PATCH1"/><vers num="2.1.PATCH2"/><vers num="2.0.PRE1"/><vers num="2.0.RELEASE"/><vers num="2.0.PATCH1"/><vers num="2.0.PATCH2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0174" published="2005-02-07" seq="2005-0174" severity="Medium" type="CVE"><desc><descript source="cve">Squid 2.5 up to 2.5.STABLE7 allows remote attackers to poison the cache or conduct certain attacks via headers that do not follow the HTTP specification, including (1) multiple Content-Length headers, (2) carriage return (CR) characters that are not part of a CRLF pair, and (3) header names containing whitespace characters.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="CONFIRM" url="http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE7-header_parsing">http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE7-header_parsing</ref><ref adv="1" source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000931">CLA-2005:931</ref><ref adv="1" patch="1" source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:034">MDKSA-2005:034</ref><ref patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-060.html">RHSA-2005:060</ref><ref patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-061.html">RHSA-2005:061</ref><ref adv="1" source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_06_squid.html">SUSE-SA:2005:006</ref><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110780531820947&amp;w=2">20050207 [USN-77-1] Squid vulnerabilities</ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/768702">VU#768702</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-announce-list/2005-May/msg00025.html">FEDORA-2005-373</ref><ref source="FEDORA" url="http://fedoranews.org/updates/FEDORA--.shtml">FLSA-2006:152809</ref><ref source="BID" url="http://www.securityfocus.com/bid/12412">12412</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:034">MDKSA-2005:034</ref></refs><vuln_soft><prod name="Squid" vendor="Squid"><vers num="2.5.STABLE7"/><vers num="2.5.STABLE6"/><vers num="2.5.STABLE5"/><vers num="2.5.STABLE4"/><vers num="2.5.STABLE3"/><vers num="2.5.STABLE2"/><vers num="2.5.STABLE1"/><vers num="2.5.6"/><vers num="2.5 Stable9"/><vers num="2.5 STABLE4"/><vers num="2.5 STABLE3"/><vers num="2.5 .STABLE6"/><vers num="2.5 .STABLE5"/><vers num="2.5 .STABLE4"/><vers num="2.5 .STABLE3"/><vers num="2.5 .STABLE1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0175" published="2005-02-07" seq="2005-0175" severity="Medium" type="CVE"><desc><descript source="cve">Squid 2.5 up to 2.5.STABLE7 allows remote attackers to poison the cache via an HTTP response splitting attack.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="CONFIRM" url="http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE7-response_splitting">http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE7-response_splitting</ref><ref adv="1" patch="1" source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000931">CLA-2005:931</ref><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-667">DSA-667</ref><ref adv="1" patch="1" source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:034">MDKSA-2005:034</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-060.html">RHSA-2005:060</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-061.html">RHSA-2005:061</ref><ref adv="1" patch="1" source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_06_squid.html">SUSE-SA:2005:006</ref><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110780531820947&amp;w=2">20050207 [USN-77-1] Squid vulnerabilities</ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/625878">VU#625878</ref><ref adv="1" source="CONFIRM" url="http://www.squid-cache.org/Advisories/SQUID-2005_5.txt">http://www.squid-cache.org/Advisories/SQUID-2005_5.txt</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-announce-list/2005-May/msg00025.html">FEDORA-2005-373</ref><ref source="FEDORA" url="http://fedoranews.org/updates/FEDORA--.shtml">FLSA-2006:152809</ref><ref source="BID" url="http://www.securityfocus.com/bid/12433">12433</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:034">MDKSA-2005:034</ref></refs><vuln_soft><prod name="Squid" vendor="Squid"><vers num="2.5.STABLE7"/><vers num="2.5.STABLE6"/><vers num="2.5.STABLE5"/><vers num="2.5.STABLE4"/><vers num="2.5.STABLE3"/><vers num="2.5.STABLE2"/><vers num="2.5.STABLE1"/><vers num="2.5.6"/><vers num="2.5 Stable9"/><vers num="2.5 STABLE4"/><vers num="2.5 STABLE3"/><vers num="2.5 .STABLE6"/><vers num="2.5 .STABLE5"/><vers num="2.5 .STABLE4"/><vers num="2.5 .STABLE3"/><vers num="2.5 .STABLE1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0176" published="2005-02-15" seq="2005-0176" severity="Medium" type="CVE"><desc><descript source="cve">The shmctl function in Linux 2.6.9 and earlier allows local users to unlock the memory of other processes, which could cause sensitive memory to be swapped to disk, which could allow it to be read by other users once it has been released.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=110846102231365&amp;w=2">20050215 [USN-82-1] Linux kernel vulnerabilities</ref><ref adv="1" source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/index.php?id=a&amp;anuncio=000930">CLA-2005:930</ref><ref adv="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-092.html">RHSA-2005:092</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1225.html">OVAL1225</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-472.html">RHSA-2005:472</ref><ref source="BID" url="http://www.securityfocus.com/bid/12598">12598</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1225">oval:org.mitre.oval:def:1225</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20060402-01-U">
20060402-01-U</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19607">
19607</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.6.9"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2008-06-24" name="CVE-2005-0177" published="2005-03-07" seq="2005-0177" severity="High" type="CVE"><desc><descript source="cve">nls_ascii.c in Linux before 2.6.8.1 uses an incorrect table size, which allows attackers to cause a denial of service (kernel crash) via a buffer overflow.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CONFIRM" url="http://linux.bkbits.net:8080/linux-2.6/cset@41e2bfbeOiXFga62XrBhzm7Kv9QDmQ">http://linux.bkbits.net:8080/linux-2.6/cset@41e2bfbeOiXFga62XrBhzm7Kv9QDmQ</ref><ref adv="1" patch="1" source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/index.php?id=a&amp;anuncio=000930">CLA-2005:930</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-092.html">RHSA-2005:092</ref><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=110846102231365&amp;w=2">20050215 [USN-82-1] Linux kernel vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/12598">12598</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.6.8.1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.2" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="10.0" CVSS_score="6.2" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-05-16" name="CVE-2005-0178" published="2005-03-07" seq="2005-0178" severity="Medium" type="CVE"><desc><descript source="cve">Race condition in the setsid function in Linux before 2.6.8.1 allows local users to cause a denial of service (crash) and possibly access portions of kernel memory, related to TTY changes, locking, and semaphores.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><race/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CONFIRM" url="http://linux.bkbits.net:8080/linux-2.6/cset@41ddda70CWJb5nNL71T4MOlG2sMG8A">http://linux.bkbits.net:8080/linux-2.6/cset@41ddda70CWJb5nNL71T4MOlG2sMG8A</ref><ref adv="1" source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/index.php?id=a&amp;anuncio=000930">CLA-2005:930</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-092.html">RHSA-2005:092</ref><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=110846102231365&amp;w=2">20050215 [USN-82-1] Linux kernel vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/12598">12598</ref></refs><vuln_soft><prod name="Linux-VServer" vendor="VServer"><vers num="1.24"/><vers num="1.23"/><vers num="1.22"/><vers num="1.21"/><vers num="1.20"/></prod><prod name="Linux Netkit" vendor="Netkit"><vers num="0.17.17"/><vers num="0.17"/></prod><prod name="Kernel" vendor="Linux"><vers num="2.6.8 rc3"/><vers num="2.6.8 rc2"/><vers num="2.6.8 rc1"/><vers num="2.6.8"/><vers num="2.6.7 rc1"/><vers num="2.6.7"/><vers num="2.6.6 rc1"/><vers num="2.6.6"/><vers num="2.6.5"/><vers num="2.6.4"/><vers num="2.6.3"/><vers num="2.6.2"/><vers num="2.6.1 rc2"/><vers num="2.6.1 rc1"/><vers num="2.6.12 rc4"/><vers num="2.6.12 rc1"/><vers num="2.6.11.7"/><vers num="2.6.11.6"/><vers num="2.6.11.5"/><vers num="2.6.11.4"/><vers num="2.6.11.3"/><vers num="2.6.11.2"/><vers num="2.6.11.1"/><vers num="2.6.11 rc4"/><vers num="2.6.11 rc3"/><vers num="2.6.11 rc2"/><vers num="2.6.11.8"/><vers num="2.6.11"/><vers num="2.6.10 rc2"/><vers num="2.6.10"/><vers num="2.6.1"/><vers num="2.6.0"/><vers num="2.6 test9 CVS"/><vers num="2.6 test9"/><vers num="2.6 test8"/><vers num="2.6 test7"/><vers num="2.6 test6"/><vers num="2.6 test5"/><vers num="2.6 test4"/><vers num="2.6 test3"/><vers num="2.6 test2"/><vers num="2.6 test11"/><vers num="2.6 test10"/><vers num="2.6 test1"/><vers num="2.6"/><vers num="2.5.9"/><vers num="2.5.8"/><vers num="2.5.7"/><vers num="2.5.69"/><vers num="2.5.68"/><vers num="2.5.67"/><vers num="2.5.66"/><vers num="2.5.65"/><vers num="2.5.64"/><vers num="2.5.63"/><vers num="2.5.62"/><vers num="2.5.61"/><vers num="2.5.60"/><vers num="2.5.6"/><vers num="2.5.59"/><vers num="2.5.58"/><vers num="2.5.57"/><vers num="2.5.56"/><vers num="2.5.55"/><vers num="2.5.54"/><vers num="2.5.53"/><vers num="2.5.52"/><vers num="2.5.51"/><vers num="2.5.50"/><vers num="2.5.5"/><vers num="2.5.49"/><vers num="2.5.48"/><vers num="2.5.47"/><vers num="2.5.46"/><vers num="2.5.45"/><vers num="2.5.44"/><vers num="2.5.43"/><vers num="2.5.42"/><vers num="2.5.41"/><vers num="2.5.40"/><vers num="2.5.4"/><vers num="2.5.39"/><vers num="2.5.38"/><vers num="2.5.37"/><vers num="2.5.36"/><vers num="2.5.35"/><vers num="2.5.34"/><vers num="2.5.33"/><vers num="2.5.32"/><vers num="2.5.31"/><vers num="2.5.30"/><vers num="2.5.3"/><vers num="2.5.29"/><vers num="2.5.28"/><vers num="2.5.27"/><vers num="2.5.26"/><vers num="2.5.25"/><vers num="2.5.24"/><vers num="2.5.23"/><vers num="2.5.22"/><vers num="2.5.21"/><vers num="2.5.20"/><vers num="2.5.2"/><vers num="2.5.19"/><vers num="2.5.18"/><vers num="2.5.17"/><vers num="2.5.16"/><vers num="2.5.15"/><vers num="2.5.14"/><vers num="2.5.13"/><vers num="2.5.12"/><vers num="2.5.11"/><vers num="2.5.10"/><vers num="2.5.1"/><vers num="2.5.0"/><vers num="2.4.9"/><vers num="2.4.8"/><vers num="2.4.7"/><vers num="2.4.6"/><vers num="2.4.5"/><vers num="2.4.4"/><vers num="2.4.3 pre3"/><vers num="2.4.31 pre1"/><vers num="2.4.30 rc3"/><vers num="2.4.30 rc2"/><vers num="2.4.30"/><vers num="2.4.3"/><vers num="2.4.29 rc2"/><vers num="2.4.29 rc1"/><vers num="2.4.29"/><vers num="2.4.28"/><vers num="2.4.27 pre5"/><vers num="2.4.27 pre4"/><vers num="2.4.27 pre3"/><vers num="2.4.27 pre2"/><vers num="2.4.27 pre1"/><vers num="2.4.27"/><vers num="2.4.26"/><vers num="2.4.25"/><vers num="2.4.24 ow1"/><vers num="2.4.24"/><vers num="2.4.23 pre9"/><vers num="2.4.23 ow2"/><vers num="2.4.23"/><vers num="2.4.22 pre10"/><vers num="2.4.22"/><vers num="2.4.21 pre7"/><vers num="2.4.21 pre4"/><vers num="2.4.21 pre1"/><vers num="2.4.21"/><vers num="2.4.20"/><vers num="2.4.2"/><vers num="2.4.19 pre6"/><vers num="2.4.19 pre5"/><vers num="2.4.19 pre4"/><vers num="2.4.19 pre3"/><vers num="2.4.19 pre2"/><vers num="2.4.19 pre1"/><vers num="2.4.19"/><vers edition="x86" num="2.4.18"/><vers num="2.4.18 pre8"/><vers num="2.4.18 pre7"/><vers num="2.4.18 pre6"/><vers num="2.4.18 pre5"/><vers num="2.4.18 pre4"/><vers num="2.4.18 pre3"/><vers num="2.4.18 pre2"/><vers num="2.4.18 pre1"/><vers num="2.4.18"/><vers num="2.4.17"/><vers num="2.4.16"/><vers num="2.4.15"/><vers num="2.4.14"/><vers num="2.4.13"/><vers num="2.4.12"/><vers num="2.4.11"/><vers num="2.4.10"/><vers num="2.4.1"/><vers num="2.4.0 test9"/><vers num="2.4.0 test8"/><vers num="2.4.0 test7"/><vers num="2.4.0 test6"/><vers num="2.4.0 test5"/><vers num="2.4.0 test4"/><vers num="2.4.0 test3"/><vers num="2.4.0 test2"/><vers num="2.4.0 test12"/><vers num="2.4.0 test11"/><vers num="2.4.0 test10"/><vers num="2.4.0 test1"/><vers num="2.4.0"/><vers num="2.3.99 pre7"/><vers num="2.3.99 pre6"/><vers num="2.3.99 pre5"/><vers num="2.3.99 pre4"/><vers num="2.3.99 pre3"/><vers num="2.3.99 pre2"/><vers num="2.3.99 pre1"/><vers num="2.3.99"/><vers num="2.3"/><vers num="2.2.9"/><vers num="2.2.8"/><vers num="2.2.7"/><vers num="2.2.6"/><vers num="2.2.5"/><vers num="2.2.4"/><vers num="2.2.3"/><vers num="2.2.27 rc2"/><vers num="2.2.25"/><vers num="2.2.24"/><vers num="2.2.23"/><vers num="2.2.22"/><vers num="2.2.21"/><vers num="2.2.20"/><vers num="2.2.2"/><vers num="2.2.19"/><vers num="2.2.18"/><vers num="2.2.17"/><vers num="2.2.16 pre6"/><vers num="2.2.16"/><vers num="2.2.15 pre20"/><vers num="2.2.15 pre16"/><vers num="2.2.15"/><vers num="2.2.14"/><vers num="2.2.13"/><vers num="2.2.12"/><vers num="2.2.11"/><vers num="2.2.10"/><vers num="2.2.1"/><vers num="2.2"/><vers num="2.1.89"/><vers num="2.1"/><vers num="2.0.9.9"/><vers num="2.0.9"/><vers num="2.0.8"/><vers num="2.0.7"/><vers num="2.0.6"/><vers num="2.0.5"/><vers num="2.0.4"/><vers num="2.0.39"/><vers num="2.0.38"/><vers num="2.0.37"/><vers num="2.0.36"/><vers num="2.0.35"/><vers num="2.0.34"/><vers num="2.0.33"/><vers num="2.0.32"/><vers num="2.0.31"/><vers num="2.0.30"/><vers num="2.0.3"/><vers num="2.0.29"/><vers num="2.0.28"/><vers num="2.0.27"/><vers num="2.0.26"/><vers num="2.0.25"/><vers num="2.0.24"/><vers num="2.0.23"/><vers num="2.0.22"/><vers num="2.0.21"/><vers num="2.0.20"/><vers num="2.0.2"/><vers num="2.0.19"/><vers num="2.0.18"/><vers num="2.0.17"/><vers num="2.0.16"/><vers num="2.0.15"/><vers num="2.0.14"/><vers num="2.0.13"/><vers num="2.0.12"/><vers num="2.0.11"/><vers num="2.0.10"/><vers num="2.0.1"/><vers num="2.0"/><vers num="2.6.20.1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0179" published="2005-03-07" seq="2005-0179" severity="Low" type="CVE"><desc><descript source="cve">Linux kernel 2.4.x and 2.6.x allows local users to cause a denial of service (CPU and memory consumption) and bypass RLIM_MEMLOCK limits via the mlockall call.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><local/></range><refs><ref adv="1" source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-January/030660.html">20050107 grsecurity 2.1.0 release / 5 Linux kernel advisories</ref><ref adv="1" source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/index.php?id=a&amp;anuncio=000930">CLA-2005:930</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-092.html">RHSA-2005:092</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-663.html">RHSA-2005:663</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17002">17002</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/1878">ADV-2005-1878</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers edition="2.6.20" num="2.6.9"/><vers num="2.6.8.1"/><vers num="2.6.8-rc3"/><vers num="2.6.8-rc2"/><vers num="2.6.8-rc1"/><vers num="2.6.8"/><vers num="2.6.7 rc1"/><vers num="2.6.7"/><vers num="2.6.6-rc1"/><vers num="2.6.6"/><vers num="2.6.5"/><vers num="2.6.4"/><vers num="2.6.3"/><vers num="2.6.2"/><vers num="2.6.12-rc4"/><vers num="2.6.12-rc1"/><vers num="2.6.12 -rc4"/><vers num="2.6.11.4"/><vers num="2.6.11.3"/><vers num="2.6.11.2"/><vers num="2.6.11.1"/><vers num="2.6.11-rc4"/><vers num="2.6.11-rc3"/><vers num="2.6.11-rc2"/><vers num="2.6.11.8"/><vers num="2.6.11.7"/><vers num="2.6.11.6"/><vers num="2.6.11.5"/><vers num="2.6.11"/><vers num="2.6.10-rc2"/><vers num="2.6.1-rc2"/><vers num="2.6.1-rc1"/><vers num="2.6.1"/><vers num="2.6.0"/><vers num="2.6 test 9 CVS"/><vers num="2.6-test9"/><vers num="2.6-test8"/><vers num="2.6-test7"/><vers num="2.6-test6"/><vers num="2.6-test5"/><vers num="2.6-test4"/><vers num="2.6-test3"/><vers num="2.6-test2"/><vers num="2.6-test11"/><vers num="2.6-test10"/><vers num="2.6-test1"/><vers num="2.6.10"/><vers num="2.6"/><vers num="2.4.9"/><vers num="2.4.8"/><vers num="2.4.7"/><vers num="2.4.6"/><vers num="2.4.5"/><vers num="2.4.4"/><vers num="2.4.3-pre3"/><vers num="2.4.31-pre1"/><vers num="2.4.30-rc3"/><vers num="2.4.30-rc2"/><vers num="2.4.30"/><vers num="2.4.3"/><vers num="2.4.29-rc2"/><vers num="2.4.29-rc1"/><vers num="2.4.29"/><vers num="2.4.28"/><vers num="2.4.27-pre5"/><vers num="2.4.27-pre4"/><vers num="2.4.27-pre3"/><vers num="2.4.27-pre2"/><vers num="2.4.27-pre1"/><vers num="2.4.27"/><vers num="2.4.26"/><vers num="2.4.25"/><vers num="2.4.24-ow1"/><vers num="2.4.24"/><vers num="2.4.23-pre9"/><vers num="2.4.23-ow2"/><vers num="2.4.23"/><vers num="2.4.22-pre10"/><vers num="2.4.22"/><vers num="2.4.21-pre7"/><vers num="2.4.21-pre4"/><vers num="2.4.21-pre1"/><vers num="2.4.21"/><vers num="2.4.20"/><vers num="2.4.2"/><vers num="2.4.19-pre6"/><vers num="2.4.19-pre5"/><vers num="2.4.19-pre4"/><vers num="2.4.19-pre3"/><vers num="2.4.19-pre2"/><vers num="2.4.19-pre1"/><vers num="2.4.19"/><vers num="2.4.18-x86"/><vers num="2.4.18-pre-8"/><vers num="2.4.18-pre-7"/><vers num="2.4.18-pre-6"/><vers num="2.4.18-pre-5"/><vers num="2.4.18-pre-4"/><vers num="2.4.18-pre-3"/><vers num="2.4.18-pre-2"/><vers num="2.4.18-pre-1"/><vers num="2.4.18"/><vers num="2.4.17"/><vers num="2.4.16"/><vers num="2.4.15"/><vers num="2.4.14"/><vers num="2.4.13"/><vers num="2.4.12"/><vers num="2.4.11"/><vers num="2.4.10"/><vers num="2.4.1"/><vers num="2.4.0-test9"/><vers num="2.4.0-test8"/><vers num="2.4.0-test7"/><vers num="2.4.0-test6"/><vers num="2.4.0-test5"/><vers num="2.4.0-test4"/><vers num="2.4.0-test3"/><vers num="2.4.0-test2"/><vers num="2.4.0-test12"/><vers num="2.4.0-test11"/><vers num="2.4.0-test10"/><vers num="2.4.0 test1"/><vers num="2.4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="3.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="4.9" CVSS_score="3.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0180" published="2005-03-07" seq="2005-0180" severity="Low" type="CVE"><desc><descript source="cve">Multiple integer signedness errors in the sg_scsi_ioctl function in scsi_ioctl.c for Linux 2.6.x allow local users to read or modify kernel memory via negative integers in arguments to the scsi ioctl, which bypass a maximum length check before calling the copy_from_user and copy_to_user functions.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-January/030660.html">20050107 grsecurity 2.1.0 release / 5 Linux kernel advisories</ref><ref adv="1" source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/index.php?id=a&amp;anuncio=000930">CLA-2005:930</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-092.html">RHSA-2005:092</ref><ref source="MANDRAKE" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2005:218">MDKSA-2005:218</ref><ref source="MANDRAKE" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2005:219">MDKSA-2005:219</ref><ref source="BID" url="http://www.securityfocus.com/bid/12198">12198</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17826">17826</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/386374">20050107 grsecurity 2.1.0 release / 5 Linux kernel advisories</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:218">MDKSA-2005:218</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:219">MDKSA-2005:219</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.6 test 9 CVS"/><vers edition="2.6.20" num="2.6.9"/><vers num="2.6.8.1"/><vers num="2.6.8-rc3"/><vers num="2.6.8-rc2"/><vers num="2.6.8-rc1"/><vers num="2.6.8"/><vers num="2.6.7 rc1"/><vers num="2.6.7"/><vers num="2.6.6-rc1"/><vers num="2.6.6"/><vers num="2.6.5"/><vers num="2.6.4"/><vers num="2.6.3"/><vers num="2.6.2"/><vers num="2.6.1-rc2"/><vers num="2.6.1-rc1"/><vers num="2.6.12-rc4"/><vers num="2.6.12-rc1"/><vers num="2.6.12 -rc4"/><vers num="2.6.11.7"/><vers num="2.6.11.6"/><vers num="2.6.11.5"/><vers num="2.6.11.4"/><vers num="2.6.11.3"/><vers num="2.6.11.2"/><vers num="2.6.11.1"/><vers num="2.6.11 -rc4"/><vers num="2.6.11 -rc3"/><vers num="2.6.11 -rc2"/><vers num="2.6.11 .8"/><vers num="2.6.11 .7"/><vers num="2.6.11 .6"/><vers num="2.6.11 .5"/><vers num="2.6.11"/><vers num="2.6.10-rc2"/><vers num="2.6.10 rc2"/><vers num="2.6.10"/><vers num="2.6.1 -rc2"/><vers num="2.6.1 -rc1"/><vers num="2.6.1"/><vers num="2.6.0"/><vers num="2.6 -test9-CVS"/><vers num="2.6 -test9"/><vers num="2.6 -test8"/><vers num="2.6 -test7"/><vers num="2.6 -test6"/><vers num="2.6 -test5"/><vers num="2.6 -test4"/><vers num="2.6 -test3"/><vers num="2.6 -test2"/><vers num="2.6 -test11"/><vers num="2.6 -test10"/><vers num="2.6 -test1"/><vers num="2.6 .10"/><vers num="2.6"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0182" published="2005-01-06" seq="2005-0182" severity="Medium" type="CVE"><desc><descript source="cve">The mod_dosevasive module 1.9 and earlier for Apache creates temporary files with predictable filenames, which could allow remote attackers to overwrite arbitrary files via a symlink attack.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110547469530582&amp;w=2">20050111 Mod_dosevasive symlink and race vulnerability</ref><ref adv="1" source="MISC" url="http://security.lss.hr/index.php?page=details&amp;ID=LSS-2005-01-01">http://security.lss.hr/index.php?page=details&amp;ID=LSS-2005-01-01</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/12181">12181</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18765">moddosevasive-symlink(18765)</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13725">13725</ref></refs><vuln_soft><prod name="mod_dosevasive" vendor="mod_dosevasive"><vers num="1.9"/><vers num="1.8"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0183" published="2005-05-02" seq="2005-0183" severity="High" type="CVE"><desc><descript source="cve">ftpfile in the Vacation plugin 0.15 and earlier for Squirrelmail allows local users to execute arbitrary commands via shell metacharacters in a command line argument.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110549426300953&amp;w=2">20050111 Squirrelmail vacation v0.15 local root exploit</ref><ref source="MISC" url="http://security.lss.hr/en/index.php?page=details&amp;ID=LSS-2005-01-03">http://security.lss.hr/en/index.php?page=details&amp;ID=LSS-2005-01-03</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18855">vacation-ftpfile-command-execution(18855)</ref><ref source="" url="http://www.squirrelmail.org/plugin_view.php?id=51"></ref><ref source="BID" url="http://www.securityfocus.com/bid/12222">12222</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1012866">1012866</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13791">13791</ref></refs><vuln_soft><prod name="Vacation Plugin" vendor="SquirrelMail"><vers num="0.15" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0184" published="2005-05-02" seq="2005-0184" severity="Low" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in ftpfile in the Vacation plugin 0.15 and earlier for Squirrelmail allows local users to read arbitrary files via a .. (dot dot) in a get request.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110549426300953&amp;w=2">20050111 Squirrelmail vacation v0.15 local root exploit</ref><ref adv="1" source="MISC" url="http://security.lss.hr/en/index.php?page=details&amp;ID=LSS-2005-01-03">http://security.lss.hr/en/index.php?page=details&amp;ID=LSS-2005-01-03</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18856">vacation-ftpfile-directory-traversal(18856)</ref><ref source="" url="http://www.squirrelmail.org/plugin_view.php?id=51"></ref><ref source="BID" url="http://www.securityfocus.com/bid/12222">12222</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1012866">1012866</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13791">13791</ref></refs><vuln_soft><prod name="Vacation Plugin" vendor="SquirrelMail"><vers num="0.15" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0185" published="2005-05-02" seq="2005-0185" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in NodeManager Professional 2.00 allows remote attackers to execute arbitrary commands via a LinkDown-Trap packet that contains a long OCTET-STRING in the Trap variable-bindings field.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110599796118583&amp;w=2">20050117 [SIG^2 G-TEC] NodeManager Professional V2.00 Buffer Overflow Vulnerability</ref><ref adv="1" source="MISC" url="http://www.security.org.sg/vuln/nodemanager200.html">http://www.security.org.sg/vuln/nodemanager200.html</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/13881/">13881</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18937">nodemanager-linkdown-bo(18937)</ref><ref source="BID" url="http://www.securityfocus.com/bid/12283">12283</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1012915">1012915</ref></refs><vuln_soft><prod name="NodeManager Professional" vendor="Mnet Soft Factory"><vers num="2.00"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0186" published="2005-01-19" seq="2005-0186" severity="Medium" type="CVE"><desc><descript source="cve">Cisco IOS 12.1YD, 12.2T, 12.3 and 12.3T, when configured for the IOS Telephony Service (ITS), CallManager Express (CME) or Survivable Remote Site Telephony (SRST), allows remote attackers to cause a denial of service (device reboot) via a malformed packet to the SCCP port.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-sa-20050119-itscme.shtml">20050119 Vulnerability in Cisco IOS Embedded Call Processing Solutions</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18956">cisco-ios-sccp-dos(18956)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1012945">1012945</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13913">13913</ref></refs><vuln_soft><prod name="IOS" vendor="Cisco"><vers num="12.1YD"/><vers num="12.2T"/><vers num="12.3"/><vers num="12.3T"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0187" published="2005-05-02" seq="2005-0187" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in the SetSkin function in AtHoc toolbar allows remote attackers to execute arbitrary code via a long skin name.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109710974324742&amp;w=2">20041006 Patch available for high risk flaws in the AtHoc Toolbar</ref><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110616363415176&amp;w=2">20050119 Multiple vulnerabilities in the AtHoc Toolbar (#NISR19012005c)</ref><ref adv="1" source="MISC" url="http://www.ngssoftware.com/advisories/athoc-01full.txt">http://www.ngssoftware.com/advisories/athoc-01full.txt</ref><ref source="BID" url="http://www.securityfocus.com/bid/11341">11341</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17627">athoc-toolbar-bo(17627)</ref></refs><vuln_soft><prod name="AtHoc Toolbar" vendor="AtHoc"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0188" published="2004-10-06" seq="2005-0188" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in the SetBaseURL function in AtHoc toolbar allows remote attackers to execute arbitrary code via format string specifiers in an invalid URL that is recorded in the debug log.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109710974324742&amp;w=2">20041006 Patch available for high risk flaws in the AtHoc Toolbar</ref><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110616363415176&amp;w=2">20050119 Multiple vulnerabilities in the AtHoc Toolbar (#NISR19012005c)</ref><ref source="MISC" url="http://www.ngssoftware.com/advisories/athoc-01full.txt">http://www.ngssoftware.com/advisories/athoc-01full.txt</ref><ref source="BID" url="http://www.securityfocus.com/bid/11341">11341</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17628">athoc-toolbar-format-string(17628)</ref></refs><vuln_soft><prod name="AtHoc Toolbar" vendor="AtHoc"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-01-05" name="CVE-2005-0189" published="2004-10-06" seq="2005-0189" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in the HandleAction function in RealPlayer 10.5 (6.0.12.1040) and earlier allows remote attackers to execute arbitrary code via a long ShowPreferences argument.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109707741022291&amp;w=2">20041006 Patch available for multiple high risk vulnerabilities in RealPlayer</ref><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110616636318261&amp;w=2">20050119 RealPlayer &apos;ShowPreferences&apos; Buffer Overflow Vulnerability (#NISR19012005e)</ref><ref adv="1" patch="1" source="NTBUGTRAQ" url="http://archives.neohapsis.com/archives/ntbugtraq/2005-q1/0046.html">20050119 RealPlayer &apos;ShowPreferences&apos; Buffer Overflow Vulnerability (#NISR19012005e)</ref><ref adv="1" patch="1" source="MISC" url="http://service.real.com/help/faq/security/040928_player/EN/">http://service.real.com/help/faq/security/040928_player/EN/</ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/698390">VU#698390</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/12311">12311</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109707741022291&amp;w=2">20041006 Patch available for multiple high risk vulnerabilities in RealPlayer</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110616636318261&amp;w=2">20050119 RealPlayer &apos;ShowPreferences&apos; Buffer Overflow Vulnerability (#NISR19012005e)</ref></refs><vuln_soft><prod name="RealPlayer" vendor="RealNetworks"><vers edition="Japanese" num="10.0"/><vers edition="German" num="10.0"/><vers edition="English" num="10.0"/><vers num="10.5_6.0.12.1040"/><vers num="10.5_6.0.12.1016 Beta"/><vers num="10.5"/><vers num="10.0 beta"/><vers num="10.0_6.0.12.690"/></prod><prod name="RealOne Player" vendor="RealNetworks"><vers num="2.0"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-01-05" name="CVE-2005-0190" published="2004-09-29" seq="2005-0190" severity="Low" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in RealPlayer 10.5 (6.0.12.1040) and earlier allows remote attackers to delete arbitrary files via a Real Metadata Packages (RMP) file with a FILENAME tag containing .. (dot dot) sequences in a filename that ends with a ? (question mark) and an allowed file extension (e.g. .mp3), which bypasses the check for the file extension.</descript></desc><loss_types><int/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109707741022291&amp;w=2">20041006 Patch available for multiple high risk vulnerabilities in RealPlayer</ref><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110616160228843&amp;w=2">20050119 RealPlayer Arbitrary File Deletion Vulnerability (#NISR19012005f)</ref><ref adv="1" patch="1" source="MISC" url="http://www.ngssoftware.com/advisories/real-02full.txt">http://www.ngssoftware.com/advisories/real-02full.txt</ref><ref adv="1" patch="1" source="CONFIRM" url="http://service.real.com/help/faq/security/040928_player/EN/">http://service.real.com/help/faq/security/040928_player/EN/</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/11308">11308</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/12672/">12672</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/17551">realplayer-media-file-deletion(17551)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109707741022291&amp;w=2">20041006 Patch available for multiple high risk vulnerabilities in RealPlayer</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110616160228843&amp;w=2">20050119 RealPlayer Arbitrary File Deletion Vulnerability (#NISR19012005f)</ref></refs><vuln_soft><prod name="RealPlayer" vendor="RealNetworks"><vers edition="Japanese" num="10.0"/><vers edition="German" num="10.0"/><vers edition="English" num="10.0"/><vers num="10.5_6.0.12.1040"/><vers num="10.5_6.0.12.1016 Beta"/><vers num="10.5"/><vers num="10.0 beta"/><vers num="10.0_6.0.12.690"/></prod><prod name="RealOne Player" vendor="RealNetworks"><vers num="2.0"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-01-05" name="CVE-2005-0191" published="2005-01-19" seq="2005-0191" severity="Medium" type="CVE"><desc><descript source="cve">Off-by-one buffer overflow in the processing of tags in Real Metadata Package (RMP) files in RealPlayer 10.5 (6.0.12.1040) and earlier could allow remote attackers to execute arbitrary code via a long tag.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109707741022291&amp;w=2">20041006 Patch available for multiple high risk vulnerabilities in RealPlayer</ref><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110616302008401&amp;w=2">20050119 RealPlayer Miscellaneous Vulnerabilities (#NISR19012005g)</ref><ref adv="1" patch="1" source="MISC" url="http://www.ngssoftware.com/advisories/real-03full.txt">http://www.ngssoftware.com/advisories/real-03full.txt</ref><ref adv="1" patch="1" source="CONFIRM" url="http://service.real.com/help/faq/security/040928_player/EN/">http://service.real.com/help/faq/security/040928_player/EN/</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18982">realplayer-long-filename-offbyone-bo(18982)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109707741022291&amp;w=2">20041006 Patch available for multiple high risk vulnerabilities in RealPlayer</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110616302008401&amp;w=2">20050119 RealPlayer Miscellaneous Vulnerabilities (#NISR19012005g)</ref></refs><vuln_soft><prod name="RealPlayer" vendor="RealNetworks"><vers edition="Japanese" num="10.0"/><vers edition="German" num="10.0"/><vers edition="English" num="10.0"/><vers num="10.5_6.0.12.1040"/><vers num="10.5_6.0.12.1016 Beta"/><vers num="10.5"/><vers num="10.0 beta"/><vers num="10.0_6.0.12.690"/></prod><prod name="RealOne Player" vendor="RealNetworks"><vers num="2.0"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-01-05" name="CVE-2005-0192" published="2004-10-06" seq="2005-0192" severity="Low" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in the parsing of Skin file names in RealPlayer 10.5 (6.0.12.1040) and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in an RJS filename.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/><input/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109707741022291&amp;w=2">20041006 Patch available for multiple high risk vulnerabilities in RealPlayer</ref><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110616302008401&amp;w=2">20050119 RealPlayer Miscellaneous Vulnerabilities (#NISR19012005g)</ref><ref adv="1" patch="1" source="MISC" url="http://www.ngssoftware.com/advisories/real-03full.txt">http://www.ngssoftware.com/advisories/real-03full.txt</ref><ref adv="1" patch="1" source="MISC" url="http://service.real.com/help/faq/security/040928_player/EN/">http://service.real.com/help/faq/security/040928_player/EN/</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18984">realplayer-rjs-filenane-directory-traversal(18984)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=109707741022291&amp;w=2">20041006 Patch available for multiple high risk vulnerabilities in RealPlayer</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110616302008401&amp;w=2">20050119 RealPlayer Miscellaneous Vulnerabilities (#NISR19012005g)</ref></refs><vuln_soft><prod name="RealPlayer" vendor="RealNetworks"><vers edition="Japanese" num="10.0"/><vers edition="German" num="10.0"/><vers edition="English" num="10.0"/><vers num="10.5_6.0.12.1040"/><vers num="10.5_6.0.12.1016 Beta"/><vers num="10.5"/><vers num="10.0 beta"/><vers num="10.0_6.0.12.690"/></prod><prod name="RealOne Player" vendor="RealNetworks"><vers num="2.0"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0193" published="2005-01-22" seq="2005-0193" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the (1) -v and (2) -a switches in mRouter in iSync 1.5 in Mac OS X 10.3.7 and earlier allows local users to execute arbitrary code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110642400018425&amp;w=2">20050122 Mac OS X 10.3 iSync Privilege Escalation</ref><ref adv="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/Apr/msg00001.html">APPLE-SA-2005-04-19</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19011">isync-mrouter-bo(19011)</ref><ref source="BID" url="http://www.securityfocus.com/bid/12334">12334</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1012974">1012974</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13965">13965</ref></refs><vuln_soft><prod name="mRouter" vendor="iSync"><vers num="1.5"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0194" published="2005-05-02" seq="2005-0194" severity="High" type="CVE"><desc><descript source="cve">Squid 2.5, when processing the configuration file, parses empty Access Control Lists (ACLs), including proxy_auth ACLs without defined auth schemes, in a way that effectively removes arguments, which could allow remote attackers to bypass intended ACLs if the administrator ignores the parser warnings.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref patch="1" source="CONFIRM" url="http://www.squid-cache.org/Versions/v2/2.5/bugs/squid-2.5.STABLE7-empty_acls.patch">http://www.squid-cache.org/Versions/v2/2.5/bugs/squid-2.5.STABLE7-empty_acls.patch</ref><ref adv="1" source="CONFIRM" url="http://www.squid-cache.org/bugs/show_bug.cgi?id=1166">http://www.squid-cache.org/bugs/show_bug.cgi?id=1166</ref><ref patch="1" source="CONFIRM" url="http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE7-empty_acls">http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE7-empty_acls</ref><ref patch="1" source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000923">CLA-2005:923</ref><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-667">DSA-667</ref><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110901183320453&amp;w=2">20050221 [USN-84-1] Squid vulnerabilities</ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/260421">VU#260421</ref><ref source="FEDORA" url="http://fedoranews.org/updates/FEDORA--.shtml">FLSA-2006:152809</ref></refs><vuln_soft><prod name="Squid" vendor="Squid"><vers num="2.5.STABLE6"/><vers num="2.5.STABLE5"/><vers num="2.5.STABLE4"/><vers num="2.5.STABLE3"/><vers num="2.5.STABLE2"/><vers num="2.5.STABLE1"/><vers num="2.4.STABLE7"/><vers num="2.4.STABLE6"/><vers num="2.4.STABLE4"/><vers num="2.4.STABLE3"/><vers num="2.4.STABLE2"/><vers num="2.4.STABLE1"/><vers num="2.3.DEVEL2"/><vers num="2.3.DEVEL3"/><vers num="2.3.STABLE1"/><vers num="2.3.STABLE2"/><vers num="2.3.STABLE3"/><vers num="2.3.STABLE4"/><vers num="2.3.STABLE5"/><vers num="2.2.PRE1"/><vers num="2.2.PRE2"/><vers num="2.2.DEVEL3"/><vers num="2.2.DEVEL4"/><vers num="2.2.STABLE1"/><vers num="2.2.STABLE2"/><vers num="2.2.STABLE3"/><vers num="2.2.STABLE4"/><vers num="2.2.STABLE5"/><vers num="2.1.PRE1"/><vers num="2.1.PRE3"/><vers num="2.1.PRE4"/><vers num="2.1.RELEASE"/><vers num="2.1.PATCH1"/><vers num="2.1.PATCH2"/><vers num="2.0.PRE1"/><vers num="2.0.RELEASE"/><vers num="2.0.PATCH1"/><vers num="2.0.PATCH2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0195" published="2005-05-02" seq="2005-0195" severity="Medium" type="CVE"><desc><descript source="cve">Cisco IOS 12.0S through 12.3YH allows remote attackers to cause a denial of service (device restart) via a crafted IPv6 packet.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-sa-20050126-ipv6.shtml">20050126 Multiple Crafted IPv6 Packets Cause Reload</ref><ref adv="1" patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA05-026A.html">TA05-026A</ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/472582">VU#472582</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19072">cisco-ios-ipv6-dos(19072)</ref></refs><vuln_soft><prod name="IOS" vendor="Cisco"><vers num="12.0S"/><vers num="12.0SX"/><vers num="12.0SZ"/><vers num="12.2B"/><vers num="12.2BC"/><vers num="12.2BX"/><vers num="12.2BZ"/><vers num="12.2CX"/><vers num="12.2CZ"/><vers num="12.2EW"/><vers num="12.2EWA"/><vers num="12.2JK"/><vers num="12.2MC"/><vers num="12.2S"/><vers num="12.2SE"/><vers num="12.2SU"/><vers num="12.2SV"/><vers num="12.2SW"/><vers num="12.2SX"/><vers num="12.2SXA"/><vers num="12.2SXB"/><vers num="12.2SXD"/><vers num="12.2SY"/><vers num="12.2SZ"/><vers num="12.2T"/><vers num="12.2YT"/><vers num="12.2YU"/><vers num="12.2YV"/><vers num="12.2YZ"/><vers num="12.2ZC"/><vers num="12.2ZD"/><vers num="12.2ZE"/><vers num="12.2ZF"/><vers num="12.2ZG"/><vers num="12.2ZH"/><vers num="12.2ZI"/><vers num="12.2ZJ"/><vers num="12.2ZL"/><vers num="12.2ZN"/><vers num="12.2ZO"/><vers num="12.2ZP"/><vers num="12.3"/><vers num="12.3BC"/><vers num="12.3B"/><vers num="12.3BW"/><vers num="12.3JA"/><vers num="12.3T"/><vers num="12.3XA"/><vers num="12.3XB"/><vers num="12.3XC"/><vers num="12.3XD"/><vers num="12.3XE"/><vers num="12.3XF"/><vers num="12.3XG"/><vers num="12.3XH"/><vers num="12.3XI"/><vers num="12.3J"/><vers num="12.3XK"/><vers num="12.3XL"/><vers num="12.3XM"/><vers num="12.3XN"/><vers num="12.3XQ"/><vers num="12.3XR"/><vers num="12.3XS"/><vers num="12.3XT"/><vers num="12.3XU"/><vers num="12.3XX"/><vers num="12.3XW"/><vers num="12.3XY"/><vers num="12.3XZ"/><vers num="12.3YA"/><vers num="12.3YD"/><vers num="12.3YE"/><vers num="12.3YF"/><vers num="12.3YG"/><vers num="12.3YH"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0196" published="2005-05-02" seq="2005-0196" severity="Medium" type="CVE"><desc><descript source="cve">Cisco IOS 12.0 through 12.3YL, with BGP enabled and running the bgp log-neighbor-changes command, allows remote attackers to cause a denial of service (device reload) via a malformed BGP packet.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-sa-20050126-bgp.shtml">20050126 Cisco IOS Misformed BGP Packet Causes Reload</ref><ref adv="1" patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA05-026A.html">TA05-026A</ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/689326">VU#689326</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19074">cisco-ios-bgp-packetdos(19074)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013013">1013013</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14034">14034</ref></refs><vuln_soft><prod name="IOS" vendor="Cisco"><vers num="12.0"/><vers num="12.0DA"/><vers num="12.0DB"/><vers num="12.0DC"/><vers num="12.0S"/><vers num="12.0SC"/><vers num="12.0SP"/><vers num="12.0ST"/><vers num="12.0SX"/><vers num="12.0SY"/><vers num="12.0SZ"/><vers num="12.0W5"/><vers num="12.0WC"/><vers num="12.0WT"/><vers num="12.0WX"/><vers num="12.0XA"/><vers num="12.0XB"/><vers num="12.0XC"/><vers num="12.0XD"/><vers num="12.0XE"/><vers num="12.0XF"/><vers num="12.0XG"/><vers num="12.0XH"/><vers num="12.0XI"/><vers num="12.0XJ"/><vers num="12.0XK"/><vers num="12.0XL"/><vers num="12.0XM"/><vers num="12.0XN"/><vers num="12.0XP"/><vers num="12.0XQ"/><vers num="12.0XR"/><vers num="12.0XS"/><vers num="12.0XT"/><vers num="12.0XU"/><vers num="12.0XV"/><vers num="12.1"/><vers num="12.1AA"/><vers num="12.1AX"/><vers num="12.1AY"/><vers num="12.1AZ"/><vers num="12.1DA"/><vers num="12.1DB"/><vers num="12.1DC"/><vers num="12.1E"/><vers num="12.1EA"/><vers num="12.1EC"/><vers num="12.1EO"/><vers num="12.1EV"/><vers num="12.1EW"/><vers num="12.1EX"/><vers num="12.1EY"/><vers num="12.1T"/><vers num="12.1XF"/><vers num="12.1XG"/><vers num="12.1XH"/><vers num="12.1XI"/><vers num="12.1XJ"/><vers num="12.1XA"/><vers num="12.1XB"/><vers num="12.1XL"/><vers num="12.1XM"/><vers num="12.1XP"/><vers num="12.1XQ"/><vers num="12.1XR"/><vers num="12.1XT"/><vers num="12.1XU"/><vers num="12.1XV"/><vers num="12.1YA"/><vers num="12.1YB"/><vers num="12.1XC"/><vers num="12.1XD"/><vers num="12.1XE"/><vers num="12.1YF"/><vers num="12.1YH"/><vers num="12.1YI"/><vers num="12.1YJ"/><vers num="12.2"/><vers num="12.2B"/><vers num="12.2BC"/><vers num="12.2BW"/><vers num="12.2BX"/><vers num="12.2BY"/><vers num="12.2BZ"/><vers num="12.2CZ"/><vers num="12.2DA"/><vers num="12.2DD"/><vers num="12.2DX"/><vers num="12.2EW"/><vers num="12.2JK"/><vers num="12.2MB"/><vers num="12.2MC"/><vers num="12.2MX"/><vers num="12.2S"/><vers num="12.2SE"/><vers num="12.2SU"/><vers num="12.2SW"/><vers num="12.2SX"/><vers num="12.2SXA"/><vers num="12.2SXB"/><vers num="12.2SXD"/><vers num="12.2SY"/><vers num="12.2SZ"/><vers num="12.2T"/><vers num="12.2X"/><vers num="12.2XA"/><vers num="12.2XB"/><vers num="12.2XC"/><vers num="12.2XD"/><vers num="12.2XE"/><vers num="12.2XF"/><vers num="12.2XG"/><vers num="12.2XH"/><vers num="12.2XI"/><vers num="12.2XJ"/><vers num="12.2XK"/><vers num="12.2XL"/><vers num="12.2XM"/><vers num="12.2XN"/><vers num="12.2XQ"/><vers num="12.2XS"/><vers num="12.2XT"/><vers num="12.2XU"/><vers num="12.2XW"/><vers num="12.2XZ"/><vers num="12.2YA"/><vers num="12.2YB"/><vers num="12.2YC"/><vers num="12.2YE"/><vers num="12.2YF"/><vers num="12.2YG"/><vers num="12.2YH"/><vers num="12.2YJ"/><vers num="12.2YK"/><vers num="12.2YL"/><vers num="12.2YM"/><vers num="12.2YN"/><vers num="12.2YO"/><vers num="12.2YP"/><vers num="12.2YQ"/><vers num="12.2YR"/><vers num="12.2YS"/><vers num="12.2YT"/><vers num="12.2YU"/><vers num="12.2YV"/><vers num="12.2YW"/><vers num="12.2YX"/><vers num="12.2YY"/><vers num="12.2YZ"/><vers num="12.2ZA"/><vers num="12.2ZB"/><vers num="12.2ZC"/><vers num="12.2ZD"/><vers num="12.2ZE"/><vers num="12.2ZF"/><vers num="12.2ZG"/><vers num="12.2ZH"/><vers num="12.2ZI"/><vers num="12.2ZJ"/><vers num="12.2ZK"/><vers num="12.2ZL"/><vers num="12.2ZM"/><vers num="12.2ZN"/><vers num="12.2ZO"/><vers num="12.2ZP"/><vers num="12.3"/><vers num="12.3B"/><vers num="12.3BW"/><vers num="12.3T"/><vers num="12.3XA"/><vers num="12.3XB"/><vers num="12.3XC"/><vers num="12.3XD"/><vers num="12.3XE"/><vers num="12.3XF"/><vers num="12.3XG"/><vers num="12.3XH"/><vers num="12.3XI"/><vers num="12.3XJ"/><vers num="12.3XK"/><vers num="12.3XL"/><vers num="12.3XN"/><vers num="12.3XQ"/><vers num="12.3XR"/><vers num="12.3XS"/><vers num="12.3XU"/><vers num="12.3XV"/><vers num="12.3XX"/><vers num="12.3YA"/><vers num="12.3YC"/><vers num="12.3YD"/><vers num="12.3YE"/><vers num="12.3YF"/><vers num="12.3YH"/><vers num="12.3YJ"/><vers num="12.3YL"/></prod></vuln_soft></entry><entry CVSS_base_score="6.1" CVSS_exploit_subscore="6.5" CVSS_impact_subscore="6.9" CVSS_score="6.1" CVSS_vector="(AV:A/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2008-07-22" name="CVE-2005-0197" published="2005-05-02" seq="2005-0197" severity="Medium" type="CVE"><desc><descript source="cve">Cisco IOS 12.1T, 12.2, 12.2T, 12.3 and 12.3T, with Multi Protocol Label Switching (MPLS) installed but disabled, allows remote attackers to cause a denial of service (device reload) via a crafted packet sent to the disabled interface.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><local_network/></range><refs><ref adv="1" patch="1" source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-sa-20050126-les.shtml">20050126 Crafted Packet Causes Reload on Cisco Routers</ref><ref adv="1" patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA05-026A.html">TA05-026A</ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/583638">VU#583638</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19071">cisco-ios-mpls-dos(19071)</ref><ref source="BID" url="http://www.securityfocus.com/bid/12369">12369</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013015">1013015</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14031">14031</ref></refs><vuln_soft><prod name="IOS" vendor="Cisco"><vers num="12.1T"/><vers num="12.2"/><vers num="12.2T"/><vers num="12.3"/><vers num="12.3T"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0198" published="2005-05-02" seq="2005-0198" severity="High" type="CVE"><desc><descript source="cve">A logic error in the CRAM-MD5 code for the University of Washington IMAP (UW-IMAP) server, when Challenge-Response Authentication Mechanism with MD5 (CRAM-MD5) is enabled, does not properly enforce all the required conditions for successful authentication, which allows remote attackers to authenticate as arbitrary users.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><access/><design/></vuln_types><range><network/></range><refs><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/702777">VU#702777</ref><ref patch="1" source="CONFIRM" url="http://www.kb.cert.org/vuls/id/CRDY-68QSL5">http://www.kb.cert.org/vuls/id/CRDY-68QSL5</ref><ref patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200502-02.xml">GLSA-200502-02</ref><ref patch="1" source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:026">MDKSA-2005:026</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-128.html">RHSA-2005:128</ref><ref source="BID" url="http://www.securityfocus.com/bid/12391">12391</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013037">1013037</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14057">14057</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14097">14097</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:026">MDKSA-2005:026</ref></refs><vuln_soft><prod name="UW-IMAP" vendor="University of Washington"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0199" published="2005-05-02" seq="2005-0199" severity="High" type="CVE"><desc><descript source="cve">Integer underflow in the Lists_MakeMask() function in lists.c in ngIRCd before 0.8.2 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long MODE line that causes an incorrect length calculation, which leads to a buffer overflow.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref patch="1" source="MLIST" url="http://arthur.ath.cx/pipermail/ngircd-ml/2005-January/000228.html">[ngIRCd-ML] 20050126 ngIRCd 0.8.2</ref><ref adv="1" source="CONFIRM" url="http://bugs.gentoo.org/show_bug.cgi?id=79705">http://bugs.gentoo.org/show_bug.cgi?id=79705</ref><ref patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200501-40.xml">GLSA-200501-40</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/12397">12397</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19143">ngircd-listmakemask-bo(19143)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013047">1013047</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14056">14056</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14059">14059</ref></refs><vuln_soft><prod name="ngIRCd" vendor="ngIRCd"><vers num="0.8.1"/><vers num="0.8"/><vers num="0.7.7"/><vers num="0.7.6"/><vers num="0.7.5"/><vers num="0.7.1"/><vers num="0.7"/><vers num="0.6.1"/><vers num="0.6"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-25" name="CVE-2005-0200" published="2005-05-02" seq="2005-0200" severity="Medium" type="CVE"><desc><descript source="cve">TikiWiki before 1.8.5 does not properly validate files that have been uploaded to the temp directory, which could allow remote attackers to upload and execute arbitrary PHP scripts, a different vulnerability than CVE-2004-1386.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200501-41.xml">GLSA-200501-41</ref><ref patch="1" source="CONFIRM" url="http://tikiwiki.org/art102">http://tikiwiki.org/art102</ref><ref adv="1" source="MISC" url="http://www.lovebug.org/imd_advisory.txt">http://www.lovebug.org/imd_advisory.txt</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13948">13948</ref></refs><vuln_soft><prod name="TikiWiki" vendor="TikiWiki Project"><vers num="1.8.4.1"/><vers num="1.8.4"/><vers num="1.8.3"/><vers num="1.8.2"/><vers num="1.8.1"/><vers num="1.8"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0201" published="2005-06-29" seq="2005-0201" severity="Low" type="CVE"><desc><descript source="cve">D-BUS (dbus) before 0.22 does not properly restrict access to a socket, if the socket address is known, which allows local users to listen or send arbitrary messages on another user&apos;s per-user session bus via that socket.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:105">MDKSA-2005:105</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-102.html">RHSA-2005:102</ref><ref adv="1" source="AUSCERT" url="http://www.auscert.org.au/render.html?it=5156">ESB-2005.0435</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-144-1">USN-144-1</ref><ref source="BID" url="http://www.securityfocus.com/bid/12435">12435</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013075">1013075</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14119">14119</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15638">15638</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15833">15833</ref><ref source="SECUNIA" url="http://secunia.com/advisories/15844">15844</ref></refs><vuln_soft><prod name="D-BUS" vendor="D-BUS"><vers num="0.22" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0202" published="2005-05-02" seq="2005-0202" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in the true_path function in private.py for Mailman 2.1.5 and earlier allows remote attackers to read arbitrary files via &quot;.../....///&quot; sequences, which are not properly cleansed by regular expressions that are intended to remove &quot;../&quot; and &quot;./&quot; sequences.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/><input/></vuln_types><range><network/></range><refs><ref adv="1" source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-February/031562.html">20050209 Administrivia: List Compromised due to Mailman Vulnerability</ref><ref patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/Mar/msg00000.html">APPLE-SA-2005-03-21</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-674">DSA-674</ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200502-11.xml">GLSA-200502-11</ref><ref patch="1" source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:037">MDKSA-2005:037</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-136.html">RHSA-2005:136</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-137.html">RHSA-2005:137</ref><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110805795122386&amp;w=2">20050209 [USN-78-1] Mailman vulnerability</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013145">1013145</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14211">14211</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:037">MDKSA-2005:037</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_07_mailman.html">SUSE-SA:2005:007</ref></refs><vuln_soft><prod name="Mailman" vendor="GNU"><vers num="2.1b1"/><vers num="2.1"/><vers num="2.1.1"/><vers num="2.1.2"/><vers num="2.1.3"/><vers num="2.1.4"/><vers num="2.1.5"/></prod></vuln_soft></entry><entry modified="2005-10-20" name="CVE-2005-0203" published="2005-06-09" reject="1" seq="2005-0203" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: none.  Reason: This candidate has been revoked by its Candidate Numbering Authority (CNA) because it was initially assigned to a problem that was not a security issue.  Notes: none.</descript></desc><refs/></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0204" published="2005-05-02" seq="2005-0204" severity="Medium" type="CVE"><desc><descript source="cve">Linux kernel before 2.6.9, when running on the AMD64 and Intel EM64T architectures, allows local users to write to privileged IO ports via the OUTS instruction.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-092.html">RHSA-2005:092</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-293.html">RHSA-2005:293</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2006/0006">2006-0006</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18784">18784</ref><ref source="BID" url="http://www.securityfocus.com/bid/12598">12598</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.6.8.1"/><vers num="2.6.8"/><vers num="2.6.7"/><vers num="2.6.6"/><vers num="2.6.5"/><vers num="2.6.4"/><vers num="2.6.3"/><vers num="2.6.2"/><vers num="2.6.1"/><vers num="2.6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0205" published="2005-05-02" seq="2005-0205" severity="Medium" type="CVE"><desc><descript source="cve">KPPP 2.1.2 in KDE 3.1.5 and earlier, when setuid root without certain wrappers, does not properly close a privileged file descriptor for a domain socket, which allows local users to read and write to /etc/hosts and /etc/resolv.conf and gain control over DNS name resolution by opening a number of file descriptors before executing kppp.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=208&amp;type=vulnerabilities">20050228 KPPP Privileged File Descriptor Leak Vulnerability</ref><ref adv="1" patch="1" source="CONFIRM" url="http://www.kde.org/info/security/advisory-20050228-1.txt">http://www.kde.org/info/security/advisory-20050228-1.txt</ref><ref patch="1" source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000934">CLA-2005:934</ref><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-692">DSA-692</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-175.html">RHSA-2005:175</ref></refs><vuln_soft><prod name="KDE" vendor="KDE"><vers num="3.1.5"/><vers num="3.1.4"/><vers num="3.1.3"/><vers num="3.1.2"/><vers num="3.1.1"/><vers num="3.1"/></prod><prod name="KPPP" vendor="Bernd Wuebben"><vers num="2.1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-25" name="CVE-2005-0206" published="2005-04-27" seq="2005-0206" severity="High" type="CVE"><desc><descript source="cve">The patch for integer overflow vulnerabilities in Xpdf 2.0 and 3.0 (CVE-2004-0888) is incomplete for 64-bit architectures on certain Linux distributions such as Red Hat, which could leave Xpdf users exposed to the original vulnerabilities.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="RedHat" url="http://www.redhat.com/support/errata/RHSA-2005-213.html">xpdf security update</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/11501">bid 11501</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:041">MDKSA-2005:041</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:042">MDKSA-2005:042</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:043">MDKSA-2005:043</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:044">MDKSA-2005:044</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:052">MDKSA-2005:052</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:056">MDKSA-2005:056</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-034.html">RHSA-2005:034</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-053.html">RHSA-2005:053</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-057.html">RHSA-2005:057</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-132.html">RHSA-2005:132</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/17818">xpdf-pdf-bo(17818)</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:041">MDKSA-2005:041</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:042">MDKSA-2005:042</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:043">MDKSA-2005:043</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:044">MDKSA-2005:044</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:052">MDKSA-2005:052</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:056">MDKSA-2005:056</ref></refs><vuln_soft><prod name="GPdf" vendor="GNOME"><vers num="0.110"/><vers num="0.112"/><vers num="0.131"/></prod><prod name="pTeX" vendor="ASCII"><vers num="3.1.4"/></prod><prod name="Desktop" vendor="Red Hat"><vers num="3.0"/></prod><prod name="CUPS" vendor="Easy Software Products"><vers num="1.0.4_8"/><vers num="1.0.4"/><vers num="1.1.1"/><vers num="1.1.4_5"/><vers num="1.1.4_3"/><vers num="1.1.4_2"/><vers num="1.1.4"/><vers num="1.1.6"/><vers num="1.1.7"/><vers num="1.1.10"/><vers num="1.1.12"/><vers num="1.1.13"/><vers num="1.1.14"/><vers num="1.1.15"/><vers num="1.1.16"/><vers num="1.1.17"/><vers num="1.1.18"/><vers num="1.1.19 rc5"/><vers num="1.1.19"/><vers num="1.1.20"/></prod><prod name="Mandrake Corporate Server" vendor="MandrakeSoft"><vers edition="x86_64" num="3.0"/><vers num="3.0"/></prod><prod name="PDFTOHTML" vendor="PDFTOHTML"><vers num="0.32b"/><vers num="0.32a"/><vers num="0.33a"/><vers num="0.33"/><vers num="0.34"/><vers num="0.35"/><vers num="0.36"/></prod><prod name="Linux" vendor="Gentoo"><vers num=""/></prod><prod name="Xpdf" vendor="Xpdf"><vers num="0.90"/><vers num="0.91"/><vers num="0.92"/><vers num="0.93"/><vers num="1.1"/><vers num="1.0a"/><vers num="1.0"/><vers num="2.3"/><vers num="2.1"/><vers num="2.0"/><vers num="3.0"/></prod><prod name="Ubuntu Linux" vendor="Ubuntu"><vers edition="ppc" num="4.1"/><vers edition="ia64" num="4.1"/><vers edition="ia64" num="4.1"/></prod><prod name="Enterprise Linux AS" vendor="Red Hat"><vers edition="Advanced Servers" num="3.0"/><vers edition="Advanced Server" num="2.1"/><vers edition="Advanced Server" num="2.1"/></prod><prod name="Enterprise Linux ES" vendor="Red Hat"><vers edition="Enterprise Server" num="3.0"/><vers edition="Enterprise Server" num="2.1"/><vers edition="Enterprise Server" num="2.1"/></prod><prod name="ProPack" vendor="SGI"><vers num="3.0"/></prod><prod name="Advanced Workstation Itanium Processor" vendor="Red Hat"><vers edition="IA64" num="2.1"/><vers num="2.1"/></prod><prod name="cstetex" vendor="CSTeX"><vers num="2.0.2"/></prod><prod name="kpdf" vendor="KDE"><vers num="3.2"/></prod><prod name="SuSE Linux" vendor="SuSE"><vers num="1.0"/><vers num="2.0"/><vers num="3.0"/><vers num="4.0"/><vers num="4.2"/><vers num="4.3"/><vers num="4.4"/><vers num="4.4.1"/><vers num="5.0"/><vers num="5.1"/><vers num="5.2"/><vers num="5.3"/><vers num="6.0"/><vers num="6.1 alpha"/><vers num="6.1"/><vers num="6.2"/><vers edition="ppc" num="6.3"/><vers num="6.3 alpha"/><vers num="6.3"/><vers edition="ppc" num="6.4"/><vers edition="i386" num="6.4"/><vers num="6.4 alpha"/><vers num="6.4"/><vers edition="sparc" num="7.0"/><vers edition="ppc" num="7.0"/><vers edition="i386" num="7.0"/><vers num="7.0 alpha"/><vers num="7.0"/><vers edition="x86" num="7.1"/><vers edition="spa" num="7.1"/><vers edition="sparc" num="7.1"/><vers num="7.1 alpha"/><vers num="7.1"/><vers edition="i386" num="7.2"/><vers num="7.2"/><vers edition="sparc" num="7.3"/><vers edition="ppc" num="7.3"/><vers edition="i386" num="7.3"/><vers num="7.3"/><vers edition="i386" num="8.0"/><vers num="8.0"/><vers num="8.1"/><vers num="8.2"/><vers edition="x86_64" num="9.0"/><vers num="9.0"/><vers edition="x86_64" num="9.1"/><vers num="9.1"/><vers edition="x86_64" num="9.2"/><vers num="9.2"/></prod><prod name="Enterprise Linux WS" vendor="Red Hat"><vers edition="Workstation" num="3.0"/><vers edition="Workstation" num="2.1"/><vers edition="Workstation" num="2.1"/></prod><prod name="Debian Linux" vendor="Debian"><vers num="3.0 sparc"/><vers num="3.0 s_390"/><vers num="3.0 ppc"/><vers num="3.0 mipsel"/><vers num="3.0 mips"/><vers num="3.0 m68k"/><vers num="3.0 ia-64"/><vers num="3.0 ia-32"/><vers num="3.0 hppa"/><vers num="3.0 arm"/><vers num="3.0 alpha"/><vers num="3.0"/></prod><prod name="Advanced Linux Environment" vendor="SGI"><vers num="3.0"/></prod><prod name="Koffice" vendor="KDE"><vers num="1.3 Beta3"/><vers num="1.3 Beta2"/><vers num="1.3 Beta1"/><vers num="1.3"/><vers num="1.3.1"/><vers num="1.3.2"/><vers num="1.3.3"/></prod><prod name="KDE" vendor="KDE"><vers num="3.2"/><vers num="3.2.1"/><vers num="3.2.2"/><vers num="3.2.3"/><vers num="3.3"/><vers num="3.3.1"/></prod><prod name="Linux" vendor="Red Hat"><vers edition="i386" num="9.0"/></prod><prod name="teTeX" vendor="teTeX"><vers num="1.0.6"/><vers num="1.0.7"/><vers num="2.0"/><vers num="2.0.1"/><vers num="2.0.2"/></prod><prod name="Fedora" vendor="Red Hat"><vers num="Core 3.0"/><vers num="Core 2.0"/><vers num="Core 1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0207" published="2005-05-02" seq="2005-0207" severity="Low" type="CVE"><desc><descript source="cve">Unknown vulnerability in Linux kernel 2.4.x, 2.5.x, and 2.6.x allows NFS clients to cause a denial of service via O_DIRECT.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref patch="1" source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000930">CLA-2005:930</ref><ref adv="1" patch="1" source="SUSE" url="http://www.securityfocus.com/advisories/7880">SUSE-SA:2005:003</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/12330">12330</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-366.html">RHSA-2005:366</ref></refs><vuln_soft><prod name="SuSE Linux" vendor="SuSE"><vers num="9.2"/><vers num="9.1"/><vers num="9.0"/><vers num="8.2"/><vers num="8.1"/></prod><prod name="Conectiva Linux" vendor="Conectiva"><vers num="10.0"/></prod><prod name="SuSE Linux Enterprise Server" vendor="SuSE"><vers num="9"/><vers num="8"/></prod><prod name="Desktop" vendor="Red Hat"><vers num="4.0"/></prod><prod name="SuSE Novell Linux Desktop" vendor="SuSE"><vers num="9.0"/></prod><prod name="Kernel" vendor="Linux"><vers num="2.6.10 rc2"/><vers num="2.6.10"/><vers edition="2.6.20" num="2.6.9"/><vers num="2.6.8 rc3"/><vers num="2.6.8 rc2"/><vers num="2.6.8 rc1"/><vers num="2.6.8"/><vers num="2.6.7 rc1"/><vers num="2.6.7"/><vers num="2.6.6 rc1"/><vers num="2.6.6"/><vers num="2.6.5"/><vers num="2.6.4"/><vers num="2.6.3"/><vers num="2.6.2"/><vers num="2.6.1 rc2"/><vers num="2.6.1 rc1"/><vers num="2.6.1"/><vers num="2.6 test9 CVS"/><vers num="2.6 test9"/><vers num="2.6 test8"/><vers num="2.6 test7"/><vers num="2.6 test6"/><vers num="2.6 test5"/><vers num="2.6 test4"/><vers num="2.6 test3"/><vers num="2.6 test2"/><vers num="2.6 test11"/><vers num="2.6 test10"/><vers num="2.6 test1"/><vers num="2.6"/><vers num="2.5.69"/><vers num="2.5.68"/><vers num="2.5.67"/><vers num="2.5.66"/><vers num="2.5.65"/><vers num="2.5.64"/><vers num="2.5.63"/><vers num="2.5.62"/><vers num="2.5.61"/><vers num="2.5.60"/><vers num="2.5.59"/><vers num="2.5.58"/><vers num="2.5.57"/><vers num="2.5.56"/><vers num="2.5.55"/><vers num="2.5.54"/><vers num="2.5.53"/><vers num="2.5.52"/><vers num="2.5.51"/><vers num="2.5.50"/><vers num="2.5.49"/><vers num="2.5.48"/><vers num="2.5.47"/><vers num="2.5.46"/><vers num="2.5.45"/><vers num="2.5.44"/><vers num="2.5.43"/><vers num="2.5.42"/><vers num="2.5.41"/><vers num="2.5.40"/><vers num="2.5.39"/><vers num="2.5.38"/><vers num="2.5.37"/><vers num="2.5.36"/><vers num="2.5.35"/><vers num="2.5.34"/><vers num="2.5.33"/><vers num="2.5.32"/><vers num="2.5.31"/><vers num="2.5.30"/><vers num="2.5.29"/><vers num="2.5.28"/><vers num="2.5.27"/><vers num="2.5.26"/><vers num="2.5.25"/><vers num="2.5.24"/><vers num="2.5.23"/><vers num="2.5.22"/><vers num="2.5.21"/><vers num="2.5.20"/><vers num="2.5.19"/><vers num="2.5.18"/><vers num="2.5.17"/><vers num="2.5.16"/><vers num="2.5.15"/><vers num="2.5.14"/><vers num="2.5.13"/><vers num="2.5.12"/><vers num="2.5.11"/><vers num="2.5.10"/><vers num="2.5.9"/><vers num="2.5.8"/><vers num="2.5.7"/><vers num="2.5.6"/><vers num="2.5.5"/><vers num="2.5.4"/><vers num="2.5.3"/><vers num="2.5.2"/><vers num="2.5.1"/><vers num="2.5.0"/><vers num="2.4.29 rc2"/><vers num="2.4.29 rc1"/><vers num="2.4.28"/><vers num="2.4.27 pre5"/><vers num="2.4.27 pre4"/><vers num="2.4.27 pre3"/><vers num="2.4.27 pre2"/><vers num="2.4.27 pre1"/><vers num="2.4.27"/><vers num="2.4.26"/><vers num="2.4.25"/><vers num="2.4.24 ow1"/><vers num="2.4.24"/><vers num="2.4.23 pre9"/><vers num="2.4.23 ow2"/><vers num="2.4.23"/><vers num="2.4.22"/><vers num="2.4.21 pre7"/><vers num="2.4.21 pre4"/><vers num="2.4.21 pre1"/><vers num="2.4.21"/><vers num="2.4.20"/><vers num="2.4.19 pre6"/><vers num="2.4.19 pre5"/><vers num="2.4.19 pre4"/><vers num="2.4.19 pre3"/><vers num="2.4.19 pre2"/><vers num="2.4.19 pre1"/><vers num="2.4.19"/><vers num="2.4.18 pre8"/><vers num="2.4.18 pre7"/><vers num="2.4.18 pre6"/><vers num="2.4.18 pre5"/><vers num="2.4.18 pre4"/><vers num="2.4.18 pre3"/><vers num="2.4.18 pre2"/><vers num="2.4.18 pre1"/><vers edition="x86" num="2.4.18"/><vers num="2.4.18"/><vers num="2.4.17"/><vers num="2.4.16"/><vers num="2.4.15"/><vers num="2.4.14"/><vers num="2.4.13"/><vers num="2.4.12"/><vers num="2.4.11"/><vers num="2.4.10"/><vers num="2.4.9"/><vers num="2.4.8"/><vers num="2.4.7"/><vers num="2.4.6"/><vers num="2.4.5"/><vers num="2.4.4"/><vers num="2.4.3"/><vers num="2.4.2"/><vers num="2.4.1"/><vers num="2.4.0 test9"/><vers num="2.4.0 test8"/><vers num="2.4.0 test7"/><vers num="2.4.0 test6"/><vers num="2.4.0 test5"/><vers num="2.4.0 test4"/><vers num="2.4.0 test3"/><vers num="2.4.0 test2"/><vers num="2.4.0 test12"/><vers num="2.4.0 test11"/><vers num="2.4.0 test10"/><vers num="2.4.0 test1"/><vers num="2.4.0"/></prod><prod name="Enterprise Linux" vendor="Red Hat"><vers edition="Workstation" num="4.0"/><vers edition="Enterprise Server" num="4.0"/><vers edition="Advanced Server" num="4.0"/></prod><prod name="SuSE Linux Desktop" vendor="SuSE"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-25" name="CVE-2005-0208" published="2005-05-02" seq="2005-0208" severity="Medium" type="CVE"><desc><descript source="cve">The HTML parsing functions in Gaim before 1.1.4 allow remote attackers to cause a denial of service (application crash) via malformed HTML that causes &quot;an invalid memory access,&quot; a different vulnerability than CVE-2005-0473.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="CONFIRM" url="http://gaim.sourceforge.net/security/?id=12">http://gaim.sourceforge.net/security/?id=12</ref><ref patch="1" source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000933">CLA-2005:933</ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200503-03.xml">GLSA-200503-03</ref><ref patch="1" source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:049">MDKSA-2005:049</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-215.html">RHSA-2005:215</ref><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110935655500670&amp;w=2">20050225 [USN-85-1] Gaim vulnerabilities</ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/795812">VU#795812</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14386">14386</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/426078/100/0/threaded">FLSA:158543</ref><ref source="BID" url="http://www.securityfocus.com/bid/12660">12660</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_36_sudo.html">SUSE-SA:2005:036</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:049">MDKSA-2005:049</ref></refs><vuln_soft><prod name="Gaim" vendor="Rob Flynn"><vers num="1.1.0"/><vers num="1.1.1"/><vers num="1.1.2"/><vers num="1.1.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2008-06-24" name="CVE-2005-0209" published="2005-05-02" seq="2005-0209" severity="High" type="CVE"><desc><descript source="cve">Netfilter in Linux kernel 2.6.8.1 allows remote attackers to cause a denial of service (kernel crash) via crafted IP packet fragments.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111091402626556&amp;w=2">20050315 [USN-95-1] Linux kernel vulnerabilities</ref><ref patch="1" source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000945">CLA-2005:945</ref><ref adv="1" patch="1" source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_18_kernel.html">SUSE-SA:2005:018</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-366.html">RHSA-2005:366</ref><ref source="BID" url="http://www.securityfocus.com/bid/12598">12598</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-420.html">RHSA-2005:420</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.6.8.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.9" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.9" CVSS_score="4.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2008-06-24" name="CVE-2005-0210" published="2005-05-02" seq="2005-0210" severity="Medium" type="CVE"><desc><descript source="cve">Netfilter in the Linux kernel 2.6.8.1 allows local users to cause a denial of service (memory consumption) via certain packet fragments that are reassembled twice, which causes a data structure to be allocated twice.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=111091402626556&amp;w=2">20050315 [USN-95-1] Linux kernel vulnerabilities</ref><ref patch="1" source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000945">CLA-2005:945</ref><ref adv="1" patch="1" source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_18_kernel.html">SUSE-SA:2005:018</ref><ref source="MANDRAKE" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2005:218">MDKSA-2005:218</ref><ref source="MANDRAKE" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2005:219">MDKSA-2005:219</ref><ref source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2005-366.html">RHSA-2005:366</ref><ref source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2005-663.html">RHSA-2005:663</ref><ref source="BID" url="http://www.securityfocus.com/bid/12816">12816</ref><ref source="OSVDB" url="http://www.osvdb.org/14966">14966</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14295">14295</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17826">17826</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17002">17002</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/1878">ADV-2005-1878</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:218">MDKSA-2005:218</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:219">MDKSA-2005:219</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.6.8.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0211" published="2005-05-02" seq="2005-0211" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in wccp.c in Squid 2.5 before 2.5.STABLE7 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long WCCP packet, which is processed by a recvfrom function call that uses an incorrect length parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref patch="1" source="CONFIRM" url="http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE7-wccp_buffer_overflow">http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE7-wccp_buffer_overflow</ref><ref patch="1" source="CONFIRM" url="http://www.squid-cache.org/Versions/v2/2.5/bugs/squid-2.5.STABLE7-wccp_buffer_overflow.patch">http://www.squid-cache.org/Versions/v2/2.5/bugs/squid-2.5.STABLE7-wccp_buffer_overflow.patch</ref><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-667">DSA-667</ref><ref patch="1" source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:034">MDKSA-2005:034</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-060.html">RHSA-2005:060</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-061.html">RHSA-2005:061</ref><ref adv="1" patch="1" source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_06_squid.html">SUSE-SA:2005:006</ref><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110780531820947&amp;w=2">20050207 [USN-77-1] Squid vulnerabilities</ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/886006">VU#886006</ref><ref source="BID" url="http://www.securityfocus.com/bid/12432">12432</ref><ref source="OSVDB" url="http://www.osvdb.org/13319">13319</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013045">1013045</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14076">14076</ref><ref source="FEDORA" url="http://fedoranews.org/updates/FEDORA--.shtml">FLSA-2006:152809</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:034">MDKSA-2005:034</ref></refs><vuln_soft><prod name="Squid" vendor="Squid"><vers num="2.5.STABLE6"/><vers num="2.5.STABLE5"/><vers num="2.5.STABLE4"/><vers num="2.5.STABLE3"/><vers num="2.5.STABLE2"/><vers num="2.5.STABLE1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0212" published="2005-05-02" seq="2005-0212" severity="Medium" type="CVE"><desc><descript source="cve">The Amp II engine as used by Gore: Ultimate Soldier 1.50 and earlier allows remote attackers to cause a denial of service (infinite loop) via a zero byte UDP packet.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="Luigi Auriemma" url="http://aluigi.altervista.org/adv/amp2zero-adv.txt">http://aluigi.altervista.org/adv/amp2zero-adv.txt</ref><ref source="BID" url="http://www.securityfocus.com/bid/12192">12192</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18789">amp-3d-socket-dos(18789)</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13754">13754</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110503597505648&amp;w=2">20050106 Socket unreacheable in Amp II engine</ref></refs><vuln_soft><prod name="Amp II 3D Game Engine" vendor="Amp"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0213" published="2005-05-02" seq="2005-0213" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in WinHKI 1.4d allows remote attackers to overwrite arbitrary files via a .. (dot dot) in a zip file.</descript></desc><loss_types><int/></loss_types><vuln_types><access/><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110505334903257&amp;w=2">20050106 WinAc AND WinHKI ZIP File Directory Transversal </ref><ref source="BID" url="http://www.securityfocus.com/bid/12176">12176</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18798">winhki-zip-directory-traversal(18798)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1012798">1012798</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13738">13738</ref></refs><vuln_soft><prod name="WinHKI" vendor="Webtoolmaster Software"><vers num="1.4d"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0214" published="2005-05-02" seq="2005-0214" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in Simple PHP Blog (SPHPBlog) 0.3.7c allows remote attackers to read or create arbitrary files via a .. (dot dot) in the entry parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110512850603989&amp;w=2">20050107 Simple PHP Blog directory traversal vulnerability </ref><ref adv="1" source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2005-01/0210.html">20050107 Simple PHP Blog directory traversal vulnerability </ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/12193">12193</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18802">sphp-dotdot-directory-traversal(18802)</ref></refs><vuln_soft><prod name="Simple PHP Blog" vendor="Alexander Palmo"><vers num="0.3.7c"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0215" published="2005-05-02" seq="2005-0215" severity="Medium" type="CVE"><desc><descript source="cve">Mozilla 1.6 and possibly other versions allows remote attackers to cause a denial of service (application crash) via a XBM (X BitMap) file with a large (1) height or (2) width value.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110512665029209&amp;w=2">20050107 Mozilla XBM Image Vulnerability</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18803">mozilla-xbm-dos(18803)</ref></refs><vuln_soft><prod name="Mozilla" vendor="Mozilla"><vers num="1.6"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0216" published="2005-05-02" seq="2005-0216" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in formmail.php in Woltlab Burning Board Lite 1.0.0, 1.0.1e, and possibly other versions, allows remote attackers to inject arbitrary web sript and HTML via the userid parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110537385427004&amp;w=2">20050108 Security Advisory: Woltlab Burning Board Lite formmail.php XSS </ref><ref source="BID" url="http://www.securityfocus.com/bid/12199">12199</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18814">wbb-formmail-userid-xss(18814)</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13782">13782</ref></refs><vuln_soft><prod name="Burning Board Lite" vendor="Woltlab"><vers num="1.0.1e"/><vers num="1.0.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0217" published="2005-05-02" seq="2005-0217" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in index.php in Invision Community Blog allows remote attackers to execute arbitrary SQL commands via the eid parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110538277223800&amp;w=2">20050109 SQL Injection Vulnerability in Invision Community Blog</ref><ref source="BID" url="http://www.securityfocus.com/bid/12205">12205</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18815">icb-sql-injection(18815)</ref><ref source="OSVDB" url="http://www.osvdb.org/12817">12817</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1012831">1012831</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13783">13783</ref></refs><vuln_soft><prod name="Invision Community Blog" vendor="Invision Power Services"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0218" published="2005-05-02" seq="2005-0218" severity="Medium" type="CVE"><desc><descript source="cve">ClamAV 0.80 and earlier allows remote attackers to bypass virus scanning via a base64 encoded image in a data: (RFC 2397) URL.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="CONFIRM" url="http://sourceforge.net/project/shownotes.php?release_id=300116">http://sourceforge.net/project/shownotes.php?release_id=300116</ref><ref patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200501-46.xml">GLSA-200501-46</ref><ref patch="1" source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:025">MDKSA-2005:025</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/13900/">13900</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:025">MDKSA-2005:025</ref></refs><vuln_soft><prod name="ClamAV" vendor="Clam Anti-Virus"><vers num="0.80"/><vers num="0.68.1"/><vers num="0.68"/><vers num="0.67"/><vers num="0.65"/><vers num="0.60"/><vers num="0.54"/><vers num="0.53"/><vers num="0.52"/><vers num="0.51"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-08-17" name="CVE-2005-0219" published="2005-05-02" seq="2005-0219" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Gallery 1.3.4-pl1 allow remote attackers to inject arbitrary web script or HTML via (1) the index field in add_comment.php, (2) set_albumName, (3) slide_index, (4) slide_full, (5) slide_loop, (6) slide_pause, (7) slide_dir fields in slideshow_low.php, or (8) username field in search.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110608459222364&amp;w=2">20050117 Gallery v1.3.4-pl1, v1.4.4-pl2, 2.0 Alpha Cross Site Scripting Vulnerability</ref><ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2005-q1/0031.html">20050117 Gallery v1.3.4-pl1, v1.4.4-pl2, 2.0 Alpha Cross Site Scripting Vulnerability</ref><ref patch="1" source="CONFIRM" url="http://gallery.menalto.com/modules.php?op=modload&amp;name=News&amp;file=article&amp;sid=147">http://gallery.menalto.com/modules.php?op=modload&amp;name=News&amp;file=article&amp;sid=147</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18938">gallery-multiple-xss(18938)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/43473">gallery-multiple-scripts-xss(43473)</ref></refs><vuln_soft><prod name="Gallery" vendor="Gallery Project"><vers num="1.3.4 pl1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-08-17" name="CVE-2005-0220" published="2005-05-02" seq="2005-0220" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting vulnerability in login.php in Gallery 1.4.4-pl2 allows remote attackers to inject arbitrary web script or HTML via the username field.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110608459222364&amp;w=2">20050117 Gallery v1.3.4-pl1, v1.4.4-pl2, 2.0 Alpha Cross Site Scripting Vulnerability</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200501-45.xml">GLSA-200501-45</ref><ref patch="1" source="CONFIRM" url="http://gallery.menalto.com/modules.php?op=modload&amp;name=News&amp;file=article&amp;sid=147">http://gallery.menalto.com/modules.php?op=modload&amp;name=News&amp;file=article&amp;sid=147</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/13887/">13887</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18938">gallery-multiple-xss(18938)</ref></refs><vuln_soft><prod name="Gallery" vendor="Gallery Project"><vers num="1.4.4 pl2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-08-17" name="CVE-2005-0221" published="2005-01-17" seq="2005-0221" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in login.php in Gallery 2.0 Alpha allows remote attackers to inject arbitrary web script or HTML via the g2_form[subject] field.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110608459222364&amp;w=2">20050117 Gallery v1.3.4-pl1, v1.4.4-pl2, 2.0 Alpha Cross Site Scripting Vulnerability</ref><ref adv="1" source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2005-q1/0031.html">20050117 [VulnWatch] Gallery v1.3.4-pl1, v1.4.4-pl2, 2.0 Alpha Cross Site Scripting Vulnerability</ref><ref adv="1" source="MISC" url="http://theinsider.deep-ice.com/texts/advisory69.txt">http://theinsider.deep-ice.com/texts/advisory69.txt</ref><ref adv="1" patch="1" source="CONFIRM" url="http://gallery.menalto.com/modules.php?op=modload&amp;name=News&amp;file=article&amp;sid=147">http://gallery.menalto.com/modules.php?op=modload&amp;name=News&amp;file=article&amp;sid=147</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18938">gallery-multiple-xss(18938)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/43472">gallery-g2formsubject-xss(43472)</ref></refs><vuln_soft><prod name="Gallery" vendor="Gallery Project"><vers num="2.0 Alpha"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-08-17" name="CVE-2005-0222" published="2005-05-02" seq="2005-0222" severity="Medium" type="CVE"><desc><descript source="cve">main.php in Gallery 2.0 Alpha allows remote attackers to gain sensitive information by changing the value of g2_subView parameter, which reveals the path in an error message.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110608459222364&amp;w=2">20050117 Gallery v1.3.4-pl1, v1.4.4-pl2, 2.0 Alpha Cross Site Scripting Vulnerability</ref><ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2005-q1/0031.html">20050117 [VulnWatch] Gallery v1.3.4-pl1, v1.4.4-pl2, 2.0 Alpha Cross Site Scripting Vulnerability</ref><ref adv="1" source="MISC" url="http://theinsider.deep-ice.com/texts/advisory69.txt">http://theinsider.deep-ice.com/texts/advisory69.txt</ref><ref source="CONFIRM" url="http://gallery.menalto.com/modules.php?op=modload&amp;name=News&amp;file=article&amp;sid=147">http://gallery.menalto.com/modules.php?op=modload&amp;name=News&amp;file=article&amp;sid=147</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18940">gallery-mainphp-obtain-information(18940)</ref></refs><vuln_soft><prod name="Gallery" vendor="Gallery Project"><vers num="2.0 Alpha"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0223" published="2005-05-02" seq="2005-0223" severity="Medium" type="CVE"><desc><descript source="cve">The Software Development Kit (SDK) and Run Time Environment (RTE) 1.4.1 and 1.4.2 for Tru64 UNIX allows remote attackers to cause a denial of service (Java Virtual Machine hang) via object deserialization.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="HP" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110719624029320&amp;w=2">SSRT4875</ref></refs><vuln_soft><prod name="RTE" vendor="Sun"><vers num="1.4.1"/><vers num="1.4.2"/></prod><prod name="Tru64" vendor="Compaq"><vers num=""/></prod><prod name="SDK" vendor="Sun"><vers num="1.4.1"/><vers num="1.4.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0224" published="2005-01-31" seq="2005-0224" severity="Medium" type="CVE"><desc><descript source="cve">Unknown vulnerability in HP-UX B.11.04 running Virtualvault 4.5 through 4.7, when running the TGA daemon, allows remote attackers to cause a denial of service via certain network traffic.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="HP" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110726808700080&amp;w=2">SSRT5900</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14082/">14082</ref></refs><vuln_soft><prod name="VirtualVault" vendor="HP"><vers num="4.5"/><vers num="4.6"/><vers num="4.7"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0225" published="2005-05-02" seq="2005-0225" severity="Low" type="CVE"><desc><descript source="cve">firehol.sh in FireHOL before 1.224 creates temporary files with predictable file names, which could allow local users to overwrite arbitrary files via a symlink attack.</descript></desc><loss_types><int/></loss_types><vuln_types><exception/></vuln_types><range><local/></range><refs><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200502-01.xml">GLSA-200502-01</ref><ref source="CONFIRM" url="http://cvs.sourceforge.net/viewcvs.py/firehol/firehol/firehol.sh">http://cvs.sourceforge.net/viewcvs.py/firehol/firehol/firehol.sh</ref><ref source="BID" url="http://www.securityfocus.com/bid/12336">12336</ref><ref source="OSVDB" url="http://www.osvdb.org/13137">13137</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1012969">1012969</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13970">13970</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14102">14102</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19032">firehol-symlink(19032)</ref></refs><vuln_soft><prod name="FireHOL" vendor="FireHOL"><vers num="1.224"/><vers num="1.223"/><vers num="1.222"/><vers num="1.221"/><vers num="1.220"/><vers num="1.219"/><vers num="1.218"/><vers num="1.217"/><vers num="1.216"/><vers num="1.215"/><vers num="1.214"/><vers num="1.213"/><vers num="1.212"/><vers num="1.211"/><vers num="1.210"/><vers num="1.209"/><vers num="1.208"/><vers num="1.207"/><vers num="1.206"/><vers num="1.205"/><vers num="1.204"/><vers num="1.203"/><vers num="1.202"/><vers num="1.201"/><vers num="1.200"/><vers num="1.199"/><vers num="1.198"/><vers num="1.197"/><vers num="1.196"/><vers num="1.195"/><vers num="1.194"/><vers num="1.193"/><vers num="1.192"/><vers num="1.191"/><vers num="1.190"/><vers num="1.189"/><vers num="1.188"/><vers num="1.187"/><vers num="1.186"/><vers num="1.185"/><vers num="1.184"/><vers num="1.183"/><vers num="1.182"/><vers num="1.181"/><vers num="1.180"/><vers num="1.179"/><vers num="1.178"/><vers num="1.177"/><vers num="1.176"/><vers num="1.175"/><vers num="1.174"/><vers num="1.173"/><vers num="1.172"/><vers num="1.171"/><vers num="1.170"/><vers num="1.169"/><vers num="1.168"/><vers num="1.167"/><vers num="1.166"/><vers num="1.165"/><vers num="1.164"/><vers num="1.163"/><vers num="1.162"/><vers num="1.161"/><vers num="1.160"/><vers num="1.159"/><vers num="1.158"/><vers num="1.157"/><vers num="1.156"/><vers num="1.155"/><vers num="1.154"/><vers num="1.153"/><vers num="1.152"/><vers num="1.151"/><vers num="1.150"/><vers num="1.149"/><vers num="1.148"/><vers num="1.147"/><vers num="1.146"/><vers num="1.145"/><vers num="1.144"/><vers num="1.143"/><vers num="1.142"/><vers num="1.141"/><vers num="1.140"/><vers num="1.139"/><vers num="1.138"/><vers num="1.137"/><vers num="1.136"/><vers num="1.135"/><vers num="1.134"/><vers num="1.133"/><vers num="1.132"/><vers num="1.131"/><vers num="1.130"/><vers num="1.129"/><vers num="1.128"/><vers num="1.127"/><vers num="1.126"/><vers num="1.125"/><vers num="1.124"/><vers num="1.123"/><vers num="1.122"/><vers num="1.121"/><vers num="1.120"/><vers num="1.119"/><vers num="1.118"/><vers num="1.117"/><vers num="1.116"/><vers num="1.115"/><vers num="1.114"/><vers num="1.113"/><vers num="1.112"/><vers num="1.111"/><vers num="1.110"/><vers num="1.109"/><vers num="1.108"/><vers num="1.107"/><vers num="1.106"/><vers num="1.105"/><vers num="1.104"/><vers num="1.103"/><vers num="1.102"/><vers num="1.101"/><vers num="1.100"/><vers num="1.99"/><vers num="1.98"/><vers num="1.97"/><vers num="1.96"/><vers num="1.95"/><vers num="1.94"/><vers num="1.93"/><vers num="1.92"/><vers num="1.91"/><vers num="1.90"/><vers num="1.89"/><vers num="1.88"/><vers num="1.87"/><vers num="1.86"/><vers num="1.85"/><vers num="1.84"/><vers num="1.83"/><vers num="1.82"/><vers num="1.81"/><vers num="1.80"/><vers num="1.79"/><vers num="1.78"/><vers num="1.77"/><vers num="1.76"/><vers num="1.75"/><vers num="1.74"/><vers num="1.73"/><vers num="1.72"/><vers num="1.71"/><vers num="1.70"/><vers num="1.69"/><vers num="1.68"/><vers num="1.67"/><vers num="1.66"/><vers num="1.65"/><vers num="1.64"/><vers num="1.63"/><vers num="1.62"/><vers num="1.61"/><vers num="1.60"/><vers num="1.59"/><vers num="1.58"/><vers num="1.57"/><vers num="1.56"/><vers num="1.55"/><vers num="1.54"/><vers num="1.53"/><vers num="1.52"/><vers num="1.51"/><vers num="1.50"/><vers num="1.49"/><vers num="1.48"/><vers num="1.47"/><vers num="1.46"/><vers num="1.45"/><vers num="1.44"/><vers num="1.43"/><vers num="1.42"/><vers num="1.41"/><vers num="1.40"/><vers num="1.39"/><vers num="1.38"/><vers num="1.37"/><vers num="1.36"/><vers num="1.35"/><vers num="1.34"/><vers num="1.33"/><vers num="1.32"/><vers num="1.31"/><vers num="1.30"/><vers num="1.29"/><vers num="1.28"/><vers num="1.27"/><vers num="1.26"/><vers num="1.25"/><vers num="1.24"/><vers num="1.23"/><vers num="1.22"/><vers num="1.21"/><vers num="1.20"/><vers num="1.19"/><vers num="1.18"/><vers num="1.17"/><vers num="1.16"/><vers num="1.15"/><vers num="1.14"/><vers num="1.13"/><vers num="1.12"/><vers num="1.11"/><vers num="1.10"/><vers num="1.9"/><vers num="1.8"/><vers num="1.7"/><vers num="1.6"/><vers num="1.5"/><vers num="1.4"/><vers num="1.3"/><vers num="1.2"/><vers num="1.1"/><vers num="1.1.1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0226" published="2005-02-03" seq="2005-0226" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in the Log_Resolver function in log.c for ngIRCd 0.8.2 and earlier, when compiled with IDENT, logging to SYSLOG, and with DEBUG enabled, allows remote attackers to execute arbitrary code.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110746413108183&amp;w=2">20050203 ngIRCd &lt;= v0.8.2 Format String Vulnerability</ref><ref adv="1" patch="1" source="MISC" url="http://www.nosystem.com.ar/advisories/advisory-11.txt">http://www.nosystem.com.ar/advisories/advisory-11.txt</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14114/">14114</ref><ref source="BID" url="http://www.securityfocus.com/bid/12434">12434</ref></refs><vuln_soft><prod name="ngIRCd" vendor="ngIRCd"><vers num="0.8.2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0227" published="2005-05-02" seq="2005-0227" severity="Medium" type="CVE"><desc><descript source="cve">PostgreSQL (pgsql) 7.4.x, 7.2.x, and other versions allows local users to load arbitrary shared libraries and execute code via the LOAD extension.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" source="MLIST" url="http://archives.postgresql.org/pgsql-bugs/2005-01/msg00269.php">[pgsql-bugs] 20050121 Privilege escalation via LOAD</ref><ref patch="1" source="MLIST" url="http://archives.postgresql.org/pgsql-announce/2005-02/msg00000.php">[pgsql-announce] 20050201 PostgreSQL Security Release</ref><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-668">DSA-668</ref><ref patch="1" source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200502-08.xml">200502-08</ref><ref patch="1" source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:040">MDKSA-2005:040</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-138.html">RHSA-2005:138</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-150.html">RHSA-2005:150</ref><ref adv="1" patch="1" source="TRUSTIX" url="http://www.trustix.org/errata/2005/0003/">2005-0003</ref><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110726899107148&amp;w=2">20050201 [USN-71-1] PostgreSQL vulnerability</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/12948">12948</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_36_sudo.html">SUSE-SA:2005:036</ref><ref source="BID" url="http://www.securityfocus.com/bid/12411">
12411</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:040">MDKSA-2005:040</ref></refs><vuln_soft><prod name="PostgreSQL" vendor="PostgreSQL"><vers num="7.4.1"/><vers num="7.4.2"/><vers num="7.4.3"/><vers num="7.4.4"/><vers num="7.4.5"/><vers num="7.4.6"/><vers num="7.4.7"/><vers num="7.2.1"/><vers num="7.2.2"/><vers num="7.2.3"/><vers num="7.2.4"/><vers num="7.2.5"/><vers num="7.2.6"/><vers num="7.2.7"/></prod></vuln_soft></entry><entry modified="2005-10-25" name="CVE-2005-0228" published="2005-05-02" reject="1" seq="2005-0228" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2004-1388.  Reason: This candidate is a duplicate of CVE-2004-1388.  Notes: All CVE users should reference CVE-2004-1388 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript></desc><refs/></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-05-12" name="CVE-2005-0229" published="2005-04-27" seq="2005-0229" severity="Medium" type="CVE"><desc><descript source="cve">CitrusDB 0.3.5 and earlier stores the newfile.txt temporary data file under the web root, which allows remote attackers to steal credit card information via a direct request to newfile.txt.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/12402">bid 12402</ref><ref adv="1" patch="1" source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=110824766519417&amp;w=2">20050212 Credit Card data disclosure in CitrusDB</ref><ref source="CONFIRM" url="http://www.citrusdb.org/forums/viewtopic.php?t=49">http://www.citrusdb.org/forums/viewtopic.php?t=49</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19145">citrus-information-disclosure(19145)</ref><ref adv="1" source="" url="http://www.redteam-pentesting.de/advisories/rt-sa-2005-001.txt"></ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013040">1013040</ref></refs><vuln_soft><prod name="CitrusDB Customer Database" vendor="CitrusDB"><vers num="0.1.2"/><vers num="0.2"/><vers num="0.2.1"/><vers num="0.3"/><vers num="0.3.1"/><vers num="0.3.5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0230" published="2005-05-02" seq="2005-0230" severity="Medium" type="CVE"><desc><descript source="cve">Firefox 1.0 does not prevent the user from dragging an executable file to the desktop when it has an image/gif content type but has a dangerous extension such as .bat or .exe, which allows remote attackers to bypass the intended restriction and execute arbitrary commands via malformed GIF files that can still be parsed by the Windows batch file parser, aka &quot;firedragging.&quot;</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200503-30.xml">GLSA-200503-30</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval100033.html">OVAL100033</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_04_25.html">SUSE-SA:2006:022</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19823">19823</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100033">oval:org.mitre.oval:def:100033</ref><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110780995232064&amp;w=2">20050207 Firedragging [Firefox 1.0]</ref><ref source="MISC" url="http://www.mikx.de/firedragging/">http://www.mikx.de/firedragging/</ref><ref adv="1" source="CONFIRM" url="https://bugzilla.mozilla.org/show_bug.cgi?id=279945">https://bugzilla.mozilla.org/show_bug.cgi?id=279945</ref><ref patch="1" source="CONFIRM" url="http://www.mozilla.org/security/announce/mfsa2005-25.html">http://www.mozilla.org/security/announce/mfsa2005-25.html</ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200503-10.xml">GLSA-200503-10</ref></refs><vuln_soft><prod name="Firefox" vendor="Mozilla"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0231" published="2005-02-07" seq="2005-0231" severity="Low" type="CVE"><desc><descript source="cve">Firefox 1.0 does not invoke the Javascript Security Manager when a user drags a javascript: or data: URL to a tab, which allows remote attackers to bypass the security model, aka &quot;firetabbing.&quot;</descript></desc><loss_types><int/></loss_types><vuln_types><access/><input/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110781134617144&amp;w=2">20050207 Firetabbing [Firefox 1.0]</ref><ref adv="1" source="MISC" url="http://www.mikx.de/firetabbing/">http://www.mikx.de/firetabbing/</ref><ref adv="1" patch="1" source="CONFIRM" url="https://bugzilla.mozilla.org/show_bug.cgi?id=280056">https://bugzilla.mozilla.org/show_bug.cgi?id=280056</ref><ref adv="1" patch="1" source="CONFIRM" url="http://www.mozilla.org/security/announce/mfsa2005-26.html">http://www.mozilla.org/security/announce/mfsa2005-26.html</ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200503-10.xml">GLSA-200503-10</ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200503-30.xml">GLSA-200503-30</ref><ref adv="1" patch="1" source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_16_mozilla_firefox.html">SUSE-SA:2005:016</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19264">mozilla-firefox-tab-gain-access(19264)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval100032.html">OVAL100032</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-176.html">RHSA-2005:176</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-384.html">RHSA-2005:384</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100032">oval:org.mitre.oval:def:100032</ref></refs><vuln_soft><prod name="Firefox" vendor="Mozilla"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0232" published="2005-05-02" seq="2005-0232" severity="Low" type="CVE"><desc><descript source="cve">Firefox 1.0 allows remote attackers to modify Boolean configuration parameters for the about:config site by using a plugin such as Flash, and the -moz-opacity filter, to display the about:config site then cause the user to double-click at a certain screen position, aka &quot;Fireflashing.&quot;</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref source="MISC" url="http://www.mikx.de/fireflashing/">http://www.mikx.de/fireflashing/</ref><ref adv="1" source="CONFIRM" url="https://bugzilla.mozilla.org/show_bug.cgi?id=280664">https://bugzilla.mozilla.org/show_bug.cgi?id=280664</ref><ref adv="1" source="CONFIRM" url="http://www.mozilla.org/security/announce/mfsa2005-27.html">http://www.mozilla.org/security/announce/mfsa2005-27.html</ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200503-10.xml">GLSA-200503-10</ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200503-30.xml">GLSA-200503-30</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-323.html">RHSA-2005:323</ref><ref adv="1" patch="1" source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_16_mozilla_firefox.html">SUSE-SA:2005:016</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19266">mozilla-firefox-aboutconfig-modify(19266)</ref><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110781055630856&amp;w=2">20050207 Fireflashing [Firefox 1.0]</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-176.html">RHSA-2005:176</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-384.html">RHSA-2005:384</ref></refs><vuln_soft><prod name="Firefox" vendor="Mozilla"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-21" name="CVE-2005-0233" published="2005-02-08" seq="2005-0233" severity="High" type="CVE"><desc><descript source="cve">The International Domain Name (IDN) support in Firefox 1.0, Camino .8.5, and Mozilla before 1.7.6 allows remote attackers to spoof domain names using punycode encoded domain names that are decoded in URLs and SSL certificates in a way that uses homograph characters from other character sets, which facilitates phishing attacks.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-February/031459.html">20050206 state of homograph attacks</ref><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110782704923280&amp;w=2">20050208 International Domain Name [IDN] support in modern browsers allows attackers to spoof domain name URLs + SSL certs.</ref><ref adv="1" source="MISC" url="http://www.shmoo.com/idn">http://www.shmoo.com/idn</ref><ref adv="1" source="MISC" url="http://www.shmoo.com/idn/homograph.txt">http://www.shmoo.com/idn/homograph.txt</ref><ref adv="1" patch="1" source="CONFIRM" url="http://www.mozilla.org/security/announce/mfsa2005-29.html">http://www.mozilla.org/security/announce/mfsa2005-29.html</ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200503-10.xml">GLSA-200503-10</ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200503-30.xml">GLSA-200503-30</ref><ref adv="1" patch="1" source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_16_mozilla_firefox.html">SUSE-SA:2005:016</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19236">multiple-browsers-idn-spoof(19236)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval100029.html">OVAL100029</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-176.html">RHSA-2005:176</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-384.html">RHSA-2005:384</ref><ref source="BID" url="http://www.securityfocus.com/bid/12461">12461</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100029">oval:org.mitre.oval:def:100029</ref></refs><vuln_soft><prod name="OmniWeb" vendor="OmniGroup"><vers num="5"/></prod><prod name="Opera Web Browser" vendor="Opera Software"><vers num="7.54"/></prod><prod name="Camino" vendor="Mozilla"><vers num=".8.5"/></prod><prod name="Mozilla Browser" vendor="Mozilla"><vers num="1.6"/><vers num="1.5.1"/><vers num="1.5"/><vers num="1.4.4"/><vers num="1.4.2"/><vers num="1.4.1"/><vers num="1.4b"/><vers num="1.4a"/><vers num="1.4"/><vers num="1.3.1"/><vers num="1.3"/><vers num="1.2.1"/><vers num="1.2 Beta"/><vers num="1.2 Alpha"/><vers num="1.2"/><vers num="1.1 Beta"/><vers num="1.1 Alpha"/><vers num="1.1"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0 RC2"/><vers num="1.0 RC1"/><vers num="1.0"/><vers num="0.9.9"/><vers num="0.9.8"/><vers num="0.9.7"/><vers num="0.9.6"/><vers num="0.9.5"/><vers num="0.9.48"/><vers num="0.9.4.1"/><vers num="0.9.4"/><vers num="0.9.35"/><vers num="0.9.3"/><vers num="0.9.2.1"/><vers num="0.9.2"/><vers num="0.8"/></prod><prod name="Firefox" vendor="Mozilla"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0234" published="2005-05-02" seq="2005-0234" severity="Medium" type="CVE"><desc><descript source="cve">The International Domain Name (IDN) support in Safari 1.2.5 allows remote attackers to spoof domain names using punycode encoded domain names that are decoded in URLs and SSL certificates in a way that uses homograph characters from other character sets, which facilitates phishing attacks.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-February/031459.html">20050206 state of homograph attacks</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110782704923280&amp;w=2">20050208 International Domain Name [IDN] support in modern browsers allows attackers to spoof domain name URLs + SSL certs.</ref><ref source="MISC" url="http://www.shmoo.com/idn">http://www.shmoo.com/idn</ref><ref adv="1" source="MISC" url="http://www.shmoo.com/idn/homograph.txt">http://www.shmoo.com/idn/homograph.txt</ref><ref adv="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2005/Mar/msg00000.html">APPLE-SA-2005-03-21</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19236">multiple-browsers-idn-spoof(19236)</ref><ref source="BID" url="http://www.securityfocus.com/bid/12461">12461</ref></refs><vuln_soft><prod name="Safari" vendor="Apple"><vers num="1.2.5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0235" published="2005-05-02" seq="2005-0235" severity="Medium" type="CVE"><desc><descript source="cve">The International Domain Name (IDN) support in Opera 7.54 allows remote attackers to spoof domain names using punycode encoded domain names that are decoded in URLs and SSL certificates in a way that uses homograph characters from other character sets, which facilitates phishing attacks.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-February/031459.html">20050206 state of homograph attacks</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110782704923280&amp;w=2">20050208 International Domain Name [IDN] support in modern browsers allows attackers to spoof domain name URLs + SSL certs.</ref><ref source="MISC" url="http://www.shmoo.com/idn">http://www.shmoo.com/idn</ref><ref source="MISC" url="http://www.shmoo.com/idn/homograph.txt">http://www.shmoo.com/idn/homograph.txt</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19236">multiple-browsers-idn-spoof(19236)</ref><ref source="BID" url="http://www.securityfocus.com/bid/12461">12461</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_31_opera.html">SUSE-SA:2005:031</ref></refs><vuln_soft><prod name="Opera Web Browser" vendor="Opera Software"><vers num="7.54"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-21" name="CVE-2005-0236" published="2005-05-02" seq="2005-0236" severity="Medium" type="CVE"><desc><descript source="cve">The International Domain Name (IDN) support in Omniweb 5 allows remote attackers to spoof domain names using punycode encoded domain names that are decoded in URLs and SSL certificates in a way that uses homograph characters from other character sets, which facilitates phishing attacks.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-February/031459.html">20050206 state of homograph attacks</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110782704923280&amp;w=2">20050208 International Domain Name [IDN] support in modern browsers allows attackers to spoof domain name URLs + SSL certs.</ref><ref source="MISC" url="http://www.shmoo.com/idn">http://www.shmoo.com/idn</ref><ref source="MISC" url="http://www.shmoo.com/idn/homograph.txt">http://www.shmoo.com/idn/homograph.txt</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19236">multiple-browsers-idn-spoof(19236)</ref><ref source="BID" url="http://www.securityfocus.com/bid/12461">12461</ref></refs><vuln_soft><prod name="OmniWeb" vendor="OmniGroup"><vers num="5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0237" published="2005-05-02" seq="2005-0237" severity="Medium" type="CVE"><desc><descript source="cve">The International Domain Name (IDN) support in Konqueror 3.2.1 on KDE 3.2.1 allows remote attackers to spoof domain names using punycode encoded domain names that are decoded in URLs and SSL certificates in a way that uses homograph characters from other character sets, which facilitates phishing attacks.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-February/031459.html">20050206 state of homograph attacks</ref><ref adv="1" source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-February/031460.html">20050206 Re: state of homograph attacks</ref><ref source="MISC" url="http://www.shmoo.com/idn">http://www.shmoo.com/idn</ref><ref source="MISC" url="http://www.shmoo.com/idn/homograph.txt">http://www.shmoo.com/idn/homograph.txt</ref><ref adv="1" patch="1" source="CONFIRM" url="http://www.kde.org/info/security/advisory-20050316-2.txt">http://www.kde.org/info/security/advisory-20050316-2.txt</ref><ref patch="1" source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:058">MDKSA-2005:058</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/14162">14162</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19236">multiple-browsers-idn-spoof(19236)</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-325.html">RHSA-2005:325</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/427976/100/0/threaded">FLSA:178606</ref><ref source="BID" url="http://www.securityfocus.com/bid/12461">12461</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:058">MDKSA-2005:058</ref></refs><vuln_soft><prod name="KDE" vendor="KDE"><vers num="3.2.1"/></prod><prod name="Konqueror" vendor="KDE"><vers num="3.2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-21" name="CVE-2005-0238" published="2005-05-02" seq="2005-0238" severity="Medium" type="CVE"><desc><descript source="cve">The International Domain Name (IDN) support in Epiphany allows remote attackers to spoof domain names using punycode encoded domain names that are decoded in URLs and SSL certificates in a way that uses homograph characters from other character sets, which facilitates phishing attacks.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-February/031459.html">20050206 state of homograph attacks</ref><ref adv="1" source="MISC" url="http://www.shmoo.com/idn">http://www.shmoo.com/idn</ref><ref adv="1" source="MISC" url="http://www.shmoo.com/idn/homograph.txt">http://www.shmoo.com/idn/homograph.txt</ref><ref adv="1" patch="1" source="CONFIRM" url="https://bugzilla.redhat.com/beta/show_bug.cgi?id=147399">https://bugzilla.redhat.com/beta/show_bug.cgi?id=147399</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19236">multiple-browsers-idn-spoof(19236)</ref><ref source="BID" url="http://www.securityfocus.com/bid/12461">12461</ref></refs><vuln_soft><prod name="OmniWeb" vendor="OmniGroup"><vers num="5"/></prod><prod name="Opera Web Browser" vendor="Opera Software"><vers num="7.54"/></prod><prod name="Epiphany" vendor="GNOME"><vers num=""/></prod><prod name="Camino" vendor="Mozilla"><vers num=".8.5"/></prod><prod name="Mozilla Browser" vendor="Mozilla"><vers num="1.6"/><vers num="1.5.1"/><vers num="1.5"/><vers num="1.4.4"/><vers num="1.4.2"/><vers num="1.4.1"/><vers num="1.4b"/><vers num="1.4a"/><vers num="1.4"/><vers num="1.3.1"/><vers num="1.3"/><vers num="1.2.1"/><vers num="1.2 Beta"/><vers num="1.2 Alpha"/><vers num="1.2"/><vers num="1.1 Beta"/><vers num="1.1 Alpha"/><vers num="1.1"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0 RC2"/><vers num="1.0 RC1"/><vers num="1.0"/><vers num="0.9.9"/><vers num="0.9.8"/><vers num="0.9.7"/><vers num="0.9.6"/><vers num="0.9.5"/><vers num="0.9.48"/><vers num="0.9.4.1"/><vers num="0.9.4"/><vers num="0.9.35"/><vers num="0.9.3"/><vers num="0.9.2.1"/><vers num="0.9.2"/><vers num="0.8"/></prod><prod name="Firefox" vendor="Mozilla"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0239" published="2005-05-02" seq="2005-0239" severity="High" type="CVE"><desc><descript source="cve">viewcert.php in the S/MIME plugin 0.4 and 0.5 for Squirrelmail allows remote attackers to execute arbitrary commands via shell metacharacters in the cert parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=191&amp;type=vulnerabilities&amp;flashstatus=false">20050207 SquirrelMail S/MIME Plugin Command Injection Vulnerability</ref><ref source="CONFIRM" url="http://www.squirrelmail.org/plugin_view.php?id=54">http://www.squirrelmail.org/plugin_view.php?id=54</ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/502328">VU#502328</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19242">squirrelmail-smime-command-execution(19242)</ref></refs><vuln_soft><prod name="S/MIME Plugin" vendor="Squirrelmail"><vers num="0.4"/><vers num="0.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0240" published="2005-05-02" seq="2005-0240" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in chdev on IBM AIX 5.2 allows local users to execute arbitrary code via format string specifiers in a command line argument, which is not properly handled when printing an error message.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref source="IDEFENSE" url="http://www.idefense.com/application/poi/display?type=vulnerabilities">20050207 IBM AIX chdev Local Format String Vulnerability</ref><ref adv="1" source="AIXAPAR" url="http://www-1.ibm.com/support/docview.wss?uid=isg1IY67455">IY67455</ref><ref adv="1" source="AIXAPAR" url="http://www-1.ibm.com/support/docview.wss?uid=isg1IY67654">IY67654</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19244">aix-chdev-format-string(19244)</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="5.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0241" published="2005-05-02" seq="2005-0241" severity="Medium" type="CVE"><desc><descript source="cve">The httpProcessReplyHeader function in http.c for Squid 2.5-STABLE7 and earlier does not properly set the debug context when it is handling &quot;oversized&quot; HTTP reply headers, which might allow remote attackers to poison the cache or bypass access controls based on header size.</descript></desc><loss_types><int/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref patch="1" source="CONFIRM" url="http://www.squid-cache.org/bugs/show_bug.cgi?id=1216">http://www.squid-cache.org/bugs/show_bug.cgi?id=1216</ref><ref patch="1" source="CONFIRM" url="http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE7-oversize_reply_headers">http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE7-oversize_reply_headers</ref><ref patch="1" source="CONFIRM" url="http://www.squid-cache.org/Versions/v2/2.5/bugs/squid-2.5.STABLE7-oversize_reply_headers.patch">http://www.squid-cache.org/Versions/v2/2.5/bugs/squid-2.5.STABLE7-oversize_reply_headers.patch</ref><ref patch="1" source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000931">CLA-2005:931</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-060.html">RHSA-2005:060</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-061.html">RHSA-2005:061</ref><ref adv="1" patch="1" source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_06_squid.html">SUSE-SA:2005:006</ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/823350">VU#823350</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19060">squid-http-cache-poisoning(19060)</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14091">14091</ref><ref source="FEDORA" url="http://fedoranews.org/updates/FEDORA--.shtml">FLSA-2006:152809</ref><ref source="BID" url="http://www.securityfocus.com/bid/12412">12412</ref></refs><vuln_soft><prod name="Squid" vendor="Squid"><vers num="2.5.STABLE7"/><vers num="2.5.STABLE6"/><vers num="2.5.STABLE5"/><vers num="2.5.STABLE4"/><vers num="2.5.STABLE3"/><vers num="2.5.STABLE2"/><vers num="2.5.STABLE1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0242" published="2005-02-18" seq="2005-0242" severity="Medium" type="CVE"><desc><descript source="cve">The Audio Setup Wizard (asw.dll) in Yahoo! Messenger 6.0.0.1750, and possibly other versions, allows attackers to arbitrary code by placing a malicious ping.exe program into the Messenger program directory, which is installed with weak default permissions.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="MISC" url="http://secunia.com/secunia_research/2004-6/advisory/">http://secunia.com/secunia_research/2004-6/advisory/</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/11815">11815</ref></refs><vuln_soft><prod name="Messenger" vendor="Yahoo"><vers num="6.0.0.1750"/><vers num="6.0"/><vers num="5.6.0.1351"/><vers num="5.6"/><vers num="5.5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0243" published="2005-02-17" seq="2005-0243" severity="Medium" type="CVE"><desc><descript source="cve">Yahoo! Messenger 6.0.0.1750, and possibly other versions before 6.0.0.1921, does not properly display long filenames in file dialog boxes, which could allow remote attackers to trick users into downloading and executing programs via file names containing a large number of spaces and multiple file extensions.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="MISC" url="http://secunia.com/secunia_research/2005-2/advisory/">http://secunia.com/secunia_research/2005-2/advisory/</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/13712">13712</ref></refs><vuln_soft><prod name="Messenger" vendor="Yahoo"><vers num="6.0.0.1750"/><vers num="6.0"/><vers num="5.6.0.1351"/><vers num="5.6"/><vers num="5.5"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0244" published="2005-05-02" seq="2005-0244" severity="Medium" type="CVE"><desc><descript source="cve">PostgreSQL 8.0.0 and earlier allows local users to bypass the EXECUTE permission check for functions by using the CREATE AGGREGATE command.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" source="MLIST" url="http://archives.postgresql.org/pgsql-hackers/2005-01/msg00922.php">[pgsql-hackers] 20050127 Permissions on aggregate component functions</ref><ref adv="1" patch="1" source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:040">MDKSA-2005:040</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-138.html">RHSA-2005:138</ref><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110806034116082&amp;w=2">20050210 [USN-79-1] PostgreSQL vulnerabilities</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/12948">12948</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19184">postgresql-security-bypass(19184)</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_36_sudo.html">SUSE-SA:2005:036</ref><ref source="BID" url="http://www.securityfocus.com/bid/12417">
12417</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:040">MDKSA-2005:040</ref></refs><vuln_soft><prod name="PostgreSQL" vendor="PostgreSQL"><vers num="8.0.0"/><vers num="7.4"/><vers num="7.4.1"/><vers num="7.4.2"/><vers num="7.4.3"/><vers num="7.4.4"/><vers num="7.4.5"/><vers num="7.4.6"/><vers num="7.4.7"/><vers num="7.3"/><vers num="7.3.1"/><vers num="7.3.2"/><vers num="7.3.3"/><vers num="7.3.4"/><vers num="7.3.5"/><vers num="7.3.6"/><vers num="7.3.7"/><vers num="7.3.8"/><vers num="7.3.9"/><vers num="7.2"/><vers num="7.2.1"/><vers num="7.2.2"/><vers num="7.2.3"/><vers num="7.2.4"/><vers num="7.2.5"/><vers num="7.2.6"/><vers num="7.2.7"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-25" name="CVE-2005-0245" published="2005-02-01" seq="2005-0245" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in gram.y for PostgreSQL 8.0.0 and earlier may allow attackers to execute arbitrary code via a large number of arguments to a refcursor function (gram.y), which leads to a heap-based buffer overflow, a different vulnerability than CVE-2005-0247.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="MLIST" url="http://archives.postgresql.org/pgsql-patches/2005-01/msg00216.php">[pgsql-patches] 20050120 Re: WIP: pl/pgsql cleanup</ref><ref adv="1" source="MLIST" url="http://archives.postgresql.org/pgsql-committers/2005-01/msg00298.php">[pgsql-committers] 20050121 pgsql: Prevent overrunning a heap-allocated buffer is more than 1024</ref><ref adv="1" source="MLIST" url="http://archives.postgresql.org/pgsql-committers/2005-02/msg00049.php">[pgsql-committers] 20050207 pgsql: Prevent 4 more buffer overruns in the PL/PgSQL parser.</ref><ref adv="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-683">DSA-683</ref><ref adv="1" patch="1" source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:040">MDKSA-2005:040</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-138.html">RHSA-2005:138</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-150.html">RHSA-2005:150</ref><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110806034116082&amp;w=2">20050210 [USN-79-1] PostgreSQL vulnerabilities</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/12948">12948</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19188">postgresql-cursor-bo(19188)</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_36_sudo.html">SUSE-SA:2005:036</ref><ref source="BID" url="http://www.securityfocus.com/bid/12417">
12417</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:040">MDKSA-2005:040</ref></refs><vuln_soft><prod name="PostgreSQL" vendor="PostgreSQL"><vers num="8.0"/><vers num="7.4.7"/><vers num="7.4.6"/><vers num="7.4.5"/><vers num="7.4.4"/><vers num="7.4.3"/><vers num="7.4.2"/><vers num="7.4.1"/><vers num="7.4"/><vers num="7.3.9"/><vers num="7.3.8"/><vers num="7.3.7"/><vers num="7.3.6"/><vers num="7.3.5"/><vers num="7.3.4"/><vers num="7.3.3"/><vers num="7.3.2"/><vers num="7.3.1"/><vers num="7.3"/><vers num="7.2.7"/><vers num="7.2.6"/><vers num="7.2.5"/><vers num="7.2.4"/><vers num="7.2.3"/><vers num="7.2.2"/><vers num="7.2.1"/><vers num="7.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0246" published="2005-05-02" seq="2005-0246" severity="Medium" type="CVE"><desc><descript source="cve">The intagg contrib module for PostgreSQL 8.0.0 and earlier allows attackers to cause a denial of service (crash) via crafted arrays.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="MLIST" url="http://archives.postgresql.org/pgsql-committers/2005-01/msg00401.php">[pgsql-committers] 20050127 pgsql: Fix security and 64-bit issues in contrib/intagg.</ref><ref adv="1" patch="1" source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:040">MDKSA-2005:040</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-138.html">RHSA-2005:138</ref><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110806034116082&amp;w=2">20050210 [USN-79-1] PostgreSQL vulnerabilities</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/12948">12948</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19185">postgresql-contribintagg-dos(19185)</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_36_sudo.html">SUSE-SA:2005:036</ref><ref source="BID" url="http://www.securityfocus.com/bid/12417">
12417</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:040">MDKSA-2005:040</ref></refs><vuln_soft><prod name="PostgreSQL" vendor="PostgreSQL"><vers num="8.0.0"/><vers num="7.4"/><vers num="7.4.1"/><vers num="7.4.2"/><vers num="7.4.3"/><vers num="7.4.4"/><vers num="7.4.5"/><vers num="7.4.6"/><vers num="7.4.7"/><vers num="7.3"/><vers num="7.3.1"/><vers num="7.3.2"/><vers num="7.3.3"/><vers num="7.3.4"/><vers num="7.3.5"/><vers num="7.3.6"/><vers num="7.3.7"/><vers num="7.3.8"/><vers num="7.3.9"/><vers num="7.2"/><vers num="7.2.1"/><vers num="7.2.2"/><vers num="7.2.3"/><vers num="7.2.4"/><vers num="7.2.5"/><vers num="7.2.6"/><vers num="7.2.7"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-25" name="CVE-2005-0247" published="2005-05-02" seq="2005-0247" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in gram.y for PostgreSQL 8.0.1 and earlier may allow attackers to execute arbitrary code via (1) a large number of variables in a SQL statement being handled by the read_sql_construct function, (2) a large number of INTO variables in a SELECT statement being handled by the make_select_stmt function, (3) a large number of arbitrary variables in a SELECT statement being handled by the make_select_stmt function, and (4) a large number of INTO variables in a FETCH statement being handled by the make_fetch_stmt function, a different set of vulnerabilities than CVE-2005-0245.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref patch="1" source="MLIST" url="http://archives.postgresql.org/pgsql-committers/2005-02/msg00049.php">[pgsql-committers] 20050207 pgsql: Prevent 4 more buffer overruns in the PL/PgSQL parser.</ref><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-683">DSA-683</ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200502-19.xml">GLSA-200502-19</ref><ref patch="1" source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:040">MDKSA-2005:040</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-138.html">RHSA-2005:138</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-150.html">RHSA-2005:150</ref><ref adv="1" patch="1" source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_27_postgresql.html">SUSE-SA:2005:027</ref><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110806034116082&amp;w=2">20050210 [USN-79-1] PostgreSQL vulnerabilities</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19378">postgresql-fetch-makefetchstmt-bo(19378)</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19377">postgresql-makeselectstmt-arbitrary-bo(19377)</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19376">postgresql-makeselectstmt-input-bo(19376)</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/19375">postgresql-readsqlconstruct-bo(19375)</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_36_sudo.html">SUSE-SA:2005:036</ref><ref source="BID" url="http://www.securityfocus.com/bid/12417">
12417</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:040">MDKSA-2005:040</ref></refs><vuln_soft><prod name="PostgreSQL" vendor="PostgreSQL"><vers num="8.0.1"/><vers num="8.0.0"/><vers num="7.4"/><vers num="7.4.1"/><vers num="7.4.2"/><vers num="7.4.3"/><vers num="7.4.4"/><vers num="7.4.5"/><vers num="7.4.6"/><vers num="7.4.7"/><vers num="7.3"/><vers num="7.3.1"/><vers num="7.3.2"/><vers num="7.3.3"/><vers num="7.3.4"/><vers num="7.3.5"/><vers num="7.3.6"/><vers num="7.3.7"/><vers num="7.3.8"/><vers num="7.3.9"/><vers num="7.2"/><vers num="7.2.1"/><vers num="7.2.2"/><vers num="7.2.3"/><vers num="7.2.4"/><vers num="7.2.5"/><vers num="7.2.6"/><vers num="7.2.7"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0248" published="2005-05-02" seq="2005-0248" severity="High" type="CVE"><desc><descript source="cve">The Solaris Management Console (SMC) GUI for Solaris 8 and 9, when creating user accounts that are configured for password aging, creates the accounts with a blank password, which allows remote or local attackers to break into those accounts.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref patch="1" source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57717-1">57717</ref><ref adv="1" source="CIAC" url="http://www.ciac.org/ciac/bulletins/p-096.shtml">P-096</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/12260">12260</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/13803/">13803</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18868">solaris-smc-blank-password(18868)</ref><ref source="BID" url="http://www.securityfocus.com/bid/12260/">12260</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1012860">1012860</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers edition="x86" num="9.0"/><vers edition="SPARC" num="9.0"/><vers edition="x86" num="8.0"/><vers num="8.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-28" name="CVE-2005-0249" published="2005-02-08" seq="2005-0249" severity="High" type="CVE"><desc><descript source="cve">Heap-based buffer overflow in the DEC2EXE module for Symantec AntiVirus Library allows remote attackers to execute arbitrary code via a UPX compressed file containing a negative virtual offset to a crafted PE header.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS" url="http://xforce.iss.net/xforce/alerts/id/187">20050208 Symantec AntiVirus Library Heap Overflow</ref><ref adv="1" patch="1" source="CONFIRM" url="http://www.symantec.com/avcenter/security/Content/2005.02.08.html">http://www.symantec.com/avcenter/security/Content/2005.02.08.html</ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/107822">VU#107822</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18869">upx-engine-gain-control(18869)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013133">1013133</ref></refs><vuln_soft><prod name="Symantec Web Security" vendor="Symantec"><vers num="3.0.1.59"/><vers num="3.0.1.60"/><vers num="3.0.1.61"/><vers num="3.0.1.62"/><vers num="3.0.1.63"/><vers num="3.0.1.67"/><vers num="3.0.1.68"/></prod><prod name="Norton System Works" vendor="Symantec"><vers edition="Windows" num="2004"/><vers edition="Macintosh" num="3.0" prev="1"/></prod><prod name="Norton Internet Security" vendor="Symantec"><vers edition="Professional" num="2004"/><vers edition="Macintosh" num="3.0" prev="1"/></prod><prod name="SAV_Filter Domino NT" vendor="Symantec"><vers num="3.1.1"/></prod><prod name="Symantec Mail Security SMTP" vendor="Symantec"><vers num="4.0.2" prev="1"/></prod><prod name="Symantec Gateway Security" vendor="Symantec"><vers num="2.0"/><vers num="2.0.1"/><vers num="1.0"/></prod><prod name="Symantec AntiVirus Scan Engine Netapp NetCache" vendor="Symantec"><vers num="4.0" prev="1"/><vers num="4.3.3" prev="1"/></prod><prod name="Symantec AntiVirus Scan Engine Netapp Filer" vendor="Symantec"><vers num="4.0" prev="1"/><vers num="4.3.3" prev="1"/></prod><prod name="Mail Security" vendor="Symantec"><vers edition="Exchange" num="4.01 build461"/><vers edition="Exchange" num="4.01 build459"/><vers edition="Exchange" num="4.01 build458"/><vers edition="Exchange" num="4.5 build719"/><vers edition="Domino" num="4.0"/></prod><prod name="BrightMail AntiSpam" vendor="Symantec"><vers num="4.0" prev="1"/><vers num="5.5" prev="1"/></prod><prod name="SAV_Filter Domino NT Ports" vendor="Symantec"><vers edition="AIX" num="build3.0.5"/><vers edition="OS_400" num="build3.0.5"/></prod><prod name="Symantec AntiVirus" vendor="Symantec"><vers edition="Corporate" num="8.1.1 build8.1.1.314a"/><vers edition="Corporate" num="8.1.1 build8.1.1.319"/><vers edition="Corporate" num="8.1.1 build8.1.1.323"/><vers edition="Corporate" num="8.1.1 build8.1.1.329"/><vers edition="Corporate" num="8.01 build8.01.434"/><vers edition="Corporate" num="8.01 build8.01.437"/><vers edition="Corporate" num="8.01 build8.01.446"/><vers edition="Corporate" num="8.01 build8.01.457"/><vers edition="Corporate" num="8.01 build8.01.460"/><vers edition="Corporate" num="8.1 build8.01.464"/><vers edition="Corporate" num="8.01 build8.01.471"/></prod><prod name="Symantec AntiVirus Scan Engine" vendor="Symantec"><vers num="4.0" prev="1"/><vers num="4.3" prev="1"/><vers edition="Bluecoat" num="4.0" prev="1"/><vers edition="Bluecoat" num="4.3.3" prev="1"/><vers edition="Filers" num="4.3.3" prev="1"/><vers edition="Caching" num="4.3.3" prev="1"/></prod><prod name="Norton Antivirus" vendor="Symantec"><vers edition="Windows" num="2004"/><vers edition="Macintosh OSX" num="9.0" prev="1"/><vers edition="Macintosh Corporate" num="9.0"/></prod><prod name="Norton AntiVirus for Exchange" vendor="Symantec"><vers num="2.18 build 83"/></prod><prod name="Symantec Client Security" vendor="Symantec"><vers num="1.1.1 MR1 build 8.1.1.314a"/><vers num="1.1.1 MR2 build 8.1.1.319"/><vers num="1.1.1 MR3 build 8.1.1.323"/><vers num="1.1.1 MR4 build 8.1.1.329"/><vers num="1.1.1 MR5 build 8.1.1.336"/><vers num="1.0.1 MR3 build 8.01.434"/><vers num="1.0.1 build 8.01.437"/><vers num="1.0.1 MR4 build 8.01.446"/><vers num="1.0.1 MR5 build 8.01.457"/><vers num="1.0.1 MR6 build 8.01.460"/><vers num="1.0.1 MR7 build 8.01.464"/><vers num="1.0.1 MR8 build 8.01.471"/></prod><prod name="Symantec AntiVirus SMTP" vendor="Symantec"><vers num="3.1.1"/><vers num="3.1.2"/><vers num="3.1.3"/><vers num="3.1.4"/><vers num="3.1.5"/><vers num="3.1.6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0250" published="2005-05-02" seq="2005-0250" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in auditselect on IBM AIX 5.1, 5.2, and 5.3 allows local users to execute arbitrary code via format string specifiers in a command line argument.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=193&amp;type=vulnerabilities&amp;flashstatus=false">20050208 IBM AIX auditselect Local Format String Vulnerability</ref><ref adv="1" source="AIXAPAR" url="http://www-1.ibm.com/support/docview.wss?uid=isg1IY67519">IY67519</ref><ref adv="1" source="AIXAPAR" url="http://www-1.ibm.com/support/docview.wss?uid=isg1IY67472">IY67472</ref><ref adv="1" source="AIXAPAR" url="http://www-1.ibm.com/support/docview.wss?uid=isg1IY67802">IY67802</ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/896729">VU#896729</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/12496">12496</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/14198">14198</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19255">aix-auditselect-format-string(19255)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013103">1013103</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="5.1"/><vers num="5.2"/><vers num="5.3"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0251" published="2005-05-02" seq="2005-0251" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in bibindex.php for BibORB 1.3.2, and possibly earlier versions, allows remote attackers to inject arbitrary HTML and web script via the search parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110868948719773&amp;w=2">20050217 Advisory: Multiple Vulnerabilities in BibORB</ref><ref adv="1" source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=110864983905770&amp;w=2">20050217 Advisory: Multiple Vulnerabilities in BibORB</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/12583">12583</ref></refs><vuln_soft><prod name="BibORB" vendor="BibORB"><vers num="1.3.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0252" published="2005-05-02" seq="2005-0252" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in BibORB 1.3.2, and possibly earlier versions, allows remote attackers to execute arbitrary SQL commands via the (1) Username or (2) Password.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110868948719773&amp;w=2">20050217 Advisory: Multiple Vulnerabilities in BibORB</ref><ref adv="1" source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=110864983905770&amp;w=2">20050217 Advisory: Multiple Vulnerabilities in BibORB</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/12583">12583</ref></refs><vuln_soft><prod name="BibORB" vendor="BibORB"><vers num="1.3.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0253" published="2005-05-02" seq="2005-0253" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in index.php for BibORB 1.3.2, and possibly earlier versions, allows remote attackers to delete arbitrary files via a Delete action and .. (dot dot) sequences in the database_name parameter.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110868948719773&amp;w=2">20050217 Advisory: Multiple Vulnerabilities in BibORB</ref><ref adv="1" source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=110864983905770&amp;w=2">20050217 Advisory: Multiple Vulnerabilities in BibORB</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/12583">12583</ref></refs><vuln_soft><prod name="BibORB" vendor="BibORB"><vers num="1.3.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0254" published="2005-05-02" seq="2005-0254" severity="Medium" type="CVE"><desc><descript source="cve">BibORB 1.3.2, and possibly earlier versions, does not properly enforce a restriction for uploading only PDF and PS files, which allows remote attackers to upload arbitrary files that are presented to other users with PDF or PS icons, which may trick some users into downloading and executing those files.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110868948719773&amp;w=2">20050217 Advisory: Multiple Vulnerabilities in BibORB</ref><ref adv="1" source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=110864983905770&amp;w=2">20050217 Advisory: Multiple Vulnerabilities in BibORB</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/12583">12583</ref></refs><vuln_soft><prod name="BibORB" vendor="BibORB"><vers num="1.3.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0255" published="2005-05-02" seq="2005-0255" severity="Medium" type="CVE"><desc><descript source="cve">String handling functions in Mozilla 1.7.3, Firefox 1.0, and Thunderbird before 1.0.2, such as the nsTSubstring_CharT::Replace function, do not properly check the return values of other functions that resize the string, which allows remote attackers to cause a denial of service and possibly execute arbitrary code by forcing an out-of-memory state that causes a reallocation to fail and return a pointer to a fixed address, which leads to heap corruption.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=200&amp;type=vulnerabilities">20050228 Mozilla Firefox and Mozilla Browser Out Of Memory Heap Corruption Design Error</ref><ref adv="1" source="CONFIRM" url="http://www.mozilla.org/security/announce/mfsa2005-18.html">http://www.mozilla.org/security/announce/mfsa2005-18.html</ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200503-10.xml">GLSA-200503-10</ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200503-30.xml">GLSA-200503-30</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-277.html">RHSA-2005:277</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-337.html">RHSA-2005:337</ref><ref adv="1" patch="1" source="SUSE" url="http://www.novell.com/linux/security/advisories/2005_16_mozilla_firefox.html">SUSE-SA:2005:016</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval100040.html">OVAL100040</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-176.html">RHSA-2005:176</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_04_25.html">SUSE-SA:2006:022</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19823">19823</ref><ref source="BID" url="http://www.securityfocus.com/bid/12659">12659</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:100040">oval:org.mitre.oval:def:100040</ref></refs><vuln_soft><prod name="Mozilla" vendor="Mozilla"><vers num="1.7.3"/></prod><prod name="Thunderbird" vendor="Mozilla"><vers num="1.0"/><vers num="0.9"/><vers num="0.8"/><vers num="0.7"/><vers num="0.6"/><vers num="0.5"/><vers num="0.4"/><vers num="0.3"/><vers num="0.2"/><vers num="0.1"/></prod><prod name="Firefox" vendor="Mozilla"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2008-01-03" name="CVE-2005-0256" published="2005-05-02" seq="2005-0256" severity="Medium" type="CVE"><desc><descript source="cve">The wu_fnmatch function in wu_fnmatch.c in wu-ftpd 2.6.1 and 2.6.2 allows remote attackers to cause a denial of service (CPU exhaustion by recursion) via a glob pattern with a large number of * (wildcard) characters, as demonstrated using the dir command.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=207&amp;type=vulnerabilities">20050225 WU-FTPD File Globbing Denial of Service Vulnerability</ref><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2005/dsa-705">DSA-705</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57795-1">57795</ref><ref source="SCO" url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.63/SCOSA-2005.63.txt">SCOSA-2005.63</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18210">18210</ref><ref source="HP" url="http://itrc.hp.com/service/cki/docDisplay.do?docId=c00637342">HPSBUX02110</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2005/0588">ADV-2005-0588</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1271">ADV-2006-1271</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/14411">14411</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19561">19561</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101699-1">101699</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1265">oval:org.mitre.oval:def:1265</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1333">oval:org.mitre.oval:def:1333</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1762">oval:org.mitre.oval:def:1762</ref><ref source="OSVDB" url="http://www.osvdb.org/14203">14203</ref></refs><vuln_soft><prod name="wu-ftpd" vendor="Washington University"><vers num="2.6.1"/><vers num="2.6.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0258" published="2005-03-14" seq="2005-0258" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in (1) usercp_register.php and (2) usercp_avatar.php for phpBB 2.0.11, and possibly other versions, with gallery avatars enabled, allows remote attackers to delete (unlink) arbitrary files via &quot;/../&quot; sequences in the avatarselect parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="iDefense" url="http://www.idefense.com/application/poi/display?id=205&amp;type=vulnerabilities">phpBB Group phpBB2 Arbitrary File Unlink Vulnerability</ref><ref adv="1" source="Phpbb.com" url="http://www.phpbb.com/support/documents.php?mode=changelog">PhPBB CHANGELOG</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/12623">bid 12623</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200503-02.xml">GLSA-200503-02</ref></refs><vuln_soft><prod name="PhpBB" vendor="PhpBB Group"><vers num="2.0.0"/><vers num="2.0 RC4"/><vers num="2.0 RC3"/><vers num="2.0 RC2"/><vers num="2.0 RC1"/><vers num="2.0 Beta1"/><vers num="2.0.1"/><vers num="2.0.2"/><vers num="2.0.3"/><vers num="2.0.4"/><vers num="2.0.5"/><vers num="2.0.6d"/><vers num="2.0.6c"/><vers num="2.0.6"/><vers num="2.0.7a"/><vers num="2.0.7"/><vers num="2.0.8a"/><vers num="2.0.8"/><vers num="2.0.9"/><vers num="2.0.10"/><vers num="2.0.11"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0259" published="2005-03-14" seq="2005-0259" severity="Medium" type="CVE"><desc><descript source="cve">phpBB 2.0.11, and possibly other versions, with remote avatars and avatar uploading enabled, allows local users to read arbitrary files by providing both a local and remote location for an avatar, then modifying the &quot;Upload Avatar from a URL:&quot; field to reference the target file.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="iDefense" url="http://www.idefense.com/application/poi/display?id=204&amp;type=vulnerabilities">phpBB Group phpBB Arbitrary File Disclosure Vulnerability</ref><ref adv="1" source="Phpbb.com" url="http://www.phpbb.com/support/documents.php?mode=changelog">PhPBB CHANGELOG</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/12621">bid 12621</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200503-02.xml">GLSA-200503-02</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/774686">VU#774686</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14362/">14362</ref></refs><vuln_soft><prod name="PhpBB" vendor="PhpBB Group"><vers num="2.0.0"/><vers num="2.0 RC4"/><vers num="2.0 RC3"/><vers num="2.0 RC2"/><vers num="2.0 RC1"/><vers num="2.0 Beta1"/><vers num="2.0.1"/><vers num="2.0.2"/><vers num="2.0.3"/><vers num="2.0.4"/><vers num="2.0.5"/><vers num="2.0.6d"/><vers num="2.0.6c"/><vers num="2.0.6"/><vers num="2.0.7a"/><vers num="2.0.7"/><vers num="2.0.8a"/><vers num="2.0.8"/><vers num="2.0.9"/><vers num="2.0.10"/><vers num="2.0.11"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0260" published="2005-05-02" seq="2005-0260" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in the Discovery Service for BrightStor ARCserve Backup 11.1 and earlier allows remote attackers to execute arbitrary code via a long packet to UDP port 41524, which is not properly handled in a recvfrom call.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=194&amp;type=vulnerabilities">20050209 Computer Associates BrightStor ARCserve Backup v11 Discovery Service Remote Buffer Overflow Vulnerability</ref><ref patch="1" source="CONFIRM" url="http://supportconnectw.ca.com/public/enews/BrightStor/brigcurrent.asp#news1">http://supportconnectw.ca.com/public/enews/BrightStor/brigcurrent.asp#news1</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19251">brightstor-discovery-bo(19251)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1013138">1013138</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14183">14183</ref></refs><vuln_soft><prod name="BrightStor ARCServe Backup" vendor="Computer Associates"><vers num="11.1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0261" published="2005-02-10" seq="2005-0261" severity="Low" type="CVE"><desc><descript source="cve">lspath in AIX 5.2, 5.3, and possibly earlier versions, does not drop privileges before processing the -f option, which allows local users to read one line of arbitrary files.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=195&amp;type=vulnerabilities">20050210 IBM AIX lspath Local File Access Vulnerability</ref><ref adv="1" patch="1" source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY67457&amp;apar=only">IY67457</ref><ref adv="1" patch="1" source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY67655&amp;apar=only">IY67655</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19281">ibm-aix-ispath-information-disclosure(19281)</ref><ref source="BID" url="http://www.securityfocus.com/bid/12513">12513</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14232">14232</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="5.3"/><vers num="5.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0262" published="2005-05-02" seq="2005-0262" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in ipl_varyon on AIX 5.1, 5.2, and 5.3 allows local users to execute arbitrary code via a long -d argument.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=196&amp;type=vulnerabilities">20050210 IBM AIX ipl_varyon Local Buffer Overflow Vulnerability</ref><ref source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY67812&amp;apar=only">IY67812</ref><ref source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY67750&amp;apar=only">IY67750</ref><ref source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY66933&amp;apar=only">IY66933</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19282">ibm-aix-iplvaryon-bo(19282)</ref><ref source="BID" url="http://www.securityfocus.com/bid/12516">12516</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14231">14231</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="5.1"/><vers num="5.2"/><vers num="5.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0263" published="2005-05-02" seq="2005-0263" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in netpmon on AIX 5.1, 5.2, and 5.3 allows local users to execute arbitrary code via a long -O argument.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="IDEFENSE" url="http://www.idefense.com/application/poi/display?id=197&amp;type=vulnerabilities">20050210 IBM AIX netpmon Local Buffer Overflow Vulnerability</ref><ref source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY67807&amp;apar=only">IY67807</ref><ref source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY67136&amp;apar=only">IY67136</ref><ref source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY67124&amp;apar=only">IY67124</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19278">ibm-aix-netpmon-bo(19278)</ref><ref source="BID" url="http://www.securityfocus.com/bid/12517">12517</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14237">14237</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="5.1"/><vers num="5.2"/><vers num="5.3"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0264" published="2005-05-02" seq="2005-0264" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in browse.php in OWL 0.7 and 0.8 allow remote attackers to inject arbitrary web script or HTML via the (1) expand or (2) order parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110461644407935&amp;w=2">20050101 Various Vulnerabilities in OWL Intranet Engine</ref><ref source="BID" url="http://www.securityfocus.com/bid/12114">12114</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18705">owl-intranet-engine-xss(18705)</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13695">13695</ref></refs><vuln_soft><prod name="Owl Intranet Engine" vendor="Owl"><vers num="0.73"/><vers num="0.72"/><vers num="0.71"/><vers num="0.7"/><vers num="0.6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0265" published="2005-05-02" seq="2005-0265" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in browse.php in OWL 0.7 and 0.8 allow remote attackers to execute arbitrary SQL commands via the (1) parent or (2) sortposted parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110461644407935&amp;w=2">20050101 Various Vulnerabilities in OWL Intranet Engine</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/12114">12114</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18704">owl-intranet-engine-sql-injection(18704)</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13695">13695</ref></refs><vuln_soft><prod name="Owl Intranet Engine" vendor="Owl"><vers num="0.7"/><vers num="0.8"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0266" published="2005-01-01" seq="2005-0266" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in SugarCRM 1.X allows remote attackers to inject arbitrary web script or HTML via the (1) return_module, (2) return_action, (3) name, (4) module, or (5) record parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110461706232174&amp;w=2">20050101 Cross Site Scripting Vulnerabilities and Possible Code Execution</ref><ref source="BID" url="http://www.securityfocus.com/bid/12113">12113</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18719">sugar-sales-index-xss(18719)</ref></refs><vuln_soft><prod name="SugarCRM" vendor="SugarCRM"><vers num="2.0.1a"/><vers num="2.0.1"/><vers num="1.5d"/><vers num="1.1f"/><vers num="1.1e"/><vers num="1.1d"/><vers num="1.1c"/><vers num="1.1b"/><vers num="1.1a"/><vers num="1.1"/><vers num="1.0g"/><vers num="1.0f"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0267" published="2005-05-02" seq="2005-0267" severity="High" type="CVE"><desc><descript source="cve">index.php in FlatNuke 2.5.1 allows remote attackers to create an andministrator account via carriage returns and #10 in the url_avatar field, which is interpreted as a sensitive directive.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110477752916772&amp;w=2">20050102 Multiple Vulnerabilities in FlatNuke</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/12150">12150</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18741">flatnuke-indexphp-gain-access(18741)</ref></refs><vuln_soft><prod name="FlatNuke" vendor="FlatNuke"><vers num="2.5.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0268" published="2005-01-03" seq="2005-0268" severity="High" type="CVE"><desc><descript source="cve">Direct code injection vulnerability in FlatNuke 2.5.1 allows remote attackers to execute arbitrary PHP code by placing the code into the url_avatar field.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110477752916772&amp;w=2">20050102 Multiple Vulnerabilities in FlatNuke</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/12150">12150</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18746">flatnuke-indexphp-xss(18746)</ref></refs><vuln_soft><prod name="FlatNuke" vendor="FlatNuke"><vers num="2.5.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-06-15" name="CVE-2005-0269" published="2005-05-02" seq="2005-0269" severity="High" type="CVE"><desc><descript source="cve">The file extension check in GNUBoard 3.40 and earlier only verifies extensions that contain all lowercase letters, which allows remote attackers to upload arbitrary files via file extensions that include uppercase letters.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110477648219738&amp;w=2">20050103 STG Security Advisory: [SSA-20041224-21] File extensions</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18729">gnuboard-gbupdate-file-upload(18729)</ref><ref source="BID" url="http://www.securityfocus.com/bid/12149">12149</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13711">13711</ref></refs><vuln_soft><prod name="GNUBoard" vendor="SIR"><vers num="3.40"/><vers num="3.39"/><vers num="3.38"/><vers num="3.37"/><vers num="3.36"/><vers num="3.35"/><vers num="3.34"/><vers num="3.33"/><vers num="3.32"/><vers num="3.31"/><vers num="3.30"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-22" name="CVE-2005-0270" published="2005-05-02" seq="2005-0270" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in ReviewPost PHP Pro before 2.84 allow remote attackers to inject arbitrary web script or HTML via the (1) si parameter to showcat.php, (2) cat or (3) page parameter to showproduct.php, or (4) report parameter to reportproduct.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110485682424110&amp;w=2">20050103 Serious Vulnerabilities In PhotoPost ReviewPost</ref><ref adv="1" source="MISC" url="http://www.gulftech.org/?node=research&amp;article_id=00062-01022005">http://www.gulftech.org/?node=research&amp;article_id=00062-01022005</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/13697/">13697</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18731">reviewpost-php-xss(18731)</ref></refs><vuln_soft><prod name="ReviewPost PHP Pro" vendor="PhotoPost"><vers num="2.84" prev="1"/><vers num="2.5.1"/><vers num="2.5"/><vers num="1.0.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-22" name="CVE-2005-0271" published="2005-01-03" seq="2005-0271" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in ReviewPost PHP Pro before 2.84 allow remote attackers to execute arbitrary SQL commands via the (1) cat parameter to showcat.php or (2) product parameter to addfav.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110485682424110&amp;w=2">20050103 Serious Vulnerabilities In PhotoPost ReviewPost</ref><ref adv="1" patch="1" source="MISC" url="http://www.gulftech.org/?node=research&amp;article_id=00062-01022005">http://www.gulftech.org/?node=research&amp;article_id=00062-01022005</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/13697/">13697</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18732">reviewpost-php-sql-injection(18732)</ref></refs><vuln_soft><prod name="ReviewPost PHP Pro" vendor="PhotoPost"><vers num="2.5.1" prev="1"/><vers num="2.5"/><vers num="1.0.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-22" name="CVE-2005-0272" published="2005-05-02" seq="2005-0272" severity="High" type="CVE"><desc><descript source="cve">ReviewPost PHP Pro before 2.84 allows remote attackers to upload and execute arbitrary PHP files by posting a review file with multiple extensions, which bypasses the intended restrictions.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110485682424110&amp;w=2">20050103 Serious Vulnerabilities In PhotoPost ReviewPost</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/13697/">13697</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18735">reviewpost-php-file-upload(18735)</ref></refs><vuln_soft><prod name="ReviewPost PHP Pro" vendor="PhotoPost"><vers num="2.5.1" prev="1"/><vers num="2.5"/><vers num="1.0.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-27" name="CVE-2005-0273" published="2005-05-02" seq="2005-0273" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in showgallery.php in PhotoPost before 4.86 allow remote attackers to execute arbitrary SQL commands via the (1) cat or (2) ppuser parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110486165802196&amp;w=2">20050103 Multiple PhotoPost Pro Vulnerabilities</ref><ref adv="1" source="MISC" url="http://www.gulftech.org/?node=research&amp;article_id=00063-01032005">http://www.gulftech.org/?node=research&amp;article_id=00063-01032005</ref><ref source="BID" url="http://www.securityfocus.com/bid/12156">12156</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/13680/">13680</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18744">photopost-php-showgallery-xss(18744)</ref></refs><vuln_soft><prod name="PhotoPost PHP Pro" vendor="PhotoPost"><vers num="4.85" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-27" name="CVE-2005-0274" published="2005-01-03" seq="2005-0274" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in showgallery.php in PhotoPost before 4.86 allow remote attackers to inject arbitrary web script or HTML via the (1) cat, (2) si, (3) page, or (4) ppuser parameters.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110486165802196&amp;w=2">20050103 Multiple PhotoPost Pro Vulnerabilities</ref><ref adv="1" patch="1" source="MISC" url="http://www.gulftech.org/?node=research&amp;article_id=00063-01032005">http://www.gulftech.org/?node=research&amp;article_id=00063-01032005</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/12156">12156</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/13680/">13680</ref><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18744">photopost-php-showgallery-xss(18744)</ref></refs><vuln_soft><prod name="PhotoPost PHP Pro" vendor="PhotoPost"><vers num="4.85" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0275" published="2005-05-02" seq="2005-0275" severity="Medium" type="CVE"><desc><descript source="cve">TFTP in 3Com 3CDaemon 2.0 revision 10 allows remote attackers to cause a denial of service (application crash) via a GET request containing an MS-DOS device name.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110485674622696&amp;w=2">20050104 3Com 3CDaemon Multiple Vulnerabilities</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18750">3cdaemon-reserved-name-dos(18750)</ref></refs><vuln_soft><prod name="3CDaemon" vendor="3Com"><vers num="2.0 revision 10"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0276" published="2005-05-02" seq="2005-0276" severity="Medium" type="CVE"><desc><descript source="cve">Multiple format string vulnerabilities in the FTP service in 3Com 3CDaemon 2.0 revision 10 allow remote attackers to cause a denial of service (application crash) via format string specifiers in (1) the username, (2) cd, (3) delete, (4) rename, (5) rmdir, (6) literal, (7) stat, or (8) CWD commands.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110485674622696&amp;w=2">20050104 3Com 3CDaemon Multiple Vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/12155">12155</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18751">3cdaemon-login-dos(18751)</ref></refs><vuln_soft><prod name="3CDaemon" vendor="3Com"><vers num="2.0 revision 10"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0277" published="2005-05-02" seq="2005-0277" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in the FTP service in 3Com 3CDaemon 2.0 revision 10 allows remote attackers to cause a denial of service (application crash) and execute arbitrary code via (1) a long username in the USER command or (2) an FTP command that contains a long argument, such as cd, send, or ls.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110485674622696&amp;w=2">20050104 3Com 3CDaemon Multiple Vulnerabilities</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110886719528518&amp;w=2">20050218 3com 3CDaemon FTP Unauthorized </ref><ref source="BID" url="http://www.securityfocus.com/bid/12155">12155</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18754">3cdaemon-long-command-dos(18754)</ref></refs><vuln_soft><prod name="3CDaemon" vendor="3Com"><vers num="2.0 revision 10"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0278" published="2005-05-02" seq="2005-0278" severity="Medium" type="CVE"><desc><descript source="cve">The FTP service in 3Com 3CDaemon 2.0 revision 10 allows remote attackers to gain sensitive information via a cd command that contains an MS-DOS device name, which reveals the installation path in an error message.</descript></desc><loss_types><conf/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110485674622696&amp;w=2">20050104 3Com 3CDaemon Multiple Vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/12155">12155</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18756">3cdaemon-command-obtain-information(18756)</ref></refs><vuln_soft><prod name="3CDaemon" vendor="3Com"><vers num="2.0 revision 10"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-08-23" name="CVE-2005-0279" published="2005-05-02" seq="2005-0279" severity="Medium" type="CVE"><desc><descript source="cve">Soldner Secret Wars 30830 and earlier does not properly handle the &quot;message too long&quot; socket error, which allows remote attackers to cause a denial of service (socket termination) via a long UDP packet.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110486654213504&amp;w=2">20050104 Socket termination, format string and XSS in Soldner Secret Wars</ref><ref source="BID" url="http://www.securityfocus.com/bid/12162">12162</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18749">soldner-secret-wars-dos(18749)</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13716">13716</ref></refs><vuln_soft><prod name="Soldner Secret Wars" vendor="Jowood Productions"><vers num="30830" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-08-23" name="CVE-2005-0280" published="2005-01-04" seq="2005-0280" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in Soldner Secret Wars 30830 and earlier allows remote attackers to cause a denial of service (server crash) and possibly execute arbitrary code via format string specifiers in a message.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110486654213504&amp;w=2">20050104 Socket termination, format string and XSS in Soldner Secret Wars</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/12162">12162</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18752">soldner-secret-wars-format-string(18752)</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13716">13716</ref></refs><vuln_soft><prod name="Soldner Secret Wars" vendor="Jowood Productions"><vers num="30830"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-08-23" name="CVE-2005-0281" published="2005-05-02" seq="2005-0281" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in the web interface in Soldner Secret Wars 30830 allows remote attackers to inject arbitrary web script or HTML via a user message, which is not filtered or quoted when the administrator views the server logs.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110486654213504&amp;w=2">20050104 Socket termination, format string and XSS in Soldner Secret Wars</ref><ref source="BID" url="http://www.securityfocus.com/bid/12162">12162</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18753">soldner-secret-wars-xss(18753)</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13716">13716</ref></refs><vuln_soft><prod name="Soldner Secret Wars" vendor="Jowood Productions"><vers num="30830" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0282" published="2005-05-02" seq="2005-0282" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in member.php in MyBulletinBoard (MyBB) allows remote attackers to execute arbitrary SQL commands via the uid parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110486566600980&amp;w=2">20050104 MyBB SQL Injection</ref><ref source="BID" url="http://www.securityfocus.com/bid/12161">12161</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/187">mybb-member-sql-injection(18755)</ref></refs><vuln_soft><prod name="MyBulletinBoard" vendor="MyBulletinBoard"><vers num="1.0 RC4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0283" published="2005-01-04" seq="2005-0283" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in index.php in QwikiWiki allows remote attackers to read arbitrary files via a .. (dot dot) and a %00 at the end of the filename in the page parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110486832621053&amp;w=2">20050104 QWikiwiki directory traversal vulnerability</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/12163">12163</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18748">qwikiwiki-directory-traversal(18748)</ref><ref source="" url="http://www.qwikiwiki.com/index.php?page=QwikiVulnerability"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/12044">12044</ref></refs><vuln_soft><prod name="QwikiWiki" vendor="David Barrett"><vers num="1.4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0284" published="2005-01-10" seq="2005-0284" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in addentry.php in Woltlab Burning Book 1.0 Gold, 1.1.1e, and possibly other versions, allows remote attackers to execute arbitrary SQL commands via the user-agent parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110548032401506&amp;w=2">20050110 Woltlab Burning Book addentry.php SQL Injection</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18859">woltlab-book-addentry-sql-injection(18859)</ref></refs><vuln_soft><prod name="Burning Book" vendor="Woltlab"><vers num="1.0 Gold"/><vers num="1.1.1e"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0285" published="2005-05-02" seq="2005-0285" severity="Medium" type="CVE"><desc><descript source="cve">Webseries Payment Application does not properly restrict privileged operations, which allows remote authenticated users to gain privileges by directly accessing certain URLs.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110547396124885&amp;w=2">20050110 Portcullis Security Advisory 05-001</ref><ref source="BID" url="http://www.securityfocus.com/bid/12216">12216</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18848">webseries-pa-url-security-bypass(18848)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1012854">1012854</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13821">13821</ref></refs><vuln_soft><prod name="WebSeries Payment Application" vendor="BottomLine"><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0286" published="2005-05-02" seq="2005-0286" severity="Medium" type="CVE"><desc><descript source="cve">eMotion MediaPartner Web Server 5.0 and 5.1 allows remote attackers to obtain sensitive information via an HTTP request for a .bhtml file that contains a (1) . (dot) or (2) + (plus sign) at the end, which returns the source code for that file.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110547824902053&amp;w=2">20050110 Portcullis Security Advisory 05-004</ref><ref source="BID" url="http://www.securityfocus.com/bid/12236">12236</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18861">mediapartner-bhtml-source-disclosure(18861)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1012855">1012855</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13820">13820</ref></refs><vuln_soft><prod name="MediaPartner Web Server" vendor="eMotion"><vers num="5.0"/><vers num="5.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0287" published="2005-01-10" seq="2005-0287" severity="Medium" type="CVE"><desc><descript source="cve">Bottomline Webseries Payment Application allows remote attackers to read arbitrary files on the network via a report template with modified ReportPath or ReportName values.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110548383812462&amp;w=2">20050110 Portcullis Security Advisory 05-009</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18862">webseries-report-execution(18862)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1012854">1012854</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13821">13821</ref></refs><vuln_soft><prod name="WebSeries Payment Application" vendor="BottomLine"><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="3.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="4.9" CVSS_score="3.6" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0288" published="2005-01-11" seq="2005-0288" severity="Low" type="CVE"><desc><descript source="cve">The change password functionality in Bottomline Webseries Payment Application does not require the old password when users enter a new password, which could allow remote authenticated users to change other users&apos; passwords.</descript></desc><loss_types><avail/><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110549684319400&amp;w=2">20050110 Portcullis Security Advisory 05-008</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/12231">12231</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18860">webseries-pa-password-gain-access(18860)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1012854">1012854</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13821">13821</ref></refs><vuln_soft><prod name="WebSeries Payment Application" vendor="BottomLine"><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0289" published="2005-05-02" seq="2005-0289" severity="Medium" type="CVE"><desc><descript source="cve">Apple AirPort Express prior to 6.1.1 and Extreme prior to 5.5.1, configured as a Wireless Data Service (WDS), allows remote attackers to cause a denial of service (device freeze) by connecting to UDP port 161 and before link-state change occurs.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110582124528867&amp;w=2">20050115 Apple Airport WDS DoS</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18865">apple-airport-dos(18865)</ref><ref source="BID" url="http://www.securityfocus.com/bid/12152">12152</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13753">13753</ref></refs><vuln_soft><prod name="AirPort Express" vendor="Apple"><vers num="6.1" prev="1"/></prod><prod name="AirPort Extreme" vendor="Apple"><vers num="5.5" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0290" published="2005-01-17" seq="2005-0290" severity="High" type="CVE"><desc><descript source="cve">NETGEAR FVS318 running firmware 2.4, and possibly other versions, allows remote attackers to bypass the filters using hex encoded URLs, as demonstrated using a hex encoded file extension.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><access/><input/></vuln_types><range><network/></range><refs><ref adv="1" source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-January/030984.html">20050117 Multiple Vulnerabilities in Netgear FVS318 Router</ref><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110599727631560&amp;w=2">20050117 Multiple Vulnerabilities in Netgear FVS318 Router</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/12278">12278</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18920">netgear-fvs318-filter-bypass(18920)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1012913">1012913</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13787">13787</ref></refs><vuln_soft><prod name="FVS318v2" vendor="NetGear"><vers num="2.4"/></prod><prod name="FVS318" vendor="NetGear"><vers num="2.4"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0291" published="2005-01-17" seq="2005-0291" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in the log viewer in NETGEAR FVS318 running firmware 2.4, and possibly other versions, allows remote attackers to inject arbitrary web script or HTML via a blocked URL phrase.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-January/030984.html">20050117 Multiple Vulnerabilities in Netgear FVS318 Router</ref><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110599727631560&amp;w=2">20050117 Multiple Vulnerabilities in Netgear FVS318 Router</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/12278">12278</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18921">netgear-fvs318-log-xss(18921)</ref><ref source="OSVDB" url="http://www.osvdb.org/13012">13012</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1012913">1012913</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13787">13787</ref></refs><vuln_soft><prod name="FVS318v2" vendor="NetGear"><vers num="2.4"/></prod><prod name="FVS318" vendor="NetGear"><vers num="2.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0292" published="2005-01-17" seq="2005-0292" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in index.php in PHP Gift Registry (phpGiftReg) 1.4.0, and possibly other versions before 1.5.0b1, allow remote attackers to execute arbitrary SQL commands via the (1) messageid, (2) shopper, (3) shopfor, or (4) itemid parameters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-January/030965.html">20050116 phpGiftReq SQL Injection</ref><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110599710017066&amp;w=2">20050116 phpGiftReq SQL Injection</ref><ref adv="1" patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/392485">20050307 Re: phpGiftReq SQL Injection</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/12289">12289</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/13873">13873</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18925">phpgiftregistry-sql-injection(18925)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1012910">1012910</ref></refs><vuln_soft><prod name="phpgiftreg" vendor="PHP Gift Registry"><vers num="1.4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0293" published="2005-05-02" seq="2005-0293" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in minis.php in Minis 0.2.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the month parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110599953704025&amp;w=2">20050116 Minis directory traversal vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/12279">12279</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/18928">minis-month-directory-traversal(18928)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1012911">1012911</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13866">13866</ref></refs><vuln_soft><prod name="Minis" vendor="Minis"><vers num="0.2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0294" published="2005-01-16" seq="2005-0294" severity="Medium" type="CVE"><desc><descript source="cve">minis.php in Minis 0.2.1 allows remote attackers to cause a denial of service (infinite loop) via an HTTP request for a file that the web server does not have permission to read, as demonstrated using the month parameter.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2005-January/030966.html">20050116 Minis directory traversal vulnerability</ref><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110599953704025&amp;w=2">20050116 Minis directory traversal vulnerability</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18929">minis-month-dos(18929)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1012911">1012911</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13866">13866</ref></refs><vuln_soft><prod name="Minis" vendor="Minis"><vers num="0.2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0295" published="2005-01-17" seq="2005-0295" severity="Medium" type="CVE"><desc><descript source="cve">npptnt2.sys in nProtect Gameguard provides unrestricted I/O to any process that calls it, which allows local users to gain privileges.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110608422029555&amp;w=2">20050116 Unrestricted I/O access vulnerability in INCA Gameguard</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/12280">12280</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18952">nprotect-npptnt2-gain-access(18952)</ref><ref source="SECUNIA" url="http://secunia.com/advisories/13928">13928</ref></refs><vuln_soft><prod name="nProtect Gameguard" vendor="INCA"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0296" published="2005-01-17" seq="2005-0296" severity="Medium" type="CVE"><desc><descript source="cve">** DISPUTED **  NOTE: this issue has been disputed by the vendor.  The error module in Novell GroupWise WebAccess allows remote attackers who have not authenticated to read potentially sensitive information, such as the version, via an incorrect login and a modified (1) error or (2) modify parameter that returns template files or the &quot;about&quot; information page.  NOTE: the vendor has disputed this issue.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110608203729814&amp;w=2">20050117 Novell GroupWise WebAccess error modules loading</ref><ref adv="1" source="FULLDISC" url="http://www.derkeiler.com/Mailing-Lists/Full-Disclosure/2005-01/0771.html">20050121 NOVL-2005-10096251 GroupWise WebAccess error handling modules (report)</ref><ref adv="1" source="BUGTRAQ" url="http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2005-01/0341.html">20050127 NOVL-2005-10096251 GroupWise WebAccess error handling modules (report)</ref><ref adv="1" source="MISC" url="http://support.novell.com/servlet/tidfinder/10096251">http://support.novell.com/servlet/tidfinder/10096251</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/12285">12285</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/18954">groupwise-error-auth-bypass(18954)</ref><ref source="OSVDB" url="http://www.osvdb.org/13135">13135</ref></refs><vuln_soft><prod name="GroupWise WebAccess" vendor="Novell"><vers num="6.5 SP2"/><vers num="6.5 SP1"/><vers num="6.5"/><vers num="6.0 SP4"/></prod><prod name="Groupwise" vendor="Novell"><vers num="6.5 SP2"/><vers num="6.5 SP1"/><vers num="6.5"/><vers num="6.0 SP4"/><vers num="6.0 SP3"/><vers num="6.0 SP2"/><vers num="6.0 SP1"/><vers num="6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2005-0297" published="2005-01-18" seq="2005-0297" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in Oracle Database 9i and 10g allows remote attackers to execute arbitrary SQL commands and gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110606477308492&amp;w=2">20050118 Multiple high risk vulnerabilities in Oracle RDBMS 10g/9i</ref></refs><vuln_soft><prod name="Oracle9i Database Server" vendor="Oracle"><vers num=""/></prod><prod name="Oracle1