<?xml version="1.0" encoding="UTF-8"?>
<nvd nvd_xml_version="1.2" pub_date="2008-09-05" xmlns="http://nvd.nist.gov/feeds/cve/1.2" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://nvd.nist.gov/feeds/cve/1.2 http://nvd.nist.gov/schema/nvdcve.xsd"><!--This XML file has been upgraded to support CVSS version 2.  The following new attributes have been added to CVS entries:
* CVSS_version - Indicates the version of the CVSS data
* CVSS_base_score - The CVSSv2 base score
* CVSS_impact_subscore - The CVSSv2 impact sub-score
* CVSS_exploit_subscore - the CVSSv2 exploit sub-score

The following attributes have been mapped to new content in CVS entries:
* CVSS_score - This attribute is the same as the CVSS_base_score and is now deprecated.
* CVSS_vector - Contains the new CVSSv2 vector string--><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" discovered="2005-08-03" modified="2007-06-26" name="CVE-2006-0001" published="2006-09-12" seq="2006-0001" severity="Medium" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in Microsoft Publisher 2000 through 2003 allows user-assisted remote attackers to execute arbitrary code via a crafted PUB file, which causes an overflow when parsing fonts.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/445824/100/0/threaded">20060912 Computer Terrorism (UK) :: Incident Response Centre - Microsoft Publisher Font Parsing Vulnerability</ref><ref adv="1" patch="1" source="" url="http://www.computerterrorism.com/research/ct12-09-2006-2.htm">Security Advisory : CT12-09-2006-2</ref><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/Bulletin/MS06-054.mspx">MS06-054</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/19951">19951</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/3565">ADV-2006-3565</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/21863">21863</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-255A.html">TA06-255A</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/406236">VU#406236</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1016825">1016825</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/28648">publisher-pub-code-execution(28648)</ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/446630/100/100/threaded">HPSBST02134</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:590">oval:org.mitre.oval:def:590</ref><ref source="SREASON" url="http://securityreason.com/securityalert/1548">1548</ref></refs><vuln_soft><prod name="Office" vendor="Microsoft"><vers num="2000 SP3"/><vers num="XP SP3"/><vers num="2003 SP1"/><vers num="2003 SP2"/></prod><prod name="Publisher" vendor="Microsoft"><vers num="2000"/><vers num="2002"/><vers num="2003"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-05" name="CVE-2006-0002" published="2006-01-10" seq="2006-0002" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Microsoft Outlook 2000 through 2003, Exchange 5.0 Server SP2 and 5.5 SP4, Exchange 2000 SP3, and Office allows remote attackers to execute arbitrary code via an e-mail message with a crafted Transport Neutral Encapsulation Format (TNEF) MIME attachment, related to message length validation.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms06-003.mspx">MS06-003</ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/252146">VU#252146</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16197">16197</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0119">ADV-2006-0119</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18368">18368</ref><ref patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421520/100/0/threaded">20060110 Microsoft Outlook Critical Vulnerability</ref><ref patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421518/100/0/threaded">20060110 Microsoft Exchange Critical Vulnerability</ref><ref adv="1" patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-010A.html">TA06-010A</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015461">1015461</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015460">1015460</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-004.htm"></ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1082">oval:org.mitre.oval:def:1082</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1165">oval:org.mitre.oval:def:1165</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1316">oval:org.mitre.oval:def:1316</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1456">oval:org.mitre.oval:def:1456</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1485">oval:org.mitre.oval:def:1485</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:624">oval:org.mitre.oval:def:624</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/22878">
win-tnef-overflow(22878)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/330">330</ref><ref source="SREASON" url="http://securityreason.com/securityalert/331">331</ref></refs><vuln_soft><prod name="exchange srv" vendor="Microsoft"><vers num="2000 SP3"/><vers num="5.5 SP4"/><vers num="5.5 SP3"/><vers num="5.5 SP2"/><vers num="5.5 SP1"/><vers num="5.5"/><vers num="5.0 SP2"/><vers num="5.0 SP1"/><vers num="5.0"/></prod><prod name="Office" vendor="Microsoft"><vers num="XP SP3"/><vers num="2003 SP2"/><vers num="2003 SP1"/><vers num="2000 SP3"/></prod><prod name="Outlook" vendor="Microsoft"><vers num="2003"/><vers num="2002 SP3"/><vers num="2000 SP3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-13" name="CVE-2006-0003" published="2006-04-11" seq="2006-0003" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the RDS.Dataspace ActiveX control, which is contained in ActiveX Data Objects (ADO) and distributed in Microsoft Data Access Components (MDAC) 2.7 and 2.8, allows remote attackers to execute arbitrary code via unknown attack vectors.</descript></desc><sols><sol source="nvd">http://www.microsoft.com/technet/security/Bulletin/MS06-014.mspx</sol></sols><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><range><network/><user_init/></range><refs><ref adv="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms06-014.mspx">MS06-014</ref><ref adv="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-101A.html">TA06-101A</ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/234812">VU#234812</ref><ref source="BID" url="http://www.securityfocus.com/bid/17462">17462</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1319">ADV-2006-1319</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19583">19583</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015894">1015894</ref><ref source="" url="http://www.hitachi-support.com/security_e/vuls_e/HS06-013_e/01-e.html"></ref><ref source="" url="http://www.hitachi-support.com/security_e/vuls_e/HS06-013_e/index-e.html"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/2452">ADV-2006-2452</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20719">20719</ref><ref source="OSVDB" url="http://www.osvdb.org/24517">24517</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1204">oval:org.mitre.oval:def:1204</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1323">oval:org.mitre.oval:def:1323</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1511">oval:org.mitre.oval:def:1511</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1742">oval:org.mitre.oval:def:1742</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1778">oval:org.mitre.oval:def:1778</ref><ref source="" url="http://www.securityfocus.com/data/vulnerabilities/exploits/0day_ie.pdf"></ref><ref source="BID" url="http://www.securityfocus.com/bid/20797">
20797</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25006">
mdac-rdsdataspace-execute-code(25006)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/29915">
ie-wscriptshell-command-execution(29915)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/475104/100/100/threaded">20070729 Exploit In Internet Explorer</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/475118/100/100/threaded">20070730 RE: Exploit In Internet Explorer</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/475108/100/100/threaded">20070730 Re: Exploit In Internet Explorer</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/475490/100/100/threaded">20070731 Re: Exploit In Internet Explorer</ref><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/2052">2052</ref><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/2164">2164</ref></refs><vuln_soft><prod name="MDAC" vendor="Microsoft"><vers num="2.8"/><vers num="2.7 SP1"/><vers num="2.7"/><vers num="2.5 SP3"/><vers num="2.8 SP2"/><vers num="2.8 SP1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-28" name="CVE-2006-0004" published="2006-02-14" seq="2006-0004" severity="Medium" type="CVE"><desc><descript source="cve">Microsoft PowerPoint 2000 in Office 2000 SP3 has an interaction with Internet Explorer that allows remote attackers to obtain sensitive information via a PowerPoint presentation that attempts to access objects in the Temporary Internet Files Folder (TIFF).</descript></desc><loss_types><conf/></loss_types><vuln_types><env/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms06-010.mspx">MS06-010</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/963628">VU#963628</ref><ref source="BID" url="http://www.securityfocus.com/bid/16634">16634</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0579">ADV-2006-0579</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015632">1015632</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18865">18865</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24490">powerpoint-tiff-information-disclosure(24490)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1555">oval:org.mitre.oval:def:1555</ref></refs><vuln_soft><prod name="Office" vendor="Microsoft"><vers num="2000 SP3"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-03-03" name="CVE-2006-0005" published="2006-02-14" seq="2006-0005" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the plug-in for Microsoft Windows Media Player (WMP) 9 and 10, when used in browsers other than Internet Explorer and set as the default application to handle media files, allows remote attackers to execute arbitrary code via HTML with an EMBED element containing a long src attribute.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms06-006.mspx">MS06-006</ref><ref source="IDEFENSE" url="http://www.idefense.com/intelligence/vulnerabilities/display.php?id=393">20060214 Microsoft Windows Media Player Plugin Buffer Overflow Vulnerability</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/692060">VU#692060</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-045A.html">TA06-045A</ref><ref source="BID" url="http://www.securityfocus.com/bid/16644">16644</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0575">ADV-2006-0575</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015628">1015628</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18852">18852</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24493">win-mediaplayer-plugin-embed-bo(24493)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1559">oval:org.mitre.oval:def:1559</ref></refs><vuln_soft><prod name="Windows 2000 Advanced Server" vendor="Microsoft"><vers num="SP1"/><vers num="SP2"/><vers num="SP3"/><vers num="SP4"/><vers num="unknown"/></prod><prod name="windows-nt" vendor="Microsoft"><vers edition="SP1" num="XP_tablet_PC"/><vers edition="SP2" num="XP_tablet_PC"/><vers edition="unknown" num="XP_tablet_PC"/><vers edition="unknown" num="XP"/><vers edition="sp1" num="XP"/><vers edition="sp2" num="XP"/><vers edition="unknown" num="XP"/><vers edition="sp1" num="XP"/><vers edition="sp2" num="XP"/><vers edition="unknown" num="XP"/><vers edition="unknown" num="XP"/><vers edition="sp1" num="XP"/><vers edition="sp2" num="XP"/><vers edition="unknown" num="XP"/><vers edition="unknown" num="XP"/><vers edition="unknown" num="2000"/><vers edition="sp1" num="2000"/><vers edition="sp2" num="2000"/><vers edition="sp3" num="2000"/><vers edition="sp4" num="2000"/><vers edition="SP4" num="Datacenter Server"/><vers edition="SP3" num="Datacenter Server"/><vers edition="SP2" num="Datacenter Server"/><vers edition="SP1" num="Datacenter Server"/><vers edition="unknown" num="Datacenter Server"/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers num="Datacenter Edition"/><vers num="Datacenter Edition 64-bit"/><vers num="Datacenter SP1"/><vers num="Enterprise Edition"/><vers num="Enterprise Edition 64-bit"/><vers num="Enterprise SP1"/><vers num="Standard"/><vers num="Standard 64-bit"/><vers num="Standard SP1"/><vers num="Web Edition"/><vers num="Web Edition SP1"/></prod><prod name="Windows Server 2000" vendor="Microsoft"><vers num="none"/><vers num="SP1"/><vers num="SP2"/><vers num="SP3"/><vers num="SP4"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-04-01" name="CVE-2006-0006" published="2006-02-14" seq="2006-0006" severity="High" type="CVE"><desc><descript source="cve">Heap-based buffer overflow in the bitmap processing routine in Microsoft Windows Media Player 7.1 on Windows 2000 SP4, Media Player 9 on Windows 2000 SP4 and XP SP1, and Media Player 10 on XP SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted bitmap (.BMP) file that specifies a size of 0 but contains additional data.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-045A.html">TA06-045A</ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/291396">VU#291396</ref><ref adv="1" patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms06-005.mspx">MS06-005</ref><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/424983/100/0/threaded">20060214 [EEYEB-20051017] Windows Media Player BMP Heap Overflow</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/425158/100/0/threaded">20060215 Windows Media Player BMP Heap Overflow (MS06-005)</ref><ref adv="1" patch="1" source="" url="http://www.eeye.com/html/research/advisories/AD20060214.html"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16633">16633</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0574">ADV-2006-0574</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015627">1015627</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18835">18835</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24488">win-media-player-bmp-bo(24488)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1256">oval:org.mitre.oval:def:1256</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1578">oval:org.mitre.oval:def:1578</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1598">oval:org.mitre.oval:def:1598</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1661">oval:org.mitre.oval:def:1661</ref><ref source="SREASON" url="http://securityreason.com/securityalert/423">423</ref></refs><vuln_soft><prod name="Windows 98" vendor="Microsoft"><vers num="SE"/><vers num="Gold"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers edition="FR" num="SP4"/><vers num="SP1"/></prod><prod name="Windows XP" vendor="Microsoft"><vers edition="Tablet PC" num="SP2"/><vers edition="Tablet PC" num="SP1"/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers num="R2"/></prod><prod name="Windows ME" vendor="Microsoft"><vers num=""/></prod><prod name="Windows Media Player" vendor="Microsoft"><vers num="10"/><vers num="9"/><vers num="7.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-08-28" name="CVE-2006-0007" published="2006-07-11" seq="2006-0007" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in GIFIMP32.FLT, as used in Microsoft Office 2003 SP1 and SP2, Office XP SP3, Office 2000 SP3, and other products, allows user-assisted attackers to execute arbitrary code via a crafted GIF image that triggers memory corruption when it is parsed.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms06-039.mspx">MS06-039</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/668564">VU#668564</ref><ref source="BID" url="http://www.securityfocus.com/bid/18915">18915</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/2757">ADV-2006-2757</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21013">21013</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-192A.html">TA06-192A</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1016470">1016470</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/439887/100/0/threaded">20060712 NSFOCUS SA2006-04 : Microsoft Office GIF Filter Buffer Overflow Vulnerability</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:21">oval:org.mitre.oval:def:21</ref><ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2006-q3/0005.html">
20060712 NSFOCUS SA2006-04 : Microsoft Office GIF Filter Buffer Overflow Vulnerability</ref><ref source="OSVDB" url="http://www.osvdb.org/27146">
27146</ref></refs><vuln_soft><prod name="Office" vendor="Microsoft"><vers num="2003 SP2"/><vers num="2003 SP1"/><vers num="2000 SP3"/><vers num="XP SP3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-19" name="CVE-2006-0008" published="2006-02-14" seq="2006-0008" severity="High" type="CVE"><desc><descript source="cve">The ShellAbout API call in Korean Input Method Editor (IME) in Korean versions of Microsoft Windows XP SP1 and SP2, Windows Server 2003 up to SP1, and Office 2003, allows local users to gain privileges by launching the &quot;shell about dialog box&quot; and clicking the &quot;End-User License Agreement&quot; link, which executes Notepad with the privileges of the program that displays the about box.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms06-009.mspx">MS06-009</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/425141/100/0/threaded">20060215 Security advisory: Windows IME Vulnerability (MS06-009)</ref><ref adv="1" source="" url="http://www.ryanstyle.com/alert/my/5/ms06_009_eng.html"></ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/739844">VU#739844</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16643">16643</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0578">ADV-2006-0578</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015631">1015631</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18859">18859</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24492">win-korean-ime-privilege-elevation(24492)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1595">oval:org.mitre.oval:def:1595</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1650">oval:org.mitre.oval:def:1650</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1664">oval:org.mitre.oval:def:1664</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1688">oval:org.mitre.oval:def:1688</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:727">oval:org.mitre.oval:def:727</ref></refs><vuln_soft><prod name="Windows XP" vendor="Microsoft"><vers edition="64-bit" num="Professional"/><vers edition="Gold" num="Professional"/><vers edition="Gold" num="Professional"/><vers edition="Gold" num="Professional"/><vers edition="SP2" num="Home"/><vers edition="SP1" num="Home"/><vers num="Home"/><vers edition="SP2" num="Tablet PC"/><vers edition="SP2" num="Tablet PC"/><vers edition="SP2" num="Tablet PC"/><vers edition="SP2" num="Media Center"/><vers edition="SP1" num="Media Center"/><vers num="Media Center"/></prod><prod name="Office" vendor="Microsoft"><vers num="2003 SP2"/><vers num="2003 SP1"/><vers edition="Student_Teacher" num="2003"/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers num="Standard 64-bit"/><vers num="Enterprise 64-bit"/><vers edition="Datacenter 64-bit" num="R2"/><vers edition="SP1" num="Web"/><vers num="Web"/><vers edition="SP1" num="Standard"/><vers edition="64-bit" num="Standard"/><vers edition="SP1" num="Enterprise 64-bit"/><vers edition="SP1" num="Enterprise"/><vers edition="64-bit" num="Enterprise"/><vers edition="SP1" num="Datacenter 64-bit"/><vers edition="SP1" num="R2"/><vers edition="64-bit" num="R2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-08-27" name="CVE-2006-0009" published="2006-03-14" seq="2006-0009" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in Microsoft Office 2000 SP3, XP SP3, and other versions and packages, allows user-assisted attackers to execute arbitrary code via a routing slip that is longer than specified by the provided length field, as exploited by malware such as TROJ_MDROPPER.BH and Trojan.PPDropper.E in attacks against PowerPoint.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms06-012.mspx">MS06-012</ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/682820">VU#682820</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015766">1015766</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19138">19138</ref><ref adv="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-073A.html">TA06-073A</ref><ref adv="1" patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/427671/100/0/threaded">20060314 SYMSA-2006-001: Buffer overflow in Microsoft Office 2000, Office XP (2002), and Office 2003 Routing Slip Metadata</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/17000">17000</ref><ref source="" url="http://www.symantec.com/enterprise/research/SYMSA-2006-001.txt"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0950">ADV-2006-0950</ref><ref source="OSVDB" url="http://www.osvdb.org/23903">23903</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25009">office-routing-slip-bo(25009)</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-069.htm"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/19238">19238</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/443890/100/0/threaded">20060819 New PowerPoint 0-day and Trojan - FAQ document ready</ref><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2006-08/0597.html">20060822 Major updates in PowerPoint FAQ document - not a 0-day issue</ref><ref source="" url="http://isc.sans.org/diary.php?storyid=1618"></ref><ref source="" url="http://blogs.securiteam.com/?p=557"></ref><ref source="" url="http://blogs.securiteam.com/?p=559"></ref><ref source="" url="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ%5FMDROPPER%2EBH"></ref><ref source="" url="http://www.darkreading.com/document.asp?doc_id=101970"></ref><ref source="SECTRACK" url="http://securitytracker.com/id?1016720">1016720</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/444051/100/200/threaded">20060822 Major updates in PowerPoint FAQ document - not a 0-day issue</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-September/049540.html">20060919 New PowerPoint 0-day Trojan in the wild</ref><ref source="" url="http://blogs.securiteam.com/?author=28"></ref><ref source="" url="http://www.symantec.com/security_response/writeup.jsp?docid=2006-091810-5028-99"></ref><ref source="BID" url="http://www.securityfocus.com/bid/20059">20059</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/3678">ADV-2006-3678</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/29009">powerpoint-presentation-code-execution(29009)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/446425/100/0/threaded">20060919 Microsoft PowerPoint 0-day Vulnerability FAQ - September written</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/446370/100/0/threaded">20060919 New PowerPoint 0-day Trojan in the wild</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1016886">1016886</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1504">oval:org.mitre.oval:def:1504</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1553">oval:org.mitre.oval:def:1553</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1653">oval:org.mitre.oval:def:1653</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:798">oval:org.mitre.oval:def:798</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/432004/30/5340/threaded">20060422 PowerPoint Phishing Trojan</ref></refs><vuln_soft><prod name="Office" vendor="Microsoft"><vers num="2000 SP3"/><vers num="XP SP3"/><vers num="2003 SP1"/><vers num="2003 SP2"/><vers edition="Mac" num="v. X"/><vers edition="Mac" num="2004"/></prod><prod name="Works Suite" vendor="Microsoft"><vers num="2006"/><vers num="2005"/><vers num="2004"/><vers num="2003"/><vers num="2002"/><vers num="2001"/><vers num="2000"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-19" name="CVE-2006-0010" published="2006-01-10" seq="2006-0010" severity="High" type="CVE"><desc><descript source="cve">Heap-based buffer overflow in T2EMBED.DLL in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 up to SP1, Windows 98, and Windows ME allows remote attackers to execute arbitrary code via an e-mail message or web page with a crafted Embedded Open Type (EOT) web font that triggers the overflow during decompression.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms06-002.mspx">MS06-002</ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/915930">VU#915930</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16194">16194</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0118">ADV-2006-0118</ref><ref source="OSVDB" url="http://www.osvdb.org/18829">18829</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18365">18365</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-010A.html">TA06-010A</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015459">1015459</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-004.htm"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/18391">18391</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18311">18311</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421885/100/0/threaded">20060110 [EEYEB-2000801] - Windows Embedded Open Type (EOT) Font Heap Overflow Vulnerability</ref><ref source="" url="http://www130.nortelnetworks.com/cgi-bin/eserv/cs/main.jsp?cscat=BLTNDETAIL&amp;DocumentOID=375525"></ref><ref source="EEYE" url="http://www.eeye.com/html/Research/Advisories/EEYEB20050801.html">EEYEB20050801</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1126">oval:org.mitre.oval:def:1126</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1185">oval:org.mitre.oval:def:1185</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1462">oval:org.mitre.oval:def:1462</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1491">oval:org.mitre.oval:def:1491</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:698">oval:org.mitre.oval:def:698</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:714">oval:org.mitre.oval:def:714</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/23922">
win-embedded-fonts-bo(23922)</ref></refs><vuln_soft><prod name="Windows 98" vendor="Microsoft"><vers num="SE"/><vers num="Gold"/></prod><prod name="Windows NT" vendor="Microsoft"><vers num="Workstation 4.0 SP6a"/><vers num="Workstation 4.0 SP6"/><vers num="Workstation 4.0 SP5"/><vers num="Workstation 4.0 SP4"/><vers num="Workstation 4.0 SP3"/><vers num="Workstation 4.0 SP2"/><vers num="Workstation 4.0 SP1"/><vers num="Workstation 4.0"/><vers num="Terminal Server 4.0 SP6a"/><vers num="Terminal Server 4.0 SP6"/><vers num="Terminal Server 4.0 SP5"/><vers num="Terminal Server 4.0 SP4"/><vers num="Terminal Server 4.0 SP3"/><vers num="Terminal Server 4.0 SP2"/><vers num="Terminal Server 4.0 SP1"/><vers num="Terminal Server 4.0 alpha"/><vers num="Terminal Server 4.0"/><vers num="Server 4.0 SP6a"/><vers num="Server 4.0 SP6"/><vers num="Server 4.0 SP5"/><vers num="Server 4.0 SP4"/><vers num="Server 4.0 SP3"/><vers num="Server 4.0 SP2"/><vers num="Server 4.0 SP1"/><vers num="Server 4.0"/><vers num="Enterprise Server 4.0 SP6a"/><vers num="Enterprise Server 4.0 SP6"/><vers num="Enterprise Server 4.0 SP5"/><vers num="Enterprise Server 4.0 SP4"/><vers num="Enterprise Server 4.0 SP3"/><vers num="Enterprise Server 4.0 SP2"/><vers num="Enterprise Server 4.0 SP1"/><vers num="Enterprise Server 4.0"/><vers num="4.0 SP6a alpha"/><vers num="4.0 SP6a"/><vers num="4.0 SP6 alpha"/><vers num="4.0 SP6"/><vers num="4.0 SP5 alpha"/><vers num="4.0 SP5"/><vers num="4.0 SP4 alpha"/><vers num="4.0 SP4"/><vers num="4.0 SP3 alpha"/><vers num="4.0 SP3"/><vers num="4.0 SP2 alpha"/><vers num="4.0 SP2"/><vers num="4.0 SP1 alpha"/><vers num="4.0 SP1"/><vers num="4.0 alpha"/><vers num="4.0"/><vers num="3.5.1 SP5 alpha"/><vers num="3.5.1 SP5"/><vers num="3.5.1 SP4"/><vers num="3.5.1 SP3"/><vers num="3.5.1 SP2"/><vers num="3.5.1 SP1"/><vers num="3.5.1"/><vers num="3.5"/></prod><prod name="Windows XP" vendor="Microsoft"><vers edition="64-bit" num="Professional"/><vers edition="Gold" num="Professional"/><vers edition="Gold" num="Professional"/><vers edition="Gold" num="Professional"/><vers edition="SP2" num="Home"/><vers edition="SP1" num="Home"/><vers num="Home"/><vers edition="SP2" num="Tablet PC"/><vers edition="SP2" num="Tablet PC"/><vers edition="SP2" num="Tablet PC"/><vers edition="SP2" num="Media Center"/><vers edition="SP1" num="Media Center"/><vers num="Media Center"/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers num="Standard 64-bit"/><vers num="Enterprise 64-bit"/><vers edition="Datacenter 64-bit" num="R2"/><vers edition="SP1" num="Web"/><vers num="Web"/><vers edition="SP1" num="Standard"/><vers edition="64-bit" num="Standard"/><vers edition="SP1" num="Enterprise 64-bit"/><vers edition="SP1" num="Enterprise"/><vers edition="64-bit" num="Enterprise"/><vers edition="SP1" num="Datacenter 64-bit"/><vers edition="SP1" num="R2"/><vers edition="64-bit" num="R2"/></prod><prod name="Windows ME" vendor="Microsoft"><vers num=""/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num="Server SP4"/><vers num="Server SP3"/><vers num="Server SP2"/><vers num="Server SP1"/><vers num="Server"/><vers num="Professional SP4"/><vers num="Professional SP3"/><vers num="Professional SP2"/><vers num="Professional SP1"/><vers num="Professional"/><vers num="Datacenter Server SP4"/><vers num="Datacenter Server SP3"/><vers num="Datacenter Server SP2"/><vers num="Datacenter Server SP1"/><vers num="Datacenter Server"/><vers num="Advanced Server SP4"/><vers num="Advanced Server SP3"/><vers num="Advanced Server SP2"/><vers num="Advanced Server SP1"/><vers num="Advanced Server"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-19" name="CVE-2006-0012" published="2006-04-11" seq="2006-0012" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Windows Explorer in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 allows remote attackers to execute arbitrary code via attack vectors involving COM objects and &quot;crafted files and directories,&quot; aka the &quot;Windows Shell Vulnerability.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><range><network/><user_init/></range><refs><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms06-015.mspx">MS06-015</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-101A.html">TA06-101A</ref><ref source="BID" url="http://www.securityfocus.com/bid/17464">17464</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1320">ADV-2006-1320</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19606">19606</ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/641460">VU#641460</ref><ref source="OSVDB" url="http://www.osvdb.org/24516">24516</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015897">1015897</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25554">win-explorer-com-code-execution(25554)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1191">oval:org.mitre.oval:def:1191</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1448">oval:org.mitre.oval:def:1448</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1679">oval:org.mitre.oval:def:1679</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1743">oval:org.mitre.oval:def:1743</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1764">oval:org.mitre.oval:def:1764</ref></refs><vuln_soft><prod name="Windows 98" vendor="Microsoft"><vers num="SE"/><vers num="Gold"/></prod><prod name="Windows XP" vendor="Microsoft"><vers edition="64-bit" num="Professional"/><vers edition="Gold" num="Professional"/><vers edition="Gold" num="Professional"/><vers edition="Gold" num="Professional"/><vers edition="SP2" num="Home"/><vers edition="SP1" num="Home"/><vers num="Home"/><vers edition="SP2" num="Tablet PC"/><vers edition="SP2" num="Tablet PC"/><vers edition="SP2" num="Tablet PC"/><vers edition="SP2" num="Media Center"/><vers edition="SP1" num="Media Center"/><vers num="Media Center"/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers num="Standard 64-bit"/><vers num="Enterprise 64-bit"/><vers edition="Datacenter 64-bit" num="R2"/><vers edition="SP1" num="Web"/><vers num="Web"/><vers edition="SP1" num="Standard"/><vers edition="64-bit" num="Standard"/><vers edition="SP1" num="Enterprise 64-bit"/><vers edition="SP1" num="Enterprise"/><vers edition="64-bit" num="Enterprise"/><vers edition="SP1" num="Datacenter 64-bit"/><vers edition="SP1" num="R2"/><vers edition="64-bit" num="R2"/></prod><prod name="Windows ME" vendor="Microsoft"><vers num=""/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num="Server SP4"/><vers num="Server SP3"/><vers num="Server SP2"/><vers num="Server SP1"/><vers num="Server"/><vers num="Professional SP4"/><vers num="Professional SP3"/><vers num="Professional SP2"/><vers num="Professional SP1"/><vers num="Professional"/><vers num="Datacenter Server SP4"/><vers num="Datacenter Server SP3"/><vers num="Datacenter Server SP2"/><vers num="Datacenter Server SP1"/><vers num="Datacenter Server"/><vers num="Advanced Server SP4"/><vers num="Advanced Server SP3"/><vers num="Advanced Server SP2"/><vers num="Advanced Server SP1"/><vers num="Advanced Server"/></prod></vuln_soft></entry><entry CVSS_base_score="6.5" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="6.4" CVSS_score="6.5" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-19" name="CVE-2006-0013" published="2006-02-14" seq="2006-0013" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in the Web Client service (WebClnt.dll) for Microsoft Windows XP SP1 and SP2, and Server 2003 up to SP1, allows remote authenticated users or Guests to execute arbitrary code via crafted RPC requests, a different vulnerability than CVE-2005-1207.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms06-008.mspx">MS06-008</ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/388900">VU#388900</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16636">16636</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18857">18857</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0577">ADV-2006-0577</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015630">1015630</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24491">msrpc-webclient-message-bo(24491)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1220">oval:org.mitre.oval:def:1220</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1547">oval:org.mitre.oval:def:1547</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1602">oval:org.mitre.oval:def:1602</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:683">oval:org.mitre.oval:def:683</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:716">oval:org.mitre.oval:def:716</ref></refs><vuln_soft><prod name="Windows XP" vendor="Microsoft"><vers edition="64-bit" num="Professional"/><vers edition="Gold" num="Professional"/><vers edition="Gold" num="Professional"/><vers edition="Gold" num="Professional"/><vers edition="SP2" num="Home"/><vers edition="SP1" num="Home"/><vers num="Home"/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers num="Standard 64-bit"/><vers num="Enterprise 64-bit"/><vers edition="Datacenter 64-bit" num="R2"/><vers edition="SP1" num="Web"/><vers num="Web"/><vers edition="SP1" num="Standard"/><vers edition="64-bit" num="Standard"/><vers edition="SP1" num="Enterprise 64-bit"/><vers edition="SP1" num="Enterprise"/><vers edition="64-bit" num="Enterprise"/><vers edition="SP1" num="Datacenter 64-bit"/><vers edition="SP1" num="R2"/><vers edition="64-bit" num="R2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2005-09-20" modified="2006-04-13" name="CVE-2006-0014" published="2006-04-11" seq="2006-0014" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in Microsoft Outlook Express 5.5 and 6 allows remote attackers to execute arbitrary code via a crafted Windows Address Book (WAB) file containing &quot;certain Unicode strings&quot; and modified length values.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/430645/100/0/threaded">20060411 ZDI-06-007: Microsoft Windows Address Book (WAB) File Format Parsing Vulnerability</ref><ref adv="1" source="" url="http://www.zerodayinitiative.com/advisories/ZDI-06-007.html"></ref><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms06-016.mspx">MS06-016</ref><ref source="BID" url="http://www.securityfocus.com/bid/17459">17459</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1321">ADV-2006-1321</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19617">19617</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015898">1015898</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1611">oval:org.mitre.oval:def:1611</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1682">oval:org.mitre.oval:def:1682</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1769">oval:org.mitre.oval:def:1769</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1771">oval:org.mitre.oval:def:1771</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1780">oval:org.mitre.oval:def:1780</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1791">oval:org.mitre.oval:def:1791</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:812">oval:org.mitre.oval:def:812</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-April/045003.html">
20060411 ZDI-06-007: Microsoft Windows Address Book (WAB) File Format Parsing Vulnerability</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25535">
outlook-express-wab-bo(25535)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/691">691</ref></refs><vuln_soft><prod name="Outlook Express" vendor="Microsoft"><vers num="6.0 SP1"/><vers num="6.0"/><vers num="5.5 SP2"/><vers num="5.5 SP1"/><vers num="5.5"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-19" name="CVE-2006-0015" published="2006-04-11" seq="2006-0015" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in _vti_bin/_vti_adm/fpadmdll.dll in Microsoft FrontPage Server Extensions 2002 and SharePoint Team Services allows remote attackers to inject arbitrary web script or HTML, then leverage the attack to execute arbitrary programs or create new accounts, via the (1) operation, (2) command, and (3) name parameters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/Bulletin/MS06-017.mspx">MS06-017</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1322">ADV-2006-1322</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19623">19623</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/430803/100/0/threaded">20060412 Vulnerability in Microsoft FrontPage Server Extensions Could Allow Cross-Site Scripting</ref><ref adv="1" patch="1" source="" url="http://www.argeniss.com/research/ARGENISS-ADV-040602.txt"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/17452">17452</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015895">1015895</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015896">1015896</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1748">oval:org.mitre.oval:def:1748</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25537">
fpse-html-xss(25537)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/704">704</ref></refs><vuln_soft><prod name="SharePoint Team Services" vendor="Microsoft"><vers num=""/></prod><prod name="FrontPage Server Extensions" vendor="Microsoft"><vers num="2002"/></prod></vuln_soft></entry><entry modified="2005-11-30" name="CVE-2006-0018" published="2005-11-29" reject="1" seq="2006-0018" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2005-3899.  Reason: This candidate is a duplicate of CVE-2005-3899.  Notes: All CVE users should reference CVE-2005-3899 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript></desc><refs/></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-30" name="CVE-2006-0019" published="2006-01-20" seq="2006-0019" severity="High" type="CVE"><desc><descript source="cve">Heap-based buffer overflow in the encodeURI and decodeURI functions in the kjs JavaScript interpreter engine in KDE 3.2.0 through 3.5.0 allows remote attackers to execute arbitrary code via a crafted, UTF-8 encoded URI.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/422464/100/0/threaded">20060119 [KDE Security Advisory] kjs encodeuri/decodeuri heap overflow</ref><ref adv="1" patch="1" source="" url="http://www.kde.org/info/security/advisory-20060119-1.txt"></ref><ref patch="1" source="" url="ftp://ftp.kde.org/pub/kde/security_patches/post-3.4.3-kdelibs-kjs.diff"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0265">ADV-2006-0265</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18500">18500</ref><ref adv="1" source="DEBIAN" url="http://www.debian.org/security/2006/dsa-948">DSA-948</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:019">MDKSA-2006:019</ref><ref adv="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0184.html">RHSA-2006:0184</ref><ref source="SUSE" url="http://www.securityfocus.com/archive/1/archive/1/422489/100/0/threaded">SUSE-SA:2006:003</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18540">18540</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18561">18561</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200601-11.xml">GLSA-200601-11</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-245-1">USN-245-1</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18552">18552</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18559">18559</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18570">18570</ref><ref source="BID" url="http://www.securityfocus.com/bid/16325">16325</ref><ref source="OSVDB" url="http://www.osvdb.org/22659">22659</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015512">1015512</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24242">kde-kjs-bo(24242)</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18899">18899</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/427976/100/0/threaded">FLSA:178606</ref><ref source="SLACKWARE" url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2006&amp;m=slackware-security.361107">SSA:2006-045-05</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18583">18583</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:019">MDKSA-2006:019</ref><ref source="SREASON" url="http://securityreason.com/securityalert/364">364</ref></refs><vuln_soft><prod name="KDE" vendor="KDE"><vers num="3.5.0"/><vers num="3.4.2"/><vers num="3.4.1"/><vers num="3.4.0"/><vers num="3.4"/><vers num="3.3.x"/><vers num="3.3.2"/><vers num="3.3.1"/><vers num="3.3.0"/><vers num="3.3"/><vers num="3.2.x"/><vers num="3.2.3"/><vers num="3.2.2"/><vers num="3.2.1"/><vers num="3.2.0 Beta1"/><vers num="3.2.0"/><vers num="3.2"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-04-22" name="CVE-2006-0020" published="2006-01-10" seq="2006-0020" severity="High" type="CVE"><desc><descript source="cve">An unspecified Microsoft WMF parsing application, as used in Internet Explorer 5.01 SP4 on Windows 2000 SP4, and 5.5 SP2 on Windows Millennium, and possibly other versions, allows attackers to cause a denial of service (crash) and possibly execute code via a crafted WMF file with a manipulated WMF header size, possibly involving an integer overflow, a different vulnerability than CVE-2005-4560, and aka &quot;WMF Image Parsing Memory Corruption Vulnerability.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="MLIST" url="http://linuxbox.org/pipermail/funsec/2006-January/002828.html">[funsec] 20060110 Another WMF flaw without a Microsoft patch</ref><ref adv="1" source="" url="http://www.microsoft.com/technet/security/advisory/913333.mspx"></ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/312956">VU#312956</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16516">16516</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0469">ADV-2006-0469</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18729">18729</ref><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms06-004.mspx">MS06-004</ref><ref adv="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-045A.html">TA06-045A</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18912">18912</ref><ref source="OSVDB" url="http://www.osvdb.org/22976">22976</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1638">oval:org.mitre.oval:def:1638</ref></refs><vuln_soft><prod name="Windows 98" vendor="Microsoft"><vers num="SE"/><vers num="Gold"/></prod><prod name="Windows XP" vendor="Microsoft"><vers edition="Tablet PC" num="SP2"/><vers edition="Tablet PC" num="SP1"/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers num="SP1"/><vers num="R2"/></prod><prod name="Windows ME" vendor="Microsoft"><vers num=""/></prod><prod name="Windows 2000" vendor="Microsoft"><vers edition="FR" num="SP4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2008-03-24" name="CVE-2006-0021" published="2006-02-14" seq="2006-0021" severity="High" type="CVE"><desc><descript source="cve">Microsoft Windows XP SP1 and SP2, and Server 2003 up to SP1, allows remote attackers to cause a denial of service (hang) via an IGMP packet with an invalid IP option, aka the &quot;IGMP v3 DoS Vulnerability.&quot;</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms06-007.mspx">MS06-007</ref><ref adv="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-018A.html">TA06-018A</ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/839284">VU#839284</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16645">16645</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0576">ADV-2006-0576</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18853">18853</ref><ref adv="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-045A.html">TA06-045A</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015629">1015629</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24489">win-igmpv3-dos(24489)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1310">oval:org.mitre.oval:def:1310</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1425">oval:org.mitre.oval:def:1425</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1647">oval:org.mitre.oval:def:1647</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1662">oval:org.mitre.oval:def:1662</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:678">oval:org.mitre.oval:def:678</ref><ref source="" url="http://www.securiteam.com/exploits/5PP0T0KI0O.html"></ref><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/1599">1599</ref></refs><vuln_soft><prod name="Windows XP" vendor="Microsoft"><vers edition="64-bit" num="Professional"/><vers edition="Gold" num="Professional"/><vers edition="Gold" num="Professional"/><vers edition="Gold" num="Professional"/><vers edition="SP2" num="Home"/><vers edition="SP1" num="Home"/><vers num="Home"/><vers edition="SP1" num="Embedded"/><vers num="Embedded"/><vers edition="SP1" num="64-bit Version 2003"/><vers num="64-bit Version 2003"/><vers edition="SP1" num="64-bit"/><vers num="64-bit"/><vers edition="SP2" num="Tablet PC"/><vers edition="SP2" num="Tablet PC"/><vers edition="SP2" num="Tablet PC"/><vers edition="SP2" num="Media Center"/><vers edition="SP1" num="Media Center"/><vers num="Media Center"/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers num="Standard 64-bit"/><vers num="Enterprise 64-bit"/><vers edition="Datacenter 64-bit" num="R2"/><vers edition="SP1" num="Web"/><vers num="Web"/><vers edition="SP1" num="Standard"/><vers edition="64-bit" num="Standard"/><vers edition="SP1" num="Enterprise"/><vers edition="64-bit" num="Enterprise"/><vers edition="SP1" num="Datacenter 64-bit"/><vers edition="SP1" num="R2"/><vers edition="64-bit" num="R2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="10.0" CVSS_score="7.6" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-08-17" name="CVE-2006-0022" published="2006-06-13" seq="2006-0022" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Microsoft PowerPoint in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP1 and SP2, Office 2004 for Mac, and v. X for Mac allows user-assisted attackers to execute arbitrary code via a PowerPoint document with a malformed record, which triggers memory corruption.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms06-028.mspx">MS06-028</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/190089">VU#190089</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/18382">18382</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/2325">ADV-2006-2325</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/20633">20633</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-164A.html">TA06-164A</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1016287">1016287</ref><ref source="OSVDB" url="http://www.osvdb.org/26435">26435</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26784">powerpoint-record-bo(26784)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1069">oval:org.mitre.oval:def:1069</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1836">oval:org.mitre.oval:def:1836</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1984">oval:org.mitre.oval:def:1984</ref></refs><vuln_soft><prod name="PowerPoint" vendor="Microsoft"><vers edition="Mac" num="2004"/><vers num="2003 SP3"/><vers num="2003 SP2"/><vers num="2003 SP1"/><vers num="2003"/><vers num="2002 SP3"/><vers num="2002 SP2"/><vers num="2002 SP1"/><vers num="2002"/><vers num="2000 SP3"/><vers num="2000 SR1"/><vers num="2000 SP2"/><vers num="2000"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="3.1" CVSS_impact_subscore="6.4" CVSS_score="4.3" CVSS_vector="(AV:L/AC:L/Au:S/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-28" name="CVE-2006-0023" published="2006-02-07" seq="2006-0023" severity="Medium" type="CVE"><desc><descript source="cve">Microsoft Windows XP SP1 and SP2 before August 2004, and possibly other operating systems and versions, uses insecure default ACLs that allow the Authenticated Users group to gain privileges by modifying critical configuration information for the (1) Simple Service Discovery Protocol (SSDP), (2) Universal Plug and Play Device Host (UPnP), (3) NetBT, (4) SCardSvr, (5) DHCP, and (6) DnsCache services, aka &quot;Permissive Windows Services DACLs.&quot;  NOTE: the NetBT, SCardSvr, DHCP, DnsCache already require privileged access to exploit.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><config/></vuln_types><range><local/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/423587/100/0/threaded">20060131 Windows Access Control Demystified</ref><ref source="" url="http://www.cs.princeton.edu/~sudhakar/papers/winval.pdf"></ref><ref adv="1" source="" url="http://www.microsoft.com/technet/security/advisory/914457.mspx"></ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/953860">VU#953860</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0417">ADV-2006-0417</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24463">win-auth-users-insecure-permissions(24463)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015595">1015595</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18756">18756</ref><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms06-011.mspx">MS06-011</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015765">1015765</ref><ref source="" url="http://www130.nortelnetworks.com/cgi-bin/eserv/cs/main.jsp?cscat=BLTNDETAIL&amp;DocumentOID=391523&amp;RenditionID="></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19313">19313</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-069.htm"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/19238">19238</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1671">oval:org.mitre.oval:def:1671</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1696">oval:org.mitre.oval:def:1696</ref></refs><vuln_soft><prod name="Windows XP" vendor="Microsoft"><vers edition="Tablet PC" num="SP1"/><vers edition="Tablet PC" num="SP2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-17" name="CVE-2006-0024" published="2006-03-15" seq="2006-0024" severity="Medium" type="CVE"><desc><descript source="cve">Multiple unspecified vulnerabilities in Adobe Flash Player 8.0.22.0 and earlier allow remote attackers to execute arbitrary code via a crafted SWF file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="" url="http://www.macromedia.com/devnet/security/security_zone/apsb06-03.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17106">17106</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0952">ADV-2006-0952</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19218">19218</ref><ref adv="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0268.html">RHSA-2006:0268</ref><ref source="OSVDB" url="http://www.osvdb.org/23908">23908</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25005">macromedia-swf-code-execution(25005)</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-075A.html">TA06-075A</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/945060">VU#945060</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015770">1015770</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19259">19259</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_15_flashplayer.html">SUSE-SA:2006:015</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200603-20.xml">GLSA-200603-20</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19198">19198</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19328">19328</ref><ref source="" url="http://www.opera.com/docs/changelogs/windows/854/"></ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms06-020.mspx">MS06-020</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-129A.html">TA06-129A</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1744">ADV-2006-1744</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2006/May/msg00003.html">APPLE-SA-2006-05-11</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-132A.html">TA06-132A</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20077">20077</ref><ref source="BID" url="http://www.securityfocus.com/bid/17951">17951</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1779">ADV-2006-1779</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1894">oval:org.mitre.oval:def:1894</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1922">oval:org.mitre.oval:def:1922</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1262">
ADV-2006-1262</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20045">
20045</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=307179"></ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2007/Dec/msg00002.html">APPLE-SA-2007-12-17</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-352A.html">TA07-352A</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/4238">ADV-2007-4238</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28136">28136</ref></refs><vuln_soft><prod name="Flash" vendor="Macromedia"><vers num="8.0.22.0" prev="1"/><vers num="7.0.61.0"/><vers num="7.0.60.0"/><vers num="7.0.19.0"/><vers num="7.0 r19"/><vers num="6.0.79.0"/><vers num="6.0.65.0"/><vers num="6.0.47.0"/><vers num="6.0.40.0"/><vers num="6.0.29.0"/><vers num="6.0"/><vers num="5.0 r50"/><vers num="5.0"/><vers num="4.0 r12"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-02-22" modified="2006-06-14" name="CVE-2006-0025" published="2006-06-13" seq="2006-0025" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in Microsoft Windows Media Player 9 and 10 allows remote attackers to execute arbitrary code via a PNG image with a large chunk size.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="IDEFENSE" url="http://www.idefense.com/intelligence/vulnerabilities/display.php?id=406">20060613 Windows Media Player PNG Chunk Decoding Stack-Based Buffer Overflow</ref><ref adv="1" patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms06-024.mspx">MS06-024</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/18385">18385</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/2322">ADV-2006-2322</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/20626">20626</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-164A.html">TA06-164A</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/608020">VU#608020</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1016284">1016284</ref><ref source="OSVDB" url="http://www.osvdb.org/26430">26430</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26788">win-media-player-png-bo(26788)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1230">oval:org.mitre.oval:def:1230</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1729">oval:org.mitre.oval:def:1729</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1805">oval:org.mitre.oval:def:1805</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1807">oval:org.mitre.oval:def:1807</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1820">oval:org.mitre.oval:def:1820</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1974">oval:org.mitre.oval:def:1974</ref></refs><vuln_soft><prod name="Windows Media Player" vendor="Microsoft"><vers num="9"/><vers num="10"/></prod></vuln_soft></entry><entry CVSS_base_score="6.5" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="6.4" CVSS_score="6.5" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-07-12" name="CVE-2006-0026" published="2006-07-11" seq="2006-0026" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in Microsoft Internet Information Services (IIS) 5.0, 5.1, and 6.0 allows local and possibly remote attackers to execute arbitrary code via crafted Active Server Pages (ASP).</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms06-034.mspx">MS06-034</ref><ref patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/395588">VU#395588</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/18858">18858</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/2752">ADV-2006-2752</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1016466">1016466</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/21006">21006</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/26796">iis-asp-bo(26796)</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-192A.html">TA06-192A</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:435">oval:org.mitre.oval:def:435</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2006-07/0316.html">

20060718 ASP.DLL Include File Buffer Overflow</ref><ref source="OSVDB" url="http://www.osvdb.org/27152">
27152</ref></refs><vuln_soft><prod name="IIS" vendor="Microsoft"><vers num="6.0"/><vers num="5.1"/><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-11" name="CVE-2006-0027" published="2006-05-09" seq="2006-0027" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Microsoft Exchange allows remote attackers to execute arbitrary code via e-mail messages with crafted (1) vCal or (2) iCal Calendar properties.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms06-019.mspx">MS06-019</ref><ref patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-129A.html">TA06-129A</ref><ref patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/303452">VU#303452</ref><ref source="BID" url="http://www.securityfocus.com/bid/17908">17908</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1743">ADV-2006-1743</ref><ref source="OSVDB" url="http://www.osvdb.org/25338">25338</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1016048">1016048</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20029">20029</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25556">exchange-calendar-code-execution(25556)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1818">oval:org.mitre.oval:def:1818</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1996">oval:org.mitre.oval:def:1996</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2035">oval:org.mitre.oval:def:2035</ref></refs><vuln_soft><prod name="exchange srv" vendor="Microsoft"><vers num="2003 SP2"/><vers num="2003 SP1"/><vers num="2000 SP3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-08-28" name="CVE-2006-0028" published="2006-03-14" seq="2006-0028" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-assisted attackers to execute arbitrary code via a BIFF parsing format file containing malformed BOOLERR records that lead to memory corruption, probably involving invalid pointers.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><range><network/><user_init/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/427632/100/0/threaded">20060314 ZDI-06-004: Microsoft Excel File Format Parsing Vulnerability</ref><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms06-012.mspx">MS06-012</ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/339878">VU#339878</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015766">1015766</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19138">19138</ref><ref adv="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-073A.html">TA06-073A</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25225">excel-parsing-format-file-bo(25225)</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0950">ADV-2006-0950</ref><ref source="OSVDB" url="http://www.osvdb.org/23899">23899</ref><ref source="" url="http://www.zerodayinitiative.com/advisories/ZDI-06-004.html"></ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-069.htm"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/19238">19238</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1158">oval:org.mitre.oval:def:1158</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1411">oval:org.mitre.oval:def:1411</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1509">oval:org.mitre.oval:def:1509</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1635">oval:org.mitre.oval:def:1635</ref><ref source="SREASON" url="http://securityreason.com/securityalert/583">583</ref></refs><vuln_soft><prod name="Office" vendor="Microsoft"><vers num="2000 SP3"/><vers num="XP SP3"/><vers num="2003 SP1"/><vers num="2003 SP2"/><vers edition="Mac" num="v. X"/><vers edition="Mac" num="2004"/></prod><prod name="Excel" vendor="Microsoft"><vers num="2000"/><vers num="2002"/><vers num="2003"/><vers edition="Mac OS X" num="X"/><vers edition="Mac OS X" num="2004"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-08-28" name="CVE-2006-0029" published="2006-03-14" seq="2006-0029" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-assisted attackers to execute arbitrary code via an Excel file with a malformed description, which leads to memory corruption.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><range><network/><user_init/></range><refs><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms06-012.mspx">MS06-012</ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/235774">VU#235774</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015766">1015766</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19138">19138</ref><ref adv="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-073A.html">TA06-073A</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25227">excel-description-bo(25227)</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0950">ADV-2006-0950</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-069.htm"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/19238">19238</ref><ref source="OSVDB" url="http://www.osvdb.org/23900">23900</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1522">oval:org.mitre.oval:def:1522</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1570">oval:org.mitre.oval:def:1570</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1579">oval:org.mitre.oval:def:1579</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1633">oval:org.mitre.oval:def:1633</ref><ref source="SREASON" url="http://securityreason.com/securityalert/585">585</ref><ref source="SREASON" url="http://securityreason.com/securityalert/586">586</ref></refs><vuln_soft><prod name="Office" vendor="Microsoft"><vers num="2000 SP3"/><vers num="XP SP3"/><vers num="2003 SP1"/><vers num="2003 SP2"/><vers edition="Mac" num="v. X"/><vers edition="Mac" num="2004"/></prod><prod name="Excel" vendor="Microsoft"><vers num="2000"/><vers num="2002"/><vers num="2003"/><vers edition="Mac OS X" num="X"/><vers edition="Mac OS X" num="2004"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-08-28" name="CVE-2006-0030" published="2006-03-14" seq="2006-0030" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-assisted attackers to execute arbitrary code via an Excel file with a malformed graphic, which leads to memory corruption.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><range><network/><user_init/></range><refs><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms06-012.mspx">MS06-012</ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/123222">VU#123222</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015766">1015766</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19138">19138</ref><ref adv="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-073A.html">TA06-073A</ref><ref source="OSVDB" url="http://www.osvdb.org/23901">23901</ref><ref source="BID" url="http://www.securityfocus.com/bid/16181">16181</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0950">ADV-2006-0950</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25229">excel-graphic-bo(25229)</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-069.htm"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/19238">19238</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1401">oval:org.mitre.oval:def:1401</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1510">oval:org.mitre.oval:def:1510</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1630">oval:org.mitre.oval:def:1630</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1666">oval:org.mitre.oval:def:1666</ref></refs><vuln_soft><prod name="Office" vendor="Microsoft"><vers num="2000 SP3"/><vers num="XP SP3"/><vers num="2003 SP1"/><vers num="2003 SP2"/><vers edition="Mac" num="v. X"/><vers edition="Mac" num="2004"/></prod><prod name="Excel" vendor="Microsoft"><vers num="2000"/><vers num="2002"/><vers num="2003"/><vers edition="Mac OS X" num="X"/><vers edition="Mac OS X" num="2004"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-08-28" name="CVE-2006-0031" published="2006-03-14" seq="2006-0031" severity="Medium" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-assisted attackers to execute arbitrary code via an Excel file with a malformed record with a modified length value, which leads to memory corruption.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms06-012.mspx">MS06-012</ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/104302">VU#104302</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015766">1015766</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19138">19138</ref><ref adv="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-073A.html">TA06-073A</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/17101">17101</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25228">excel-record-bo(25228)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/427699/100/0/threaded">20060315 [xfocus-SD-060314]Microsoft Office Excel Buffer Overflow Vulnerability</ref><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2006-02/1521.html">20060314 [xfocus-SD-060314]Microsoft Office Excel Buffer Overflow Vulnerability</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0950">ADV-2006-0950</ref><ref source="OSVDB" url="http://www.osvdb.org/23902">23902</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-069.htm"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/19238">19238</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1327">oval:org.mitre.oval:def:1327</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1525">oval:org.mitre.oval:def:1525</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1750">oval:org.mitre.oval:def:1750</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:763">oval:org.mitre.oval:def:763</ref><ref source="SREASON" url="http://securityreason.com/securityalert/589">589</ref></refs><vuln_soft><prod name="Office" vendor="Microsoft"><vers num="2000 SP3"/><vers num="XP SP3"/><vers num="2003 SP1"/><vers num="2003 SP2"/><vers edition="Mac" num="v. X"/><vers edition="Mac" num="2004"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-10-05" name="CVE-2006-0032" published="2006-09-12" seq="2006-0032" severity="Low" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in the Indexing Service in Microsoft Windows 2000, XP, and Server 2003, when the Encoding option is set to Auto Select, allows remote attackers to inject arbitrary web script or HTML via a UTF-7 encoded URL, which is injected into an error message whose charset is set to UTF-7.</descript></desc><sols><sol source="nvd">Successful exploitation requires that the Indexing service is accessible through IIS.</sol></sols><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/Bulletin/MS06-053.mspx">MS06-053</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/19927">19927</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/3564">ADV-2006-3564</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/21861">21861</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-255A.html">TA06-255A</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/108884">VU#108884</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1016826">1016826</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/28651">ms-indexing-service-xss(28651)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/447511/100/0/threaded">20061001 Microsoft Internet Information Services UTF-7 XSS Vulnerability [MS06-053]</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/447509/100/0/threaded">20061002 IE UXSS (Universal XSS in IE, was Re: Microsoft Internet Information Services UTF-7 XSS Vulnerability [MS06-053])</ref><ref source="" url="http://www.geocities.jp/ptrs_sec/advisory09e.html"></ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/446630/100/100/threaded">HPSBST02134</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:535">oval:org.mitre.oval:def:535</ref></refs><vuln_soft><prod name="Windows XP" vendor="Microsoft"><vers edition="SP2" num="Tablet PC"/><vers edition="SP2" num="Tablet PC"/><vers edition="SP2" num="Tablet PC"/><vers edition="64-bit" num="Professional"/><vers edition="Gold" num="Professional"/><vers edition="Gold" num="Professional"/><vers edition="Gold" num="Professional"/><vers edition="SP2" num="Media Center"/><vers edition="SP1" num="Media Center"/><vers num="Media Center"/><vers edition="SP2" num="Home"/><vers edition="SP1" num="Home"/><vers num="Home"/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers edition="SP1 Beta 1" num="Web"/><vers edition="SP1" num="Web"/><vers num="Web"/><vers num="Standard 64-bit"/><vers edition="SP1 Beta 1" num="Standard"/><vers edition="SP1" num="Standard"/><vers num="Standard"/><vers num="Enterprise 64-bit"/><vers edition="SP1 Beta 1" num="Enterprise Edition Itanium"/><vers edition="SP1" num="Enterprise Edition Itanium"/><vers num="Enterprise Edition Itanium"/><vers edition="SP1 Beta 1" num="Enterprise Edition"/><vers edition="SP1" num="Enterprise Edition"/><vers edition="Enterprise" num="SP1"/><vers edition="Datacenter 64-bit" num="R2"/><vers edition="SP1 Beta 1" num="Datacenter Edition Itanium"/><vers edition="SP1" num="Datacenter Edition Itanium"/><vers num="Datacenter Edition Itanium"/><vers edition="SP1 Beta 1" num="Datacenter Edition"/><vers edition="SP1" num="Datacenter Edition"/><vers num="Datacenter Edition"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num="Server SP4"/><vers num="Server SP3"/><vers num="Server SP2"/><vers num="Server SP1"/><vers num="Server"/><vers num="Resource Kit"/><vers num="Professional SP4"/><vers num="Professional SP3"/><vers num="Professional SP2"/><vers num="Professional SP1"/><vers num="Professional"/><vers num="Datacenter Server SP4"/><vers num="Datacenter Server SP3"/><vers num="Datacenter Server SP2"/><vers num="Datacenter Server SP1"/><vers num="Datacenter Server"/><vers num="Advanced Server SP4"/><vers num="Advanced Server SP3"/><vers num="Advanced Server SP2"/><vers num="Advanced Server SP1"/><vers num="Advanced Server"/></prod></vuln_soft></entry><entry CVSS_base_score="4.0" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="4.9" CVSS_score="4.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-08-28" name="CVE-2006-0033" published="2006-07-11" seq="2006-0033" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Microsoft Office 2003 SP1 and SP2, Office XP SP3, Office 2000 SP3, and other products, allows user-assisted attackers to execute arbitrary code via a crafted PNG image that triggers memory corruption when it is parsed.</descript></desc><loss_types><avail/><int/></loss_types><vuln_types><exception/></vuln_types><range><network/><user_init/></range><refs><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms06-039.mspx">MS06-039</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/18913">18913</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/459388">VU#459388</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/2757">ADV-2006-2757</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21013">21013</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-192A.html">TA06-192A</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1016470">1016470</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:163">oval:org.mitre.oval:def:163</ref><ref source="" url="http://www.fortinet.com/FortiGuardCenter/advisory/FG-2006-22.html"></ref><ref source="OSVDB" url="http://www.osvdb.org/27147">
27147</ref></refs><vuln_soft><prod name="Office" vendor="Microsoft"><vers num="2003 SP2"/><vers num="2003 SP1"/><vers num="2000 SP3"/><vers num="XP SP3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" discovered="2005-10-11" modified="2007-08-13" name="CVE-2006-0034" published="2006-05-09" seq="2006-0034" severity="High" type="CVE"><desc><descript source="cve">Heap-based buffer overflow in the CRpcIoManagerServer::BuildContext function in msdtcprx.dll for Microsoft Distributed Transaction Coordinator (MSDTC) for Windows NT 4.0 and Windows 2000 SP2 and SP3 allows remote attackers to execute arbitrary code via a long fifth argument to the BuildContextW or BuildContext opcode, which triggers a bug in the NdrAllocate function, aka the MSDTC Invalid Memory Access Vulnerability.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/433430/100/0/threaded">20060509 [EEYEB20051011A] - Microsoft Distributed Transaction Coordinator Heap Overflow</ref><ref adv="1" patch="1" source="" url="http://www.eeye.com/html/research/advisories/AD20060509a.html"></ref><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms06-018.mspx">MS06-018</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/17906">17906</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1742">ADV-2006-1742</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/20000">20000</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/433677/100/0/threaded">20060511 Microsoft MSDTC NdrAllocate Validation Vulnerability</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1016047">1016047</ref><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2006-05/0238.html">20060509 [EEYEB20051011A] - Microsoft Distributed Transaction Coordinator Heap Overflow</ref><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2006-05/0269.html">20060510 Microsoft MSDTC NdrAllocate Validation Vulnerability</ref><ref source="OSVDB" url="http://www.osvdb.org/25335">25335</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1222">oval:org.mitre.oval:def:1222</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1477">oval:org.mitre.oval:def:1477</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1908">oval:org.mitre.oval:def:1908</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25559">msdtc-network-message-dos(25559)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/863">863</ref></refs><vuln_soft><prod name="distributed transaction coordinator" vendor="Microsoft"><vers num=""/></prod><prod name="Windows NT" vendor="Microsoft"><vers num="Workstation 4.0 SP6a"/><vers num="Workstation 4.0 SP6"/><vers num="Workstation 4.0 SP5"/><vers num="Workstation 4.0 SP4"/><vers num="Workstation 4.0 SP3"/><vers num="Workstation 4.0 SP2"/><vers num="Workstation 4.0 SP1"/><vers num="Workstation 4.0"/><vers num="Terminal Server 4.0 SP6a"/><vers num="Terminal Server 4.0 SP6"/><vers num="Terminal Server 4.0 SP5"/><vers num="Terminal Server 4.0 SP4"/><vers num="Terminal Server 4.0 SP3"/><vers num="Terminal Server 4.0 SP2"/><vers num="Terminal Server 4.0 SP1"/><vers num="Terminal Server 4.0"/><vers num="Server 4.0 SP6a"/><vers num="Server 4.0 SP6"/><vers num="Server 4.0 SP5"/><vers num="Server 4.0 SP4"/><vers num="Server 4.0 SP3"/><vers num="Server 4.0 SP2"/><vers num="Server 4.0 SP1"/><vers num="Server 4.0"/><vers num="Enterprise Server 4.0 SP6a"/><vers num="Enterprise Server 4.0 SP6"/><vers num="Enterprise Server 4.0 SP5"/><vers num="Enterprise Server 4.0 SP4"/><vers num="Enterprise Server 4.0 SP3"/><vers num="Enterprise Server 4.0 SP2"/><vers num="Enterprise Server 4.0 SP1"/><vers num="Enterprise Server 4.0"/><vers num="4.0 SP6a"/><vers num="4.0 SP6"/><vers num="4.0 SP5"/><vers num="4.0 SP4"/><vers num="4.0 SP3"/><vers num="4.0 SP2"/><vers num="4.0 SP1"/><vers num="4.0"/></prod><prod name="Windows XP" vendor="Microsoft"><vers edition="SP2" num="Tablet PC"/><vers edition="SP2" num="Tablet PC"/><vers edition="Gold" num="Professional"/><vers edition="Gold" num="Professional"/><vers edition="SP1" num="Media Center"/><vers num="Media Center"/><vers edition="SP1" num="Home"/><vers num="Home"/><vers edition="SP1" num="Embedded"/><vers num="Embedded"/><vers edition="SP1" num="64-bit Version 2003"/><vers num="64-bit Version 2003"/><vers edition="SP1" num="64-bit"/><vers num="64-bit"/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers num="Web"/><vers edition="64-bit" num="Standard"/><vers num="Enterprise 64-bit"/><vers edition="64-bit" num="Enterprise"/><vers edition="Datacenter 64-bit" num="R2"/><vers edition="64-bit" num="R2"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num="Server SP4"/><vers num="Server SP3"/><vers num="Server SP2"/><vers num="Server SP1"/><vers num="Server"/><vers num="Professional SP4"/><vers num="Professional SP3"/><vers num="Professional SP2"/><vers num="Professional SP1"/><vers num="Professional"/><vers num="Datacenter Server SP4"/><vers num="Datacenter Server SP3"/><vers num="Datacenter Server SP2"/><vers num="Datacenter Server SP1"/><vers num="Datacenter Server"/><vers num="Advanced Server SP4"/><vers num="Advanced Server SP3"/><vers num="Advanced Server SP2"/><vers num="Advanced Server SP1"/><vers num="Advanced Server"/></prod></vuln_soft></entry><entry CVSS_base_score="4.9" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.9" CVSS_score="4.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-05" name="CVE-2006-0035" published="2006-01-11" seq="2006-0035" severity="Medium" type="CVE"><desc><descript source="cve">The netlink_rcv_skb function in af_netlink.c in Linux kernel 2.6.14 and 2.6.15 allows local users to cause a denial of service (infinite loop) via a nlmsg_len field of 0.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><local/></range><refs><ref adv="1" source="" url="http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=ad8e4b75c8a7bed475d72ce09bf5267188621961"></ref><ref patch="1" source="TRUSTIX" url="http://www.trustix.org/errata/2006/0004">2006-0004</ref><ref source="BID" url="http://www.securityfocus.com/bid/16414">16414</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18482">18482</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0220">
ADV-2006-0220</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24202">
kernel-afnetlink-dos(24202)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/388">388</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.6.15-rc7"/><vers num="2.6.15-rc6"/><vers num="2.6.15-rc5"/><vers num="2.6.15-rc4"/><vers num="2.6.15-rc3"/><vers num="2.6.15-rc2"/><vers num="2.6.15-rc1"/><vers num="2.6.15"/><vers num="2.6.14-rc4"/><vers num="2.6.14-rc3"/><vers num="2.6.14-rc2"/><vers num="2.6.14-rc1"/><vers num="2.6.14.4"/><vers num="2.6.14.3"/><vers num="2.6.14.2"/><vers num="2.6.14.1"/><vers num="2.6.14"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-24" name="CVE-2006-0036" published="2006-01-23" seq="2006-0036" severity="High" type="CVE"><desc><descript source="cve">ip_nat_pptp in the PPTP NAT helper (netfilter/ip_nat_helper_pptp.c) in Linux kernel 2.6.14, and other versions, allows remote attackers to cause a denial of service (memory corruption or crash) via an inbound PPTP_IN_CALL_REQUEST packet that causes a null pointer to be used in an offset calculation.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=15db34702cfafd24acc60295cf14861e497502ab"></ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2006/0004">2006-0004</ref><ref source="BID" url="http://www.securityfocus.com/bid/16414">16414</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18482">18482</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0220">
ADV-2006-0220</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24203">
kernel-pptpincallrequest-dos(24203)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/388">388</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.6.14"/></prod></vuln_soft></entry><entry CVSS_base_score="4.9" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.9" CVSS_score="4.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-24" name="CVE-2006-0037" published="2006-01-23" seq="2006-0037" severity="Medium" type="CVE"><desc><descript source="cve">ip_nat_pptp in the PPTP NAT helper (netfilter/ip_nat_helper_pptp.c) in Linux kernel 2.6.14, and other versions, allows local users to cause a denial of service (memory corruption or crash) via a crafted outbound packet that causes an incorrect offset to be calculated from pointer arithmetic when non-linear SKBs (socket buffers) are used.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref source="" url="http://kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=03b9feca89366952ae5dfe4ad8107b1ece50b710"></ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2006/0004">2006-0004</ref><ref source="BID" url="http://www.securityfocus.com/bid/16414">16414</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18482">18482</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0220">
ADV-2006-0220</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24204">
kernel-pptpnathelper-dos(24204)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/388">388</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.6.14"/></prod></vuln_soft></entry><entry CVSS_base_score="6.9" CVSS_exploit_subscore="3.4" CVSS_impact_subscore="10.0" CVSS_score="6.9" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-04-17" name="CVE-2006-0038" published="2006-03-22" seq="2006-0038" severity="Medium" type="CVE"><desc><descript source="cve">Integer overflow in the do_replace function in netfilter for Linux before 2.6.16-rc3, when using &quot;virtualization solutions&quot; such as OpenVZ, allows local users with CAP_NET_ADMIN rights to cause a buffer overflow in the copy_from_user function.</descript></desc><sols><sol source="nvd">Linux kernel version 2.6.16 has been released to address this issue.</sol></sols><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref source="" url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=186295"></ref><ref source="" url="http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=ee4bb818ae35f68d1f848eae0a7b150a38eb4168"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/17178">17178</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19330">19330</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1046">ADV-2006-1046</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25400">linux-netfilter-doreplace-overflow(25400)</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1097">DSA-1097</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20671">20671</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-302-1">USN-302-1</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20716">20716</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1103">DSA-1103</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/2554">ADV-2006-2554</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20914">20914</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0575.html">RHSA-2006:0575</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21465">21465</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-200.htm"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/22417">22417</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.6.16 -rc1"/><vers num="2.6.15 .4"/><vers num="2.6.15 .3"/><vers num="2.6.15 .2"/><vers num="2.6.15 .1"/><vers num="2.6.15 -rc3"/><vers num="2.6.15 -rc2"/><vers num="2.6.15 -rc1"/><vers num="2.6.15"/><vers num="2.6.14.5"/><vers num="2.6.14.4"/><vers num="2.6.14.3"/><vers num="2.6.14.2"/><vers num="2.6.14.1"/><vers num="2.6.14 -rc4"/><vers num="2.6.14 -rc3"/><vers num="2.6.14 rc2"/><vers num="2.6.14 rc1"/><vers num="2.6.14"/><vers num="2.6.13.4"/><vers num="2.6.13.3"/><vers num="2.6.13.2"/><vers num="2.6.13.1"/><vers num="2.6.13 rc7"/><vers num="2.6.13 rc6"/><vers num="2.6.13 rc4"/><vers num="2.6.13 rc1"/><vers num="2.6.13"/><vers num="2.6.12.6"/><vers num="2.6.12.5"/><vers num="2.6.12.4"/><vers num="2.6.12.3"/><vers num="2.6.12.2"/><vers num="2.6.12.1"/><vers num="2.6.12 rc5"/><vers num="2.6.12 rc4"/><vers num="2.6.12 rc1"/><vers num="2.6.11.8"/><vers num="2.6.11.7"/><vers num="2.6.11.6"/><vers num="2.6.11.5"/><vers num="2.6.11.12"/><vers num="2.6.11.11"/><vers num="2.6.11 rc4"/><vers num="2.6.11 rc3"/><vers num="2.6.11 rc2"/><vers num="2.6.11"/><vers num="2.6.10 rc2"/><vers num="2.6.10"/><vers edition="2.6.20" num="2.6.9"/><vers num="2.6.8-rc3"/><vers num="2.6.8-rc2"/><vers num="2.6.8-rc1"/><vers num="2.6.8"/><vers num="2.6.7 rc1"/><vers num="2.6.7"/><vers num="2.6.6-rc1"/><vers num="2.6.6"/><vers num="2.6.5"/><vers num="2.6.4"/><vers num="2.6.3"/><vers num="2.6.2"/><vers num="2.6.1 rc2"/><vers num="2.6.1 rc1"/><vers num="2.6.1"/><vers num="2.6 test9 CVS"/><vers num="2.6 test9"/><vers num="2.6 test8"/><vers num="2.6 test7"/><vers num="2.6 test6"/><vers num="2.6 test5"/><vers num="2.6 test4"/><vers num="2.6 test3"/><vers num="2.6 test2"/><vers num="2.6 test11"/><vers num="2.6 test10"/><vers num="2.6 test1"/><vers num="2.6"/><vers num="2.6.15.5"/></prod></vuln_soft></entry><entry CVSS_base_score="1.2" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="2.9" CVSS_score="1.2" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-05-16" modified="2006-05-22" name="CVE-2006-0039" published="2006-05-19" seq="2006-0039" severity="Low" type="CVE"><desc><descript source="cve">Race condition in the do_add_counters function in netfilter for Linux kernel 2.6.16 allows local users with CAP_NET_ADMIN capabilities to read kernel memory by triggering the race condition in a way that produces a size value that is inconsistent with allocated memory, which leads to a buffer over-read in IPT_ENTRY_ITERATE.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/><race/></vuln_types><range><local/></range><refs><ref source="" url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=191698"></ref><ref patch="1" source="" url="http://bugs.gentoo.org/show_bug.cgi?id=133465"></ref><ref patch="1" source="" url="http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=2722971cbe831117686039d5c334f2c0f560be13"></ref><ref source="" url="http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.16.17"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1893">ADV-2006-1893</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20185">20185</ref><ref source="BID" url="http://www.securityfocus.com/bid/18113">18113</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26583">linux-doaddcounters-race-condition(26583)</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1097">DSA-1097</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20671">20671</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1103">DSA-1103</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/2554">ADV-2006-2554</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20914">20914</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-311-1">USN-311-1</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20991">20991</ref><ref source="OSVDB" url="http://www.osvdb.org/25697">25697</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0689.html">RHSA-2006:0689</ref><ref source="SECUNIA" url="http://secunia.com/advisories/22292">22292</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-249.htm"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/22945">22945</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21476">
21476</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.6.16"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-10" name="CVE-2006-0040" published="2006-03-09" seq="2006-0040" severity="Medium" type="CVE"><desc><descript source="cve">GNOME Evolution 2.4.2.1 and earlier allows remote attackers to cause a denial of service (CPU and memory consumption) via a text e-mail with a large number of URLs, possibly due to unknown problems in gtkhtml.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426452/100/0/threaded">20060301 Evolution Emailer DoS</ref><ref source="BID" url="http://www.securityfocus.com/bid/16889">16889</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0801">ADV-2006-0801</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19049">19049</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19094">19094</ref><ref source="BID" url="http://www.securityfocus.com/bid/16899">16899</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25050">
evolution-email-dos(25050)</ref></refs><vuln_soft><prod name="Evolution" vendor="GNOME"><vers num="2.4.2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-17" name="CVE-2006-0042" published="2006-02-18" seq="2006-0042" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in (1) apreq_parse_headers and (2) apreq_parse_urlencoded functions in Apache2::Request (Libapreq2) before 2.07 allows remote attackers cause a denial of service (CPU consumption) via unknown attack vectors that result in quadratic computational complexity.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref source="" url="http://svn.apache.org/viewcvs.cgi/httpd/apreq/tags/v2_07/CHANGES?rev=376998&amp;view=markup"></ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18846">18846</ref><ref source="" url="http://svn.apache.org/viewcvs.cgi/httpd/apreq/tags/v2_07/CHANGES?rev=376998&amp;view=markup"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16710">16710</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0645">ADV-2006-0645</ref><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1000">DSA-1000</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19139">19139</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200604-08.xml">GLSA-200604-08</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19658">19658</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24917">
libapreq2-parsing-dos(24917)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/737">737</ref></refs><vuln_soft><prod name="Libapreq2" vendor="Libapreq2"><vers num="2.06 dev"/><vers num="2.05 dev"/><vers num="2.04 dev"/><vers num="2.03 dev"/><vers num="2.02 dev"/><vers num="2.01 dev"/><vers num="1.33"/><vers num="1.3"/><vers num="1.2"/><vers num="1.1"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-01" name="CVE-2006-0043" published="2006-01-30" seq="2006-0043" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in the realpath function in nfs-server rpc.mountd, as used in SUSE Linux 9.1 through 10.0, allows local users to execute arbitrary code via unspecified vectors involving mount requests and symlinks.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="SUSE" url="http://lists.suse.com/archive/suse-security-announce/2006-Jan/0007.html">SuSE-SA:2006:005</ref><ref source="BID" url="http://www.securityfocus.com/bid/16388">16388</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0348">ADV-2006-0348</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18614">18614</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18638">18638</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24347">nfs-rpcmountd-realpath-bo(24347)</ref><ref source="" url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=350020"></ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-975">DSA-975</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18889">18889</ref></refs><vuln_soft><prod name="SuSE Linux" vendor="SuSE"><vers num="Professional 10.0"/><vers edition="x86_64" num="Professional 9.3"/><vers num="Professional 9.3"/><vers edition="x86_64" num="Professional 9.2"/><vers num="Professional 9.2"/><vers edition="x86_64" num="Professional 9.1"/><vers num="Professional 9.1"/><vers edition="x86_64" num="Personal 9.3"/><vers num="Personal 9.3"/><vers edition="x86_64" num="Personal 9.2"/><vers num="Personal 9.2"/><vers edition="x86_64" num="Personal 9.1"/><vers num="Personal 9.1"/></prod><prod name="SuSE Novell Linux Desktop" vendor="SuSE"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-18" name="CVE-2006-0044" published="2006-01-17" seq="2006-0044" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in context.py in Albatross web application toolkit before 1.33 allows remote attackers to execute arbitrary commands via unspecified vectors involving template files and the &quot;handling of submitted form fields&quot;.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="" url="http://www.object-craft.com.au/projects/albatross/news.html"></ref><ref source="" url="http://security.debian.org/pool/updates/main/a/albatross/albatross_1.20-2.diff.gz"></ref><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2006/dsa-942">DSA-942</ref><ref source="BID" url="http://www.securityfocus.com/bid/16252">16252</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0196">ADV-2006-0196</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18457">18457</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18496">18496</ref><ref source="OSVDB" url="http://www.osvdb.org/22451">22451</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24130">
albatross-context-command-execution(24130)</ref></refs><vuln_soft><prod name="Albatross" vendor="Albatross"><vers num="1.32"/><vers num="1.30"/><vers num="1.20"/><vers num="1.10"/><vers num="1.01"/><vers num="1.00"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-30" name="CVE-2006-0045" published="2006-01-20" seq="2006-0045" severity="High" type="CVE"><desc><descript source="cve">crawl before 4.0.0 does not securely call programs when saving and loading games, which allows local users to gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2006/dsa-949">DSA-949</ref><ref source="BID" url="http://www.securityfocus.com/bid/16337">16337</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0303">ADV-2006-0303</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18545">18545</ref><ref source="OSVDB" url="http://www.osvdb.org/22690">22690</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18573">18573</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24262">crawl-insecure-command-execution(24262)</ref></refs><vuln_soft><prod name="Dungeon Crawl" vendor="Linley Henzell"><vers num="4.0.0 b23"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-14" name="CVE-2006-0046" published="2006-02-13" seq="2006-0046" severity="High" type="CVE"><desc><descript source="cve">squid_redirect script in adzapper before 2006-01-29 allows remote attackers to cause a denial of service (CPU consumption) via a URL with a large number of trailing / (forward slashes), which might produce inefficient regular expressions.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2006/dsa-966">DSA-966</ref><ref source="" url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=350308"></ref><ref source="" url="http://bugs.debian.org/cgi-bin/bugreport.cgi/squid_redirect.diff?bug=350308;msg=5;att=1"></ref><ref source="" url="http://adzapper.sourceforge.net/cvslog.html"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0491">ADV-2006-0491</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18771">18771</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18777">18777</ref><ref source="BID" url="http://www.securityfocus.com/bid/16558">16558</ref><ref source="OSVDB" url="http://www.osvdb.org/22900">22900</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24640">
adzapper-squid-redirect-dos(24640)</ref></refs><vuln_soft><prod name="adzapper" vendor="Cameron Simpson"><vers num="2006-01-29"/><vers num="2006-01-28"/><vers num="2006-01-25"/><vers num="2006-01-24"/><vers num="2006-01-23"/><vers num="2006-01-15"/><vers num="2006-01-14"/><vers num="2006-01-07"/><vers num="2006-01-05"/><vers num="2006-01-01"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2008-05-20" name="CVE-2006-0047" published="2006-03-07" seq="2006-0047" severity="Medium" type="CVE"><desc><descript source="cve">packets.c in Freeciv 2.0 before 2.0.8 allows remote attackers to cause a denial of service (server crash) via crafted packets with negative compressed size values.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="" url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=355211"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0838">ADV-2006-0838</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19120">19120</ref><ref adv="1" patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/426866/100/0/threaded">20060306 Out of memory crash in Freeciv 2.0.7</ref><ref adv="1" patch="1" source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:053">MDKSA-2006:053</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16975">16975</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200603-11.xml">GLSA-200603-1</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19253">19253</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-994">DSA-994</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19227">19227</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25166">freeciv-packets-dos(25166)</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:053">MDKSA-2006:053</ref></refs><vuln_soft><prod name="Freeciv" vendor="Freeciv"><vers num="2.0.7a"/><vers num="2.0.7"/><vers num="2.0.6"/><vers num="2.0.5"/><vers num="2.0.4"/><vers num="2.0.3"/><vers num="2.0.2"/><vers num="2.0.1"/><vers num="2.0.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-27" name="CVE-2006-0048" published="2006-04-25" seq="2006-0048" severity="Medium" type="CVE"><desc><descript source="cve">Francesco Stablum tcpick 0.2.1 allows remote attackers to cause a denial of service (segmentation fault) via certain fragmented packets, possibly involving invalid headers and an attacker-controlled payload length.  NOTE: this issue might be a buffer overflow or overread.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="" url="http://sourceforge.net/mailarchive/forum.php?thread_id=9989610&amp;forum_id=37151"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17665">17665</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1466">ADV-2006-1466</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26090">
tcpick-writec-dos(26090)</ref></refs><vuln_soft><prod name="tcpick" vendor="Francesco Stablum"><vers num="0.2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-14" name="CVE-2006-0049" published="2006-03-13" seq="2006-0049" severity="Medium" type="CVE"><desc><descript source="cve">gpg in GnuPG before 1.4.2.2 does not properly verify non-detached signatures, which allows attackers to inject unsigned data via a data packet that is not associated with a control packet, which causes the check for concatenated signatures to report that the signature is valid, a different vulnerability than CVE-2006-0455.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/427324/100/0/threaded">20060313 GnuPG does not detect injection of unsigned data</ref><ref adv="1" patch="1" source="MLIST" url="http://lists.gnupg.org/pipermail/gnupg-announce/2006q1/000216.html">[gnupg-announce] 20060309 [Announce] GnuPG does not detect injection of unsigned data</ref><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2006/dsa-993">DSA-993</ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200603-08.xml">GLSA-200603-08</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-264-1">USN-264-1</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/17058">17058</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0915">ADV-2006-0915</ref><ref patch="1" source="OSVDB" url="http://www.osvdb.org/23790">23790</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015749">1015749</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19173">19173</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-announce-list/2006-March/msg00021.html">FEDORA-2006-147</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19203">19203</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19244">19244</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0266.html">RHSA-2006:0266</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2006/0014">2006-0014</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19231">19231</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19249">19249</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19287">19287</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:055">MDKSA-2006:055</ref><ref source="SUSE" url="http://lists.suse.de/archive/suse-security-announce/2006-Mar/0003.html">SUSE-SA:2006:014</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19197">19197</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19232">19232</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19234">19234</ref><ref source="SLACKWARE" url="http://www.slackware.com/security/viewer.php?l=slackware-security&amp;y=2006&amp;m=slackware-security.476477">SSA:2006-072-02</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20060401-01-U">20060401-01-U</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19532">19532</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/433931/100/0/threaded">FLSA-2006:185355</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25184">
gnupg-nondetached-sig-verification(25184)</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:055">MDKSA-2006:055</ref><ref source="SREASON" url="http://securityreason.com/securityalert/450">450</ref><ref source="SREASON" url="http://securityreason.com/securityalert/568">568</ref></refs><vuln_soft><prod name="GNU Privacy Guard" vendor="GNU"><vers num="1.4.2.1"/><vers num="1.4.2"/><vers num="1.4.1"/><vers num="1.4"/><vers num="1.3.4"/><vers num="1.3.3"/><vers num="1.2.7"/><vers num="1.2.6"/><vers num="1.2.5"/><vers num="1.2.4"/><vers num="1.2.3"/><vers num="1.2.2 rc1"/><vers num="1.2.2 r1"/><vers num="1.2.2"/><vers num="1.2.1"/><vers num="1.2"/><vers num="1.0.7"/><vers num="1.0.6"/><vers num="1.0.5"/><vers num="1.0.4"/><vers num="1.0.3b"/><vers num="1.0.3"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="1.2" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="2.9" CVSS_score="1.2" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-23" name="CVE-2006-0050" published="2006-03-23" seq="2006-0050" severity="Low" type="CVE"><desc><descript source="cve">snmptrapfmt in Debian 3.0 allows local users to overwrite arbitrary files via a symlink attack on a temporary log file.</descript></desc><loss_types><int/></loss_types><vuln_types><design/><race/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1013">DSA-1013</ref><ref source="BID" url="http://www.securityfocus.com/bid/17182">17182</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19318">19318</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25442">snmptrapfmt-log-temprary-file(25442)</ref></refs><vuln_soft><prod name="Debian Linux" vendor="Debian"><vers num="3.1 sparc"/><vers num="3.1 s_390"/><vers num="3.1 ppc"/><vers num="3.1 mipsel"/><vers num="3.1 mips"/><vers num="3.1 m68k"/><vers num="3.1 ia-64"/><vers num="3.1 ia-32"/><vers num="3.1 hppa"/><vers num="3.1 arm"/><vers num="3.1 amd64"/><vers num="3.1 alpha"/><vers num="3.1"/><vers num="3.0 sparc"/><vers num="3.0 s_390"/><vers num="3.0 ppc"/><vers num="3.0 mipsel"/><vers num="3.0 mips"/><vers num="3.0 m68k"/><vers num="3.0 ia-64"/><vers num="3.0 ia-32"/><vers num="3.0 hppa"/><vers num="3.0 arm"/><vers num="3.0 alpha"/><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-09-21" name="CVE-2006-0051" published="2006-04-05" seq="2006-0051" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in playlistimport.cpp in Kaffeine Player 0.4.2 through 0.7.1 allows user-assisted attackers to execute arbitrary code via long HTTP request headers when Kaffeine is &quot;fetching remote playlists&quot;, which triggers the overflow in the http_peek function.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="" url="http://www.kde.org/info/security/advisory-20060404-1.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17372">17372</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1229">ADV-2006-1229</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19525">19525</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1023">DSA-1023</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/430319/100/0/threaded">20060405 [Kaffeine Security Advisory] Heap based buffer overflow in http_peek()</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200604-04.xml">GLSA-200604-04</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:065">MDKSA-2006:065</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_08_sr.html">SUSE-SR:2006:008</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-268-1">USN-268-1</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015863">1015863</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19540">19540</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19542">19542</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19549">19549</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19557">19557</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19571">19571</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25631">kaffeine-http-peek-bo(25631)</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:065">MDKSA-2006:065</ref></refs><vuln_soft><prod name="Kaffeine Player" vendor="Kaffeine"><vers num="0.7.1"/><vers num="0.5 rc1"/><vers num="0.4.3b"/><vers num="0.4.3"/><vers num="0.4.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-31" name="CVE-2006-0052" published="2006-03-31" seq="2006-0052" severity="Medium" type="CVE"><desc><descript source="cve">The attachment scrubber (Scrubber.py) in Mailman 2.1.5 and earlier, when using Python&apos;s library email module 2.5, allows remote attackers to cause a denial of service (mailing list delivery failure) via a multipart MIME message with a single part that has two blank lines between the first boundary and the end boundary.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:061">MDKSA-2006:061</ref><ref patch="1" source="" url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=358892"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/17311">17311</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015851">1015851</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1027">DSA-1027</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19545">19545</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_08_sr.html">SUSE-SR:2006:008</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-267-1">USN-267-1</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19522">19522</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19571">19571</ref><ref source="OSVDB" url="http://www.osvdb.org/24367">24367</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0486.html">RHSA-2006:0486</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20624">20624</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20060602-01-U.asc">20060602-01-U</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20782">20782</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:061">MDKSA-2006:061</ref></refs><vuln_soft><prod name="Mailman" vendor="GNU"><vers num="2.1.5"/><vers num="2.1.4"/><vers num="2.1.3"/><vers num="2.1.2"/><vers num="2.1.1"/><vers num="2.1b1"/><vers num="2.1"/><vers num="2.0.14"/><vers num="2.0.13"/><vers num="2.0.12"/><vers num="2.0.11"/><vers num="2.0.10"/><vers num="2.0.9"/><vers num="2.0.7"/><vers num="2.0.6"/><vers num="2.0.5"/><vers num="2.0.4"/><vers num="2.0.3"/><vers num="2.0.2"/><vers num="2.0.1"/><vers num="2.0 beta5"/><vers num="2.0 beta4"/><vers num="2.0 beta3"/><vers num="2.0.8"/><vers num="2.0"/><vers num="1.1"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2008-04-28" name="CVE-2006-0053" published="2006-04-10" seq="2006-0053" severity="Low" type="CVE"><desc><descript source="cve">Imager (libimager-perl) before 0.50 allows user-assisted attackers to cause a denial of service (segmentation fault) by writing a 2- or 4-channel JPEG image (or a 2-channel TGA image) to a scalar, which triggers a NULL pointer dereference.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1028">DSA-1028</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19577">19577</ref><ref source="" url="http://rt.cpan.org/Public/Bug/Display.html?id=18397"></ref><ref source="" url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=359661"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/17415">17415</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19575">19575</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1294">ADV-2006-1294</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25717">imager-jpeg-tga-dos(25717)</ref></refs><vuln_soft><prod name="Imager" vendor="Tony Cook"><vers num="0.49"/><vers num="0.48"/><vers num="0.47"/><vers num="0.45_2"/><vers num="0.45"/><vers num="0.44_1"/><vers num="0.43"/><vers num="0.42"/><vers num="0.41"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-13" name="CVE-2006-0054" published="2006-01-11" seq="2006-0054" severity="Medium" type="CVE"><desc><descript source="cve">The ipfw firewall in FreeBSD 6.0-RELEASE allows remote attackers to cause a denial of service (firewall crash) via ICMP IP fragments that match a reset, reject or unreach action, which leads to an access of an uninitialized pointer.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="FREEBSD" url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-06:04.ipfw.asc">FreeBSD-SA-06:04</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16209">16209</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18378">18378</ref><ref source="OSVDB" url="http://www.osvdb.org/22319">22319</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015477">1015477</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24073">ipfw-icmp-fragment-dos(24073)</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="6.0 Release"/><vers num="6.0 Stable"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-13" name="CVE-2006-0055" published="2006-01-11" seq="2006-0055" severity="Low" type="CVE"><desc><descript source="cve">The ispell_op function in ee on FreeBSD 4.10 to 6.0 uses predictable filenames and does not confirm which file is being written, which allows local users to overwrite arbitrary files via a symlink attack when ee invokes ispell.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="FREEBSD" url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-06:02.ee.asc">FreeBSD-SA-06:02</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16207">16207</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18404">18404</ref><ref source="OSVDB" url="http://www.osvdb.org/22320">22320</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015469">1015469</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24074">ee-ispell-op-symlink(24074)</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="6.0 Stable"/><vers num="6.0 Release"/><vers num="5.4 Releng"/><vers num="5.4 Release"/><vers num="5.4 pre"/><vers num="5.3 Stable"/><vers num="5.3 Releng"/><vers num="5.3 Release"/><vers num="5.3"/><vers num="5.2.1 Release"/><vers num="5.2 Releng"/><vers num="5.2 Release"/><vers num="5.2"/><vers num="5.1 Releng"/><vers num="5.1 Release Alpha"/><vers num="5.1 p5 Release"/><vers num="5.1 Release"/><vers num="5.1"/><vers num="5.0 Releng"/><vers num="5.0 p14 Release"/><vers num="5.0 alpha"/><vers num="5.0"/><vers num="4.11 Stable"/><vers num="4.11 Releng"/><vers num="4.11 p3 Release"/><vers num="4.10 Releng"/><vers num="4.10 p8 Release"/><vers num="4.10 Release"/><vers num="4.10"/><vers num="4.10 pre"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-02-26" name="CVE-2006-0056" published="2006-02-13" seq="2006-0056" severity="High" type="CVE"><desc><descript source="cve">Double free vulnerability in the authentication and authentication token alteration code in PAM-MySQL 0.6.x before 0.6.2 and 0.7.x before 0.7pre3 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via crafted passwords, which lead to a double free of a pointer that was created by the pam_get_item function.  NOTE: this issue only occurs in certain configurations in which there are multiple PAM modules, PAM-MySQL is not evaluated first, and there are no requisite modules before PAM-MySQL.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="" url="http://sourceforge.net/forum/forum.php?forum_id=499394"></ref><ref source="" url="http://jvn.jp/cert/JVNVU%23693909/index.html"></ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/693909">VU#693909</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16564">16564</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0490">ADV-2006-0490</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015603">1015603</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18598">18598</ref><ref source="OSVDB" url="http://www.osvdb.org/22994">22994</ref><ref source="OSVDB" url="http://www.osvdb.org/22995">22995</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200606-18.xml">GLSA-200606-18</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/20690">20690</ref></refs><vuln_soft><prod name="PAM-MySQL" vendor="PAM-MySQL"><vers num="0.4.7"/><vers num="0.4"/><vers num="0.3"/><vers num="0.2"/><vers num="0.1"/><vers num="0.7 pre2"/><vers num="0.7 pre1"/><vers num="0.6"/><vers num="0.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-30" name="CVE-2006-0057" published="2006-01-27" seq="2006-0057" severity="High" type="CVE"><desc><descript source="cve">Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to bypass the Kill bit settings for dangerous ActiveX controls via unknown vectors involving crafted HTML, which can expose the browser to attacks that would otherwise be prevented by the Kill bit setting. NOTE: CERT/CC claims that MS05-054 fixes this issue, but it is not described in MS05-054.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/998297">VU#998297</ref><ref adv="1" patch="1" source="" url="http://www.microsoft.com/technet/security/bulletin/ms05-054.mspx"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16409">16409</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24379">ie-activex-killbit-bypass(24379)</ref><ref source="OSVDB" url="http://www.osvdb.org/23657">23657</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="5.01 SP4"/><vers num="6 SP1"/><vers edition="Windows Server 2003 SP1" num="6"/><vers num="5.5 SP2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="10.0" CVSS_score="7.6" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-27" name="CVE-2006-0058" published="2006-03-22" seq="2006-0058" severity="High" type="CVE"><desc><descript source="cve">Signal handler race condition in Sendmail 8.13.x before 8.13.6 allows remote attackers to execute arbitrary code by triggering timeouts in a way that causes the setjmp and longjmp function calls to be interrupted and modify unexpected memory locations.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><race/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS" url="http://xforce.iss.net/xforce/alerts/id/216">20060322 Sendmail Remote Signal Handling Vulnerability</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0264.html">RHSA-2006:0264</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0265.html">RHSA-2006:0265</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1049">ADV-2006-1049</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1051">ADV-2006-1051</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/428536/100/0/threaded">20060322 sendmail vuln advisories (CVE-2006-0058)</ref><ref source="" url="http://www.sendmail.com/company/advisory/index.shtml"></ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1015">DSA-1015</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200603-21.xml">GLSA-200603-21</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:058">MDKSA-2006:058</ref><ref source="OPENPKG" url="http://www.openpkg.org/security/advisories/OpenPKG-SA-2006.007-sendmail.html">OpenPKG-SA-2006.007</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-081A.html">TA06-081A</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/834865">VU#834865</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19342">19342</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19363">19363</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19367">19367</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/428656/100/0/threaded">FLSA:186277</ref><ref source="FREEBSD" url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-06:13.sendmail.asc">FreeBSD-SA-06:13</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_17_sendmail.html">SUSE-SA:2006:017</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-074.htm"></ref><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/428892/100/0/threaded">HPSBUX02108</ref><ref source="OPENBSD" url="http://www.openbsd.org/errata38.html#sendmail">[3.8] 006: SECURITY FIX: March 25, 2006</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102262-1">102262</ref><ref source="BID" url="http://www.securityfocus.com/bid/17192">17192</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1068">ADV-2006-1068</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1072">ADV-2006-1072</ref><ref source="OSVDB" url="http://www.osvdb.org/24037">24037</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015801">1015801</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19368">19368</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19404">19404</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19407">19407</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19349">19349</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19360">19360</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19361">19361</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24584">smtp-timeout-bo(24584)</ref><ref source="" url="http://www.f-secure.com/security/fsc-2006-2.shtml"></ref><ref source="NETBSD" url="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2006-010.txt.asc">NetBSD-SA2006-010</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1139">ADV-2006-1139</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1157">ADV-2006-1157</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19394">19394</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19450">19450</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19466">19466</ref><ref source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY82992&amp;apar=only">IY82992</ref><ref source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY82993&amp;apar=only">IY82993</ref><ref source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY82994&amp;apar=only">IY82994</ref><ref source="SLACKWARE" url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2006&amp;m=slackware-security.619600">SSA:2006-081-01</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20060302-01-P">20060302-01-P</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20060401-01-U">20060401-01-U</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19533">19533</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19532">19532</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00018.html">FEDORA-2006-193</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00017.html">FEDORA-2006-194</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/q-151.shtml">Q-151</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19345">19345</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19346">19346</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19356">19356</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-078.htm"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/19676">19676</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102324-1">102324</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1529">ADV-2006-1529</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19774">19774</ref><ref source="SCO" url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2006.24/SCOSA-2006.24.txt">SCOSA-2006.24</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20243">20243</ref><ref source="HP" url="http://itrc.hp.com/service/cki/docDisplay.do?docId=c00692635">HPSBTU02116</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/2189">ADV-2006-2189</ref><ref source="" url="http://www14.software.ibm.com/webapp/set2/sas/f/hmc/power5/install/v52.Readme.html#MH00688"></ref><ref source="" url="http://www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd?mode=18&amp;ID=2751"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/2490">ADV-2006-2490</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20723">20723</ref><ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c00629555">HPSBUX02108</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1689">oval:org.mitre.oval:def:1689</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:058">MDKSA-2006:058</ref><ref source="SREASON" url="http://securityreason.com/securityalert/612">612</ref><ref source="SREASON" url="http://securityreason.com/securityalert/743">743</ref></refs><vuln_soft><prod name="Sendmail" vendor="Sendmail Consortium"><vers num="8.13.5"/><vers num="8.13.4"/><vers num="8.13.3"/><vers num="8.13.2"/><vers num="8.13.1"/><vers num="8.13.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-19" name="CVE-2006-0059" published="2006-05-19" seq="2006-0059" severity="High" type="CVE"><desc><descript source="cve">Heap-based buffer overflow in the ISO Transport Service over TCP (RFC 1006) implementation of LiveData ICCP Server before 5.00.035 allows remote attackers to cause a denial of service or execute arbitrary code via malformed packets.</descript></desc><sols><sol source="nvd">This vulnerability is addressed in the following product release:
LiveData, ICCP Server, 5.00.035</sol></sols><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="US-CERT" url="http://www.kb.cert.org/vuls/id/JGEI-6MMS9T">VU#190617</ref><ref patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/190617">VU#190617</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1830">ADV-2006-1830</ref><ref source="" url="http://www.digitalbond.com/SCADA_Blog/2006/05/us-cert-livedata-iccp-vulnerability.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/18010">18010</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1016113">1016113</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20146">20146</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/26490">livedata-iccp-rfc1006-bo(26490)</ref></refs><vuln_soft><prod name="ICCP Server" vendor="LiveData"><vers num="5.00.045"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-09" name="CVE-2006-0063" published="2006-01-05" seq="2006-0063" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in phpBB 2.0.19, when &quot;Allowed HTML tags&quot; is enabled, allows remote attackers to inject arbitrary web script or HTML via a permitted HTML tag with &apos; (single quote) characters and active attributes such as onmouseover, a variant of CVE-2005-4357.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://securityreason.com/achievement_securityalert/30"></ref><ref adv="1" source="" url="http://securityreason.com/securityalert/313"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0051">ADV-2006-0051</ref><ref source="OSVDB" url="http://www.osvdb.org/22672">22672</ref></refs><vuln_soft><prod name="phpBB" vendor="phpBB Group"><vers num="2.0.19"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-12" name="CVE-2006-0064" published="2006-01-03" seq="2006-0064" severity="High" type="CVE"><desc><descript source="cve">PHP remote file include vulnerability in includes/orderSuccess.inc.php in CubeCart allows remote attackers to execute arbitrary PHP code via a URL in the glob[rootDir] parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0016">ADV-2006-0016</ref><ref source="" url="http://milw0rm.com/id.php?id=1398"></ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/1398">

1398</ref></refs><vuln_soft><prod name="CubeCart" vendor="Devellion"><vers num="3.0.6" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-04" name="CVE-2006-0065" published="2006-01-03" seq="2006-0065" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in (1) functions.php, (2) functions_update.php, and (3) functions_display.php in VEGO Web Forum 1.26 and earlier allows remote attackers to execute arbitrary SQL commands via the theme_id parameter in index.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/420661/100/0/threaded">20060101 [eVuln] VEGO Web Forum SQL Injection Vulnerability</ref><ref adv="1" source="" url="http://evuln.com/vulns/1/summary.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0003">ADV-2006-0003</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18273">18273</ref><ref source="BID" url="http://www.securityfocus.com/bid/16107">16107</ref><ref source="OSVDB" url="http://www.osvdb.org/22140">22140</ref><ref source="SREASON" url="http://securityreason.com/securityalert/315">315</ref></refs><vuln_soft><prod name="VEGO Web Forum" vendor="VEGO"><vers num="1.26" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-04" name="CVE-2006-0066" published="2006-01-03" seq="2006-0066" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in index.php in PHPjournaler 1.0 allows remote attackers to execute arbitrary SQL commands via the readold parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/420666/100/0/threaded">20060101 [eVuln] PHPjournaler SQL Injection Vulnerability</ref><ref adv="1" source="" url="http://evuln.com/vulns/9/summary.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0006">ADV-2006-0006</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18265">18265</ref><ref source="BID" url="http://www.securityfocus.com/bid/16111">16111</ref><ref source="OSVDB" url="http://www.osvdb.org/22149">22149</ref></refs><vuln_soft><prod name="PHPjournaler" vendor="PHPjournaler"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-04" name="CVE-2006-0067" published="2006-01-03" seq="2006-0067" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in login.php in VEGO Links Builder 2.00 and earlier allows remote attackers to execute arbitrary SQL commands via the username parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://evuln.com/vulns/2/summary.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0004">ADV-2006-0004</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18272">18272</ref><ref source="OSVDB" url="http://www.osvdb.org/22139">22139</ref><ref source="BID" url="http://www.securityfocus.com/bid/16108">16108</ref></refs><vuln_soft><prod name="VEGO Links Builder" vendor="VEGO"><vers num="2.00" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-04" name="CVE-2006-0068" published="2006-01-03" seq="2006-0068" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in Primo Cart 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) q parameter to search.php and (2) email parameter to user.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://pridels.blogspot.com/2006/01/primo-cart-sql-inj.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0008">ADV-2006-0008</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18264">18264</ref><ref source="BID" url="http://www.securityfocus.com/bid/16125">16125</ref><ref source="OSVDB" url="http://www.osvdb.org/22146">22146</ref><ref source="OSVDB" url="http://www.osvdb.org/22147">22147</ref><ref source="" url="http://pridels0.blogspot.com/2006/01/primo-cart-sql-inj.html"></ref></refs><vuln_soft><prod name="Primo Cart" vendor="Primo Place"><vers num="1.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-08-28" name="CVE-2006-0069" published="2006-01-03" seq="2006-0069" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in addentry.php in Chipmunk Guestbook 1.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the homepage parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/420667/100/0/threaded">20060101 [eVuln] Chipmunk Guestbook XSS Vulnerability</ref><ref adv="1" source="" url="http://evuln.com/vulns/4/summary.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16112">16112</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18270">18270</ref><ref source="BID" url="http://www.securityfocus.com/bid/19087">19087</ref></refs><vuln_soft><prod name="Chipmunk Guestbook" vendor="Chipmunk PHP Scripts"><vers num="1.4" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-04" name="CVE-2006-0070" published="2006-01-03" seq="2006-0070" severity="Medium" type="CVE"><desc><descript source="cve">** DISPUTED **  Drupal allows remote attackers to conduct cross-site scripting (XSS) attacks via an IMG tag with an unusual encoded Javascript function name, as demonstrated using variations of the alert() function.  NOTE: a followup by the vendor suggests that the issue does not exist in 4.5.6 or 4.6.4 when &quot;Filtered HTML&quot; is enabled, and since &quot;Full HTML&quot; would not filter HTML by design, perhaps this should not be included in CVE.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/420671/100/0/threaded">20060102 Drupal all versiyon xss cehennem.org</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/420683/100/0/threaded">20060103 Re: Drupal all versiyon xss cehennem.org</ref></refs><vuln_soft><prod name="Drupal" vendor="Drupal"><vers num="4.5.6"/><vers num="4.6.4"/></prod></vuln_soft></entry><entry CVSS_base_score="6.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="9.2" CVSS_score="6.6" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-04" name="CVE-2006-0071" published="2006-01-03" seq="2006-0071" severity="Medium" type="CVE"><desc><descript source="cve">The ebuild for pinentry before 0.7.2-r2 on Gentoo Linux sets setgid bits for pinentry programs, which allows local users to read or overwrite arbitrary files as gid 0.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200601-01.xml">GLSA-200601-01</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16120">16120</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18284">18284</ref><ref source="OSVDB" url="http://www.osvdb.org/22211">22211</ref></refs><vuln_soft><prod name="Linux" vendor="Gentoo"><vers num=""/></prod><prod name="app-crypt_pinentry" vendor="Gentoo"><vers num="0.7.2 r1"/><vers num="0.7.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-12" name="CVE-2006-0072" published="2006-01-03" seq="2006-0072" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in termsh on SCO OpenServer 5.0.7 allows remote attackers to execute arbitrary code via a long -o command line argument.  NOTE: this is probably a different vulnerability than CVE-2005-0351 since it involves a distinct attack vector.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/420677">20060102 SCO Openserver 5.0.x exploit</ref><ref source="" url="http://downloads.securityfocus.com/vulnerabilities/exploits/Openserver_bof.c"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16122">16122</ref></refs><vuln_soft><prod name="OpenServer" vendor="SCO"><vers num="5.0.7"/><vers num="5.0.6a"/><vers num="5.0.6"/><vers num="5.0.5"/><vers num="5.0.4"/><vers num="5.0.3"/><vers num="5.0.2"/><vers num="5.0.1"/><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-04" name="CVE-2006-0073" published="2006-01-03" seq="2006-0073" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in DiscusWare Discus Freeware 3.10.5 and Professional 3.10.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors in a URL, which is not properly sanitized from the resulting error message.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/16119">16119</ref><ref source="OSVDB" url="http://www.osvdb.org/22153">22153</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18283">18283</ref></refs><vuln_soft><prod name="Discus Freeware" vendor="DiscusWare"><vers num="3.10.5"/></prod><prod name="Discus Professional" vendor="DiscusWare"><vers num="3.10.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-04" name="CVE-2006-0074" published="2006-01-03" seq="2006-0074" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in profile.php in PHPenpals allows remote attackers to execute arbitrary SQL commands via the personalID parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/420690/100/0/threaded">20060101 [eVuln] PHPenpals SQL Injection Vulnerabilit</ref><ref source="" url="http://evuln.com/vulns/5/summary.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16109">16109</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0005">ADV-2006-0005</ref><ref source="OSVDB" url="http://www.osvdb.org/22150">22150</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18269">18269</ref></refs><vuln_soft><prod name="PHPenpals" vendor="Jevontech"><vers num="310704"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-04" name="CVE-2006-0075" published="2006-01-03" seq="2006-0075" severity="High" type="CVE"><desc><descript source="cve">Direct static code injection vulnerability in phpBook 1.3.2 and earlier allows remote attackers to execute arbitrary PHP code via the e-mail field (mail variable) in a new message, which is written to a PHP file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/420698/100/0/threaded">20060101 [eVuln] phpBook PHP Code Execution (phpbook)</ref><ref patch="1" source="" url="http://evuln.com/vulns/6/summary.html"></ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/16106">16106</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0002">ADV-2006-0002</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18268">18268</ref></refs><vuln_soft><prod name="phpBook" vendor="GNU"><vers num="1.3.2" prev="1"/><vers num="1.3"/><vers num="1.2"/><vers num="1.1"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-09-21" name="CVE-2006-0076" published="2006-01-03" seq="2006-0076" severity="High" type="CVE"><desc><descript source="cve">PHP remote file include vulnerability in forum.php in oaBoard 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the inc parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/420676/100/0/threaded">20060101 [eVuln] oaBoard PHP Code Execution (oaboard)</ref><ref source="" url="http://evuln.com/vulns/3/summary.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16105">16105</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/435371/100/0/threaded">20060530 OaBoard 1.0 Remote File inclusion</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/435859/100/0/threaded">20060531 Re: OaBoard 1.0 Remote File inclusion</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1016211">1016211</ref></refs><vuln_soft><prod name="OaBoard" vendor="OaBoard"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-05" name="CVE-2006-0077" published="2006-01-03" seq="2006-0077" severity="Low" type="CVE"><desc><descript source="cve">Off-by-one error in the getfattr function in File::ExtAttr before 0.03 allows attackers to trigger a buffer overflow via unspecified attack vectors.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref patch="1" source="" url="http://sourceforge.net/project/shownotes.php?release_id=382199&amp;group_id=153116"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16118">16118</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0013">ADV-2006-0013</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18253">18253</ref><ref source="OSVDB" url="http://www.osvdb.org/22160">22160</ref></refs><vuln_soft><prod name="File::ExtAttr" vendor="Richard Dawe"><vers num="0.2"/><vers num="0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-04" name="CVE-2006-0078" published="2006-01-04" seq="2006-0078" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in B-net Software 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) name and (2) shout variables to (a) shout.php, or the (3) title and (4) message variables to (b) guestbook.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/420673/100/0/threaded">20060102 [eVuln] B-net Software Multiple XSS Vulnerabilities</ref><ref adv="1" source="" url="http://evuln.com/vulns/10/summary.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16114">16114</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18271">18271</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0018">ADV-2006-0018</ref><ref source="OSVDB" url="http://www.osvdb.org/22190">22190</ref><ref source="OSVDB" url="http://www.osvdb.org/22191">22191</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/444320/100/0/threaded">20060825 Re: [eVuln] B-net Software Multiple XSS Vulnerabilities</ref><ref source="" url="http://sourceforge.net/project/shownotes.php?release_id=442067&amp;group_id=117067"></ref><ref source="SREASON" url="http://securityreason.com/securityalert/316">316</ref></refs><vuln_soft><prod name="B-Net Software" vendor="Haddad Said"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-04" name="CVE-2006-0079" published="2006-01-04" seq="2006-0079" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in auth.php in ScozNet ScozBook BETA 1.1 allows remote attackers to execute arbitrary SQL commands via the username field (adminname variable).</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/420675/100/0/threaded">20060102 [eVuln] ScozBook &apos;adminname&apos; Authentication Bypass </ref><ref source="" url="http://evuln.com/vulns/11/summary.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16115">16115</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0027">ADV-2006-0027</ref><ref source="OSVDB" url="http://www.osvdb.org/22221">22221</ref><ref source="SREASON" url="http://securityreason.com/securityalert/318">318</ref><ref source="SECUNIA" url="http://secunia.com/advisories/8476">8476</ref></refs><vuln_soft><prod name="ScozBook" vendor="ScozNet"><vers num="1.1 BETA"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-09-20" name="CVE-2006-0080" published="2006-01-04" seq="2006-0080" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in vBulletin 3.5.2, and possibly earlier versions, allows remote attackers to inject arbitrary web script or HTML via the title of an event, which is not properly filtered by (1) calendar.php and (2) reminder.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/420663/100/0/threaded">20060101 [KAPDA::#19] - Html Injection in vBulletin 3.5.2</ref><ref adv="1" source="" url="http://kapda.ir/advisory-177.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16116">16116</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0033">ADV-2006-0033</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18299">18299</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421310/100/0/threaded">20060108 Html_Injection in vBulletin 3.5.2</ref><ref source="OSVDB" url="http://www.osvdb.org/22210">22210</ref><ref source="OSVDB" url="http://www.osvdb.org/22220">22220</ref></refs><vuln_soft><prod name="vBulletin" vendor="Jelsoft"><vers num="3.5.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-12" name="CVE-2006-0081" published="2006-01-04" seq="2006-0081" severity="High" type="CVE"><desc><descript source="cve">ialmnt5.sys in the ialmrnt5 display driver in Intel Graphics Accelerator Driver 6.14.10.4308 allows attackers to cause a denial of service (crash or screen resolution change) via a long text field, as demonstrated using a long window title.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/><exception/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/16127">16127</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18286">18286</ref><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0003.html">20060102 Buffer Overflow vulnerability in Windows Display Manager [Suspected]</ref><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0029.html">20060103 Re: Buffer Overflow vulnerability in Windows Display Manager [Suspected]</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0017">ADV-2006-0017</ref><ref source="OSVDB" url="http://www.osvdb.org/22196">22196</ref></refs><vuln_soft><prod name="Graphics Accelerator Driver" vendor="Intel"><vers num="6.14.10.4308"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-08-28" name="CVE-2006-0082" published="2006-01-04" seq="2006-0082" severity="Medium" type="CVE"><desc><descript source="cve">Format string vulnerability in the SetImageInfo function in image.c for ImageMagick 6.2.3 and other versions, and GraphicsMagick, allows user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a numeric format string specifier such as %d in the file name, a variant of CVE-2005-0397, and as demonstrated using the convert program.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="" url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=345876"></ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-246-1">USN-246-1</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18607">18607</ref><ref adv="1" patch="1" source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:024">MDKSA-2006:024</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/12717">12717</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18261">18261</ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200602-06.xml">GLSA-200602-06</ref><ref source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2006-0178.html">RHSA-2006:0178</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18851">18851</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18871">18871</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015623">1015623</ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200602-13.xml">GLSA-200602-13.xml</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19030">19030</ref><ref patch="1" source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20060301-01.U.asc">20060301-01-U</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19183">19183</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_06_sr.html">SUSE-SR:2006:006</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19408">19408</ref><ref patch="1" source="SLACKWARE" url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2006&amp;m=slackware-security.341682">SSA:2006-045-03</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1213">DSA-1213</ref><ref source="SECUNIA" url="http://secunia.com/advisories/22998">22998</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/452718/100/100/threaded">20061127 rPSA-2006-0218-1 ImageMagick</ref><ref source="" url="https://issues.rpath.com/browse/RPL-389"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/23090">23090</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:024">MDKSA-2006:024</ref><ref source="SREASON" url="http://securityreason.com/securityalert/500">500</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-231321-1">231321</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0412">ADV-2008-0412</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28800">28800</ref></refs><vuln_soft><prod name="ImageMagick" vendor="ImageMagick"><vers num="6.2.3"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-10" name="CVE-2006-0083" published="2006-01-09" seq="2006-0083" severity="Medium" type="CVE"><desc><descript source="cve">Format string vulnerability in the logging code of SMS Server Tools (smstools) 1.14.8 and earlier allows local users to execute arbitrary code via unspecified attack vectors.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-930">DSA-930</ref><ref source="BID" url="http://www.securityfocus.com/bid/16188">16188</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18343">18343</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18357">18357</ref><ref source="OSVDB" url="http://www.osvdb.org/22287">22287</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24034">smstools-logging-format-string(24034)</ref></refs><vuln_soft><prod name="SMS Server Tools" vendor="Stefan Frings"><vers edition="1.14.8" num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-05" name="CVE-2006-0084" published="2006-01-05" seq="2006-0084" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting vulnerability in index.php in raSMP 2.0.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the $_SERVER[HTTP_USER_AGENT] variable (User-Agent header).</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://evuln.com/vulns/13/summary.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16138">16138</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0030">ADV-2006-0030</ref><ref source="OSVDB" url="http://www.osvdb.org/22198">22198</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18292">18292</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015432">1015432</ref><ref source="MLIST" url="http://attrition.org/pipermail/vim/2006-January/000486.html">[VIM] 20060116 vendor ack/fix: 22198: raSMP index.php User-Agent Field XSS (fwd)</ref></refs><vuln_soft><prod name="raSMP" vendor="raSMP"><vers num="2.0.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-06" name="CVE-2006-0085" published="2006-01-05" seq="2006-0085" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in Nkads 1.0 alfa 3 allows remote attackers to execute arbitrary SQL commands via the (1) usuario_nkads_admin or (2) password_nkads_admin parameters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://www.soulblack.com.ar/repo/papers/advisory/nkads_advisory.txt"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0040">ADV-2006-0040</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18302">18302</ref><ref source="OSVDB" url="http://www.osvdb.org/22206">22206</ref></refs><vuln_soft><prod name="Nkads" vendor="Nkads"><vers num="1.0alfa3"/><vers num="1.0alfa2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-06" name="CVE-2006-0086" published="2006-01-05" seq="2006-0086" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting vulnerability in index.php in Next Generation Image Gallery 0.0.1 Lite Edition allows remote attackers to inject arbitrary web script or HTML via the page parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0037">ADV-2006-0037</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18309">18309</ref><ref source="" url="http://osvdb.org/ref/22/22202-nextgen.txt"></ref><ref source="OSVDB" url="http://www.osvdb.org/22202">22202</ref></refs><vuln_soft><prod name="Next Generation Image Gallery" vendor="Next Generation Image Gallery"><vers num="0.0.1 Lite"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-06" name="CVE-2006-0087" published="2006-01-05" seq="2006-0087" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in (1) pages.php and (2) detail.php in Lizard Cart CMS 1.04 allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/420772/100/0/threaded">20060104 [eVuln] Lizard Cart CMS SQL Injection Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/16140">16140</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0029">ADV-2006-0029</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18297">18297</ref><ref source="OSVDB" url="http://www.osvdb.org/22199">22199</ref><ref source="OSVDB" url="http://www.osvdb.org/22200">22200</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015435">1015435</ref><ref source="" url="http://www.evuln.com/vulns/12/summary.html"></ref><ref source="SREASON" url="http://securityreason.com/securityalert/314">314</ref></refs><vuln_soft><prod name="Lizard Cart CMS" vendor="Lizard Cart"><vers num="1.0.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-06" name="CVE-2006-0088" published="2006-01-05" seq="2006-0088" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in intouch.lib.php in inTouch 0.5.1 Alpha allows remote attackers to execute arbitrary SQL commands via the user parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/420672/100/0/threaded">20060101 [eVuln] inTouch Authentication Bypass</ref><ref adv="1" source="" url="http://evuln.com/vulns/8/summary.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16110">16110</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0026">ADV-2006-0026</ref><ref source="OSVDB" url="http://www.osvdb.org/22382">22382</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/23954">intouch-intouch-sql-injection(23954)</ref></refs><vuln_soft><prod name="inTouch" vendor="inTouch"><vers num="0.5.1 Alpha"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-06" name="CVE-2006-0089" published="2006-01-05" seq="2006-0089" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in ESRI ArcPad 7.0.0.156 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a .amp file with a COORDSYS tag with a long string attribute.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://users.pandora.be/bratax/advisories/b007.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16136">16136</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0032">ADV-2006-0032</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18294">18294</ref><ref source="OSVDB" url="http://www.osvdb.org/22208">22208</ref></refs><vuln_soft><prod name="ArcPad" vendor="ESRI"><vers num="7.0.0.156" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-06" name="CVE-2006-0090" published="2006-01-05" seq="2006-0090" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in index.php in IDV Directory Viewer before 2005.1 allows remote attackers to view arbitrary directory contents via a .. (dot dot) in the dir parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://sourceforge.net/project/shownotes.php?release_id=382593&amp;group_id=152499"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0031">ADV-2006-0031</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18298">18298</ref><ref source="BID" url="http://www.securityfocus.com/bid/16137">16137</ref></refs><vuln_soft><prod name="IDV Directory Viewer" vendor="IDV Directory Viewer"><vers num="2005.1 b1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-06" name="CVE-2006-0091" published="2006-01-05" seq="2006-0091" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in webmail in Open-Xchange 0.8.1-6 and earlier, with &quot;Inline HTML&quot; enabled, allows remote attackers to inject arbitrary web script or HTML via e-mail attachments, which are rendered inline.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=113629092325679&amp;w=2">20060103 Open Xchange XSS</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0034">ADV-2006-0034</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18285">18285</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015431">1015431</ref></refs><vuln_soft><prod name="Open-Xchange" vendor="Open-Xchange"><vers num="0.8.1.6" prev="1"/></prod></vuln_soft></entry><entry modified="2006-04-19" name="CVE-2006-0092" published="2006-01-05" reject="1" seq="2006-0092" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2006-0992, CVE-2006-0158.  Reason: this candidate was intended for one issue, but a typo caused it to be associated with a Novell/Groupwise issue.  In addition, this issue was a duplicate of a SiteSuite issue that was also assigned CVE-2006-0158.  Notes: All CVE users should consult CVE-2006-0992 and CVE-2006-0158 to determine which ID is appropriate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><refs><ref source="SREASON" url="http://securityreason.com/securityalert/709">709</ref></refs></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-12" name="CVE-2006-0093" published="2006-01-05" seq="2006-0093" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in @Card ME PHP allows remote attackers to inject arbitrary web script or HTML via the cat parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0039">ADV-2006-0039</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18306">18306</ref><ref source="OSVDB" url="http://www.osvdb.org/22203">22203</ref><ref source="" url="http://osvdb.org/ref/22/22203-ecardmax.txt"></ref></refs><vuln_soft><prod name="@Card ME PHP" vendor="eCardMAX.com"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-12" name="CVE-2006-0094" published="2006-01-05" seq="2006-0094" severity="High" type="CVE"><desc><descript source="cve">PHP remote file include vulnerability in forum.php in oaBoard 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the inc_stat parameter, a different vulnerability than CVE-2006-0076. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0028">ADV-2006-0028</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/17373">17373</ref></refs><vuln_soft><prod name="oaBoard" vendor="oaBoard"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-09" name="CVE-2006-0095" published="2006-01-06" seq="2006-0095" severity="Low" type="CVE"><desc><descript source="cve">dm-crypt in Linux kernel 2.6.15 and earlier does not clear a structure before it is freed, which leads to a memory disclosure that could allow local users to obtain sensitive information about a cryptographic key.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="MLIST" url="http://marc.theaimsgroup.com/?l=linux-kernel&amp;m=113640535312572&amp;w=2">[linux-kernel] 20060104 [Patch 2.6] dm-crypt: zero key before freeing it</ref><ref source="MLIST" url="http://marc.theaimsgroup.com/?l=linux-kernel&amp;m=113641114812886&amp;w=2">[linux-kernel] 20060104 [Patch 2.6] dm-crypt: Zero key material before free to avoid information leak</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0235">ADV-2006-0235</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18487">18487</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-244-1">USN-244-1</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2006/0004">2006-0004</ref><ref source="BID" url="http://www.securityfocus.com/bid/16301">16301</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:040">MDKSA-2006:040</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0132.html">RHSA-2006:0132</ref><ref source="OSVDB" url="http://www.osvdb.org/22418">22418</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015740">1015740</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19160">19160</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24189">kernel-dmcrypt-information-disclosure(24189)</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/427981/100/0/threaded">FLSA:157459-4</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1017">DSA-1017</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19374">19374</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-announce-list/2006-February/msg00037.html">FEDORA-2006-102</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18527">18527</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18774">18774</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006-05-31.html">SUSE-SA:2006:028</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20398">20398</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:040">MDKSA-2006:040</ref><ref source="SREASON" url="http://securityreason.com/securityalert/388">388</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.6.15"/><vers num="2.6.15-rc7"/><vers num="2.6.15-rc6"/><vers num="2.6.15-rc5"/><vers num="2.6.15-rc4"/><vers num="2.6.15-rc3"/><vers num="2.6.15-rc2"/><vers num="2.6.15-rc1"/><vers num="2.6.14.4"/><vers num="2.6.14.3"/><vers num="2.6.14.2"/><vers num="2.6.14.1"/><vers num="2.6.14"/><vers num="2.6.14-rc4"/><vers num="2.6.14-rc3"/><vers num="2.6.14-rc2"/><vers num="2.6.14-rc1"/><vers num="2.6.13"/><vers num="2.6.12.4"/><vers num="2.6.12.3"/><vers num="2.6.12.2"/><vers num="2.6.12.1"/><vers num="2.6.12"/><vers num="2.6.11.12"/><vers num="2.6.11.11"/><vers num="2.6.11.10"/><vers num="2.6.11.9"/><vers num="2.6.11.8"/><vers num="2.6.11.7"/><vers num="2.6.11.6"/><vers num="2.6.11.5"/><vers num="2.6.11.4"/><vers num="2.6.11.3"/><vers num="2.6.11.2"/><vers num="2.6.11.1"/><vers num="2.6.11"/><vers num="2.6.10"/><vers num="2.6.9"/><vers num="2.6.8"/><vers num="2.6.8.1"/><vers num="2.6.7"/><vers num="2.6.6"/><vers num="2.6.5"/><vers num="2.6.4"/><vers num="2.6.3"/><vers num="2.6.2"/><vers num="2.6.1"/><vers num="2.6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-30" name="CVE-2006-0096" published="2006-01-06" seq="2006-0096" severity="High" type="CVE"><desc><descript source="cve">wan/sdla.c in Linux kernel 2.6.x before 2.6.11 and 2.4.x before 2.4.29 does not require the CAP_SYS_RAWIO privilege for an SDLA firmware upgrade, with unknown impact and local attack vectors.  NOTE: further investigation suggests that this issue requires root privileges to exploit, since it is protected by CAP_NET_ADMIN; thus it might not be a vulnerability, although capabilities provide finer distinctions between privilege levels.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="" url="http://www.kernel.org/git/?p=linux/kernel/git/tglx/history.git;a=commitdiff;h=0f1d4813a4a65296e1131f320a60741732bc068f"></ref><ref source="" url="http://linux.bkbits.net:8080/linux-2.4/cset@1.1448.91.23?nav=index.html%7Csrc/%7Csrc/drivers%7Csrc/drivers/net%7Csrc/drivers/net/wan%7Crelated/drivers/net/wan/sdla.c"></ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-244-1">USN-244-1</ref><ref source="BID" url="http://www.securityfocus.com/bid/16304">16304</ref><ref source="MANDRIVA" url="http://wwwnew.mandriva.com/security/advisories?name=MDKSA-2006:044">MDKSA-2006:044</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18977">18977</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1017">DSA-1017</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19374">19374</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18527">18527</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.6.15"/><vers num="2.6.15-rc7"/><vers num="2.6.15-rc6"/><vers num="2.6.15-rc5"/><vers num="2.6.15-rc4"/><vers num="2.6.15-rc3"/><vers num="2.6.15-rc2"/><vers num="2.6.15-rc1"/><vers num="2.6.14.4"/><vers num="2.6.14.3"/><vers num="2.6.14.2"/><vers num="2.6.14.1"/><vers num="2.6.14"/><vers num="2.6.14-rc4"/><vers num="2.6.14-rc3"/><vers num="2.6.14-rc2"/><vers num="2.6.14-rc1"/><vers num="2.6.13"/><vers num="2.6.12.4"/><vers num="2.6.12.3"/><vers num="2.6.12.2"/><vers num="2.6.12.1"/><vers num="2.6.12"/><vers num="2.6.11.12"/><vers num="2.6.11.11"/><vers num="2.6.11.10"/><vers num="2.6.11.9"/><vers num="2.6.11.8"/><vers num="2.6.11.7"/><vers num="2.6.11.6"/><vers num="2.6.11.5"/><vers num="2.6.11.4"/><vers num="2.6.11.3"/><vers num="2.6.11.2"/><vers num="2.6.11.1"/><vers num="2.6.11"/><vers num="2.6.10"/><vers edition="2.6.20" num="2.6.9"/><vers num="2.6.8"/><vers num="2.6.8.1"/><vers num="2.6.7"/><vers num="2.6.6"/><vers num="2.6.5"/><vers num="2.6.4"/><vers num="2.6.3"/><vers num="2.6.2"/><vers num="2.6.1"/><vers num="2.6.0"/><vers num="2.4.28"/><vers num="2.4.27-pre5"/><vers num="2.4.27-pre4"/><vers num="2.4.27-pre3"/><vers num="2.4.27-pre2"/><vers num="2.4.27-pre1"/><vers num="2.4.27"/><vers num="2.4.26"/><vers num="2.4.25"/><vers num="2.4.24-ow1"/><vers num="2.4.24"/><vers num="2.4.23-pre9"/><vers num="2.4.23-ow2"/><vers num="2.4.23"/><vers num="2.4.22"/><vers num="2.4.21-pre7"/><vers num="2.4.21-pre4"/><vers num="2.4.21-pre1"/><vers num="2.4.21"/><vers num="2.4.20"/><vers num="2.4.19-pre6"/><vers num="2.4.19-pre5"/><vers num="2.4.19-pre4"/><vers num="2.4.19-pre3"/><vers num="2.4.19-pre2"/><vers num="2.4.19-pre1"/><vers num="2.4.19"/><vers num="2.4.18 pre-8"/><vers num="2.4.18 pre-7"/><vers num="2.4.18 pre6"/><vers num="2.4.18 pre5"/><vers num="2.4.18 pre4"/><vers num="2.4.18 pre3"/><vers num="2.4.18 pre2"/><vers num="2.4.18 pre1"/><vers edition="x86" num="2.4.18"/><vers num="2.4.18"/><vers num="2.4.17"/><vers num="2.4.16"/><vers num="2.4.15"/><vers num="2.4.14"/><vers num="2.4.13"/><vers num="2.4.12"/><vers num="2.4.11"/><vers num="2.4.10"/><vers num="2.4.9"/><vers num="2.4.8"/><vers num="2.4.7"/><vers num="2.4.6"/><vers num="2.4.5"/><vers num="2.4.4"/><vers num="2.4.3"/><vers num="2.4.2"/><vers num="2.4.1"/><vers num="2.4.0 test9"/><vers num="2.4.0 test8"/><vers num="2.4.0 test7"/><vers num="2.4.0 test6"/><vers num="2.4.0 test5"/><vers num="2.4.0 test4"/><vers num="2.4.0 test3"/><vers num="2.4.0 test2"/><vers num="2.4.0 test12"/><vers num="2.4.0 test11"/><vers num="2.4.0 test10"/><vers num="2.4.0 test1"/><vers num="2.4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-08-10" name="CVE-2006-0097" published="2006-01-06" seq="2006-0097" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in the create_named_pipe function in libmysql.c in PHP 4.3.10 and 4.4.x before 4.4.3 for Windows allows attackers to execute arbitrary code via a long (1) arg_host or (2) arg_unix_socket argument, as demonstrated by a long named pipe variable in the host argument to the mysql_connect function.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/041013.html">20060105 Windows PHP 4.x &apos;0-day&apos; buffer overflow</ref><ref source="BID" url="http://www.securityfocus.com/bid/16145">16145</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0046">ADV-2006-0046</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18275">18275</ref><ref source="OSVDB" url="http://www.osvdb.org/22232">22232</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/420986/100/0/threaded">20060105 Windows PHP 4.x </ref><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0274.html">20060108 RE: Windows PHP 4.x </ref><ref source="" url="http://www.php.net/ChangeLog-4.php#4.4.3"></ref></refs><vuln_soft><prod name="PHP" vendor="PHP"><vers num="4.4.0.2"/><vers num="4.4.0.1"/><vers num="4.4.0.0"/><vers num="4.3.10"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-09" name="CVE-2006-0098" published="2006-01-06" seq="2006-0098" severity="Medium" type="CVE"><desc><descript source="cve">The dupfdopen function in sys/kern/kern_descrip.c in OpenBSD 3.7 and 3.8 allows local users to re-open arbitrary files by using setuid programs to access file descriptors using /dev/fd/.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><local/></range><refs><ref patch="1" source="OPENBSD" url="http://www.openbsd.org/errata37.html#fd">[3.7] 20060105 008: SECURITY FIX: January 5, 2006</ref><ref patch="1" source="" url="ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.7/common/008_fd.patch"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16144">16144</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18296">18296</ref><ref source="OSVDB" url="http://www.osvdb.org/22231">22231</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015437">1015437</ref></refs><vuln_soft><prod name="OpenBSD" vendor="OpenBSD"><vers num="3.8"/><vers num="3.7"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-09" name="CVE-2006-0099" published="2006-01-06" seq="2006-0099" severity="High" type="CVE"><desc><descript source="cve">PHP remote file include vulnerability in (1) include/templates/categories/default.php and (2) certain other include/templates/categories/ PHP scripts in Valdersoft Shopping Cart 3.0 allows remote attackers to execute arbitrary code via a URL in the catalogDocumentRoot parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://milw0rm.com/id.php?id=1401"></ref><ref source="" url="http://downloads.securityfocus.com/vulnerabilities/exploits/cijfer-vscxpl.pl"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16126">16126</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/1401">

1401</ref></refs><vuln_soft><prod name="Valdersoft Shopping Cart" vendor="Valdersoft"><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-09" name="CVE-2006-0100" published="2006-01-06" seq="2006-0100" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in NicoFTP 3.0.1.19 and earlier might allow local users to execute arbitrary code via a long string in the &quot;Name of site&quot; field of an FTP account.  NOTE: because this program executes with the privileges of the invoking user, and because remote programs do not normally have the ability to create or modify FTP accounts in this program, there may not be a typical attack vector for the issue that crosses privilege boundaries.  Therefore this may not be a vulnerability.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/420670/100/0/threaded">20060102 NicoFTP Stack Overflow</ref><ref source="SREASON" url="http://securityreason.com/securityalert/317">317</ref></refs><vuln_soft><prod name="NicoFTP" vendor="NicoSW"><vers num="3.0.1.19" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-01-06" modified="2006-05-11" name="CVE-2006-0101" published="2006-01-06" seq="2006-0101" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in sBLOG 0.7.1 Beta 20051202 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) p and (2) keyword parameters in (a) index.php and (b) search.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0041">ADV-2006-0041</ref><ref source="" url="http://osvdb.org/ref/22/22373-sblog.txt"></ref><ref source="OSVDB" url="http://www.osvdb.org/22373">22373</ref><ref source="OSVDB" url="http://www.osvdb.org/22374">22374</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/23979">sblog-multiple-scripts-xss(23979)</ref></refs><vuln_soft><prod name="sBLOG" vendor="sBLOG"><vers num="0.7.1 Build2005-12-02 Beta" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-11" name="CVE-2006-0102" published="2006-01-06" seq="2006-0102" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in TinyPHPForum (TPF) 3.6 and earlier allows remote attackers to inject arbitrary web script via a javascript: scheme in an &quot;[a]&quot; bbcode tag, possibly the txt parameter to action.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/420933/100/0/threaded">20060105 [eVuln] TinyPHPForum Multiple Vulnerabilities</ref><ref adv="1" source="" url="http://evuln.com/vulns/14/summary.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0054">ADV-2006-0054</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18293">18293</ref><ref source="OSVDB" url="http://www.osvdb.org/22256">22256</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015436">1015436</ref><ref source="SREASON" url="http://securityreason.com/securityalert/320">320</ref></refs><vuln_soft><prod name="TinyPHPForum" vendor="Ralph Capper"><vers num="3.6"/><vers num="3.5"/><vers num="3.499"/><vers num="3.49"/><vers num="3.48"/><vers num="3.47"/><vers num="3.46"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-11" name="CVE-2006-0103" published="2006-01-06" seq="2006-0103" severity="Medium" type="CVE"><desc><descript source="cve">TinyPHPForum 3.6 and earlier stores the (1) users/[USERNAME].hash and (2) users/[USERNAME].email files under the web root with insufficient access control, which allows remote attackers to list all registered users and possibly obtain other sensitive information.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/420933/100/0/threaded">20060105 [eVuln] TinyPHPForum Multiple Vulnerabilities</ref><ref source="" url="http://evuln.com/vulns/14/exploit.html"></ref><ref adv="1" source="" url="http://evuln.com/vulns/14/summary.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0054">ADV-2006-0054</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18293">18293</ref><ref source="OSVDB" url="http://www.osvdb.org/22257">22257</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015436">1015436</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431133/100/0/threaded">20060417 Tiny PHP forum - vulns</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24016">
tinyphpforum-users-information-disclosure(24016)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/320">320</ref></refs><vuln_soft><prod name="TinyPHPForum" vendor="Ralph Capper"><vers num="3.6"/><vers num="3.5"/><vers num="3.499"/><vers num="3.49"/><vers num="3.48"/><vers num="3.47"/><vers num="3.46"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-09" name="CVE-2006-0104" published="2006-01-06" seq="2006-0104" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in TinyPHPForum 3.6 and earlier allows remote attackers to create a new user account, create a new topic, or view the profile of a user account, as demonstrated via a .. (dot dot) in the uname parameter to profile.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/420933/100/0/threaded">20060105 [eVuln] TinyPHPForum Multiple Vulnerabilities</ref><ref source="" url="http://evuln.com/vulns/14/exploit.html"></ref><ref adv="1" source="" url="http://evuln.com/vulns/14/summary.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0054">ADV-2006-0054</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18293">18293</ref><ref source="BID" url="http://www.securityfocus.com/bid/16163">16163</ref><ref source="OSVDB" url="http://www.osvdb.org/22258">22258</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015436">1015436</ref><ref source="SREASON" url="http://securityreason.com/securityalert/320">320</ref></refs><vuln_soft><prod name="TinyPHPForum" vendor="Ralph Capper"><vers num="3.6"/><vers num="3.5"/><vers num="3.499"/><vers num="3.49"/><vers num="3.48"/><vers num="3.47"/><vers num="3.46"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-11" name="CVE-2006-0105" published="2006-01-10" seq="2006-0105" severity="Medium" type="CVE"><desc><descript source="cve">PostgreSQL 8.0.x before 8.0.6 and 8.1.x before 8.1.2, when running on Windows, allows remote attackers to cause a denial of service (postmaster exit and no new connections) via a large number of simultaneous connection requests.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref patch="1" source="MLIST" url="http://archives.postgresql.org/pgsql-announce/2006-01/msg00001.php">[pgsql-announce] 20060109 CRITICAL RELEASE: Minor Releases to Fix DoS Vulnerability</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421592/100/0/threaded">20060111 PostgreSQL security releases 8.0.6 and 8.1.2</ref><ref source="" url="http://www.postgresql.org/about/news.456"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16201">16201</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0114">ADV-2006-0114</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015482">1015482</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18419">18419</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24049">
postgresql-connection-request-dos(24049)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/327">327</ref></refs><vuln_soft><prod name="PostgreSQL" vendor="PostgreSQL"><vers num="8.0.5"/><vers num="8.0.4"/><vers num="8.0.3"/><vers num="8.0.2"/><vers num="8.0.1"/><vers num="8.0"/><vers num="8.1.1"/><vers num="8.1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-11" name="CVE-2006-0106" published="2006-01-06" seq="2006-0106" severity="High" type="CVE"><desc><descript source="cve">gdi/driver.c and gdi/printdrv.c in Wine 20050930, and other versions, implement the SETABORTPROC GDI Escape function call for Windows Metafile (WMF) files, which allows attackers to execute arbitrary code, the same vulnerability as CVE-2005-4560 but in a different codebase.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="MLIST" url="http://lists.immunitysec.com/pipermail/dailydave/2006-January/002806.html">[Dailydave] 20060105 WMF goes away :&lt;</ref><ref patch="1" source="" url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=346197"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0098">ADV-2006-0098</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18323">18323</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200601-09.xml">GLSA-200601-09</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18451">18451</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/422128/100/0/threaded">20060117 ERRATA: [ GLSA 200601-09 ] Wine: Windows Metafile SETABORTPROC vulnerability</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:014">MDKSA-2006:014</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_02_sr.html">SUSE-SR:2006:002</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18549">18549</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-954">DSA-954</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18578">18578</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/23846">
win-wmf-execute-code(23846)</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:014">MDKSA-2006:014</ref></refs><vuln_soft><prod name="Wine" vendor="Wine"><vers num="2005-09-30"/><vers num="0.9.5"/><vers num="0.9.4"/><vers num="0.9.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-11" name="CVE-2006-0107" published="2006-01-06" seq="2006-0107" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in Timecan CMS allows remote attackers to execute arbitrary SQL commands via the viewID parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.  Due to the unavailability of the original source, it cannot be determined if this is the same issue as identified by CVE-2006-0108.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/16159">16159</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18324">18324</ref><ref source="OSVDB" url="http://www.osvdb.org/22252">22252</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24014">
timecancms-sql-injection(24014)</ref></refs><vuln_soft><prod name="Timecan CMS" vendor="Idea Development ID Oy"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-11" name="CVE-2006-0108" published="2006-01-06" seq="2006-0108" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in mcl_login.asp in Timecan CMS allows remote attackers to execute arbitrary SQL commands via the email parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.  Due to the unavailability of the original source, it cannot be determined if this is the same issue as identified by CVE-2006-0107.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0078">ADV-2006-0078</ref><ref source="OSVDB" url="http://www.osvdb.org/22253">22253</ref><ref source="OSVDB" url="http://www.osvdb.org/22252">22252</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24014">
timecancms-sql-injection(24014)</ref></refs><vuln_soft><prod name="Timecan CMS" vendor="Idea Development ID Oy"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-01-06" modified="2006-05-11" name="CVE-2006-0109" published="2006-01-06" seq="2006-0109" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting vulnerability in category.php in Modular Merchant Shopping Cart allows remote attackers to inject arbitrary web script or HTML via the cat parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/16160">16160</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0076">ADV-2006-0076</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18320">18320</ref><ref source="OSVDB" url="http://www.osvdb.org/22243">22243</ref><ref source="" url="http://osvdb.org/ref/22/22243-modular.txt"></ref><ref source="" url="http://www.modularmerchant.com/forums/viewtopic.php?t=46"></ref><ref source="MLIST" url="http://attrition.org/pipermail/vim/2006-February/000548.html">[VIM] 20060214 vendor ack/fix 22243: Modular Merchant Marketplace Shopping Cart category.php cat Variable XSS (fwd)</ref></refs><vuln_soft><prod name="Shopping Cart" vendor="Modular Merchant"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-01-06" modified="2006-05-11" name="CVE-2006-0110" published="2006-01-06" seq="2006-0110" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in escribir.php in Foro Domus 2.10 allows remote attackers to inject arbitrary web script via the email parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421056/100/0/threaded">20060106 [eVuln] Proyecto Domus &apos;email&apos; XSS Vulnerability</ref><ref source="" url="http://evuln.com/vulns/16/summary.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16154">16154</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0073">ADV-2006-0073</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18327">18327</ref><ref source="OSVDB" url="http://www.osvdb.org/22263">22263</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24020">
domus-escribir-xss(24020)</ref></refs><vuln_soft><prod name="Foro Domus" vendor="Javier Suarez Sanz"><vers num="2.10"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-01-06" modified="2006-05-11" name="CVE-2006-0111" published="2006-01-06" seq="2006-0111" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting vulnerability in index.php in Boxcar Media Shopping Cart allows remote attackers to inject arbitrary web script or HTML via the (1) parent or (2) pg parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0080">ADV-2006-0080</ref><ref source="" url="http://osvdb.org/ref/22/22360-boxcar.txt"></ref><ref source="OSVDB" url="http://www.osvdb.org/22360">22360</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24019">boxcar-index-xss(24019)</ref></refs><vuln_soft><prod name="Shopping Cart" vendor="Boxcar Media"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-11" name="CVE-2006-0112" published="2006-01-06" seq="2006-0112" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in Enhanced Simple PHP Gallery 1.7 allows remote attackers to inject arbitrary web script or HTML via the dir parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://osvdb.org/ref/22/22201-espg.txt"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0036">ADV-2006-0036</ref><ref source="OSVDB" url="http://www.osvdb.org/22201">22201</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18310">18310</ref></refs><vuln_soft><prod name="Enhanced Simple PHP Gallery" vendor="Enhanced Simple PHP Gallery"><vers num="1.7"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-11" name="CVE-2006-0113" published="2006-01-06" seq="2006-0113" severity="Medium" type="CVE"><desc><descript source="cve">Enhanced Simple PHP Gallery 1.7 allows remote attackers to obtain the full path of the application via a direct request to sp_helper_functions.php, which leaks the pathname in an error message.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/><design/></vuln_types><range><network/></range><refs><ref source="" url="http://osvdb.org/ref/22/22201-espg.txt"></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18310">18310</ref><ref source="OSVDB" url="http://www.osvdb.org/22417">22417</ref></refs><vuln_soft><prod name="Enhanced Simple PHP Gallery" vendor="Enhanced Simple PHP Gallery"><vers num="1.7"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-01-09" modified="2006-05-10" name="CVE-2006-0114" published="2006-01-09" seq="2006-0114" severity="Medium" type="CVE"><desc><descript source="cve">The vCard functions in Joomla! 1.0.5 use predictable sequential IDs for vcards and do not restrict access to them, which allows remote attackers to obtain valid e-mail addresses to conduct spam attacks by modifying the contact_id parameter to index2.php.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://forum.joomla.org/index.php/topic,29031.0.html"></ref><ref source="" url="http://forge.joomla.org/sf/go/artf2950"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16185">16185</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0097">ADV-2006-0097</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18361">18361</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24042">
joomla-vcard-information-disclosure(24042)</ref></refs><vuln_soft><prod name="Joomla" vendor="Joomla"><vers num="1.0.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-11" name="CVE-2006-0115" published="2006-01-09" seq="2006-0115" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in OnePlug Solutions OnePlug CMS allow remote attackers to execute arbitrary SQL commands via the (1) Press_Release_ID parameter in press/details.asp, (2) Service_ID parameter in services/details.asp, and (3) Product_ID parameter in products/details.asp.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/16155">16155</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0079">ADV-2006-0079</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18325">18325</ref><ref source="OSVDB" url="http://www.osvdb.org/22248">22248</ref><ref source="OSVDB" url="http://www.osvdb.org/22249">22249</ref><ref source="OSVDB" url="http://www.osvdb.org/22250">22250</ref><ref source="" url="http://osvdb.org/ref/22/22248-oneplug.txt"></ref></refs><vuln_soft><prod name="OnePlug CMS" vendor="OnePlug Solutions"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-11" name="CVE-2006-0116" published="2006-01-09" seq="2006-0116" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting vulnerability search.inetstore in iNETstore Ebusiness Software 2.0 allows remote attackers to inject arbitrary web script or HTML via the searchterm parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/16156">16156</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0075">ADV-2006-0075</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18322">18322</ref><ref source="OSVDB" url="http://www.osvdb.org/22251">22251</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/423137/100/0/threaded">20060126 Re: [OSVDB Mods] iNETstore E Commerce Solution - Cross Site Scripting</ref><ref source="MLIST" url="http://www.attrition.org/pipermail/vim/2006-January/000515.html">[VIM] 20060127 vendor confirms versions: iNETstore E Commerce Solution - Cross Site Scripting (fwd)</ref><ref source="" url="http://osvdb.org/ref/22/22251-inetstore.txt"></ref></refs><vuln_soft><prod name="iNETstore Online" vendor="iNETstore"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-09" name="CVE-2006-0117" published="2006-01-09" seq="2006-0117" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in IBM Lotus Notes and Domino Server before 6.5.5 allows attackers to cause a denial of service (router crash or hang) via unspecified vectors involving &quot;CD to MIME Conversion&quot;.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="" url="http://www-1.ibm.com/support/docview.wss?uid=swg27007054"></ref><ref source="" url="http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/50c634bfe193efa5852570e4001baace?OpenDocument"></ref><ref source="" url="http://www-10.lotus.com/ldd/r5fixlist.nsf/e7dbb5aee9a94c56852570c90056a95d/21d8fd7989fdf78d852570e4001bae68?OpenDocument"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16158">16158</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18328">18328</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0081">ADV-2006-0081</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24205">
lotus-cdtomime-dos(24205)</ref></refs><vuln_soft><prod name="Lotus Notes" vendor="IBM"><vers num="6.5.4"/><vers num="6.5.3"/><vers num="6.5.2"/><vers num="6.5.1"/><vers num="6.5"/></prod><prod name="Lotus Domino" vendor="IBM"><vers num="6.5.4 FP 2"/><vers num="6.5.4 FP 1"/><vers num="6.5.4"/><vers num="6.5.3"/><vers num="6.5.2"/><vers num="6.5.1"/><vers num="6.5.0"/></prod><prod name="Lotus Domino Enterprise Server" vendor="IBM"><vers num="6.5.4"/><vers num="6.5.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-09" name="CVE-2006-0118" published="2006-01-09" seq="2006-0118" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in IBM Lotus Notes and Domino Server before 6.5.5, when running on AIX, allows attackers to cause a denial of service (deep recursion leading to stack overflow and crash) via long formulas.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="" url="http://www-1.ibm.com/support/docview.wss?uid=swg27007054"></ref><ref source="" url="http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/50c634bfe193efa5852570e4001baace?OpenDocument"></ref><ref source="" url="http://www-10.lotus.com/ldd/r5fixlist.nsf/e7dbb5aee9a94c56852570c90056a95d/21d8fd7989fdf78d852570e4001bae68?OpenDocument"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16158">16158</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18328">18328</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0081">ADV-2006-0081</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24206">
lotus-long-formula-bo(24206)</ref></refs><vuln_soft><prod name="Lotus Notes" vendor="IBM"><vers num="6.5.4"/><vers num="6.5.3"/><vers num="6.5.2"/><vers num="6.5.1"/><vers num="6.5"/></prod><prod name="Lotus Domino" vendor="IBM"><vers num="6.5.4 FP 2"/><vers num="6.5.4 FP 1"/><vers num="6.5.4"/><vers num="6.5.3"/><vers num="6.5.2"/><vers num="6.5.1"/><vers num="6.5.0"/></prod><prod name="Lotus Domino Enterprise Server" vendor="IBM"><vers num="6.5.4"/><vers num="6.5.2"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-06-30" name="CVE-2006-0119" published="2006-01-09" seq="2006-0119" severity="High" type="CVE"><desc><descript source="cve">Multiple unspecified vulnerabilities in IBM Lotus Notes and Domino Server before 6.5.5 have unknown impact and attack vectors, due to &quot;potential security issues&quot; as identified by SPR numbers (1) GPKS6C9J67 in Agents, (2) JGAN6B6TZ3 and (3) KSPR699NBP in the Router, (4) GPKS5YQGPT in Security, or (5) HSAO6BNL6Y in the Web Server. NOTE: vector 3 is related to an issue in NROUTER in IBM Lotus Notes and Domino Server before 6.5.4 FP1, 6.5.5, and 7.0, which allows remote attackers to cause a denial of service (CPU consumption) via a crafted vCal meeting request sent via SMTP (aka SPR# KSPR699NBP).</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref source="" url="http://www-1.ibm.com/support/docview.wss?uid=swg27007054"></ref><ref source="" url="http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/f97fe7cfd9a8113b8525709200001db4?OpenDocument&amp;Highlight=0,GPKS6C9J67"></ref><ref source="" url="http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/d1150fc9c5dec8b18525709200001da6?OpenDocument&amp;Highlight=0,GPKS6C9J67"></ref><ref source="" url="http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/94a77eb898843aca8525709200001de1?OpenDocument&amp;Highlight=0,JGAN6B6TZ3"></ref><ref source="" url="http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/de2ab57a5b9547848525701b00420c2c?OpenDocument&amp;Highlight=0,KSPR699NBP"></ref><ref source="" url="http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/e4deb1cbb011c747852570e4001ba9bb?OpenDocument&amp;Highlight=0,GPKS5YQGPT"></ref><ref source="" url="http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/9a1650d1a771f3078525702a00420def?OpenDocument&amp;Highlight=0,HSAO6BNL6Y"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16158">16158</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18328">18328</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0081">ADV-2006-0081</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/438461/100/0/threaded">20060626 SYMSA-2006-006: Lotus Domino SMTP Based Denial of Service</ref><ref source="BID" url="http://www.securityfocus.com/bid/18020">18020</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/2564">ADV-2006-2564</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1016390">1016390</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20855">20855</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/27413">domino-smtp-nrouter-dos(27413)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24207">
lotus-multiple-unspecified(24207)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24211">
lotus-web-unspecified-xss(24211)</ref></refs><vuln_soft><prod name="Lotus Notes" vendor="IBM"><vers num="6.5.4"/><vers num="6.5.3"/><vers num="6.5.2"/><vers num="6.5.1"/><vers num="6.5"/></prod><prod name="Lotus Domino" vendor="IBM"><vers num="6.5.4 FP 2"/><vers num="6.5.4 FP 1"/><vers num="6.5.4"/><vers num="6.5.3"/><vers num="6.5.2"/><vers num="6.5.1"/><vers num="6.5.0"/></prod><prod name="Lotus Domino Enterprise Server" vendor="IBM"><vers num="6.5.4"/><vers num="6.5.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-09" name="CVE-2006-0120" published="2006-01-09" seq="2006-0120" severity="Medium" type="CVE"><desc><descript source="cve">Multiple unspecified vulnerabilities in IBM Lotus Notes and Domino Server before 6.5.5 allow attackers to cause a denial of service (application crash) via multiple vectors, involving (1) a malformed message sent to an &quot;Out Of Office&quot; agent (SPR LPEE6DMQWJ), (2) the compact command (RTIN5U2SAJ), (3) malformed bitmap images (MYAA6FH5HW), (4) the &quot;Delete Attachment&quot; action (YPHG6844LD), (5) parsing certificates from a remote Certificate Table (AELE6DZFJW), and (6) creating a SSL key ring with the Domino Administration client (NSUA4FQPTN).</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref source="" url="http://www-1.ibm.com/support/docview.wss?uid=swg27007054"></ref><ref source="" url="http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/258394eaa824f2c08525708a004209d3?OpenDocument"></ref><ref source="" url="http://www-10.lotus.com/ldd/r5fixlist.nsf/e7dbb5aee9a94c56852570c90056a95d/040482aeb1416bb7852570e4001badd6?OpenDocument"></ref><ref source="" url="http://www-10.lotus.com/ldd/r5fixlist.nsf/e7dbb5aee9a94c56852570c90056a95d/2bb4f466a9e986ae852570e4001babbb?OpenDocument"></ref><ref source="" url="http://www-10.lotus.com/ldd/r5fixlist.nsf/e7dbb5aee9a94c56852570c90056a95d/4118a1f266afb26c852570e4001baf5e?OpenDocument"></ref><ref source="" url="http://www-10.lotus.com/ldd/r5fixlist.nsf/e7dbb5aee9a94c56852570c90056a95d/5f166a44ee743b2c852570e4001baf31?OpenDocument"></ref><ref source="" url="http://www-10.lotus.com/ldd/r5fixlist.nsf/e7dbb5aee9a94c56852570c90056a95d/ad0dd14aa109f96b852570e4001bb08c?OpenDocument"></ref><ref source="" url="http://www-10.lotus.com/ldd/r5fixlist.nsf/e7dbb5aee9a94c56852570c90056a95d/ced5f873baea4e8b852570e4001baa6d?OpenDocument"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16158">16158</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18328">18328</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0081">ADV-2006-0081</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24214">
lotus-bmp-dos(24214)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24216">
lotus-certificate-parsing-dos(24216)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24213">
lotus-compact-dos(24213)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24215">
lotus-delete-attachment-dos(24215)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24212">
lotus-outofoffice-dos(24212)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24217">
lotus-ssl-keyring-dos(24217)</ref></refs><vuln_soft><prod name="Lotus Notes" vendor="IBM"><vers num="6.5.4"/><vers num="6.5.3"/><vers num="6.5.2"/><vers num="6.5.1"/><vers num="6.5"/></prod><prod name="Lotus Domino" vendor="IBM"><vers num="6.5.4 FP 2"/><vers num="6.5.4 FP 1"/><vers num="6.5.4"/><vers num="6.5.3"/><vers num="6.5.2"/><vers num="6.5.1"/><vers num="6.5.0"/></prod><prod name="Lotus Domino Enterprise Server" vendor="IBM"><vers num="6.5.4"/><vers num="6.5.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-09" name="CVE-2006-0121" published="2006-01-09" seq="2006-0121" severity="High" type="CVE"><desc><descript source="cve">Multiple memory leaks in IBM Lotus Notes and Domino Server before 6.5.5 allow attackers to cause a denial of service (memory consumption and crash) via unknown vectors related to (1) unspecified vectors during the SSL handshake (SPR# MKIN67MQVW), (2) the stash file during the SSL handshake (SPR# MKIN693QUT), and possibly other vectors. NOTE: due to insufficient information in the original vendor advisory, it is not clear whether there is an attacker role in other memory leaks that are specified in the advisory.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref source="" url="http://www-1.ibm.com/support/docview.wss?uid=swg27007054"></ref><ref source="" url="http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/20f66e356a76c90f8525702a00420e08?OpenDocument&amp;Highlight=0,MKIN67MQVW"></ref><ref source="" url="http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/2221243535d88a2b8525701b00420cd6?OpenDocument&amp;Highlight=0,MKIN693QUT"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16158">16158</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18328">18328</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0081">ADV-2006-0081</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24223">
lotus-ssl-handshake-dos(24223)</ref></refs><vuln_soft><prod name="Lotus Notes" vendor="IBM"><vers num="6.5.4"/><vers num="6.5.3"/><vers num="6.5.2"/><vers num="6.5.1"/><vers num="6.5"/></prod><prod name="Lotus Domino" vendor="IBM"><vers num="6.5.4 FP 2"/><vers num="6.5.4 FP 1"/><vers num="6.5.4"/><vers num="6.5.3"/><vers num="6.5.2"/><vers num="6.5.1"/><vers num="6.5.0"/></prod><prod name="Lotus Domino Enterprise Server" vendor="IBM"><vers num="6.5.4"/><vers num="6.5.2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-11" name="CVE-2006-0122" published="2006-01-09" seq="2006-0122" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Public/Index.asp in Aquifer CMS allows remote attackers to inject arbitrary web script or HTML via the Keyword parameter.</descript></desc><sols><sol source="nvd">Vendor provided solution:

&quot;Liquid Development has identified this vulnerability in all shipping versions of AquiferCMS and coded a software fix. The fix will be included in all releases of AquiferCMS built on or after January 24, 2006. Customers should contact Liquid Development to obtain the fix for this vulnerability.  For more information visit www.aquifercms.com.&quot; 
</sol></sols><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/16162">16162</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0074">ADV-2006-0074</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18326">18326</ref><ref patch="1" source="OSVDB" url="http://www.osvdb.org/22247">22247</ref><ref source="MLIST" url="http://attrition.org/pipermail/vim/2006-January/000509.html">[VIM] 20060124 vendor ack/fix: Aquifer CMS Index.asp Keyword Variable XSS (fwd)</ref><ref source="" url="http://osvdb.org/ref/22/22247-aquifer.txt"></ref></refs><vuln_soft><prod name="Aquifer CMS" vendor="Aquifer CMS"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-01-05" modified="2006-05-11" name="CVE-2006-0123" published="2006-01-09" seq="2006-0123" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in ADN Forum 1.0b allow remote attackers to execute arbitrary SQL commands via the (1) fid parameter in index.php and (2) pagid parameter in verpag.php, and possibly other vectors.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/420990/100/0/threaded">20060105 [eVuln] ADNForum Multiple Vulnerabilities</ref><ref adv="1" source="" url="http://evuln.com/vulns/15/summary.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16157">16157</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0077">ADV-2006-0077</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015445">1015445</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18300">18300</ref><ref source="OSVDB" url="http://www.osvdb.org/22240">22240</ref><ref source="OSVDB" url="http://www.osvdb.org/22241">22241</ref></refs><vuln_soft><prod name="ADN Forum" vendor="ADN Forum"><vers num="1.0b"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-09" name="CVE-2006-0124" published="2006-01-09" seq="2006-0124" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in crear.php in ADN Forum 1.0b allows remote attackers to inject arbirary web script or HTML via the titulo parameter, which is used by the &quot;Topic name&quot; field.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/420990/100/0/threaded">20060105 [eVuln] ADNForum Multiple Vulnerabilities</ref><ref adv="1" source="" url="http://evuln.com/vulns/15/summary.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16157">16157</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0077">ADV-2006-0077</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18300">18300</ref><ref source="OSVDB" url="http://www.osvdb.org/22242">22242</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015445">1015445</ref></refs><vuln_soft><prod name="ADN Forum" vendor="ADN Forum"><vers num="1.0b"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-09" name="CVE-2006-0125" published="2006-01-09" seq="2006-0125" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in appserv/main.php in AppServ 2.4.5 allows remote attackers to include arbitrary files via the appserv_root parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.  There is not enough detail from these third party sources to know whether this is directory traversal, remote file include, or another issue.</descript></desc><loss_types><int/></loss_types><range><network/></range><refs><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0053">ADV-2006-0053</ref><ref source="OSVDB" url="http://www.osvdb.org/22228">22228</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18163">18163</ref><ref source="BID" url="http://www.securityfocus.com/bid/16166">16166</ref></refs><vuln_soft><prod name="AppServ" vendor="AppServ Open Project"><vers num="2.4.5"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-09" name="CVE-2006-0126" published="2006-01-09" seq="2006-0126" severity="Medium" type="CVE"><desc><descript source="cve">rxvt-unicode before 6.3, on certain platforms that use openpty and non-Unix pty devices such as Linux and most BSD platforms, does not maintain the intended permissions of tty devices, which allows local users to gain read and write access to the devices.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="" url="http://dist.schmorp.de/rxvt-unicode/Changes"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0052">ADV-2006-0052</ref><ref patch="1" source="OSVDB" url="http://www.osvdb.org/22223">22223</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18301">18301</ref></refs><vuln_soft><prod name="rxvt-unicode" vendor="rxvt-unicode"><vers num="6.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.0" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="2.9" CVSS_score="4.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-11" name="CVE-2006-0127" published="2006-01-09" seq="2006-0127" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in the IMAP service of Rockliffe MailSite before 6.1.22.1 allows remote authenticated users to rename the folders of other users via a .. (dot dot) in the RENAME command.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/040969.html">20060104 Rockliffe Directory Transversal Vulnerability</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/041039.html">20060105 Re: Rockliffe Directory Transversal Vulnerability</ref><ref adv="1" patch="1" source="" url="http://zur.homelinux.com/Advisories/RockliffeMailsiteDirTransveral.txt"></ref><ref patch="1" source="OSVDB" url="http://www.osvdb.org/22229">22229</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18318">18318</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0055">ADV-2006-0055</ref></refs><vuln_soft><prod name="MailSite" vendor="Rockliffe"><vers num="6.1.22.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-11" name="CVE-2006-0128" published="2006-01-09" seq="2006-0128" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the IMAP service of Rockliffe MailSite before 6.1.22.1 allows remote attackers to have an unknown impact via unknown attack vectors.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/040969.html">20060104 Rockliffe Directory Transversal Vulnerability</ref><ref adv="1" patch="1" source="" url="http://zur.homelinux.com/Advisories/RockliffeMailsiteDirTransveral.txt"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39991">rockliffe-imap-unspecified-bo(39991)</ref></refs><vuln_soft><prod name="MailSite" vendor="Rockliffe"><vers num="6.1.22.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-11" name="CVE-2006-0129" published="2006-01-09" seq="2006-0129" severity="Medium" type="CVE"><desc><descript source="cve">Mail Management Agent (MAILMA) (aka Mail Management Server) in Rockliffe MailSite 7.0.3.1 and earlier generates different responses depending on whether or not a username is valid, which allows remote attackers to enumerate valid usernames via user requests to TCP port 106.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/040970.html">20060104 Rockliffe Mailsite User Enumeration Flaw</ref><ref adv="1" source="" url="http://zur.homelinux.com/Advisories/RockliffeMailsiteUserEnum.txt"></ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18318">18318</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0055">ADV-2006-0055</ref><ref source="OSVDB" url="http://www.osvdb.org/22230">22230</ref></refs><vuln_soft><prod name="MailSite" vendor="Rockliffe"><vers num="7.0.3.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-11" name="CVE-2006-0130" published="2006-01-09" seq="2006-0130" severity="High" type="CVE"><desc><descript source="cve">Mail Management Agent (MAILMA) (aka Mail Management Server) in Rockliffe MailSite 7.0.3.1 and earlier allows remote attackers to attempt authentication with an unlimited number of user account names and passwords without denying connections, limiting the rate of connections, or locking out an account.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/040970.html">20060104 Rockliffe Mailsite User Enumeration Flaw</ref><ref adv="1" source="" url="http://zur.homelinux.com/Advisories/RockliffeMailsiteUserEnum.txt"></ref></refs><vuln_soft><prod name="MailSite" vendor="Rockliffe"><vers num="7.0.3.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-11" name="CVE-2006-0131" published="2006-01-09" seq="2006-0131" severity="Medium" type="CVE"><desc><descript source="cve">boastMachine 3.1 allows remote attackers to obtain sensitive information via a direct request to (1) footer.php and (2) side_menu.php, which reveals the path in an error message.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/420969/100/0/threaded">20060105 [ECHO_ADV_25$2006] Full path disclosure on boastMachine v3.1</ref><ref source="" url="http://echo.or.id/adv/adv26-K-159-2006.txt"></ref></refs><vuln_soft><prod name="BoastMachine" vendor="BoastMachine"><vers num="3.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-15" name="CVE-2006-0132" published="2006-01-09" seq="2006-0132" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in webftp.php in SysCP WebFTP 1.2.6 and possibly earlier allows remote attackers to include and execute arbitrary local PHP scripts, and possibly read other types of files, via a .. (dot dot) and a trailing null in the webftp_language parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/420973/100/0/threaded">20060104 SysCP WebFTP local file inclusion vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/16175">16175</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0090">ADV-2006-0090</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18355">18355</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24018">
webftp-language-file-include(24018)</ref></refs><vuln_soft><prod name="WebFTP" vendor="WebFTP"><vers num="1.2.6"/></prod></vuln_soft></entry><entry CVSS_base_score="3.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="4.9" CVSS_score="3.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-15" name="CVE-2006-0133" published="2006-01-09" seq="2006-0133" severity="Low" type="CVE"><desc><descript source="cve">Multiple directory traversal vulnerabilities in AIX 5.3 ML03 allow local users to determine the existence of files and read partial contents of certain files via a .. (dot dot) in the argument to (1) getCommand.new (aka getCommand) and (2) getShell, a different vulnerability than CVE-2005-4273.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/><design/></vuln_types><range><local/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/420589/100/0/threaded">20060101 [xfocus-SD-060101]AIX getCommand&amp;getShell two vulnerabilities</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015429">1015429</ref><ref source="BID" url="http://www.securityfocus.com/bid/16102">16102</ref><ref source="BID" url="http://www.securityfocus.com/bid/16103">16103</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="5.3 ML03"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-15" name="CVE-2006-0134" published="2006-01-09" seq="2006-0134" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in register.php in TheWebForum (twf) 1.2.1 allows remote attackers to inject arbitrary web script or HTML via the www parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421039/100/0/threaded">20060106 [eVuln] TheWebForum Script Insertion and Authentication Bypass</ref><ref source="" url="http://evuln.com/vulns/17/exploit.html"></ref><ref source="" url="http://evuln.com/vulns/17/summary.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16161">16161</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0093">ADV-2006-0093</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015450">1015450</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18392">18392</ref><ref source="OSVDB" url="http://www.osvdb.org/22295">22295</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24007">
thewebforum-register-xss(24007)</ref></refs><vuln_soft><prod name="TheWebForum" vendor="TheWebForum"><vers num="1.2.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-15" name="CVE-2006-0135" published="2006-01-09" seq="2006-0135" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in login.php in TheWebForum (twf) 1.2.1 allows remote attackers to execute arbitrary SQL commands and bypass login authentication via the username parameter (aka the u variable).</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421039/100/0/threaded">20060106 [eVuln] TheWebForum Script Insertion and Authentication Bypass</ref><ref source="" url="http://evuln.com/vulns/17/exploit.html"></ref><ref source="" url="http://evuln.com/vulns/17/summary.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16161">16161</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0093">ADV-2006-0093</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015450">1015450</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18392">18392</ref><ref source="OSVDB" url="http://www.osvdb.org/22294">22294</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24027">thewebforum-login-sql-injection(24027)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/321">321</ref></refs><vuln_soft><prod name="TheWebForum" vendor="TheWebForum"><vers num="1.2.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-15" name="CVE-2006-0136" published="2006-01-09" seq="2006-0136" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in the guestbook module in modules.php in Phanatic Softwares Chimera Web Portal System 0.2 allow remote attackers to inject arbitrary web script or HTML via the (1) comment_poster, (2) comment_poster_email, (3) comment_poster_homepage, and (4) comment_text parameters.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/420669/100/0/threaded">20060101 [eVuln] Chimera Web Portal System Multiple Vulnerabilities</ref><ref source="" url="http://evuln.com/vulns/7/exploit.html"></ref><ref source="" url="http://evuln.com/vulns/7/summary.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0025">ADV-2006-0025</ref><ref source="BID" url="http://www.securityfocus.com/bid/16113">16113</ref></refs><vuln_soft><prod name="Chimera Web Portal" vendor="Phanatic Softwares"><vers num="0.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-15" name="CVE-2006-0137" published="2006-01-09" seq="2006-0137" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in linkcategory.php in Phanatic Softwares Chimera Web Portal System 0.2 allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/420669/100/0/threaded">20060101 [eVuln] Chimera Web Portal System Multiple Vulnerabilities</ref><ref source="" url="http://evuln.com/vulns/7/exploit.html"></ref><ref source="" url="http://evuln.com/vulns/7/summary.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0025">ADV-2006-0025</ref><ref source="BID" url="http://www.securityfocus.com/bid/16113">16113</ref><ref source="OSVDB" url="http://www.osvdb.org/22420">22420</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/23963">chimera-linkcategory-sql-injection(23963)</ref></refs><vuln_soft><prod name="Chimera Web Portal" vendor="Phanatic Softwares"><vers num="0.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-15" name="CVE-2006-0138" published="2006-01-09" seq="2006-0138" severity="Medium" type="CVE"><desc><descript source="cve">aMSN (aka Alvaro&apos;s Messenger) allows remote attackers to cause a denial of service (client hang and termination of client&apos;s instant-messaging session) by repeatedly sending crafted data to the default file-transfer port (TCP 6891).</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://www.securiteam.com/exploits/5JP090KHFQ.html"></ref><ref source="OSVDB" url="http://www.osvdb.org/22186">22186</ref></refs><vuln_soft><prod name="aMSN" vendor="aMSN"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-15" name="CVE-2006-0139" published="2006-01-09" seq="2006-0139" severity="Medium" type="CVE"><desc><descript source="cve">The send-private-message functionality (send-private-message.asp) in PD9 Software MegaBBS 2.1 allows remote attackers to read private messages of other users via a modified replyid parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.hamid.ir/security/megabbs.txt"></ref><ref adv="1" patch="1" source="" url="http://www.pd9soft.com/megabbs/forums/thread-view.asp?tid=4924"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16168">16168</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0095">ADV-2006-0095</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18342">18342</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015452">1015452</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24050">
megabbs-sendprivatemessage-disclosure(24050)</ref></refs><vuln_soft><prod name="MegaBBS" vendor="PD9 Software"><vers num="2.1"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-15" name="CVE-2006-0140" published="2006-01-09" seq="2006-0140" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in post.php in NavBoard V16 Stable(2.6.0) and V17beta2 allows remote attackers to inject arbitrary web script or HTML via the (1) b, (2) textlarge, and (3) url bbcode tags.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421149/100/0/threaded">20060107 [eVuln] NavBoard BBcode XSS Vulnerability</ref><ref adv="1" source="" url="http://evuln.com/vulns/19/summary.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16165">16165</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0092">ADV-2006-0092</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18345">18345</ref><ref source="OSVDB" url="http://www.osvdb.org/22277">22277</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24021">
navboard-post-xss(24021)</ref></refs><vuln_soft><prod name="Navboard" vendor="Navboard"><vers num="V17 Beta2"/><vers num="V16 Stable2.6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2006-01-09" modified="2006-05-10" name="CVE-2006-0141" published="2006-01-09" seq="2006-0141" severity="Medium" type="CVE"><desc><descript source="cve">Qualcomm Eudora Internet Mail Server (EIMS) before 3.2.8 allows remote attackers to cause a denial of service (crash) via (1) malformed NTLM authentication requests, or a malformed (2) Incoming Mail X or (3) Temporary Mail file.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://www.eudora.co.nz/updates.html"></ref><ref patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0099">ADV-2006-0099</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18356">18356</ref><ref source="BID" url="http://www.securityfocus.com/bid/16179">16179</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24033">
eims-corrupted-mail-dos(24033)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24032">
eims-ntlm-auth-dos(24032)</ref></refs><vuln_soft><prod name="Internet Mail Server" vendor="Eudora"><vers num="3.2.8"/><vers num="3.2.7"/><vers num="3.2.6"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-15" name="CVE-2006-0142" published="2006-01-09" seq="2006-0142" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in andromeda.php in Andromeda 1.9.3.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the s parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0096">ADV-2006-0096</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18359">18359</ref><ref source="BID" url="http://www.securityfocus.com/bid/16183">16183</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24031">
andromeda-script-xss(24031)</ref></refs><vuln_soft><prod name="Andromeda" vendor="Andromeda Software"><vers num="1.9.3.4" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-10" name="CVE-2006-0143" published="2006-01-09" seq="2006-0143" severity="High" type="CVE"><desc><descript source="cve">Microsoft Windows Graphics Rendering Engine (GRE) allows remote attackers to corrupt memory and cause a denial of service (crash) via a WMF file containing (1) ExtCreateRegion or (2) ExtEscape function calls with arguments with inconsistent lengths.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421257/100/0/threaded">20060107 Microsoft Windows GRE WMF Format Multiple Memory Overrun Vulnerabilities</ref><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421258/100/0/threaded">20060109 [UPDATE]Microsoft Windows GRE WMF Format Multiple Unauthorized Memory Access Vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/16167">16167</ref><ref source="" url="http://blogs.technet.com/msrc/archive/2006/01/09/417198.aspx"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0115">ADV-2006-0115</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015453">1015453</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24044">
win-gre-wmf-dos(24044)</ref><ref source="" url="http://lostmon.blogspot.com/2007/08/windows-extended-file-attributes-buffer.html"></ref></refs><vuln_soft><prod name="Windows 98" vendor="Microsoft"><vers num="SE"/><vers num="Gold"/></prod><prod name="Windows XP" vendor="Microsoft"><vers edition="64-bit" num="Professional"/><vers edition="Gold" num="Professional"/><vers edition="Gold" num="Professional"/><vers edition="Gold" num="Professional"/><vers edition="SP2" num="Home"/><vers edition="SP1" num="Home"/><vers num="Home"/><vers edition="SP2" num="Tablet PC"/><vers edition="SP2" num="Tablet PC"/><vers edition="SP2" num="Tablet PC"/><vers edition="SP2" num="Media Center"/><vers edition="SP1" num="Media Center"/><vers num="Media Center"/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers num="Standard 64-bit"/><vers num="Enterprise 64-bit"/><vers edition="Datacenter 64-bit" num="R2"/><vers edition="SP1" num="Web"/><vers num="Web"/><vers edition="SP1" num="Standard"/><vers edition="64-bit" num="Standard"/><vers edition="SP1" num="Enterprise 64-bit"/><vers edition="SP1" num="Enterprise"/><vers edition="64-bit" num="Enterprise"/><vers edition="SP1" num="Datacenter 64-bit"/><vers edition="SP1" num="R2"/><vers edition="64-bit" num="R2"/></prod><prod name="Windows ME" vendor="Microsoft"><vers num=""/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num="Server SP4"/><vers num="Server SP3"/><vers num="Server SP2"/><vers num="Server SP1"/><vers num="Server"/><vers num="Professional SP4"/><vers num="Professional SP3"/><vers num="Professional SP2"/><vers num="Professional SP1"/><vers num="Professional"/><vers num="Datacenter Server SP4"/><vers num="Datacenter Server SP3"/><vers num="Datacenter Server SP2"/><vers num="Datacenter Server SP1"/><vers num="Datacenter Server"/><vers num="Advanced Server SP4"/><vers num="Advanced Server SP3"/><vers num="Advanced Server SP2"/><vers num="Advanced Server SP1"/><vers num="Advanced Server"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-04-04" name="CVE-2006-0144" published="2006-01-09" seq="2006-0144" severity="High" type="CVE"><desc><descript source="cve">The proxy server feature in go-pear.php in PHP PEAR 0.2.2, as used in Apache2Triad, allows remote attackers to execute arbitrary PHP code by redirecting go-pear.php to a malicious proxy server that provides a modified version of Tar.php with a malicious extractModify function.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/16174">16174</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421469/100/0/threaded">20060109 New PEAR / Apache2Triad Exploit</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18390">18390</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0148">ADV-2006-0148</ref><ref source="" url="http://apache2triad.net/forums/viewtopic.php?p=14670"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24076">gopear-proxy-redirection(24076)</ref></refs><vuln_soft><prod name="PEAR" vendor="PHP"><vers num="0.2.2"/></prod><prod name="Apache2Triad" vendor="Apache2Triad"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-09" name="CVE-2006-0145" published="2006-01-09" seq="2006-0145" severity="Medium" type="CVE"><desc><descript source="cve">The kernfs_xread function in kernfs in NetBSD 1.6 through 2.1, and OpenBSD 3.8, does not properly validate file offsets against negative 32-bit values that occur as a result of truncation, which allows local users to read arbitrary kernel memory and gain privileges via the lseek system call.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/><design/></vuln_types><range><local/></range><refs><ref source="NETBSD" url="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2006-001.txt.asc">NetBSD-SA2006-001</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16173">16173</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18388">18388</ref><ref source="OSVDB" url="http://www.osvdb.org/22293">22293</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/423827/100/0/threaded">20060202 [SLAB] NetBSD / OpenBSD kernfs_xread patch evasion</ref><ref adv="1" source="" url="http://www.securitylab.net/research/2006/02/advisory_netbsd_openbsd_kernfs.html"></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18712">18712</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24035">
netbsd-kernfs-memory-disclosure(24035)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/405">405</ref></refs><vuln_soft><prod name="NetBSD" vendor="NetBSD"><vers num="2.1"/><vers num="2.0.3"/><vers num="2.0.2"/><vers num="2.0.1"/><vers num="2.0"/><vers num="1.6.2"/><vers num="1.6.1"/><vers num="1.6 Beta"/><vers num="1.6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-01-03" name="CVE-2006-0146" published="2006-01-09" seq="2006-0146" severity="High" type="CVE"><desc><descript source="cve">The server.php test script in ADOdb for PHP before 4.70, as used in multiple products including (1) Mantis, (2) PostNuke, (3) Moodle, (4) Cacti, (5) Xaraya, (6) PHPOpenChat, (7) MAXdev MD-Pro, and (8) MediaBeez, when the MySQL root password is empty, allows remote attackers to execute arbitrary SQL commands via the sql parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://secunia.com/secunia_research/2005-64/advisory/"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16187">16187</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0101">ADV-2006-0101</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0102">ADV-2006-0102</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0103">ADV-2006-0103</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0104">ADV-2006-0104</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0105">ADV-2006-0105</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/17418">17418</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18254">18254</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18267">18267</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18260">18260</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18276">18276</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18233">18233</ref><ref patch="1" source="OSVDB" url="http://www.osvdb.org/22290">22290</ref><ref patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/423784/100/0/threaded">20060202 Bug for libs in php link directory 2.0</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0447">ADV-2006-0447</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18720">18720</ref><ref patch="1" source="" url="http://www.xaraya.com/index.php/news/569"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0370">ADV-2006-0370</ref><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1029">DSA-1029</ref><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1030">DSA-1030</ref><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1031">DSA-1031</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19555">19555</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19590">19590</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19591">19591</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/430448/100/0/threaded">20060409 PhpOpenChat 3.0.x ADODB Server.php </ref><ref source="" url="http://retrogod.altervista.org/phpopenchat_30x_sql_xpl.html"></ref><ref source="" url="http://www.maxdev.com/Article550.phtml"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1304">ADV-2006-1304</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1305">ADV-2006-1305</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19563">19563</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19600">19600</ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200604-07.xml">GLSA-200604-07</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1419">ADV-2006-1419</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19699">19699</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19691">19691</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24051">adodb-server-command-execution(24051)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/466171/100/0/threaded">20070418 MediaBeez Sql query Execution .. Wear isn&apos;t ?? :)</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/24954">24954</ref><ref source="SREASON" url="http://securityreason.com/securityalert/713">713</ref></refs><vuln_soft><prod name="Mantis" vendor="Mantis"><vers num="1.0.0 rc4"/><vers num="0.19.4"/></prod><prod name="ADOdb" vendor="John Lim"><vers num="4.68"/><vers num="4.66"/></prod><prod name="Moodle" vendor="Moodle"><vers num="1.5.3"/></prod><prod name="Cacti" vendor="The Cacti Group"><vers num="0.8.6g"/></prod><prod name="MediaBeez" vendor="MediaBeez"><vers num=""/></prod><prod name="PostNuke" vendor="PostNuke Software Foundation"><vers num="0.761"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-09-08" name="CVE-2006-0147" published="2006-01-09" seq="2006-0147" severity="High" type="CVE"><desc><descript source="cve">Dynamic code evaluation vulnerability in tests/tmssql.php test script in ADOdb for PHP before 4.70, as used in multiple products including (1) Mantis, (2) PostNuke, (3) Moodle, (4) Cacti, (5) Xaraya, (6) PhpOpenChat, possibly (7) MAXdev MD-Pro, and (8) Simplog, allows remote attackers to execute arbitrary PHP functions via the do parameter, which is saved in a variable that is then executed as a function, as demonstrated using phpinfo.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://secunia.com/secunia_research/2005-64/advisory/"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0101">ADV-2006-0101</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0102">ADV-2006-0102</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0103">ADV-2006-0103</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0104">ADV-2006-0104</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/17418">17418</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18254">18254</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18267">18267</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18260">18260</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18276">18276</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18233">18233</ref><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1029">DSA-1029</ref><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1030">DSA-1030</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-1031">DSA-1031</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19555">19555</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19590">19590</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19591">19591</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/430448/100/0/threaded">20060409 PhpOpenChat 3.0.x ADODB Server.php </ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/430743/100/0/threaded">20060412 Simplog &lt;=0.9.2 multiple vulnerabilities</ref><ref source="" url="http://retrogod.altervista.org/phpopenchat_30x_sql_xpl.html"></ref><ref source="" url="http://milw0rm.com/exploits/1663"></ref><ref source="" url="http://retrogod.altervista.org/simplog_092_incl_xpl.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1305">ADV-2006-1305</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1332">ADV-2006-1332</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19600">19600</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19628">19628</ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200604-07.xml">GLSA-200604-07</ref><ref patch="1" source="OSVDB" url="http://www.osvdb.org/22291">22291</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19691">
19691</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24052">
adodb-tmssql-command-execution(24052)</ref></refs><vuln_soft><prod name="Mantis" vendor="Mantis"><vers num="1.0.0 rc4"/><vers num="0.19.4"/></prod><prod name="ADOdb" vendor="John Lim"><vers num="4.68"/><vers num="4.66"/></prod><prod name="Moodle" vendor="Moodle"><vers num="1.5.3"/></prod><prod name="Cacti" vendor="The Cacti Group"><vers num="0.8.6g"/></prod><prod name="PostNuke" vendor="PostNuke Software Foundation"><vers num="0.761"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-15" name="CVE-2006-0148" published="2006-01-09" seq="2006-0148" severity="Medium" type="CVE"><desc><descript source="cve">NetSarang Xlpd 2.1 allows remote attackers to cause a denial of service (crash) via a large number of connections from the same IP address.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://www.ipomonis.com/advisories/xlpd.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16164">16164</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015444">1015444</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24041">
xlpd-connection-dos(24041)</ref></refs><vuln_soft><prod name="Xlpd" vendor="NetSarang"><vers num="2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-15" name="CVE-2006-0149" published="2006-01-09" seq="2006-0149" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in SimpBook 1.0, with html_enable on (the default), allows remote attackers to inject arbitrary web script or HTML via the message field.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/041127.html">20060106 SimpBook &apos;message&apos; Remote Cross-Site Scripting Vulnerability</ref><ref adv="1" source="SECTRACK" url="http://securitytracker.com/id?1015451">1015451</ref></refs><vuln_soft><prod name="SimpBook" vendor="SimpBook"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" discovered="2005-12-22" modified="2006-05-10" name="CVE-2006-0150" published="2006-01-09" seq="2006-0150" severity="High" type="CVE"><desc><descript source="cve">Multiple format string vulnerabilities in the auth_ldap_log_reason function in Apache auth_ldap 1.6.0 and earlier allows remote attackers to execute arbitrary code via various vectors, including the username.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421286/100/0/threaded">20060109 Digital Armaments Security Advisory 01.09.2006: Apache auth_ldap module Multiple Format Strings Vulnerability</ref><ref adv="1" source="" url="http://www.digitalarmaments.com/2006090173928420.html"></ref><ref source="" url="http://www.rudedog.org/auth_ldap/Changes.html"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16177">16177</ref><ref adv="1" patch="1" source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0179.html">RHSA-2006:0179</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0117">ADV-2006-0117</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18382">18382</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18405">18405</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015456">1015456</ref><ref adv="1" patch="1" source="DEBIAN" url="http://www.debian.org/security/2006/dsa-952">DSA-952</ref><ref adv="1" patch="1" source="MANDRIVA" url="http://wwwnew.mandriva.com/security/advisories?name=MDKSA-2006:017">MDKSA-2006:017</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18412">18412</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18568">18568</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24030">
apache-authldap-format-string(24030)</ref></refs><vuln_soft><prod name="auth_ldap" vendor="Dave Carrigan"><vers num="1.6.0"/><vers num="1.4.3"/><vers num="1.4.2"/><vers num="1.4.0"/><vers num="1.3.4"/><vers num="1.3.3"/><vers num="1.3.2"/><vers num="1.3.1"/><vers num="1.3.0"/><vers num="1.2.4"/><vers num="1.2.3"/><vers num="1.2.2"/><vers num="1.2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-15" name="CVE-2006-0151" published="2006-01-09" seq="2006-0151" severity="High" type="CVE"><desc><descript source="cve">sudo 1.6.8 and other versions does not clear the PYTHONINSPECT environment variable, which allows limited local users to gain privileges via a Python script, a variant of CVE-2005-4158.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/><env/></vuln_types><range><local/></range><refs><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-235-2">USN-235-2</ref><ref source="BID" url="http://www.securityfocus.com/bid/16184">16184</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18358">18358</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18363">18363</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-946">DSA-946</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_02_sr.html">SUSE-SR:2006:002</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18549">18549</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18906">18906</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2006/0010">2006-0010</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18558">18558</ref><ref source="SLACKWARE" url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2006&amp;m=slackware-security.421822">SSA:2006-045-08</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19016">19016</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:159">MDKSA-2006:159</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21692">21692</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:159">MDKSA-2006:159</ref></refs><vuln_soft><prod name="Sudo" vendor="Todd Miller"><vers num="1.6.8 p9"/><vers num="1.6.8 p8"/><vers num="1.6.8 p7"/><vers num="1.6.8 p5"/><vers num="1.6.8 p2"/><vers num="1.6.8 p12"/><vers num="1.6.8 p1"/><vers num="1.6.8"/><vers num="1.6.7 p5"/><vers num="1.6.7"/><vers num="1.6.6"/><vers num="1.6.5 p2"/><vers num="1.6.5 p1"/><vers num="1.6.5"/><vers num="1.6.4 p2"/><vers num="1.6.4 p1"/><vers num="1.6.4"/><vers num="1.6.3 p7"/><vers num="1.6.3 p6"/><vers num="1.6.3 p5"/><vers num="1.6.3 p4"/><vers num="1.6.3 p3"/><vers num="1.6.3 p2"/><vers num="1.6.3 p1"/><vers num="1.6.3"/><vers num="1.6.2"/><vers num="1.6.1"/><vers num="1.6"/><vers num="1.5.9"/><vers num="1.5.8"/><vers num="1.5.7"/><vers num="1.5.6"/></prod><prod name="Ubuntu Linux" vendor="Ubuntu"><vers edition="powerpc" num="5.10"/><vers edition="i386" num="5.10"/><vers edition="amd64" num="5.10"/><vers edition="powerpc" num="5.04"/><vers edition="i386" num="5.04"/><vers edition="amd64" num="5.04"/><vers edition="ia64 ppc" num="4.1"/><vers edition="ia64 ia64" num="4.1"/><vers edition="ia64" num="4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-15" name="CVE-2006-0152" published="2006-01-10" seq="2006-0152" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) in search_result.php in phpChamber 1.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the needle parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/16180">16180</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0094">ADV-2006-0094</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18360">18360</ref><ref source="OSVDB" url="http://www.osvdb.org/22282">22282</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24029">phpchamber-searchresult-xss(24029)</ref></refs><vuln_soft><prod name="phpChamber" vendor="phpChamber"><vers num="1.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-15" name="CVE-2006-0153" published="2006-01-10" seq="2006-0153" severity="High" type="CVE"><desc><descript source="cve">427BB 2.2 and 2.2.1 verifies authentication credentials based on the username, authenticated, and usertype cookies, which allows remote attackers to bypass authentication by using a valid username and usertype and setting the authenticated cookie.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421326/100/0/threaded">20060107 [eVuln] 427BB Multiple Vulnerabilities (Cookie-based Authentication Bypass, SQL Injections, XSS)</ref><ref adv="1" source="" url="http://evuln.com/vulns/18/summary.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16178">16178</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0091">ADV-2006-0091</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18354">18354</ref><ref source="OSVDB" url="http://www.osvdb.org/22274">22274</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24038">427bb-scripts-security-bypass(24038)</ref></refs><vuln_soft><prod name="fourtwosevenbb" vendor="427BB"><vers num="2.2.1"/><vers num="2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-15" name="CVE-2006-0154" published="2006-01-10" seq="2006-0154" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in showthread.php in 427BB 2.2 and 2.2.1 allows remote attackers to execute arbitrary SQL commands via the ForumID parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421326/100/0/threaded">20060107 [eVuln] 427BB Multiple Vulnerabilities (Cookie-based Authentication Bypass, SQL Injections, XSS)</ref><ref adv="1" source="" url="http://evuln.com/vulns/18/summary.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16169">16169</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0091">ADV-2006-0091</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18354">18354</ref><ref source="OSVDB" url="http://www.osvdb.org/22275">22275</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24039">427bb-showthread-sql-injection(24039)</ref></refs><vuln_soft><prod name="fourtwosevenbb" vendor="427BB"><vers num="2.2.1"/><vers num="2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-13" name="CVE-2006-0155" published="2006-01-10" seq="2006-0155" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in posts.php in 427BB 2.2 and 2.2.1 allows remote attackers to inject arbitrary Javascript via a new message with a url bbcode tag containing a javascript URI.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421326/100/0/threaded">20060107 [eVuln] 427BB Multiple Vulnerabilities (Cookie-based Authentication Bypass, SQL Injections, XSS)</ref><ref source="" url="http://evuln.com/vulns/18/summary.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0091">ADV-2006-0091</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18354">18354</ref><ref source="OSVDB" url="http://www.osvdb.org/22276">22276</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24040">427bb-posts-xss(24040)</ref></refs><vuln_soft><prod name="fourtwosevenbb" vendor="427BB"><vers num="2.2.1"/><vers num="2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-13" name="CVE-2006-0156" published="2006-01-10" seq="2006-0156" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Foxrum 4.0.4f allows remote attackers to inject arbitrary Javascript via the javascript URI in bbcode url tags in (1) addpost1.php and (2) addtopic1.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421277/100/0/threaded">20060109 [eVuln] Foxrum BBCode XSS Vulnerabilty</ref><ref adv="1" source="" url="http://evuln.com/vulns/20"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16172">16172</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0121">ADV-2006-0121</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18386">18386</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24043">
foxrum-bbcode-xss(24043)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/325">325</ref></refs><vuln_soft><prod name="foxrum" vendor="foxrum"><vers num="4.0.4f"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-13" name="CVE-2006-0157" published="2006-01-10" seq="2006-0157" severity="Medium" type="CVE"><desc><descript source="cve">settings.php in Reamday Enterprises Magic News Plus 1.0.3 allows remote attackers to change the administrator password via a change action that specifies identical values for the passwd and admin_password parameters, then declares the new password string in the new_passwd and confirm_passwd parameters.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://downloads.securityfocus.com/vulnerabilities/exploits/MagicNewsPlus-pw-change.pl"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16182">16182</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18601">18601</ref></refs><vuln_soft><prod name="Magic News Plus" vendor="Reamday Enterprises"><vers num="1.0.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-28" name="CVE-2006-0158" published="2006-01-10" seq="2006-0158" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in index.php in CyberDoc SiteSuite CMS allows remote attackers to execute arbitrary SQL commands via the page parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://osvdb.org/ref/22/22205-sitesuite.txt"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0038">ADV-2006-0038</ref><ref source="OSVDB" url="http://www.osvdb.org/22205">22205</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18305">18305</ref></refs><vuln_soft><prod name="SiteSuite CMS" vendor="CyberDoc"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-13" name="CVE-2006-0159" published="2006-01-10" seq="2006-0159" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in escribir.php in Foro Domus 2.10 allows remote attackers to execute arbitrary SQL commands via the email parameter.  NOTE: the provenance of this information is unknown, although it may be based on post-disclosure analysis of CVE-2006-0110; the details are obtained solely from third party information.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0073">ADV-2006-0073</ref><ref source="OSVDB" url="http://www.osvdb.org/22264">22264</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18327">18327</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24017">
domus-escribir-sql-injection(24017)</ref></refs><vuln_soft><prod name="Foro Domus" vendor="Javier Suarez Sanz"><vers num="2.10"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-05" name="CVE-2006-0160" published="2006-01-10" seq="2006-0160" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in add_post.php3 in Venom Board 1.22 allows remote attackers to execute arbitrary SQL commands via the (1) parent, (2) root, and (3) topic_id parameters to post.php3.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=113683807903915&amp;w=2">20060109 [eVuln] Venom Board SQL Injection Vulnerability</ref><ref adv="1" source="" url="http://evuln.com/vulns/21/summary.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16176">16176</ref><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=113683807903915&amp;w=2">20060109 [eVuln] Venom Board SQL Injection Vulnerability</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0122">ADV-2006-0122</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18383">18383</ref><ref source="OSVDB" url="http://www.osvdb.org/22297">22297</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24046">venomboard-addpost-sql-injection(24046)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/326">326</ref></refs><vuln_soft><prod name="Venom Board" vendor="Venom Board"><vers num="1.22"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-11" name="CVE-2006-0161" published="2006-01-10" seq="2006-0161" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in uucp in Sun Solaris 8 and 9 has unknown impact and attack vectors.  NOTE: due to the vagueness of the vendor advisory, it is not clear whether this is related to CVE-2004-0780.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><range><local/></range><refs><ref adv="1" patch="1" source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101933-1">101933</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0113">ADV-2006-0113</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18371">18371</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015455">1015455</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-056.htm"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/19087">19087</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1534">oval:org.mitre.oval:def:1534</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers num="8.0"/><vers edition="SPARC" num="9.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-11" name="CVE-2006-0162" published="2006-01-10" seq="2006-0162" severity="High" type="CVE"><desc><descript source="cve">Heap-based buffer overflow in libclamav/upx.c in Clam Antivirus (ClamAV) before 0.88 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted UPX files.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="" url="http://www.clamav.net/doc/0.88/ChangeLog"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16191">16191</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0116">ADV-2006-0116</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18379">18379</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015457">1015457</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200601-07.xml">GLSA-200601-07</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18453">18453</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/385908">VU#385908</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/041325.html">20060112 ZDI-06-001: Clam AntiVirus UPX Unpacking Code Execution Vulnerability</ref><ref source="" url="http://www.zerodayinitiative.com/advisories/ZDI-06-001.html"></ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-947">DSA-947</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:016">MDKSA-2006:016</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2006/0002/">2006-0002</ref><ref source="OSVDB" url="http://www.osvdb.org/22318">22318</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18478">18478</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18548">18548</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18463">18463</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24047">
clamav-libclamav-upx-bo(24047)</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:016">MDKSA-2006:016</ref><ref source="SREASON" url="http://securityreason.com/securityalert/342">342</ref></refs><vuln_soft><prod name="ClamAV" vendor="Clam Anti-Virus"><vers num="0.87.1"/><vers num=""/><vers num="0.87"/><vers num="0.86.2"/><vers num="0.86.1"/><vers num="0.86"/><vers num="0.85.1"/><vers num="0.85"/><vers num="0.84 rc2"/><vers num="0.84 rc1"/><vers num="0.84"/><vers num="0.83"/><vers num="0.82"/><vers num="0.81"/><vers num="0.80 rc4"/><vers num="0.80 rc3"/><vers num="0.80 rc2"/><vers num="0.80 rc1"/><vers num="0.80"/><vers num="0.75.1"/><vers num="0.70"/><vers num="0.68.1"/><vers num="0.68"/><vers num="0.67"/><vers num="0.65"/><vers num="0.60"/><vers num="0.54"/><vers num="0.53"/><vers num="0.52"/><vers num="0.51"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-09-23" name="CVE-2006-0163" published="2006-01-11" seq="2006-0163" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in the search module (modules/Search/index.php) of PHPNuke EV 7.7 -R1 allows remote attackers to execute arbitrary SQL commands via the query parameter, which is used by the search field.  NOTE: This is a different vulnerability than CVE-2005-3792.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://lostmon.blogspot.com/2006/01/phpnuke-ev-77-search-module-query.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16186">16186</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0120">ADV-2006-0120</ref><ref source="OSVDB" url="http://www.osvdb.org/22316">22316</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18394">18394</ref></refs><vuln_soft><prod name="PHP-Nuke EV" vendor="Francisco Burzi"><vers num="7.7 r1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-13" name="CVE-2006-0164" published="2006-01-11" seq="2006-0164" severity="High" type="CVE"><desc><descript source="cve">phgstats.inc.php in phgstats before 0.5.1, if register_globals is enabled, allows remote attackers to include arbitrary files and execute arbitrary PHP code by modifying the PHGDIR variable.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://sourceforge.net/project/shownotes.php?release_id=384232"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0123">ADV-2006-0123</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18346">18346</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24062">phgstats-php-file-include(24062)</ref><ref source="OSVDB" url="http://www.osvdb.org/22302">22302</ref><ref source="BID" url="http://www.securityfocus.com/bid/17469">17469</ref></refs><vuln_soft><prod name="phgstats" vendor="woah-projekt"><vers num="0.5"/><vers num="0.4.2"/><vers num="0.4.1"/><vers num="0.4"/><vers num="0.3.1"/><vers num="0.3"/><vers num="0.2"/><vers num="0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-13" name="CVE-2006-0165" published="2006-01-11" seq="2006-0165" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in the DataForm Entries functionality in Plain Black WebGUI before 6.8.4 (gamma) allows remote attackers to inject arbitrary Javascript via the (1) url and (2) name field of the default email form.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://sourceforge.net/project/shownotes.php?release_id=384153&amp;group_id=51417"></ref><ref source="" url="http://sourceforge.net/tracker/index.php?func=detail&amp;aid=1395371&amp;group_id=51417&amp;atid=463213"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0126">ADV-2006-0126</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18372">18372</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24053">webgui-forms-xss(24053)</ref></refs><vuln_soft><prod name="WebGUI" vendor="Plain Black"><vers num="6.8.3 Gamma"/><vers num="6.8.2 Beta"/><vers num="6.8.1 Beta"/><vers num="6.7.8 gamma"/><vers num="6.7.7 Gamma"/><vers num="6.7.6 Gamma"/><vers num="6.7.5 Gamma"/><vers num="6.7.4 Gamma"/><vers num="6.7.3 Gamma"/><vers num="6.7.2 Beta"/><vers num="6.7.1 Beta"/><vers num="6.7.0 Beta"/><vers num="6.6.5"/><vers num="6.6.4 Gamma"/><vers num="6.6.3 Gamma"/><vers num="6.6.2 Gamma"/><vers num="6.6.1 Beta"/><vers num="6.6.0 Beta"/><vers num="6.5.6 Gamma"/><vers num="6.5.5 Gamma"/><vers num="6.5.4 Gamma"/><vers num="6.5.3 Beta"/><vers num="6.5.2 Beta"/><vers num="6.5.1 Beta"/><vers num="6.5.0 Beta"/><vers num="6.4.0 Beta"/><vers num="6.3.0 Beta"/><vers num="6.2.10 Gamma"/><vers num="6.2.11 Gamma"/><vers num="5.5.8"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-09-28" name="CVE-2006-0166" published="2006-01-11" seq="2006-0166" severity="High" type="CVE"><desc><descript source="cve">Symantec Norton SystemWorks and SystemWorks Premier 2005 and 2006 stores temporary copies of files in the Norton Protected Recycle Bin NProtect directory, which is hidden from the FindFirst and FindNext Windows APIs and allows remote attackers to hide arbitrary files from virus scanners and other products.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://securityresponse.symantec.com/avcenter/security/Content/2006.01.10.html"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0143">ADV-2006-0143</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015462">1015462</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18402">18402</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24061">systemworks-nprotect-hidden(24061)</ref></refs><vuln_soft><prod name="Norton System Works" vendor="Symantec"><vers num="2005"/><vers num="2006"/><vers num="2005 Premier"/><vers num="2006 Premier"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-09-21" name="CVE-2006-0167" published="2006-01-11" seq="2006-0167" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in MyPhPim 01.05 allows remote attackers to execute arbitrary SQL commands via the (1) cal_id parameter in calendar.php3 and the (2) password field on the login page.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://evuln.com/vulns/22/summary.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0147">ADV-2006-0147</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18399">18399</ref><ref source="BID" url="http://www.securityfocus.com/bid/16210">16210</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24066">myphpim-calendar-sql-injection(24066)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24075">myphpim-login-sql-injection(24075)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421863/100/0/threaded">20060111 [eVuln] MyPhPim Multiple SQL Injection and XSS Vulnerabilities</ref><ref source="OSVDB" url="http://www.osvdb.org/22324">22324</ref><ref source="OSVDB" url="http://www.osvdb.org/22325">22325</ref></refs><vuln_soft><prod name="MyPhPim" vendor="MyPhPim"><vers num="01.05"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-09-21" name="CVE-2006-0168" published="2006-01-11" seq="2006-0168" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in MyPhPim 01.05 allows remote attackers to inject arbitrary web script or HTML via the description field on the &quot;Create New todo&quot; page.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://evuln.com/vulns/22/summary.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0147">ADV-2006-0147</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18399">18399</ref><ref source="BID" url="http://www.securityfocus.com/bid/16210">16210</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24071">myphpim-todo-xss(24071)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421863/100/0/threaded">20060111 [eVuln] MyPhPim Multiple SQL Injection and XSS Vulnerabilities</ref><ref source="OSVDB" url="http://www.osvdb.org/22326">22326</ref></refs><vuln_soft><prod name="MyPhPim" vendor="MyPhPim"><vers num="01.05"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-05" name="CVE-2006-0169" published="2006-01-11" seq="2006-0169" severity="High" type="CVE"><desc><descript source="cve">addresses.php3 in MyPhPim 01.05 does not restrict uploaded files, which allows remote attackers to execute arbitrary PHP code via the pdbfile variable, then directly accessing those files from the uploads directory.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://evuln.com/vulns/23/summary.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16208">16208</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0147">ADV-2006-0147</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18399">18399</ref><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421626/100/0/threaded">20060111 [eVuln] MyPhPim Arbitrary File Upload</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24070">myphpim-addresses-file-upload(24070)</ref></refs><vuln_soft><prod name="MyPhPim" vendor="MyPhPim"><vers num="01.05"/></prod></vuln_soft></entry><entry modified="2006-01-19" name="CVE-2006-0170" published="2006-01-11" reject="1" seq="2006-0170" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2006-0035.  Reason: This candidate is a duplicate of CVE-2006-0035.  Notes: All CVE users should reference CVE-2006-0035 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript></desc><refs/></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-19" name="CVE-2006-0171" published="2006-01-11" seq="2006-0171" severity="High" type="CVE"><desc><descript source="cve">PHP remote file include vulnerability in index.php in OrjinWeb E-commerce allows remote attackers to execute arbitrary code via a URL in the page parameter.  NOTE: it is not clear, but OrjinWeb might be an application service, in which case it should not be included in CVE.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421312/100/0/threaded">20060106 Orjinweb E-commerce</ref><ref source="BID" url="http://www.securityfocus.com/bid/16199">16199</ref><ref source="OSVDB" url="http://www.osvdb.org/22387">22387</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24097">orjinweb-url-file-include(24097)</ref></refs><vuln_soft><prod name="OrjinWeb E-commerce" vendor="Orjinweb"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="3.5" CVSS_exploit_subscore="6.8" CVSS_impact_subscore="2.9" CVSS_score="3.5" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-18" name="CVE-2006-0172" published="2006-01-11" seq="2006-0172" severity="Low" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in the file manager utility in Hummingbird Collaboration (aka Hummingbird Enterprise Collaboration) 5.21 and earlier allows remote attackers to inject arbitrary web script or HTML in an uploaded page, which is published without a check for hostile scripting.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421392/100/0/threaded">20060110 Multiple Vulnerabilities in Hummingbird Collaboration</ref><ref adv="1" source="" url="http://www.securenetwork.it/advisories/sn-2006-01.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16195">16195</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0145">ADV-2006-0145</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18411">18411</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24067">
hummingbird-enterprise-xss(24067)</ref></refs><vuln_soft><prod name="Hummingbird Enterprise Collaboration" vendor="Hummingbird"><vers num="5.21" prev="1"/><vers num="5.2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.0" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="2.9" CVSS_score="4.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-18" name="CVE-2006-0173" published="2006-01-11" seq="2006-0173" severity="Medium" type="CVE"><desc><descript source="cve">Hummingbird Collaboration (aka Hummingbird Enterprise Collaboration) 5.21 and earlier allows remote attackers to misrepresent the type and name of a file via modified doc_ext and id parameters, which might trick a user into downloading dangerous or unexpected content.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421392/100/0/threaded">20060110 Multiple Vulnerabilities in Hummingbird Collaboration</ref><ref adv="1" source="" url="http://www.securenetwork.it/advisories/sn-2006-01.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16195">16195</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0145">ADV-2006-0145</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18411">18411</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24068">
hummingbird-enterprise-file-download(24068)</ref></refs><vuln_soft><prod name="Hummingbird Enterprise Collaboration" vendor="Hummingbird"><vers num="5.21" prev="1"/><vers num="5.2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.0" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="2.9" CVSS_score="4.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-17" name="CVE-2006-0174" published="2006-01-11" seq="2006-0174" severity="Medium" type="CVE"><desc><descript source="cve">Hummingbird Collaboration (aka Hummingbird Enterprise Collaboration) 5.21 and earlier allows remote attackers to obtain sensitive information (intranet IP addresses and enumerations of valid parameter values) via a direct request to hc, which reveals the information in an error message or a cookie.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/><exception/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421392/100/0/threaded">20060110 Multiple Vulnerabilities in Hummingbird Collaboration</ref><ref source="" url="http://www.securenetwork.it/advisories/sn-2006-01.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16195">16195</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0145">ADV-2006-0145</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18411">18411</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24069">
hummingbird-enterprise-information-disclosure(24069)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/328">328</ref></refs><vuln_soft><prod name="Hummingbird Collaboration" vendor="Hummingbird"><vers num="5.21" prev="1"/><vers num="5.2"/></prod><prod name="Hummingbird Enterprise Collaboration" vendor="Hummingbird"><vers num="5.21" prev="1"/><vers num="5.2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-17" name="CVE-2006-0175" published="2006-01-11" seq="2006-0175" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in search_form.asp in Web Wiz Forums 6.34 allows remote attackers to inject arbitrary web script or HTML via the search parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0299.html">20060109 Advisory:XSS vulnerability on WebWiz Forums &lt;= 6.34 (search_form.asp)</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16196">16196</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421615/100/0/threaded">20060111 Advisory:XSS vulnerability on WebWiz Forums &lt;= 6.34 (search_form.asp)</ref><ref source="OSVDB" url="http://www.osvdb.org/22398">22398</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24048">webwizforums-searchform-xss(24048)</ref></refs><vuln_soft><prod name="Web Wiz Forums" vendor="BDC Enterprises"><vers num="6.34"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-17" name="CVE-2006-0176" published="2006-01-11" seq="2006-0176" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in certain functions in src/fileio.c and src/unix/fileio.c in xmame before 11 January 2006 may allow local users to gain privileges via a long (1) -lang, (2) -ctrlr, (3) -pb, or (4) -rec argument on many operating systems, and via a long (5) -jdev argument on Ubuntu Linux.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0353.html">20060110 mysec.org Security Advisory : Xmame buffer overflow, with a possibility of privilege escalation.</ref><ref source="BID" url="http://www.securityfocus.com/bid/16203">16203</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421849/100/0/threaded">20060110 mysec.org Security Advisory : Xmame buffer overflow, with a possibility of privilege escalation</ref><ref source="" url="http://x.mame.net/changes-unix.html"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24102">
xmame-multiple-parameters-bo(24102)</ref></refs><vuln_soft><prod name="Xmame" vendor="Xmame"><vers num="0.102"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-16" name="CVE-2006-0177" published="2006-01-11" seq="2006-0177" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in Cray UNICOS 9.0.2.2 might allow local users to gain privileges by (1) invoking /usr/bin/script with a long command line argument or (2) setting the -c option of /etc/nu to the name of a file containing a long line.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0343.html">20060110 SUID root overflows in UNICOS and partial shellcode</ref><ref source="BID" url="http://www.securityfocus.com/bid/16205">16205</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24276">
unicos-command-line-bo(24276)</ref></refs><vuln_soft><prod name="UNICOS" vendor="Cray"><vers num="9.0.2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-16" name="CVE-2006-0178" published="2006-01-11" seq="2006-0178" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in /bin/ftp in UNICOS 9.0.2.2 allows local users to have an unknown impact via format string specifiers in the quote command.  NOTE: because the program is not setuid and not normally called from remote programs, there may not be a typical attack vector for the issue that crosses privilege boundaries. Therefore this may not be a vulnerability.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0343.html">20060110 SUID root overflows in UNICOS and partial shellcode</ref><ref source="BID" url="http://www.securityfocus.com/bid/16205">16205</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24277">
unicos-ftp-format-string(24277)</ref></refs><vuln_soft><prod name="UNICOS" vendor="Cray"><vers num="9.0.2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2008-01-03" name="CVE-2006-0179" published="2006-01-11" seq="2006-0179" severity="Medium" type="CVE"><desc><descript source="cve">The Cisco IP Phone 7940 allows remote attackers to cause a denial of service (reboot) via a large amount of TCP SYN packets (syn flood) to arbitrary ports, as demonstrated to port 80.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="" url="http://downloads.securityfocus.com/vulnerabilities/exploits/cisco_ip7940_dos.pl"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16200">16200</ref><ref source="" url="http://www.milw0rm.com/id.php?id=1411"></ref><ref adv="1" source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-response-20060113-ip-phones.shtml">20060113 Response to Cisco IP Phone 7940 DoS Exploit posted on milw0rm.com</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0202">ADV-2006-0202</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015488">1015488</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18479">18479</ref><ref source="OSVDB" url="http://www.osvdb.org/22469">22469</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24117">cisco-ipphone-synflood-dos(24117)</ref></refs><vuln_soft><prod name="IP Phone" vendor="Cisco"><vers num="7940"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-13" name="CVE-2006-0180" published="2006-01-12" seq="2006-0180" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in CaLogic Calendars 1.2.2 allows remote attackers to inject arbitrary web script or HTML via the Title field on the &quot;Adding New Event&quot; page, and possibly other vectors, involving iframe tags.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="OSVDB" url="http://www.osvdb.org/22322">22322</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24077">calogic-newevent-xss(24077)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/422163/100/0/threaded">20060116 [eVuln] CaLogic Calendars Multiple XSS Vulnerabilities</ref><ref adv="1" source="" url="http://evuln.com/vulns/24/summary.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16206">16206</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0149">ADV-2006-0149</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18417">18417</ref></refs><vuln_soft><prod name="CaLogic Calendars" vendor="CaLogic"><vers num="1.2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-13" name="CVE-2006-0181" published="2006-01-12" seq="2006-0181" severity="High" type="CVE"><desc><descript source="cve">Cisco Security Monitoring, Analysis and Response System (CS-MARS) before 4.1.3 has an undocumented administrative account with a default password, which allows local users to gain privileges via the expert command.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-sa-20060111-mars.shtml">20060111 Default Administrative Password in Cisco Security Monitoring, Analysis and Response System (CS-MARS)</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16211">16211</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0154">ADV-2006-0154</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015471">1015471</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18424">18424</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24065">cisco-csmars-default-password(24065)</ref><ref source="OSVDB" url="http://www.osvdb.org/22346">22346</ref><ref source="SREASON" url="http://securityreason.com/securityalert/335">335</ref></refs><vuln_soft><prod name="CS-MARS" vendor="Cisco"><vers num="4.1.2"/><vers num="4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-13" name="CVE-2006-0182" published="2006-01-12" seq="2006-0182" severity="High" type="CVE"><desc><descript source="cve">login.php in ACal Calendar Project 2.2.5 allows remote attackers to bypass authentication by setting the ACalAuthenticate cookie variable to &quot;inside&quot;.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/><design/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://evuln.com/vulns/25/summary.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0152">ADV-2006-0152</ref><ref source="OSVDB" url="http://www.osvdb.org/22344">22344</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18432">18432</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24104">acal-login-auth-bypass(24104)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421744/100/0/threaded">20060112 [eVuln] ACal Authentication Bypass &amp; PHP Code Insertion</ref><ref source="SREASON" url="http://securityreason.com/securityalert/343">343</ref></refs><vuln_soft><prod name="Calendar Project" vendor="ACal"><vers num="2.2.5"/></prod></vuln_soft></entry><entry CVSS_base_score="6.5" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="6.4" CVSS_score="6.5" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-13" name="CVE-2006-0183" published="2006-01-12" seq="2006-0183" severity="Medium" type="CVE"><desc><descript source="cve">Direct static code injection vulnerability in edit.php in ACal Calendar Project 2.2.5 allows authenticated users to execute arbitrary PHP code via (1) the edit=header value, which modifies header.php, or (2) the edit=footer value, which modifies footer.php.  NOTE: this issue might be resultant from the poor authentication as identified by CVE-2006-0182.  Since the design of the product allows the administrator to edit the code, perhaps this issue should not be included in CVE, except as a consequence of CVE-2006-0182.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://evuln.com/vulns/25/summary.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0152">ADV-2006-0152</ref><ref source="OSVDB" url="http://www.osvdb.org/22345">22345</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18432">18432</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24107">acal-header-footer-code-execute(24107)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421744/100/0/threaded">20060112 [eVuln] ACal Authentication Bypass &amp; PHP Code Insertion</ref><ref source="SREASON" url="http://securityreason.com/securityalert/343">343</ref></refs><vuln_soft><prod name="Calendar Project" vendor="ACal"><vers num="2.2.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-13" name="CVE-2006-0184" published="2006-01-12" seq="2006-0184" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in AspTopSites allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to goto.asp or (2) password parameter to includeloginuser.asp.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://www.exploitlabs.com/files/advisories/EXPL-A-2006-001-asptopsites.txt"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0146">ADV-2006-0146</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18408">18408</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24072">asptopsites-goto-sql-injection(24072)</ref><ref source="OSVDB" url="http://www.osvdb.org/22330">22330</ref><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0351.html">20060110 AspTopSites SQL injection</ref></refs><vuln_soft><prod name="AspTopSites" vendor="MaineNet Enterprises"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-13" name="CVE-2006-0185" published="2006-01-12" seq="2006-0185" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting vulnerabilities in the (1) Pool or (2) News Modules in Php-Nuke allow remote attackers to inject arbitrary web script or HTML via javascript in the SRC attribute of an IMG tag.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/421322">20060107 Php-Nuke Pool and News Module IMG Tag Cross Site</ref><ref source="BID" url="http://www.securityfocus.com/bid/16192">16192</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0125">ADV-2006-0125</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18374">18374</ref></refs><vuln_soft><prod name="PHP-Nuke News Module" vendor="PHP-Nuke"><vers num=""/></prod><prod name="PHP-Nuke Pool Module" vendor="PHP-Nuke"><vers num=""/></prod></vuln_soft></entry><entry modified="2006-01-17" name="CVE-2006-0186" published="2006-01-12" reject="1" seq="2006-0186" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2005-4500.  Reason: This candidate is a duplicate of CVE-2005-4500.  Notes: All CVE users should reference CVE-2005-4500 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><refs/></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-08-28" name="CVE-2006-0187" published="2006-01-12" seq="2006-0187" severity="Medium" type="CVE"><desc><descript source="cve">By design, Microsoft Visual Studio 2005 automatically executes code in the Load event of a user-defined control (UserControl1_Load function), which allows user-assisted attackers to execute arbitrary code by tricking the user into opening a malicious Visual Studio project file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><design/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0151">ADV-2006-0151</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18409">18409</ref><ref source="BID" url="http://www.securityfocus.com/bid/16225">16225</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421943/100/0/threaded">20060113 Visual Studio Remote Code Execution</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24116">
visualstudio-usercontrol-code-execution(24116)</ref></refs><vuln_soft><prod name="Visual Studio" vendor="Microsoft"><vers num="2005"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-24" name="CVE-2006-0188" published="2006-02-23" seq="2006-0188" severity="Medium" type="CVE"><desc><descript source="cve">webmail.php in SquirrelMail 1.4.0 to 1.4.5 allows remote attackers to inject arbitrary web pages into the right frame via a URL in the right_frame parameter.  NOTE: this has been called a cross-site scripting (XSS) issue, but it is different than what is normally identified as XSS.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.squirrelmail.org/security/issue/2006-02-01"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16756">16756</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0689">ADV-2006-0689</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015662">1015662</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18985">18985</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24847">squirrelmail-webmail-xss(24847)</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-988">DSA-988</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-announce-list/2006-March/msg00004.html">FEDORA-2006-133</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:049">MDKSA-2006:049</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_05_sr.html">SUSE-SR:2006:005</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19131">19131</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19130">19130</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19176">19176</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200603-09.xml">GLSA-200603-09</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19205">19205</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0283.html">RHSA-2006:0283</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19960">19960</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20060501-01-U.asc">
20060501-01-U</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20210">
20210</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:049">MDKSA-2006:049</ref></refs><vuln_soft><prod name="SquirrelMail" vendor="SquirrelMail"><vers num="1.4.6 rc1"/><vers num="1.4.5"/><vers num="1.4.4 RC1"/><vers num="1.4.4"/><vers num="1.4.3 RC1"/><vers num="1.4.3 r3"/><vers num="1.4.3a"/><vers num="1.4.3"/><vers num="1.4.2"/><vers num="1.4.1"/><vers num="1.4 RC1"/><vers num="1.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-17" name="CVE-2006-0189" published="2006-01-13" seq="2006-0189" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in eStara Softphone 3.0.1.14 through 3.0.1.46 allows remote attackers to execute arbitrary code via a long attribute (aka &quot;a&quot;) field in the SDP data of a SIP packet on UDP port 5060.</descript></desc><sols><sol source="nvd">This is the vendor provided solution:

&quot;eStara has released Softphone version 3.0.1.47 to resolve the buffer overflow demonstrated in parsing SDP with long &quot;a=&quot; lines.  Licensed customers can download a new version via the email sent to them with purchase, customers testing may go back to http://www.estara.com/softphone/ to obtain a new free trial.   Version information can be gathered by going to Help-&gt;About.  eStara highly recommends all customers upgrade to avoid this issue.  If there&apos;s further questions please email us: softphone@estara.com.
 
eStara would like to thank ZwelL for bringing the issue to our attention.&quot;</sol></sols><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421596/100/0/threaded">20060111 eStara Softphone SIP stack Buffer Overflow Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/16213">16213</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0167">ADV-2006-0167</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015481">1015481</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18410">18410</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24090">estara-sip-sdp-bo(24090)</ref><ref source="OSVDB" url="http://www.osvdb.org/22348">22348</ref></refs><vuln_soft><prod name="Softphone" vendor="eStara"><vers num="3.0.1.14"/><vers num="3.0.1.46"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-13" name="CVE-2006-0190" published="2006-01-13" seq="2006-0190" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Sun Solaris 9 and 10 for the x86 platform allows local users to gain privileges or cause a denial of service (panic) via unspecified vectors, possibly involving functions from the mm driver.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><local/></range><refs><ref adv="1" patch="1" source="SUNALERT" url="http://sunsolve.sun.com/searchproxy/document.do?assetkey=1-26-102066-1">102066</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0165">ADV-2006-0165</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18421">18421</ref><ref source="BID" url="http://www.securityfocus.com/bid/16224">16224</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015478">1015478</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24084">solaris-unspecified-root-access(24084)</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-056.htm"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/19087">19087</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:702">oval:org.mitre.oval:def:702</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers edition="SPARC" num="9.0"/><vers edition="SPARC" num="10.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.9" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.9" CVSS_score="4.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-13" name="CVE-2006-0191" published="2006-01-13" seq="2006-0191" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Sun Solaris 10 allows local users to cause a denial of service (null dereference) via unspecified vectors involving the use of the find command on the &quot;/proc&quot; filesystem. NOTE: due to the vagueness of the vendor advisory, it is not clear whether this is related to CVE-2005-3250.</descript></desc><loss_types><avail/></loss_types><range><local/></range><refs><ref adv="1" patch="1" source="SUNALERT" url="http://sunsolve.sun.com/searchproxy/document.do?assetkey=1-26-102108-1">102108</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0166">ADV-2006-0166</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18420">18420</ref><ref source="BID" url="http://www.securityfocus.com/bid/16222">16222</ref><ref source="OSVDB" url="http://www.osvdb.org/22347">22347</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015479">1015479</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24085">solaris-find-proc-dos(24085)</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-056.htm"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/19087">19087</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1608">oval:org.mitre.oval:def:1608</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers edition="SPARC" num="10.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-03" name="CVE-2006-0192" published="2006-01-13" seq="2006-0192" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in Login_Validate.asp in ASPSurvey 1.10 allows remote attackers to execute arbitrary SQL commands via the Password parameter to login.asp.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0164">ADV-2006-0164</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18422">18422</ref><ref source="OSVDB" url="http://www.osvdb.org/22342">22342</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24087">aspsurvey-loginvalidate-sql-injection(24087)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/423949/100/0/threaded">20060204 sql injection in ASP Survey</ref><ref source="BID" url="http://www.securityfocus.com/bid/16496">16496</ref><ref source="SREASON" url="http://securityreason.com/securityalert/414">414</ref></refs><vuln_soft><prod name="ASPSurvey" vendor="Philip Loftin"><vers num="1.10"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-13" name="CVE-2006-0193" published="2006-01-13" seq="2006-0193" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in the Hosting Control Panel (psoft.hsphere.CP) in Positive Software H-Sphere 2.4.3 Patch 8 and earlier allows remote attackers to inject arbitrary web script or HTML via the login parameter in a login action.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421704/100/0/threaded">20060112 H-Sphere Security Vulnerability</ref><ref source="" url="http://www.psoft.net/HSdocumentation/versions/?v=all&amp;p=r"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0172">ADV-2006-0172</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18447">18447</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24096">hsphere-login-xss(24096)</ref><ref source="OSVDB" url="http://www.osvdb.org/22372">22372</ref><ref source="" url="http://www.psoft.net/HSdocumentation/versions/index.php?v=243p9&amp;p=r"></ref></refs><vuln_soft><prod name="H-Sphere" vendor="Positive Software"><vers num="2.4.3 Patch 8"/><vers num="2.4.3 Patch 7"/><vers num="2.4.3 Patch 6"/><vers num="2.4.3 Patch 5"/><vers num="2.4.3 Patch 4"/><vers num="2.4.3 Patch 3"/><vers num="2.4.3 Patch 2"/><vers num="2.4.3 Patch 1"/><vers num="2.4.3"/><vers num="2.4.3 RC2"/><vers num="2.4.2 Patch 5"/><vers num="2.4.3 RC1"/><vers num="2.4.2 Patch 4"/><vers num="2.4.3 Beta 2"/><vers num="2.4.3 Beta 1"/><vers num="2.4.2 Patch 3"/><vers num="2.4.2 Patch 2"/><vers num="2.4.2 Patch 1"/><vers num="2.4.2"/><vers num="2.4.2 RC2"/><vers num="2.4.1 Patch 7"/><vers num="2.4.2 RC1"/><vers num="2.4.2 Beta 3"/><vers num="2.4.1 Patch 6"/><vers num="2.4.1 Patch 5"/><vers num="2.4.2 Beta 2"/><vers num="2.4.1 Patch 4"/><vers num="2.4.1 Patch 3"/><vers num="2.4.1 Patch 2"/><vers num="2.4.2 Beta 1"/><vers num="2.4.1 Patch 1"/><vers num="2.4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-13" name="CVE-2006-0194" published="2006-01-13" seq="2006-0194" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in default.asp in FogBugz 4.029, and other versions before 4.0.33, allows remote attackers to inject arbitrary web script or HTML via the dest parameter in the pgLogon page.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421729/100/0/threaded">20060112 FogBugz Cross Site Scripting Vulnerability</ref><ref source="" url="http://www.fogcreek.com/FogBugz/KB/releaseNotes/WhatsNewInFogBugz4.0.33.html"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16216">16216</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0174">ADV-2006-0174</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18443">18443</ref><ref source="OSVDB" url="http://www.osvdb.org/22370">22370</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24103">fogbugz-login-xss(24103)</ref></refs><vuln_soft><prod name="FogBugz" vendor="Fog Creek Software"><vers num="4.029" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-24" name="CVE-2006-0195" published="2006-02-23" seq="2006-0195" severity="Medium" type="CVE"><desc><descript source="cve">Interpretation conflict in the MagicHTML filter in SquirrelMail 1.4.0 to 1.4.5 allows remote attackers to conduct cross-site scripting (XSS) attacks via style sheet specifiers with invalid (1) &quot;/*&quot; and &quot;*/&quot; comments, or (2) a newline in a &quot;url&quot; specifier, which is processed by certain web browsers including Internet Explorer.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.squirrelmail.org/security/issue/2006-02-10"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16756">16756</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0689">ADV-2006-0689</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015662">1015662</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18985">18985</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24848">squirrelmail-magichtml-xss(24848)</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-988">DSA-988</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-announce-list/2006-March/msg00004.html">FEDORA-2006-133</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:049">MDKSA-2006:049</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_05_sr.html">SUSE-SR:2006:005</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19131">19131</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19130">19130</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19176">19176</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200603-09.xml">GLSA-200603-09</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19205">19205</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0283.html">RHSA-2006:0283</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19960">19960</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20060501-01-U.asc">
20060501-01-U</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20210">
20210</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:049">MDKSA-2006:049</ref></refs><vuln_soft><prod name="SquirrelMail" vendor="SquirrelMail"><vers num="1.4.6 rc1"/><vers num="1.4.5"/><vers num="1.4.4 RC1"/><vers num="1.4.4"/><vers num="1.4.3 RC1"/><vers num="1.4.3 r3"/><vers num="1.4.3a"/><vers num="1.4.3"/><vers num="1.4.2"/><vers num="1.4.1"/><vers num="1.4 RC1"/><vers num="1.4"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-17" name="CVE-2006-0196" published="2006-01-13" seq="2006-0196" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Serial line sniffer (aka slsnif) 0.4.4 allows local users to gain privileges via a long value of the HOME environment variable, possibly because of a buffer overflow.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421583/100/0/threaded">20060111 Serial Line Sniffer 0.4.4 Buffer Overflow</ref><ref source="" url="http://shellcoders.com/sintigan/slsnif-ploit.pl"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24082">slsnif-home-bo(24082)</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0212">ADV-2006-0212</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18497">18497</ref></refs><vuln_soft><prod name="Serial Line Sniffer" vendor="Serial Line Sniffer"><vers num="0.4.4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-17" name="CVE-2006-0197" published="2006-01-13" seq="2006-0197" severity="Medium" type="CVE"><desc><descript source="cve">The XClientMessageEvent struct used in certain components of X.Org 6.8.2 and earlier, possibly including (1) the X server and (2) Xlib, uses a &quot;long&quot; specifier for elements of the l array, which results in inconsistent sizes in the struct on 32-bit versus 64-bit platforms, and might allow attackers to cause a denial of service (application crash) and possibly conduct other attacks.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421256/100/0/threaded">20060108 xorg server 6.8.2 and below on 64bit arch</ref></refs><vuln_soft><prod name="X.Org" vendor="X.Org"><vers num="6.8.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-17" name="CVE-2006-0198" published="2006-01-13" seq="2006-0198" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in a certain module, possibly poll or Pool, for XOOPS allows remote attackers to inject arbitrary web script or HTML via JavaScript in the SRC attribute of an IMG element in a comment.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421325/100/0/threaded">20060107 Xoops Pool Module IMG Tag Cross Site Scripting</ref><ref adv="1" source="" url="http://www.xoops.org/modules/newbb/viewtopic.php?topic_id=45637&amp;forum=2&amp;post_id=200481"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16189">16189</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24091">
xoops-pool-imagetag-xss(24091)</ref></refs><vuln_soft><prod name="Xoops Pool Module" vendor="Xoops"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-02" name="CVE-2006-0199" published="2006-01-13" seq="2006-0199" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in news.asp in Mini-Nuke CMS System 1.8.2 and earlier allows remote attackers to execute arbitrary SQL commands via the hid parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0173">ADV-2006-0173</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18439">18439</ref><ref source="OSVDB" url="http://www.osvdb.org/22384">22384</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24098">mininuke-news-sql-injection(24098)</ref><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421727/100/0/threaded">20060113 Advisory: MiniNuke CMS System &lt;= 1.8.2 (news.asp) SQL Injectionvulnerability</ref><ref adv="1" source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0439.html">20060112 Advisory: MiniNuke CMS System &lt;= 1.8.2 (news.asp) SQL Injection vulnerability</ref><ref source="" url="http://www.nukedx.com/?viewdoc=7"></ref><ref source="SREASON" url="http://securityreason.com/securityalert/340">340</ref></refs><vuln_soft><prod name="CMS System" vendor="Mini-Nuke"><vers num="1.8.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-17" name="CVE-2006-0200" published="2006-01-13" seq="2006-0200" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in the error-reporting feature in the mysqli extension in PHP 5.1.0 and 5.1.1 might allow remote attackers to execute arbitrary code via format string specifiers in MySQL error messages.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421705/100/0/threaded">20060112 Advisory 02/2006: PHP ext/mysqli Format String Vulnerability</ref><ref adv="1" source="" url="http://www.hardened-php.net/advisory_022006.113.html"></ref><ref patch="1" source="" url="http://www.php.net/release_5_1_2.php"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16219">16219</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0177">ADV-2006-0177</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18431">18431</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/24095">php-extmysqli-format-string(24095)</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015485">1015485</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0369">ADV-2006-0369</ref><ref source="SREASON" url="http://securityreason.com/securityalert/337">337</ref></refs><vuln_soft><prod name="PHP" vendor="PHP"><vers num="5.1.1"/><vers num="5.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-17" name="CVE-2006-0201" published="2006-01-13" seq="2006-0201" severity="Medium" type="CVE"><desc><descript source="cve">Dave Nielsen and Patrick Breitenbach PayPal Web Services (aka PHP Toolkit) 0.50, and possibly earlier versions, allows remote attackers to enter false payment entries into the log file via HTTP POST requests to ipn_success.php.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/421739">20060112 Multiple PHP Toolkit for PayPal Vulnerabilities</ref><ref adv="1" source="" url="http://www.uinc.ru/articles/vuln/ptpaypal050.shtml"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16218">16218</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0183">ADV-2006-0183</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18444">18444</ref><ref source="OSVDB" url="http://www.osvdb.org/22378">22378</ref></refs><vuln_soft><prod name="PHP Toolkit" vendor="PayPal"><vers num="0.50" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="3.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="4.9" CVSS_score="3.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-17" name="CVE-2006-0202" published="2006-01-13" seq="2006-0202" severity="Low" type="CVE"><desc><descript source="cve">Dave Nielsen and Patrick Breitenbach PayPal Web Services (aka PHP Toolkit) 0.50 and possibly earlier has (1) world-readable permissions for ipn/logs/ipn_success.txt, which allows local users to view sensitive information (payment data), and (2) world-writable permissions for ipn/logs, which allows local users to delete or replace payment data.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/421739">20060112 Multiple PHP Toolkit for PayPal Vulnerabilities</ref><ref adv="1" source="" url="http://www.uinc.ru/articles/vuln/ptpaypal050.shtml"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16218">16218</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0183">ADV-2006-0183</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18444">18444</ref><ref source="OSVDB" url="http://www.osvdb.org/22379">22379</ref></refs><vuln_soft><prod name="PHP Toolkit" vendor="PayPal"><vers num="0.50" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-02" name="CVE-2006-0203" published="2006-01-13" seq="2006-0203" severity="Medium" type="CVE"><desc><descript source="cve">membership.asp in Mini-Nuke CMS System 1.8.2 and earlier does not verify the old password when changing a password, which allows remote attackers to change the passwords of other members via a lostpassnew action with a modified x parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0173">ADV-2006-0173</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18439">18439</ref><ref source="OSVDB" url="http://www.osvdb.org/22385">22385</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24101">mininuke-membership-change-password(24101)</ref><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421748/100/0/threaded">20060113 Advisory: MiniNuke CMS System &lt;= 1.8.2 (membership.asp) remoteuser password change exploit</ref><ref adv="1" source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0439.html">20060112 Advisory: MiniNuke CMS System &lt;= 1.8.2 (news.asp) SQL Injection vulnerability</ref><ref adv="1" source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2006-01/0483.html">20060129 [xpl#2] MiniNuke 1.8.2 - change member&apos;s passwrod &lt; Perl &gt;</ref><ref adv="1" source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0437.html">20060112 Advisory: MiniNuke CMS System &lt;= 1.8.2 (membership.asp) remote user password change exploit</ref><ref source="SREASON" url="http://securityreason.com/securityalert/344">344</ref></refs><vuln_soft><prod name="CMS System" vendor="Mini-Nuke"><vers num="1.8.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-09-22" name="CVE-2006-0204" published="2006-01-13" seq="2006-0204" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Wordcircle 2.17 allow remote attackers to inject arbitrary web script or HTML via (1) the &quot;Course name&quot; field in index.php when the frm parameter has the value &quot;mine&quot; and (2) possibly certain other fields in unspecified scripts.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421746/100/0/threaded">20060112 [eVuln] Wordcircle Multiple SQL Injection &amp; XSS Vulnerabilities</ref><ref adv="1" source="" url="http://evuln.com/vulns/28/summary.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0185">ADV-2006-0185</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18440">18440</ref><ref source="BID" url="http://www.securityfocus.com/bid/16227">16227</ref><ref source="OSVDB" url="http://www.osvdb.org/22359">22359</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24106">wordcircle-index-xss(24106)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/345">345</ref></refs><vuln_soft><prod name="Wordcircle" vendor="Wordcircle"><vers num="2.17"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-23" name="CVE-2006-0205" published="2006-01-13" seq="2006-0205" severity="Medium" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in Wordcircle 2.17 allow remote attackers to (1) execute arbitrary SQL commands and bypass authentication via the password field in the login action to index.php (involving v_login.php and s_user.php) and (2) have other unknown impact via certain other fields in unspecified scripts.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421745/100/0/threaded">20060112 [eVuln] Wordcircle Authentication Bypass</ref><ref source="" url="http://evuln.com/vulns/27/summary.html"></ref><ref source="" url="http://evuln.com/vulns/28/summary.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16227">16227</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0185">ADV-2006-0185</ref><ref source="OSVDB" url="http://www.osvdb.org/22358">22358</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18440">18440</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24108">wordcircle-login-security-bypass(24108)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24105">wordcircle-sql-injection(24105)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421746/100/0/threaded">20060112 [eVuln] Wordcircle Multiple SQL Injection &amp; XSS Vulnerabilities</ref><ref source="SREASON" url="http://securityreason.com/securityalert/345">345</ref><ref source="SREASON" url="http://securityreason.com/securityalert/346">346</ref></refs><vuln_soft><prod name="Wordcircle" vendor="Wordcircle"><vers num="2.17"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-17" name="CVE-2006-0206" published="2006-01-13" seq="2006-0206" severity="High" type="CVE"><desc><descript source="cve">Eval injection vulnerability in Light Weight Calendar (LWC) 1.0 (20040909) and earlier allows remote attackers to execute arbitrary PHP code via the date parameter in cal.php, which is included by index.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://evuln.com/vulns/29/summary.html"></ref><ref source="" url="http://evuln.com/vulns/29/exploit.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16229">16229</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18450">18450</ref><ref source="OSVDB" url="http://www.osvdb.org/22376">22376</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24110">lwc-cal-execute-code(24110)</ref><ref source="MLIST" url="http://attrition.org/pipermail/vim/2006-March/000612.html">[VIM] 20060318 Source VERIFY - Light Weight Calendar issue is eval injection</ref></refs><vuln_soft><prod name="Light Weight Calendar" vendor="Light Weight Calendar"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-02" name="CVE-2006-0207" published="2006-01-13" seq="2006-0207" severity="Medium" type="CVE"><desc><descript source="cve">Multiple HTTP response splitting vulnerabilities in PHP 5.1.1 allow remote attackers to inject arbitrary HTTP headers via a crafted Set-Cookie header, related to the (1) session extension (aka ext/session) and the (2) header function.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.php.net/release_5_1_2.php"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0177">ADV-2006-0177</ref><ref adv="1" source="" url="http://www.hardened-php.net/advisory_012006.112.html"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16220">16220</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18431">18431</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/24094">php-session-response-splitting(24094)</ref><ref adv="1" patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015484">1015484</ref><ref adv="1" patch="1" source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:028">MDKSA-2006:028</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18697">18697</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0369">ADV-2006-0369</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-261-1">USN-261-1</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19179">19179</ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200603-22.xml">GLSA-200603-22</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19355">19355</ref><ref source="SUSE" url="http://lists.suse.de/archive/suse-security-announce/2006-Feb/0008.html">SUSE-SR:2006:004</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19012">19012</ref><ref source="DEBIAN" url="http://www.debian.org/security/2007/dsa-1331">DSA-1331</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:028">MDKSA-2006:028</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25945">25945</ref></refs><vuln_soft><prod name="PHP" vendor="PHP"><vers num="5.1.1"/><vers num="5.1"/><vers num="5.0.0.5"/><vers num="5.0.0.4"/><vers num="5.0.0.3"/><vers num="5.0.0.2"/><vers num="5.0.0.1"/><vers num="5.0.0 candidate 3"/><vers num="5.0.0 candidate 2"/><vers num="5.0.0 candidate 1"/><vers num="5.0.0.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-03" name="CVE-2006-0208" published="2006-01-13" seq="2006-0208" severity="Low" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in PHP 5.1.1, when display_errors and html_errors are on, allow remote attackers to inject arbitrary web script or HTML via inputs to PHP applications that are not filtered when they are included in the resulting error message.</descript></desc><loss_types><int/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://www.php.net/release_5_1_2.php"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0177">ADV-2006-0177</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18431">18431</ref><ref source="" url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=178028"></ref><ref adv="1" patch="1" source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:028">MDKSA-2006:028</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18697">18697</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0369">ADV-2006-0369</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16803">16803</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-261-1">USN-261-1</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19179">19179</ref><ref adv="1" patch="1" source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200603-22.xml">GLSA-200603-22</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19355">19355</ref><ref source="SUSE" url="http://lists.suse.de/archive/suse-security-announce/2006-Feb/0008.html">SUSE-SR:2006:004</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/19012">19012</ref><ref source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2006-0276.html">RHSA-2006:0276</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19832">19832</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0501.html">RHSA-2006:0501</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20222">20222</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-129.htm"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/2685">ADV-2006-2685</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20951">20951</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21252">21252</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-160.htm"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/21564">21564</ref><ref source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2006-0549.html">RHSA-2006:0549</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20060501-01-U.asc">
20060501-01-U</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20210">
20210</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:028">MDKSA-2006:028</ref></refs><vuln_soft><prod name="PHP" vendor="PHP"><vers num="5.1.1"/><vers num="5.1.0"/><vers num="5.0.5"/><vers num="5.0.4"/><vers num="5.0.3"/><vers num="5.0.2"/><vers num="5.0.1"/><vers num="5.0.0"/><vers num="5.0.0 RC3"/><vers num="5.0.0 RC2"/><vers num="5.0.0 RC1"/><vers num="5.0.0 Beta3"/><vers num="5.0.0 Beta2"/><vers num="5.0.0 Beta1"/><vers num="4.4.2"/><vers num="4.4.1"/><vers num="4.3.11"/><vers num="4.3.10"/><vers num="4.3.9"/><vers num="4.3.8"/><vers num="4.3.7"/><vers num="4.3.6"/><vers num="4.3.5"/><vers num="4.3.4"/><vers num="4.3.3"/><vers num="4.3.2"/><vers num="4.3.1"/><vers num="4.3"/><vers num="4.2.3"/><vers num="4.2.2"/><vers num="4.2.1"/><vers num="4.2.0"/><vers num="4.1.2"/><vers num="4.1.1"/><vers num="4.1.0"/><vers num="4.0.6"/><vers num="4.0.5"/><vers num="4.0.4"/><vers num="4.0.3"/><vers num="4.0.2"/><vers num="4.0.1"/><vers num="4.0.0"/><vers num="4.0 RC2"/><vers num="4.0 RC1"/><vers num="4.0 Beta 4 Patch Level 1"/><vers num="4.0 Beta 4"/><vers num="4.0 Beta 3"/><vers num="4.0 Beta 2"/><vers num="4.0 Beta 1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-16" name="CVE-2006-0209" published="2006-01-13" seq="2006-0209" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in general_functions.php in TankLogger 2.4 allows remote attackers to execute arbitrary SQL commands via the (1) livestock_id parameter to showInfo.php and (2) tank_id parameter, possibly to livestock.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://evuln.com/vulns/26/summary.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0153">ADV-2006-0153</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421743/100/0/threaded">20060112 [eVuln] TankLogger SQL Injection Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/16228">16228</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18441">18441</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24080">tanklogger-generalfunctions-sql-injection(24080)</ref><ref source="OSVDB" url="http://www.osvdb.org/22368">22368</ref><ref source="OSVDB" url="http://www.osvdb.org/22369">22369</ref><ref source="MLIST" url="http://attrition.org/pipermail/vim/2006-January/000480.html">[VIM] 20060113 Verified TankLogger SQl inject by source inspection</ref><ref source="SREASON" url="http://securityreason.com/securityalert/341">341</ref></refs><vuln_soft><prod name="TankLogger" vendor="TankLogger"><vers num="2.4"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-16" name="CVE-2006-0210" published="2006-01-13" seq="2006-0210" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in Interspire TrackPoint NX before 0.1 allows remote attackers to inject arbitrary web script or HTML via the username parameter when using the Login page.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://www.interspire.com/forum/showthread.php?p=29606"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16214">16214</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421740/100/0/threaded">20060112 Interspire TrackPoint NX XSS Vulnerability</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0175">ADV-2006-0175</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18445">18445</ref><ref source="OSVDB" url="http://www.osvdb.org/22377">22377</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24112">trackpointnx-login-xss(24112)</ref></refs><vuln_soft><prod name="TrackPoint NX" vendor="Interspire"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-16" name="CVE-2006-0211" published="2006-01-13" seq="2006-0211" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in forgotPassword.asp in Helm Hosting Control Panel 3.2.8 and earlier allows remote attackers to inject arbitrary web script or HTML via the txtEmailAddress parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421791/100/0/threaded">20060112 Helm XSS Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/16234">16234</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0203">ADV-2006-0203</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18492">18492</ref><ref source="OSVDB" url="http://www.osvdb.org/22454">22454</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24139">helm-forgotpassword-xss(24139)</ref><ref source="" url="http://www.webhostautomation.com/webhost-301"></ref></refs><vuln_soft><prod name="Helm Hosting Control Panel" vendor="Helm Hosting"><vers num="3.2.8"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-17" name="CVE-2006-0212" published="2006-01-13" seq="2006-0212" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in OBEX Push services in Toshiba Bluetooth Stack 4.00.23(T) and earlier allows remote attackers to upload arbitrary files to arbitrary remote locations specified by .. (dot dot) sequences, as demonstrated by ..\\ sequences in the RFILE argument of ussp-push.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=113712413907526&amp;w=2">20060113 DMA[2006-0112a] - &apos;Toshiba Bluetooth Stack Directory Transversal&apos;</ref><ref adv="1" source="" url="http://www.digitalmunition.com/DMA%5B2006-0112a%5D.txt"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0184">ADV-2006-0184</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18437">18437</ref><ref adv="1" source="FULLDISC" url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=113712413907526&amp;w=2">20060113 DMA[2006-0112a] - &apos;Toshiba Bluetooth Stack Directory Transversal&apos;</ref><ref source="BID" url="http://www.securityfocus.com/bid/16236">16236</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421993/100/0/threaded">20060113 DMA[2006-0112a] - &apos;Toshiba Bluetooth Stack Directory Transversal&apos;</ref><ref source="OSVDB" url="http://www.osvdb.org/22380">22380</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015486">1015486</ref><ref source="" url="http://aps.toshiba-tro.de/bluetooth/pages/driverinfo.php?txt=sp2"></ref></refs><vuln_soft><prod name="Bluetooth Stack" vendor="Toshiba"><vers num="4.00.23T" prev="1"/><vers num="4.00.11"/><vers num="4.00.01T"/><vers num="3.20.04"/><vers num="3.20.02"/><vers num="3.20.01"/><vers num="3.20.00"/><vers num="3.10.00"/><vers num="3.01.03"/><vers num="3.00.32"/><vers num="3.00.31a"/><vers num="3.00.12"/><vers num="3.00.11"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-17" name="CVE-2006-0213" published="2006-01-13" seq="2006-0213" severity="Medium" type="CVE"><desc><descript source="cve">Kolab Server 2.0.1, 2.0.2 and development versions pre-2.1-20051215 and earlier, when authenticating users via secure SMTP, stores authentication credentials in plaintext in the postfix.log file, which allows local users to gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="" url="http://kolab.org/security/kolab-vendor-notice-08.txt"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0186">ADV-2006-0186</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18438">18438</ref><ref source="OSVDB" url="http://www.osvdb.org/22381">22381</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24123">
kolab-smtp-logging(24123)</ref></refs><vuln_soft><prod name="Kolab Groupware Server" vendor="Kolab"><vers num="2.0.1"/><vers num="2.0.2"/><vers num="2005-12-15 pre2.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-16" name="CVE-2006-0214" published="2006-01-15" seq="2006-0214" severity="High" type="CVE"><desc><descript source="cve">Eval injection vulnerability in ezDatabase 2.0 and earlier allows remote attackers to execute arbitrary PHP code via the db_id parameter to visitorupload.php, as demonstrated using phpinfo and include function calls.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://pridels.blogspot.com/2006/01/ezdatabase-20-and-below.html"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/18043">18043</ref><ref source="BID" url="http://www.securityfocus.com/bid/16237">16237</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24136">
ezdatabase-visitorupload-file-include(24136)</ref><ref source="" url="http://pridels0.blogspot.com/2006/01/ezdatabase-20-and-below.html"></ref><ref source="SREASON" url="http://securityreason.com/securityalert/351">351</ref></refs><vuln_soft><prod name="ezDatabase" vendor="IndexCOR"><vers num="2.0"/><vers num="2.1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-17" name="CVE-2006-0215" published="2006-01-16" seq="2006-0215" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in admin.php in QualityEBiz Quality PPC (QPPC) 1.0 build 1644 allows remote attackers to inject arbitrary web script or HTML via the cpage parameter.  NOTE: this issue might be resultant from CVE-2006-0216.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://osvdb.org/ref/22/22352-qualityppc.txt"></ref><ref source="OSVDB" url="http://www.osvdb.org/22352">22352</ref></refs><vuln_soft><prod name="Quality PPC" vendor="QualityEBiz"><vers num="1.0 build 1644"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-02" name="CVE-2006-0216" published="2006-01-16" seq="2006-0216" severity="Medium" type="CVE"><desc><descript source="cve">admin.php in QualityEBiz Quality PPC (QPPC) 1.0 build 1644 allows remote attackers to obtain sensitive information, possibly the installation path of the application, via unspecified &quot;meta characters&quot; to the cpage parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://osvdb.org/ref/22/22352-qualityppc.txt"></ref><ref source="OSVDB" url="http://www.osvdb.org/22353">22353</ref><ref source="" url="http://osvdb.org/ref/22/22353-qualityppc.txt"></ref></refs><vuln_soft><prod name="Quality PPC" vendor="QualityEBiz"><vers num="1.0 build 1644"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-02" name="CVE-2006-0217" published="2006-01-16" seq="2006-0217" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Ultimate Auction 3.67 allow remote attackers to inject arbitrary web script or HTML via the (1) item parameter in item.pl and (2) category parameter in itemlist.pl, which reflects the XSS in an error message. NOTE: the affected version might be wrong since the current version as of 20060116 is 3.6.1.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/16239">16239</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0187">ADV-2006-0187</ref><ref source="OSVDB" url="http://www.osvdb.org/22443">22443</ref><ref source="OSVDB" url="http://www.osvdb.org/22444">22444</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18477">18477</ref><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0517.html">20060115 Ultimate Auction &lt;=3.67</ref><ref source="BID" url="http://www.securityfocus.com/bid/16254">16254</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24138">
ultimate-auction-item-xss(24138)</ref></refs><vuln_soft><prod name="Ultimate Auction" vendor="Ultimate Auction"><vers num="3.67"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-03-03" name="CVE-2006-0218" published="2006-01-16" seq="2006-0218" severity="High" type="CVE"><desc><descript source="cve">Multiple unspecified vulnerabilities in MyBulletinBoard (MyBB) before 1.0.2 have unspecified impact and attack vectors, related to (1) admin/moderate.php, (2) admin/themes.php, (3) inc/functions.php, (4) inc/functions_upload.php, (5) printthread.php, and (6) usercp.php, and probably related to SQL injection.  NOTE: it is likely that this issue subsumes CVE-2005-4602 and CVE-2005-4603.  However, since the vendor advisory is vague and additional files are mentioned, is is likely that this contains at least one distinct vulnerability from CVE-2005-4602 and CVE-2005-4603.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://community.mybboard.net/showthread.php?tid=5852"></ref></refs><vuln_soft><prod name="MyBulletinBoard" vendor="MyBulletinBoard"><vers num="1.0 Preview Release 2"/><vers num="1.0 &quot;Final&quot;"/><vers num="1.01"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-17" name="CVE-2006-0219" published="2006-01-16" seq="2006-0219" severity="High" type="CVE"><desc><descript source="cve">The original distribution of MyBulletinBoard (MyBB) to update from older versions to 1.0.2 omits or includes older versions of certain critical files, which allows attackers to conduct (1) SQL injection attacks via an attachment name that is not properly handled by inc/functions_upload.php (CVE-2005-4602), and possibly (2) other attacks related to threadmode in usercp.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://community.mybboard.net/showthread.php?tid=5853&amp;pid=35088#pid35088"></ref><ref source="" url="http://community.mybboard.net/showthread.php?tid=5853&amp;pid=35151#pid35151"></ref><ref patch="1" source="" url="http://community.mybboard.net/showthread.php?tid=5960"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16230">16230</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24115">
mybb-usercp-script-sql-injection(24115)</ref></refs><vuln_soft><prod name="MyBulletinBoard" vendor="MyBulletinBoard"><vers num="1.0 Preview Release 2"/><vers num="1.0 &quot;Final&quot;"/><vers num="1.01"/><vers num="1.0.2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-28" name="CVE-2006-0220" published="2006-01-16" seq="2006-0220" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in DCP-Portal 5.3 through 6.1.1 allow remote attackers to inject arbitrary web script or HTML via (1) the day parameter in calendar.php and (2) the input form in search.php.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.  It is possible that this issue is resultant from an SQL injection problem in CVE-2005-4227.3 and CVE-2005-4227.13.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/16232">16232</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421914/100/0/threaded">20060113 DCP Portal Cross-Site Scripting Vulnerability</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24153">
dcpportal-calendar-search-xss(24153)</ref></refs><vuln_soft><prod name="DCP-Portal" vendor="Codeworx Technologies"><vers num="6.1.1"/><vers num="6.1"/><vers num="6.0"/><vers num="5.3.2"/><vers num="5.3.1"/><vers num="5.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-02" name="CVE-2006-0221" published="2006-01-16" seq="2006-0221" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in index.asp in the Admin Panel in Dragon Design Services Network (DDSN) cm3 content manager (CM3CMS) allows remote attackers to execute arbitrary SQL commands via the (1) username or (2) password.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/16231">16231</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421941/100/0/threaded">20060113 DDSN CMS Admin Panel SQL Injection Vulnerability</ref><ref source="OSVDB" url="http://www.osvdb.org/22696">22696</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24266">cm3-login-sql-injection(24266)</ref></refs><vuln_soft><prod name="CM3CMS" vendor="DDSN"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-02" name="CVE-2006-0222" published="2006-01-16" seq="2006-0222" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in fullview.php in AlstraSoft Template Seller Pro allows remote attackers to inject arbitrary web script or HTML via the tempid parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/16233">16233</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421916/100/0/threaded">20060113 AlstraSoft Template Seller Pro Cross-Site Scripting Vulnerability</ref><ref source="OSVDB" url="http://www.osvdb.org/22746">22746</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24235">template-seller-fullview-xss(24235)</ref></refs><vuln_soft><prod name="Template Seller" vendor="AlstraSoft"><vers edition="Pro" num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-27" name="CVE-2006-0223" published="2006-01-16" seq="2006-0223" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in Shanghai TopCMM 123 Flash Chat Server Software 5.1 allows attackers to create or overwrite arbitrary files on the server via &quot;..&quot; (dot dot) sequences in the username field.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://www.123flashchat.com/flash-chat-server-v512.html"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16235">16235</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0198">ADV-2006-0198</ref><ref source="OSVDB" url="http://www.osvdb.org/22440">22440</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18455">18455</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24137">
123flashchat-user-directory-traversal(24137)</ref></refs><vuln_soft><prod name="123 Flash Chat Server" vendor="TopCMM Computing"><vers num="5.1"/><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-31" name="CVE-2006-0224" published="2006-01-24" seq="2006-0224" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in Library of Assorted Spiffy Things (LibAST) 0.6.1 and earlier, as used in Eterm and possibly other software, allows local users to execute arbitrary code as the utmp user via a long -X command line argument (alternative configuration file name).</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref source="" url="http://freshmeat.net/projects/libast/?branch_id=17907&amp;release_id=217840"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16350">16350</ref><ref source="" url="http://freshmeat.net/projects/libast/?branch_id=17907&amp;release_id=217840"></ref><ref adv="1" patch="1" source="" url="http://www.rosiello.org/en/read_bugs.php?id=25"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0314">ADV-2006-0314</ref><ref adv="1" patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/423207/100/0/threaded">20060123 [ Rosiello Security ] Eterm-LibAST Advisory</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/423366/100/0/threaded">20060123 LibAST 0.7 Release Fixes Security Vulnerability</ref><ref adv="1" patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/423088/100/0/threaded">20060125 Rosiello Security - Eterm-LibAST Advisory</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200601-14.xml">GLSA-200601-14</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18586">18586</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18632">18632</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:029">MDKSA-2006:029</ref><ref source="DEBIAN" url="http://www.debian.org/security/2006/dsa-976">DSA-976</ref><ref source="OSVDB" url="http://www.osvdb.org/22735">22735</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18916">18916</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24303">eterm-libast-filename-bo(24303)</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:029">MDKSA-2006:029</ref><ref source="SREASON" url="http://securityreason.com/securityalert/373">373</ref></refs><vuln_soft><prod name="LibAST" vendor="LibAST"><vers num="0.6.1"/><vers num="0.6"/><vers num="0.5"/><vers num="0.4"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-03-28" name="CVE-2006-0225" published="2006-01-25" seq="2006-0225" severity="Medium" type="CVE"><desc><descript source="cve">scp in OpenSSH 4.2p1 allows attackers to execute arbitrary commands via filenames that contain shell metacharacters or spaces, which are expanded twice.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref source="" url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=174026"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16369">16369</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0306">ADV-2006-0306</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18579">18579</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18595">18595</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2006/0004">2006-0004</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015540">1015540</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24305">openssh-scp-command-execution(24305)</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:034">MDKSA-2006:034</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18650">18650</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18736">18736</ref><ref source="OPENBSD" url="ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.8/common/005_ssh.patch">20060212 [3.8] 005: SECURITY FIX: February 12, 2006</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2006_08_openssh.html">SuSE-SA:2006:008</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18798">18798</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18850">18850</ref><ref source="FEDORA" url="http://www.securityfocus.com/archive/1/archive/1/425397/100/0/threaded">FLSA-2006:168935</ref><ref source="OPENPKG" url="http://www.openpkg.org/security/OpenPKG-SA-2006.003-openssh.html">OpenPKG-SA-2006.003</ref><ref source="SLACKWARE" url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2006&amp;m=slackware-security.425802">SSA:2006-045-06</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18910">18910</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200602-11.xml">GLSA-200602-11</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-255-1">USN-255-1</ref><ref source="OSVDB" url="http://www.osvdb.org/22692">22692</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18964">18964</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18969">18969</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18970">18970</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0044.html">RHSA-2006:0044</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19159">19159</ref><ref source="" url="http://www14.software.ibm.com/webapp/set2/sas/f/hmc/power5/install/v52.Readme.html#MH00688"></ref><ref source="" url="http://www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd?mode=18&amp;ID=2751"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/2490">ADV-2006-2490</ref><ref source="SECUNIA" url="http://secunia.com/advisories/20723">20723</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0298.html">RHSA-2006:0298</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21129">21129</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20060703-01-U.asc">20060703-01-P</ref><ref source="SECUNIA" url="http://secunia.com/advisories/21262">21262</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-158.htm"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/21492">21492</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-174.htm"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/21724">21724</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2006-0698.html">RHSA-2006:0698</ref><ref source="SECUNIA" url="http://secunia.com/advisories/22196">22196</ref><ref source="HP" url="http://itrc.hp.com/service/cki/docDisplay.do?docId=c00815112">HPSBUX02178</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/4869">ADV-2006-4869</ref><ref source="SECUNIA" url="http://secunia.com/advisories/23241">23241</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-262.htm"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/23340">23340</ref><ref source="" url="http://www.vmware.com/support/vi3/doc/esx-3069097-patch.html"></ref><ref source="" url="http://www.vmware.com/support/vi3/doc/esx-9986131-patch.html"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/23680">23680</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=305214"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/0930">
ADV-2007-0930</ref><ref source="SECUNIA" url="http://secunia.com/advisories/24479">
24479</ref><ref source="" url="http://blogs.sun.com/security/entry/sun_alert_102961_security_vulnerability"></ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2007-246.htm"></ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html">APPLE-SA-2007-03-13</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:034">MDKSA-2006:034</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102961-1">102961</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA07-072A.html">TA07-072A</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2007/2120">ADV-2007-2120</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1138">oval:org.mitre.oval:def:1138</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25607">25607</ref><ref source="SECUNIA" url="http://secunia.com/advisories/25936">25936</ref><ref source="SREASON" url="http://securityreason.com/securityalert/462">462</ref></refs><vuln_soft><prod name="OpenSSH" vendor="OpenBSD"><vers num="4.2 p1"/><vers num="4.1 p1"/><vers num="4.0 p1"/><vers num="3.0 p1"/><vers num="3.0"/><vers num="3.0.1 p1"/><vers num="3.0.1"/><vers num="3.0.2 p1"/><vers num="3.0.2"/><vers num="3.1 p1"/><vers num="3.1"/><vers num="3.2"/><vers num="3.2.2 p1"/><vers num="3.2.3 p1"/><vers num="3.3 p1"/><vers num="3.3"/><vers num="3.4 p1"/><vers num="3.4"/><vers num="3.5"/><vers num="3.5 p1"/><vers num="3.6"/><vers num="3.6.1 p1"/><vers num="3.6.1 p2"/><vers num="3.6.1"/><vers num="3.7"/><vers num="3.7.1 p2"/><vers num="3.7.1"/><vers num="3.8"/><vers num="3.8.1 p1"/><vers num="3.8.1"/><vers num="3.9"/><vers num="3.9.1 p1"/><vers num="3.9.1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-30" name="CVE-2006-0226" published="2006-01-18" seq="2006-0226" severity="High" type="CVE"><desc><descript source="cve">Integer overflow in IEEE 802.11 network subsystem (ieee80211_ioctl.c) in FreeBSD before 6.0-STABLE, while scanning for wireless networks, allows remote attackers to execute arbitrary code by broadcasting crafted (1) beacon or (2) probe response frames.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://www.signedness.org/advisories/sps-0x1.txt"></ref><ref source="FREEBSD" url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-06:05.80211.asc">FreeBSD-SA-06:05</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16296">16296</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18353">18353</ref><ref source="OSVDB" url="http://www.osvdb.org/22537">22537</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015518">1015518</ref><ref source="" url="http://kernelwars.blogspot.com/2007/01/alive.html"></ref><ref source="" url="http://www.blackhat.com/html/bh-europe-07/bh-eu-07-speakers.html#Eriksson"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24192">
bsd-ieee80211-bo(24192)</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="6.0 Stable"/><vers num="6.0 Release"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="4.9" CVSS_score="2.6" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-17" name="CVE-2006-0227" published="2006-01-17" seq="2006-0227" severity="Low" type="CVE"><desc><descript source="cve">Multiple unspecified vulnerabilities in lpsched in Sun Solaris 8, 9, and 10 allow local users to delete arbitrary files or disable the LP print service via unknown attack vectors.</descript></desc><loss_types><avail/><int/></loss_types><vuln_types><race/></vuln_types><range><local/></range><refs><ref patch="1" source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102033-1">102033</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0200">ADV-2006-0200</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015492">1015492</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18498">18498</ref><ref source="OSVDB" url="http://www.osvdb.org/22441">22441</ref><ref source="OSVDB" url="http://www.osvdb.org/22442">22442</ref><ref source="BID" url="http://www.securityfocus.com/bid/16245">16245</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2006-056.htm"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/19087">19087</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:662">oval:org.mitre.oval:def:662</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24127">
solaris-lpsched-dos(24127)</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers num="9.1"/><vers edition="SPARC" num="9.0"/><vers num="8.2"/><vers num="8.1"/><vers edition="x86" num="10.0"/><vers edition="SPARC" num="10.0"/><vers edition="SPARC" num="10.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-18" name="CVE-2006-0228" published="2006-01-17" seq="2006-0228" severity="High" type="CVE"><desc><descript source="cve">The RBAC functionality in grsecurity before 2.1.8 does not properly handle when the admin role creates a service and then exits the shell without unauthenticating, which causes the service to be restarted with the admin role still active.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="" url="http://www.grsecurity.org/news.php#grsec218"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16261">16261</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0199">ADV-2006-0199</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18458">18458</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24156">
grsecurity-rbac-admin-privileges(24156)</ref></refs><vuln_soft><prod name="grsecurity Kernel Patch" vendor="grsecurity"><vers num="2.1.7"/><vers num="2.1.6"/><vers num="2.1.5"/><vers num="2.1.4"/><vers num="2.1.3"/><vers num="2.1.2"/><vers num="2.1.1"/><vers num="2.1.0"/><vers num="2.0.2"/><vers num="2.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-18" name="CVE-2006-0229" published="2006-01-17" seq="2006-0229" severity="Low" type="CVE"><desc><descript source="cve">Unquoted Windows search path vulnerability in Wehntrust might allow local users to gain privileges via a malicious &quot;program.exe&quot; file in the C: folder, which is run when Wehntrust creates the autostart key.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/422020/100/0/threaded">20060116 WehnTrust - When you have to trust Wehntrust</ref><ref patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/422046/100/0/threaded">20060116 Re: [Full-disclosure] WehnTrust - When you have to trust Wehntrust</ref><ref source="BID" url="http://www.securityfocus.com/bid/16268">16268</ref><ref source="" url="http://www.wehnus.com/downloads.pl"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24315">
wehntrust-service-start-file-execution(24315)</ref></refs><vuln_soft><prod name="WehnTrust" vendor="Wehnus"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-25" name="CVE-2006-0230" published="2006-04-24" seq="2006-0230" severity="High" type="CVE"><desc><descript source="cve">Symantec Scan Engine 5.0.0.24, and possibly other versions before 5.1.0.7, uses a client-side check to verify a password, which allows remote attackers to gain administrator privileges via a modified client that sends certain XML requests.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2006-q2/0010.html">20060421 Rapid7 Advisory R7-0021: Symantec Scan Engine Authentication Fundamental Design Error</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431734/100/0/threaded">20060421 [Symantec Security Advisor] Symantec Scan Engine Multiple Vulnerabilities</ref><ref source="" url="http://www.symantec.com/avcenter/security/Content/2006.04.21.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17637">17637</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1464">ADV-2006-1464</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19734">19734</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/118388">VU#118388</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431724/100/0/threaded">20060421 Rapid7 Advisory R7-0021: Symantec Scan Engine Authentication Fundamental Design Error</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25972">
sse-unauth-admin-access(25972)</ref></refs><vuln_soft><prod name="Scan Engine" vendor="Symantec"><vers num="5.0.0.24"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-25" name="CVE-2006-0231" published="2006-04-24" seq="2006-0231" severity="Medium" type="CVE"><desc><descript source="cve">Symantec Scan Engine 5.0.0.24, and possibly other versions before 5.1.0.7, uses the same private DSA key for each installation, which allows remote attackers to conduct man-in-the-middle attacks and decrypt communications.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2006-q2/0011.html">20060421 Rapid7 Advisory R7-0022: Symantec Scan Engine Known Immutable DSA Private Key</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431725/100/0/threaded">20060421 Rapid7 Advisory R7-0022: Symantec Scan Engine Known Immutable DSA Private Key</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431734/100/0/threaded">20060421 [Symantec Security Advisor] Symantec Scan Engine Multiple Vulnerabilities</ref><ref source="" url="http://www.symantec.com/avcenter/security/Content/2006.04.21.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17637">17637</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1464">ADV-2006-1464</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015974">1015974</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19734">19734</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25973">
sse-insecure-private-key(25973)</ref></refs><vuln_soft><prod name="Scan Engine" vendor="Symantec"><vers num="5.0.0.24"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-04-26" name="CVE-2006-0232" published="2006-04-24" seq="2006-0232" severity="Medium" type="CVE"><desc><descript source="cve">Symantec Scan Engine 5.0.0.24, and possibly other versions before 5.1.0.7, stores sensitive log and virus definition files under the web root with insufficient access control, which allows remote attackers to obtain the information via direct requests.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2006-q2/0012.html">20060421 Rapid7 Advisory R7-0023: Symantec Scan Engine File Disclosure Vulnerability</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431728/100/0/threaded">20060421 Rapid7 Advisory R7-0023: Symantec Scan Engine File Disclosure Vulnerability</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/431734/100/0/threaded">20060421 [Symantec Security Advisor] Symantec Scan Engine Multiple Vulnerabilities</ref><ref source="" url="http://www.symantec.com/avcenter/security/Content/2006.04.21.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/17637">17637</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1464">ADV-2006-1464</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015974">1015974</ref><ref source="SECUNIA" url="http://secunia.com/advisories/19734">19734</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/25974">
sse-unauth-file-access(25974)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/758">758</ref><ref source="SREASON" url="http://securityreason.com/securityalert/759">759</ref></refs><vuln_soft><prod name="Scan Engine" vendor="Symantec"><vers num="5.0.0.24"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2008-01-03" name="CVE-2006-0233" published="2006-01-17" seq="2006-0233" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in functions.php in microBlog 2.0 RC-10 allows remote attackers to inject arbitrary web script and HTML via a javascript: URI in a [url] BBcode tag.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/422145/100/0/threaded">20060117 [eVuln] microBlog BBCode XSS Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/16272">16272</ref><ref source="" url="http://evuln.com/vulns/36/summary.html"></ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015496">1015496</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24140">microblog-functions-xss(24140)</ref></refs><vuln_soft><prod name="microBlog" vendor="microBlog"><vers num="2.0 rc10"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-18" name="CVE-2006-0234" published="2006-01-17" seq="2006-0234" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in index.php in microBlog 2.0 RC-10 allows remote attackers to execute arbitrary SQL commands via the (1) month and (2) year parameters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/422141/100/0/threaded">20060117 [eVuln] microBlog SQL Injection Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/16270">16270</ref><ref source="" url="http://evuln.com/vulns/35/summary.html"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0239">ADV-2006-0239</ref><ref source="OSVDB" url="http://www.osvdb.org/22512">22512</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015496">1015496</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18442">18442</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24132">
microblog-index-sql-injection(24132)</ref></refs><vuln_soft><prod name="microBlog" vendor="microBlog"><vers num="2.0 rc10"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-18" name="CVE-2006-0235" published="2006-01-17" seq="2006-0235" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in WhiteAlbum 2.5 allows remote attackers to execute arbitrary SQL commands via the dir parameter to pictures.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/422105/100/0/threaded">20060116 White Album Sql &amp;#304;njection biyosecurity.be</ref><ref source="BID" url="http://www.securityfocus.com/bid/16247">16247</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18460">18460</ref><ref source="" url="http://www.biyosecurity.be/bugs/whitealbum.txt"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0241">ADV-2006-0241</ref><ref source="OSVDB" url="http://www.osvdb.org/22520">22520</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24271">
whitealbum-pictures-sql-injection(24271)</ref></refs><vuln_soft><prod name="White Album" vendor="White Angle"><vers num="2.5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-08-28" name="CVE-2006-0236" published="2006-01-17" seq="2006-0236" severity="Medium" type="CVE"><desc><descript source="cve">GUI display truncation vulnerability in Mozilla Thunderbird 1.0.2, 1.0.6, and 1.0.7 allows user-assisted attackers to execute arbitrary code via an attachment with a filename containing a large number of spaces ending with a dangerous extension that is not displayed by Thunderbird, along with an inconsistent Content-Type header, which could be used to trick a user into downloading dangerous content by dragging or saving the attachment.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><design/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/422148/100/0/threaded">20060117 Secunia Research: Mozilla Thunderbird Attachment SpoofingVulnerability</ref><ref adv="1" patch="1" source="" url="http://secunia.com/secunia_research/2005-22/advisory"></ref><ref source="" url="https://bugzilla.mozilla.org/show_bug.cgi?id=300246"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16271">16271</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0230">ADV-2006-0230</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/15907">15907</ref><ref source="MANDRIVA" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:021">MDKSA-2006:021</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24164">
thunderbird-attachment-ext-spoofing(24164)</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:021">MDKSA-2006:021</ref></refs><vuln_soft><prod name="Thunderbird" vendor="Mozilla"><vers edition="Beta 2" num="1.5"/><vers num="1.0.7"/><vers num="1.0.6"/><vers num="1.0.5"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-18" name="CVE-2006-0237" published="2006-01-17" seq="2006-0237" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in GTP iCommerce allows remote attackers to inject arbitrary web script or HTML via the (1) cat and (2) subcat parameters.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/16255">16255</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0214">ADV-2006-0214</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18470">18470</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24150">
gtpicommerce-index-xss(24150)</ref></refs><vuln_soft><prod name="iCommerce" vendor="GTP"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-18" name="CVE-2006-0238" published="2006-01-17" seq="2006-0238" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in wp-stats.php in GaMerZ WP-Stats 2.0 allows remote attackers to execute arbitrary SQL commands via the author parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="http://www.lesterchan.net/blogs/"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16241">16241</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0192">ADV-2006-0192</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18471">18471</ref><ref source="" url="http://osvdb.org/ref/22/22450-wpstats.txt"></ref><ref source="" url="http://www.lesterchan.net/blogs/archives/2006/01/18/wp-stats-sql-injection-vulnerability"></ref><ref source="OSVDB" url="http://www.osvdb.org/22450">22450</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24163">
wpstats-script-sql-injection(24163)</ref></refs><vuln_soft><prod name="WP-Stats" vendor="GaMerZ"><vers num="2.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="4.9" CVSS_score="5.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-18" name="CVE-2006-0239" published="2006-01-17" seq="2006-0239" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Simple Blog 2.1 allow remote attackers to inject arbitrary web script or HTML via (1) a comment to comments.asp and (2) possibly certain other fields in unspecified scripts.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/422102/100/0/threaded">20060114 [HSC Security Group] Multiple SQL injection/XSS in SimpleBlog 2.1</ref><ref source="BID" url="http://www.securityfocus.com/bid/16243">16243</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0194">ADV-2006-0194</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18488">18488</ref><ref source="" url="http://www.hackerscenter.com/archive/view.asp?id=21926"></ref><ref source="OSVDB" url="http://www.osvdb.org/22448">22448</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24154">
simpleblog-comment-xss(24154)</ref></refs><vuln_soft><prod name="Simple Blog" vendor="8pixel.net"><vers num="2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-01-03" name="CVE-2006-0240" published="2006-01-17" seq="2006-0240" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in Simple Blog 2.1 allow remote attackers to execute arbitrary SQL commands via the month parameter in an archives view operation and possibly certain other parameters in unspecified scripts.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/422102/100/0/threaded">20060114 [HSC Security Group] Multiple SQL injection/XSS in SimpleBlog 2.1</ref><ref source="BID" url="http://www.securityfocus.com/bid/16243">16243</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0194">ADV-2006-0194</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18488">18488</ref><ref source="" url="http://www.hackerscenter.com/archive/view.asp?id=21926"></ref><ref source="OSVDB" url="http://www.osvdb.org/22447">22447</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24155">simpleblog-month-sql-injection(24155)</ref></refs><vuln_soft><prod name="Simple Blog" vendor="8pixel.net"><vers num="2.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-18" name="CVE-2006-0241" published="2006-01-17" seq="2006-0241" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting vulnerability in WBNews 1.1.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the Name field.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/422133/100/0/threaded">20060117 XSS in WBNews &lt; = v1.1.0</ref><ref source="BID" url="http://www.securityfocus.com/bid/16277">16277</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0237">ADV-2006-0237</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18499">18499</ref></refs><vuln_soft><prod name="WBNews" vendor="WebMobo"><vers num="1.1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-18" name="CVE-2006-0242" published="2006-01-17" seq="2006-0242" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting vulnerability in index.php in PHP Fusebox 4.0.6 allows remote attackers to inject arbitrary web script or HTML via the fuseaction parameter.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/422124/100/0/threaded">20060117 IndonesiaHack Advisory HTML injection in PHP Fusebox</ref><ref source="BID" url="http://www.securityfocus.com/bid/16274">16274</ref><ref source="SREASON" url="http://securityreason.com/securityalert/355">355</ref></refs><vuln_soft><prod name="PHP Fusebox" vendor="PHP Fusebox"><vers num="4.0.6"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-18" name="CVE-2006-0243" published="2006-01-17" seq="2006-0243" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in SMBCMS 2.1 allows remote attackers to inject arbitrary web script or HTML via the text parameter, which is used by the &quot;Search Site&quot; field.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/16281">16281</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0229">ADV-2006-0229</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18454">18454</ref><ref source="OSVDB" url="http://www.osvdb.org/22494">22494</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24187">
smbcms-sitesearch-xss(24187)</ref></refs><vuln_soft><prod name="SMBCMS" vendor="SMBCMS"><vers num="2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-18" name="CVE-2006-0244" published="2006-01-17" seq="2006-0244" severity="Medium" type="CVE"><desc><descript source="cve">** DISPUTED ** Directory traversal vulnerability in workspaces.php in phpXplorer 0.9.33 allows remote attackers to include arbitrary files via a .. (dot dot) and trailing null byte (%00) in the sShare parameter.  NOTE: a followup post claims that this is not a vulnerability since the functionality of phpXplorer supports the upload of PHP files, which would not cross privilege boundaries since the PHP functionality would support read access outside the web root.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421997/100/0/threaded">20060116 Directory traversal in phpXplorer</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/422158/100/0/threaded">20060116 Re: Directory traversal in phpXplorer</ref><ref adv="1" source="" url="http://www.arrelnet.com/advisories/adv20060116.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16263">16263</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0232">ADV-2006-0232</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18518">18518</ref><ref source="SREASON" url="http://securityreason.com/securityalert/353">353</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39982">phpxplorer-sshare-directory-traversal(39982)</ref></refs><vuln_soft><prod name="phpXplorer" vendor="phpXplorer"><vers num="0.9.33"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-08-30" name="CVE-2006-0245" published="2006-01-17" seq="2006-0245" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in CubeCart 3.0.7-pl1 allow remote attackers to inject arbitrary web script or HTML via the (3) redir, (4) productId, (5) docId, (6) act, and (7) catId parameters in index.php; and the (8) username field in a login action in index.php.  NOTE: the cart.php/redir and index.php/searchStr vectors are already covered by CVE-2005-3152.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="" url="http://bugs.cubecart.com/?do=details&amp;id=459"></ref><ref adv="1" source="" url="http://lostmon.blogspot.com/2006/01/cubecart-307-pl1-indexphp-multiple.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16259">16259</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0227">ADV-2006-0227</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18519">18519</ref><ref source="OSVDB" url="http://www.osvdb.org/22471">22471</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24177">
cubecart-index-script-xss(24177)</ref></refs><vuln_soft><prod name="CubeCart" vendor="Devellion"><vers num="3.0.7-pl1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-02" name="CVE-2006-0246" published="2006-01-17" seq="2006-0246" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in down.pl in Widexl Download Tracker 1.06 allows remote attackers to inject arbitrary web script or HTML via the ID parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/16265">16265</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0213">ADV-2006-0213</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18472">18472</ref><ref source="" url="http://osvdb.org/ref/22/22462-widexl.txt"></ref><ref source="OSVDB" url="http://www.osvdb.org/22462">22462</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24161">
downloadtracker-down-xss(24161)</ref></refs><vuln_soft><prod name="Download Tracker" vendor="Widexl"><vers num="1.0.6"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-02" name="CVE-2006-0247" published="2006-01-17" seq="2006-0247" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in anyboard.cgi in Netbula Anyboard 9.9 and earlier allows remote attackers to inject arbitrary web script or HTML via the tK parameter in a find command.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/16264">16264</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0188">ADV-2006-0188</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18469">18469</ref><ref source="" url="http://osvdb.org/ref/22/22461-anyboard.txt"></ref><ref source="OSVDB" url="http://www.osvdb.org/22461">22461</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24167">
netbula-anyboard-script-xss(24167)</ref></refs><vuln_soft><prod name="Anyboard" vendor="Netbula"><vers num="9.9.5.6" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-18" name="CVE-2006-0248" published="2006-01-17" seq="2006-0248" severity="Medium" type="CVE"><desc><descript source="cve">Virata-EmWeb web server 6_1_0, as used in (1) Intracom JetSpeed 500 and 520 and (2) Allied Data Technologies CopperJet 811 RouterPlus, allows remote attackers to access privileged information, such as user lists and configuration settings, via direct HTTP requests.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://blog.globalnetworks.gr/?p=4"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0218">ADV-2006-0218</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18483">18483</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24304">
virata-emweb-unauth-access(24304)</ref></refs><vuln_soft><prod name="JetSpeed" vendor="Intracom"><vers num="500"/><vers num="520"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-02" name="CVE-2006-0249" published="2006-01-17" seq="2006-0249" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in viewcat.php in BitDamaged geoBlog MOD_1.0 allows remote attackers to execute arbitrary SQL commands, then steal credentials and upload files, via the cat parameter ($tmpCategory variable).</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://evuln.com/vulns/33/summary.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16249">16249</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0191">ADV-2006-0191</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18504">18504</ref><ref source="OSVDB" url="http://www.osvdb.org/22463">22463</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015493">1015493</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24146">
geoBlog-viewcat-sql-injection(24146)</ref></refs><vuln_soft><prod name="geoBlog" vendor="BitDamaged"><vers num="MOD_1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-01-18" name="CVE-2006-0250" published="2006-01-17" seq="2006-0250" severity="Medium" type="CVE"><desc><descript source="cve">Format string vulnerability in the snmp_input function in snmptrapd in CMU SNMP utilities (cmu-snmp) allows remote attackers to execute arbitrary code by sending crafted SNMP messages to UDP port 162.</descript></desc><loss_types><avail/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/422086/100/0/threaded">20060116 Digital Armaments Security Advisory 01.16.2006: CMU SNMP utilities snmptrad Format String Vulnerability</ref><ref source="" url="http://www.digitalarmaments.com/2006040164883273.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16267">16267</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0234">ADV-2006-0234</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18525">18525</ref><ref source="OSVDB" url="http://www.osvdb.org/22493">22493</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24178">
cmusnmp-snmpinput-format-string(24178)</ref></refs><vuln_soft><prod name="snmptrapd" vendor="Carnegie Mellon University"><vers num="3.7"/><vers num="3.6"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-02" name="CVE-2006-0251" published="2006-01-17" seq="2006-0251" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in fom.cgi in Faq-O-Matic 2.711 allows remote attackers to inject arbitrary web script or HTML via the (1) _duration, (2) file, and (3) cmd parameters.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/16251">16251</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0189">ADV-2006-0189</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18468">18468</ref><ref source="" url="http://osvdb.org/ref/22/22439-faqomatic.txt"></ref><ref source="OSVDB" url="http://www.osvdb.org/22439">22439</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24165">
faqomatic-fom-xss(24165)</ref></refs><vuln_soft><prod name="FAQ-O-Matic" vendor="FAQ-O-Matic"><vers num="2.711" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-03" name="CVE-2006-0252" published="2006-01-17" seq="2006-0252" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in Benders Calendar 1.0 allows remote attackers to execute arbitrary SQL commands via multiple parameters, as demonstrated by the (1) year, (2) month, and (3) day parameters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/422052/100/0/threaded">20060115 [eVuln] Benders Calendar SQL Injection</ref><ref adv="1" source="" url="http://evuln.com/vulns/30/summary.html"></ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/16242">16242</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0190">ADV-2006-0190</ref><ref adv="1" source="SECTRACK" url="http://securitytracker.com/id?1015491">1015491</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18462">18462</ref><ref source="OSVDB" url="http://www.osvdb.org/22449">22449</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24120">
benderscalendar-sql-injection(24120)</ref></refs><vuln_soft><prod name="Benders Calendar" vendor="Benders Calendar"><vers num="1.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-03" name="CVE-2006-0253" published="2006-01-17" seq="2006-0253" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in the Bluetooth OBEX Object Push service in &quot;Blue Neighbors.EXE&quot; in AmbiCom Blue Neighbors 2.50 Build 2500 and earlier allows remote attackers to execute arbitrary code via a long file name, as demonstrated via a long RFILE argument to ussp-push.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref source="" url="http://www.digitalmunition.com/DMA%5B2006-0115a%5D.txt"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0219">ADV-2006-0219</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18466">18466</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/422481/100/0/threaded">20060120 DMA[2006-0115a] - %27AmbiCom Bluetooth Object Push Overflow%27</ref><ref source="BID" url="http://www.securityfocus.com/bid/16258">
16258</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24179">
ambicom-bluetooth-objectpush-bo(24179)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/366">366</ref></refs><vuln_soft><prod name="Blue Neighbors" vendor="AmbiCom"><vers num="2.50 Build 2500"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-03" name="CVE-2006-0254" published="2006-01-17" seq="2006-0254" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Apache Geronimo 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) time parameter to cal2.jsp and (2) any invalid parameter, which causes an XSS when the log file is viewed by the Web-Access-Log viewer.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/421996/100/0/threaded">20060115 Apache Geronimo 1.0 - CSS and persistent HTML-Injectionvulnerabilities</ref><ref adv="1" source="" url="http://issues.apache.org/jira/browse/GERONIMO-1474"></ref><ref adv="1" source="" url="http://www.oliverkarow.de/research/geronimo_css.txt"></ref><ref source="" url="https://issues.apache.org/jira/secure/ReleaseNote.jspa?version=12310181&amp;styleName=Html&amp;projectId=10220&amp;Create=Create"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16260">16260</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0217">ADV-2006-0217</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18485">18485</ref><ref source="" url="https://issues.apache.org/jira/secure/ReleaseNote.jspa?version=12310181&amp;styleName=Html&amp;projectId=10220&amp;Create=Create"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24159">
geronimo-webaccesslog-viewer-xss(24159)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24158">geronimo-jspexamples-xss(24158)</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2008-0261.html">RHSA-2008:0261</ref><ref source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2008-0630.html">RHSA-2008:0630</ref><ref source="SECUNIA" url="http://secunia.com/advisories/31493">31493</ref></refs><vuln_soft><prod name="Geronimo" vendor="Apache Software Foundation"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-02-03" name="CVE-2006-0255" published="2006-01-17" seq="2006-0255" severity="High" type="CVE"><desc><descript source="cve">Unquoted Windows search path vulnerability in Check Point VPN-1 SecureClient might allow local users to gain privileges via a malicious &quot;program.exe&quot; file in the C: folder, which is run when SecureClient attempts to launch the Sr_GUI.exe program.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="" url="http://secdev.zoller.lu/research/checkpoint.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16290">16290</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0258">ADV-2006-0258</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/422263/100/0/threaded">20060117 [ TZO-012006 ] Checkpoint VPN-1 SecureClient insecure usage of CreateProcess()</ref></refs><vuln_soft><prod name="VPN-1" vendor="Checkpoint"><vers num="4.1 SP6"/><vers num="4.1 SP5a"/><vers num="4.1 SP5"/><vers num="4.1 SP4"/><vers num="4.1 SP3"/><vers num="4.1 SP2"/><vers num="4.1 SP1"/><vers num="4.1"/><vers num="FP1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-03-03" name="CVE-2006-0256" published="2006-01-18" seq="2006-0256" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the Advanced Queuing component of Oracle Database server 8.1.7.4, 9.0.1.5, 9.2.0.6, 10.1.0.3 has unspecified impact and attack vectors, as identified by Oracle Vuln# DB01.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16287">16287</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/545804">VU#545804</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0243">ADV-2006-0243</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18493">18493</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0323">ADV-2006-0323</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18608">18608</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015499">1015499</ref></refs><vuln_soft><prod name="Oracle9i Database Server" vendor="Oracle"><vers num="9.2.0.6"/><vers num="9.0.1.5"/></prod><prod name="Oracle10g Database Server" vendor="Oracle"><vers num="10.1.0.3"/></prod><prod name="Oracle8i Database Server" vendor="Oracle"><vers num="8.1.7.4"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-03-03" name="CVE-2006-0257" published="2006-01-18" seq="2006-0257" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the Change Data Capture component of Oracle Database server 9.2.0.7, 10.1.0.5, and 10.2.0.1 has unspecified impact and attack vectors, as identified by Oracle Vuln# DB02.  NOTE: details are unavailable from Oracle, but they have not publicly disputed a claim by a reliable independent researcher that states that the problem is SQL injection in the CDC_ALLOCATE_LOCK function of the DBMS_CDC_UTILITY package.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16287">16287</ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/545804">VU#545804</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0243">ADV-2006-0243</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18493">18493</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0323">ADV-2006-0323</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18608">18608</ref><ref adv="1" patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015499">1015499</ref><ref source="OSVDB" url="http://www.osvdb.org/22540">22540</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24321">oracle-january2006-update(24321)</ref></refs><vuln_soft><prod name="Oracle9i Database Server" vendor="Oracle"><vers num="9.2.0.7"/></prod><prod name="Oracle10g Database Server" vendor="Oracle"><vers num="10.1.0.5"/><vers num="10.2.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-03-03" name="CVE-2006-0258" published="2006-01-18" seq="2006-0258" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the Connection Manager component of Oracle Database server 8.1.7.4 and 9.0.1.5 has unspecified impact and attack vectors, as identified by Oracle Vuln# DB03.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16287">16287</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/545804">VU#545804</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0243">ADV-2006-0243</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18493">18493</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0323">ADV-2006-0323</ref><ref source="SECUNIA" url="http://secunia.com/advisories/18608">18608</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015499">1015499</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24321">oracle-january2006-update(24321)</ref></refs><vuln_soft><prod name="Oracle9i Database Server" vendor="Oracle"><vers edition="FIPS" num="9.0.1.5"/></prod><prod name="Oracle8i Database Server" vendor="Oracle"><vers num="8.1.7.4"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" discovered="2006-01-17" modified="2008-03-03" name="CVE-2006-0259" published="2006-01-18" seq="2006-0259" severity="High" type="CVE"><desc><descript source="cve">Multiple unspecified vulnerabilities in Oracle Database server 10.1.0.5 have unspecified impact and attack vectors, as identified by Oracle Vuln# (1) DB04 and (2) DB06 in the (a) Data Pump component; (3) DB10 in the (b) Net Listener component; and (4) DB16 in the (c) Oracle Text component.  NOTE: details are unavailable from Oracle, but they have not publicly disputed a claim by a reliable independent researcher that states that DB06 is SQL injection in the GENERATE_JOB_NAME, GET_WORKERSTATUSLIST1010, GET_PARAMVALUES1010, GET_DUMPFILESET1010, GET_JOBSTATUS1010, ATTACH, and ESTABLISH_REMOTE_CONTEXT functions in DBMS_DATAPUMP.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/16287">16287</ref><ref patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/545804">VU#545804</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0243">ADV-2006-0243</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18493">18493</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0323">ADV-2006-0323</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18608">18608</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015499">1015499</ref><ref source="OSVDB" url="http://www.osvdb.org/22544">22544</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24321">oracle-january2006-update(24321)</ref></refs><vuln_soft><prod name="Oracle10g Database Server" vendor="Oracle"><vers num="10.1.0.5"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-03-03" name="CVE-2006-0260" published="2006-01-18" seq="2006-0260" severity="High" type="CVE"><desc><descript source="cve">Multiple unspecified vulnerabilities in Oracle Database server 9.2.0.7 and 10.1.0.5 have unspecified impact and attack vectors, as identified by Oracle Vuln# (1) DB05 in the (a) Data Pump component; (2) DB15 in the (b) Oracle Text component; (3) DB22 in the (c) Streams Apply component; (4) DB23 and (5) DB24 in the (d) Streams Capture component; and (6) DB26 in the (e) Streams Subcomponent.  NOTE: details are unavailable from Oracle, but they have not publicly disputed a claim by a reliable independent researcher that states that DB05 involves SQL injection in the (f) LONG2VARCHAR, LONG2VCMAX, LONG2VCNT, and LONG2CLOB functions in the DBMS_METADATA_UTIL package; (g) MAKE_FILTER, FETCH_VIEWS_ERROR, FETCH_FILTERS, FETCH_VIEWS, SET_FILTER_COMMON, DO_FILTER_SCRIPT, SET_TABLE_FILTERS, and MAKE_FILTER_TEXT functions in the DBMS_METADATA_INT package; and (h) GET_PREPOST_TABLE_ACT function in the DBMS_METADATA package.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16287">16287</ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/545804">VU#545804</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0243">ADV-2006-0243</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18493">18493</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0323">ADV-2006-0323</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18608">18608</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015499">1015499</ref><ref source="OSVDB" url="http://www.osvdb.org/22543">22543</ref><ref source="OSVDB" url="http://www.osvdb.org/22643">22643</ref><ref source="OSVDB" url="http://www.osvdb.org/22637">22637</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24321">oracle-january2006-update(24321)</ref></refs><vuln_soft><prod name="Oracle9i Database Server" vendor="Oracle"><vers num="9.2.0.7"/></prod><prod name="Oracle10g Database Server" vendor="Oracle"><vers num="10.1.0.5"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-01-03" name="CVE-2006-0261" published="2006-01-18" seq="2006-0261" severity="High" type="CVE"><desc><descript source="cve">Multiple unspecified vulnerabilities in Oracle Database server 8.1.7.4, 9.0.1.5, 9.2.0.7, and 10.1.0.5 have unspecified impact and attack vectors, as identified by Oracle Vuln# (1) DB07 in the Dictionary component and (2) DB14 in the Oracle Label Security component.  NOTE: Oracle has not disputed reliable researcher claims that DB07 involves plaintext storage of the TDE wallet password in a trace file by event 10053.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16287">16287</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/545804">VU#545804</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0243">ADV-2006-0243</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18493">18493</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0323">ADV-2006-0323</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18608">18608</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015499">1015499</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24321">oracle-january2006-update(24321)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/422255/30/7430/threaded">20060117 Oracle Database 10g Rel. 2 - Event 10053 logs TDE wallet password in cleartext</ref><ref source="" url="http://www.red-database-security.com/advisory/oracle_tde_wallet_password.html"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24168">oracle-masterkey-plaintext(24168)</ref></refs><vuln_soft><prod name="Oracle9i Database Server" vendor="Oracle"><vers num="9.2.0.7"/><vers edition="FIPS" num="9.0.1.5"/><vers num="9.0.1.5"/></prod><prod name="Oracle10g Database Server" vendor="Oracle"><vers num="10.1.0.5"/></prod><prod name="Oracle8i Database Server" vendor="Oracle"><vers num="8.1.7.4"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-03-03" name="CVE-2006-0262" published="2006-01-18" seq="2006-0262" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the Net Foundation Layer component of Oracle Database server 8.1.7.4, 9.0.1.5, 9.0.1.5 FIPS, 9.2.0.6, and 10.1.0.4 has unspecified impact and attack vectors, as identified by Oracle Vuln# DB08.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16287">16287</ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/545804">VU#545804</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0243">ADV-2006-0243</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18493">18493</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0323">ADV-2006-0323</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18608">18608</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015499">1015499</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24321">oracle-january2006-update(24321)</ref></refs><vuln_soft><prod name="Oracle8i" vendor="Oracle"><vers num="Standard 8.1.7.4"/><vers num="Enterprise 8.1.7.4"/></prod><prod name="Oracle9i" vendor="Oracle"><vers num="Standard 9.2.0.6"/><vers num="Enterprise 9.0.1.5 FIPS"/><vers num="Enterprise 9.0.1.5"/></prod><prod name="Oracle10g" vendor="Oracle"><vers num="Standard 10.1.0.4"/><vers num="Personal 10.1.0.4"/><vers num="Enterprise 10.1.0.4"/></prod><prod name="Oracle8" vendor="Oracle"><vers num="8.1.7.4"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-03-03" name="CVE-2006-0263" published="2006-01-18" seq="2006-0263" severity="High" type="CVE"><desc><descript source="cve">Multiple unspecified vulnerabilities in Oracle Database server 8.1.7.4, 9.0.1.5, 9.0.1.5 FIPS, 9.2.0.7, 10.1.0.5, and 10.2.0.1 have unspecified impact and attack vectors, as identified by Oracle Vuln# (1) DB09 in the (a) Net Listener component; and (2) DB12 and (3) DB13 in the Network Communications (RPC) component.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16287">16287</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/545804">VU#545804</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0243">ADV-2006-0243</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18493">18493</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0323">ADV-2006-0323</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18608">18608</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-018A.html">TA06-018A</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/870172">VU#870172</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015499">1015499</ref><ref source="OSVDB" url="http://www.osvdb.org/22547">22547</ref><ref source="OSVDB" url="http://www.osvdb.org/22550">22550</ref><ref source="OSVDB" url="http://www.osvdb.org/22551">22551</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24321">oracle-january2006-update(24321)</ref></refs><vuln_soft><prod name="Oracle9i Database Server" vendor="Oracle"><vers num="9.2.0.7"/><vers edition="FIPS" num="9.0.1.5"/><vers num="9.0.1.5"/></prod><prod name="Oracle10g Database Server" vendor="Oracle"><vers num="10.2.0.1"/><vers num="10.1.0.5"/></prod><prod name="Oracle8i Database Server" vendor="Oracle"><vers num="8.1.7.4"/></prod></vuln_soft></entry><entry modified="2006-02-08" name="CVE-2006-0264" published="2006-01-18" reject="1" seq="2006-0264" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2006-0259.  Reason: This candidate is subsumed by CVE-2006-0259.  An error during initial CVE analysis used the wrong set of affected versions for &quot;DB10&quot;. Notes: All CVE users should reference CVE-2006-0259 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript></desc><refs><ref source="SECTRACK" url="http://securitytracker.com/id?1015499">1015499</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24321">
oracle-january2006-update(24321)</ref></refs></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-03-03" name="CVE-2006-0265" published="2006-01-18" seq="2006-0265" severity="High" type="CVE"><desc><descript source="cve">Multiple unspecified vulnerabilities in Oracle Database server 8.1.7.4, 9.0.1.5, 9.2.0.7, 10.1.0.5, and 10.2.0.1 have unspecified impact and attack vectors, as identified by Oracle Vuln# (1) DB17 in the Oracle Text component and (2) DB18 in the Program Interface Network component.  NOTE: details are unavailable from Oracle, but they have not publicly disputed a claim by a reliable independent researcher that states that DB17 involves SQL injection in the (a) VALIDATE_STATEMENT and BUILD_DML functions in CTXSYS.DRILOAD; (b) CLEAN_DML function in CTXSYS.DRIDML; (c) GET_ROWID function in CTXSYS.CTX_DOC; (d) BROWSE_WORDS function in CTXSYS.CTX_QUERY; and (e) ODCIINDEXTRUNCATE, ODCIINDEXDROP, and ODCIINDEXDELETE functions in CATINDEXMETHODS.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16287">16287</ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/545804">VU#545804</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0243">ADV-2006-0243</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18493">18493</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0323">ADV-2006-0323</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18608">18608</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015499">1015499</ref><ref adv="1" source="" url="http://www.red-database-security.com/advisory/oracle_cpu_jan_2006.html"></ref><ref source="OSVDB" url="http://www.osvdb.org/22555">22555</ref><ref source="OSVDB" url="http://www.osvdb.org/22639">22639</ref><ref source="OSVDB" url="http://www.osvdb.org/22640">22640</ref><ref source="OSVDB" url="http://www.osvdb.org/22641">22641</ref><ref source="OSVDB" url="http://www.osvdb.org/22642">22642</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24321">oracle-january2006-update(24321)</ref></refs><vuln_soft><prod name="Oracle9i Database Server" vendor="Oracle"><vers num="9.2.0.7"/><vers num="9.0.1.5"/></prod><prod name="Oracle10g Database Server" vendor="Oracle"><vers num="10.2.0.1"/><vers num="10.1.0.5"/></prod><prod name="Oracle8i Database Server" vendor="Oracle"><vers num="8.1.7.4"/></prod></vuln_soft></entry><entry CVSS_base_score="9.0" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="10.0" CVSS_score="9.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-05-15" name="CVE-2006-0266" published="2006-01-18" seq="2006-0266" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the Query Optimizer component of Oracle Database server 9.0.1.5, 9.2.0.7, and 10.1.0.5 has unspecified impact and attack vectors, as identified by Oracle Vuln# DB19.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16287">16287</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/545804">VU#545804</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0243">ADV-2006-0243</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18493">18493</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0323">ADV-2006-0323</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18608">18608</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015499">1015499</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24321">oracle-january2006-update(24321)</ref></refs><vuln_soft><prod name="Oracle9i Database Server" vendor="Oracle"><vers num="9.2.0.7"/><vers num="9.0.1.5"/></prod><prod name="Oracle10g Database Server" vendor="Oracle"><vers num="10.1.0.5"/></prod></vuln_soft></entry><entry CVSS_base_score="9.0" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="10.0" CVSS_score="9.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-05-15" name="CVE-2006-0267" published="2006-01-18" seq="2006-0267" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the Query Optimizer component of Oracle Database server 9.2.0.6 and 10.1.0.4 has unspecified impact and attack vectors, as identified by Oracle Vuln# DB20.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16287">16287</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/545804">VU#545804</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0243">ADV-2006-0243</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18493">18493</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0323">ADV-2006-0323</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18608">18608</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015499">1015499</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24321">oracle-january2006-update(24321)</ref></refs><vuln_soft><prod name="Oracle9i Database Server" vendor="Oracle"><vers num="9.2.0.6"/></prod><prod name="Oracle10g Database Server" vendor="Oracle"><vers num="10.1.0.4"/></prod></vuln_soft></entry><entry CVSS_base_score="9.0" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="10.0" CVSS_score="9.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-05-15" name="CVE-2006-0268" published="2006-01-18" seq="2006-0268" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the Security component of Oracle Database server 9.0.1.5, 9.0.1.5 FIPS, 9.2.0.6, and 10.1.0.4 has unspecified impact and attack vectors, as identified by Oracle Vuln# DB21.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16287">16287</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/545804">VU#545804</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0243">ADV-2006-0243</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18493">18493</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0323">ADV-2006-0323</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18608">18608</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015499">1015499</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24321">oracle-january2006-update(24321)</ref></refs><vuln_soft><prod name="Oracle9i Database Server" vendor="Oracle"><vers num="9.2.0.6"/><vers edition="FIPS" num="9.0.1.5"/><vers num="9.0.1.5"/></prod><prod name="Oracle10g Database Server" vendor="Oracle"><vers num="10.1.0.4"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-04-11" name="CVE-2006-0269" published="2006-01-18" seq="2006-0269" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the Streams Capture component of Oracle Database server 10.1.0.5 and 10.2.0.1 has unspecified impact and attack vectors, as identified by Oracle Vuln# DB25.  NOTE: details are unavailable from Oracle, but they have not publicly disputed a claim by a reliable independent researcher that states that the problem is SQL injection in the SET_DIRECTORY_ROOT function in the DBMS_CDC_PUBLISH package.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16287">16287</ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/545804">VU#545804</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0243">ADV-2006-0243</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18493">18493</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0323">ADV-2006-0323</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18608">18608</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015499">1015499</ref><ref source="" url="http://www.red-database-security.com/advisory/oracle_cpu_jan_2006.html"></ref><ref source="OSVDB" url="http://www.osvdb.org/22563">22563</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24321">oracle-january2006-update(24321)</ref></refs><vuln_soft><prod name="Oracle10g" vendor="Oracle"><vers num="Standard 10.2.0.1"/><vers num="Standard 10.1.0.5"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-01-03" name="CVE-2006-0270" published="2006-01-18" seq="2006-0270" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the Transparent Data Encryption (TDE) Wallet component of Oracle Database server 10.2.0.1 has unspecified impact and attack vectors, as identified by Oracle Vuln# DB27.  NOTE: Oracle has not disputed a reliable researcher report that TDA stores the master key without encryption, which allows local users to obtain the key via the SGA.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16287">16287</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/545804">VU#545804</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0243">ADV-2006-0243</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18493">18493</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0323">ADV-2006-0323</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18608">18608</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015499">1015499</ref><ref source="" url="http://www.red-database-security.com/advisory/oracle_tde_unencrypted_sga.html"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24321">oracle-january2006-update(24321)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/422262/30/7400/threaded">20060117 Oracle Database 10g Rel. 2- Transparent Data Encryption plaintext masterkey in SGA</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24186">oracle-sga-masterkey-plaintext(24186)</ref></refs><vuln_soft><prod name="Oracle10g Database Server" vendor="Oracle"><vers num="10.2.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-03-04" name="CVE-2006-0271" published="2006-01-18" seq="2006-0271" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the Upgrade &amp; Downgrade component of Oracle Database server 8.1.7.4, 9.0.1.5, 9.2.0.7, and 10.1.0.4 has unspecified impact and attack vectors, as identified by Oracle Vuln# DB28.  NOTE: details are unavailable from Oracle, but they have not publicly disputed a claim by a reliable independent researcher that states that the problem is SQL injection in the DBMS_REGISTRY package in certain parameters to the (1) IS_COMPONENT, (2) GET_COMP_OPTION, (3) DISABLE_DDL_TRIGGERS, (4) SCRIPT_EXISTS, (5) COMP_PATH, (6) GATHER_STATS, (7) NOTHING_SCRIPT, and (8) VALIDATE_COMPONENTS functions.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16287">16287</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/545804">VU#545804</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0243">ADV-2006-0243</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18493">18493</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0323">ADV-2006-0323</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18608">18608</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015499">1015499</ref><ref source="" url="http://www.red-database-security.com/advisory/oracle_cpu_jan_2006.html"></ref><ref source="OSVDB" url="http://www.osvdb.org/22566">22566</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24321">oracle-january2006-update(24321)</ref></refs><vuln_soft><prod name="Oracle8i" vendor="Oracle"><vers num="Standard 8.1.7.4"/><vers num="Enterprise 8.1.7.4"/></prod><prod name="Oracle9i" vendor="Oracle"><vers num="Standard 9.2.0.7"/><vers num="Enterprise 9.0.1.5"/></prod><prod name="Oracle10g" vendor="Oracle"><vers num="Standard 10.1.0.4"/><vers num="Personal 10.1.0.4"/><vers num="Enterprise 10.1.0.4"/></prod><prod name="Oracle8" vendor="Oracle"><vers num="8.1.7.4"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-03-04" name="CVE-2006-0272" published="2006-01-18" seq="2006-0272" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the XML Database component of Oracle Database server 9.2.0.7 and 10.1.0.4 has unspecified impact and attack vectors, as identified by Oracle Vuln# DB29.  NOTE: based on mutual credits by the relevant sources, it is highly likely that this issue is a buffer overflow in the (a) DBMS_XMLSCHEMA and (b) DBMS_XMLSCHEMA_INT packages, as exploitable via long arguments to (1) XDB.DBMS_XMLSCHEMA.GENERATESCHEMA or (2) XDB.DBMS_XMLSCHEMA.GENERATESCHEMAS.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16287">16287</ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/545804">VU#545804</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0243">ADV-2006-0243</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18493">18493</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0323">ADV-2006-0323</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18608">18608</ref><ref source="" url="http://www.argeniss.com/research/ARGENISS-ADV-010601.txt"></ref><ref source="" url="http://www.integrigy.com/info/IntegrigySecurityAnalysis-CPU0106.pdf"></ref><ref source="" url="http://www.red-database-security.com/advisory/oracle_cpu_jan_2006.html"></ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA06-018A.html">TA06-018A</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/891644">VU#891644</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015499">1015499</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24321">oracle-january2006-update(24321)</ref><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0893.html">20060126 [Argeniss] Oracle Database Buffer overflows vulnerabilities in public procedures of XDB.DBMS_XMLSCHEMA{_INT}</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24376">oracle-xdbdbmx-xmlschema-bo(24376)</ref></refs><vuln_soft><prod name="Oracle9i" vendor="Oracle"><vers num="Standard 9.2.0.7"/></prod><prod name="Oracle10g" vendor="Oracle"><vers num="Standard 10.1.0.4"/><vers num="Personal 10.1.0.4"/><vers num="Enterprise 10.1.0.4"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-03-04" name="CVE-2006-0273" published="2006-01-18" seq="2006-0273" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the Portal component of Oracle Application Server 9.0.4.2 and 10.1.2.0 has unspecified impact and attack vectors, as identified by Oracle Vuln# AS01.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16287">16287</ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/545804">VU#545804</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0243">ADV-2006-0243</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18493">18493</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0323">ADV-2006-0323</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18608">18608</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015499">1015499</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24321">oracle-january2006-update(24321)</ref></refs><vuln_soft><prod name="Oracle10g Application Server" vendor="Oracle"><vers num="10.1.2.0"/><vers num="9.0.4.2"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-03-04" name="CVE-2006-0274" published="2006-01-18" seq="2006-0274" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the Oracle Reports Developer component of Oracle Application Server 9.0.4.2 and 10.1.2.0.2 has unspecified impact and attack vectors, as identified by Oracle Vuln# REP03.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16287">16287</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/545804">VU#545804</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0243">ADV-2006-0243</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18493">18493</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0323">ADV-2006-0323</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18608">18608</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015499">1015499</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24321">oracle-january2006-update(24321)</ref></refs><vuln_soft><prod name="Oracle10g Application Server" vendor="Oracle"><vers num="10.1.2.0.2"/><vers num="9.0.4.2"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-01-03" name="CVE-2006-0275" published="2006-01-18" seq="2006-0275" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the Oracle Reports Developer component of Oracle Application Server 9.0.4.2 has unspecified impact and attack vectors, as identified by Oracle Vuln# REP04.  NOTE: Oracle has not disputed reliable researcher claims that this issue is related to directory traversal that allows reading of portions of arbitrary XML files via the customize parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16287">16287</ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/545804">VU#545804</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0243">ADV-2006-0243</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18493">18493</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0323">ADV-2006-0323</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18608">18608</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015499">1015499</ref><ref source="" url="http://www.red-database-security.com/advisory/oracle_reports_read_any_xml_file.html"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24321">oracle-january2006-update(24321)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/422261/30/7430/threaded">20060117 Oracle Reports - Read parts of files via customize(fixed after 875 days)</ref></refs><vuln_soft><prod name="Oracle10g Application Server" vendor="Oracle"><vers num="9.0.4.2"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-03-04" name="CVE-2006-0276" published="2006-01-18" seq="2006-0276" severity="High" type="CVE"><desc><descript source="cve">Multiple unspecified vulnerabilities in Oracle Collaboration Suite Release 2, version 9.0.4.2 (Oracle9i) have unspecified impact and attack vectors, as identified by Oracle Vuln# (1) OCS01, 2) OCS02, 3) OCS03, 4) OCS04, 5) OCS05, 6) OCS06, 7) OCS07, (8) OCS08, and (9) OCS09 in the (a) Email Server component; 10) OCS10 (and (11) OCS11 in the (b) Oracle Collaboration Suite Wireless &amp; Voice (component; 12) OCS12 and (13) OCS13 in the (c) Oracle Content (Management SDK component; 14) OCS14 and (15) OCS15 in the (d) Oracle (Content Services component.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16287">16287</ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/545804">VU#545804</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0243">ADV-2006-0243</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18493">18493</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0323">ADV-2006-0323</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/18608">18608</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015499">1015499</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24321">oracle-january2006-update(24321)</ref></refs><vuln_soft><prod name="Oracle Collaboration Suite" vendor="Oracle"><vers num="Release 2 9.0.4.2"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-03-04" name="CVE-2006-0277" published="2006-01-18" seq="2006-0277" severity="High" type="CVE"><desc><descript source="cve">Multiple unspecified vulnerabilities in Oracle E-Business Suite and Applications 11.5.10 have unspecified impact and attack vectors, as identified by Oracle Vuln# (1) APPS01 in the (a) Application Install component; (2) APPS07 in the (b) Oracle Applications Framework component; (3) APPS08, (4) APPS09, (5) APPS10, and (6) APPS11 in the (c) Oracle Applications Technology Stack component; (7) APPS12 in the (d) Oracle Human Resources component; (8) APPS15 and (9) APPS16 in the (e) Oracle Marketing component; (10) APPS17 in the (f) Marketing Encyclopedia System component; (11) APPS18 in the (g) Oracle Trade Management component; and (12) APPS19 in the (h) Oracle Web Applications Desktop Integration component.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16287">16287</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/545804">VU#545804</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0243">ADV-2006-0243</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18493">18493</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0323">ADV-2006-0323</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18608">18608</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015499">1015499</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24321">oracle-january2006-update(24321)</ref></refs><vuln_soft><prod name="E-Business Suite" vendor="Oracle"><vers num="11i 11.5.10"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-03-04" name="CVE-2006-0278" published="2006-01-18" seq="2006-0278" severity="High" type="CVE"><desc><descript source="cve">Multiple unspecified vulnerabilities in Oracle E-Business Suite and Applications 11.5.9 have unspecified impact and attack vectors, as identified by Oracle Vuln# (1) APPS02 in the (a) CRM Technical Foundation component; (2) APPS03 in the (b) iProcurement component; and (3) APPS04, (4) APPS05, and (5) APPS06 in the Oracle Application Object Library component.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16287">16287</ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/545804">VU#545804</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0243">ADV-2006-0243</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18493">18493</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0323">ADV-2006-0323</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18608">18608</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015499">1015499</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24321">oracle-january2006-update(24321)</ref></refs><vuln_soft><prod name="E-Business Suite" vendor="Oracle"><vers num="11i 11.5.9"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-03-04" name="CVE-2006-0279" published="2006-01-18" seq="2006-0279" severity="High" type="CVE"><desc><descript source="cve">Multiple unspecified vulnerabilities in Oracle E-Business Suite and Applications 4.3 have unspecified impact and attack vectors, as identified by Oracle Vuln# (1) APPS13 and (2) APPS14 in the Oracle iLearning component.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16287">16287</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/545804">VU#545804</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0243">ADV-2006-0243</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18493">18493</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0323">ADV-2006-0323</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18608">18608</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015499">1015499</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24321">oracle-january2006-update(24321)</ref></refs><vuln_soft><prod name="E-Business Suite" vendor="Oracle"><vers num="4.3"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-03-04" name="CVE-2006-0280" published="2006-01-18" seq="2006-0280" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Oracle PeopleSoft Enterprise Portal 8.4 Bundle 15, 8.8 Bundle 10, and 8.9 Bundle 2 has unspecified impact and attack vectors, as identified by Oracle Vuln# PSE01.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16287">16287</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/545804">VU#545804</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0243">ADV-2006-0243</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18493">18493</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0323">ADV-2006-0323</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18608">18608</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015499">1015499</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24321">oracle-january2006-update(24321)</ref></refs><vuln_soft><prod name="PeopleSoft Enterprise Portal" vendor="Oracle"><vers num="8.9 Bundle 2"/><vers num="8.8 Bundle 10"/><vers num="8.4 Bundle 15"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-03-04" name="CVE-2006-0281" published="2006-01-18" seq="2006-0281" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Oracle JD Edwards HTML Server 8.95.F1 SP23_L1 has unspecified impact and attack vectors, as identified by Oracle Vuln# JDE01.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16287">16287</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/545804">VU#545804</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0243">ADV-2006-0243</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18493">18493</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0323">ADV-2006-0323</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18608">18608</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015499">1015499</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24321">oracle-january2006-update(24321)</ref></refs><vuln_soft><prod name="JD Edwards EnterpriseOne" vendor="Oracle"><vers num="8.95 _F1"/><vers num="SP23_L1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-03-04" name="CVE-2006-0282" published="2006-01-18" seq="2006-0282" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Oracle Database Server 8.1.7.4, 9.0.1.5, 9.0.1.5 FIPS, 9.2.0.7, and 10.1.0.5, Application Server 1.0.2.2, 9.0.4.2, and 10.1.2.0.2, and Collaboration Suite Release 2, version 9.0.4.2 (Oracle9i) has unspecified impact and attack vectors, as identified by Oracle Vuln# DBC01 in the Protocol Support component.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16287">16287</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/545804">VU#545804</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0243">ADV-2006-0243</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18493">18493</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/0323">ADV-2006-0323</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18608">18608</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1015499">1015499</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/24321">oracle-january2006-update(24321)</ref></refs><vuln_soft><prod name="Oracle Collaboration Suite" vendor="Oracle"><vers num="Release 2 9.0.4.2"/></prod><prod name="Oracle9i Database Server" vendor="Oracle"><vers num="10.1.0.5"/><vers num="9.2.0.7"/><vers edition="FIPS" num="9.0.1.5"/><vers num="9.0.1.5"/></prod><prod name="Oracle9i Application Server" vendor="Oracle"><vers num="1.0.2.2 r1"/></prod><prod name="Oracle10g Application Server" vendor="Oracle"><vers num="10.1.2.0.2"/><vers num="Release 2 10.1.2.0.2"/><vers num="9.0.4.2"/></prod><prod name="Oracle8i Database Server" vendor="Oracle"><vers num="8.1.7.4"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-03-04" name="CVE-2006-0283" published="2006-01-18" seq="2006-0283" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Oracle Database Server 10.1.0.4.2, Application Server 10.1.2.0.2, and Collaboration Suite Release 2, version 9.0.4.2 (Oracle9i) has unspecified impact and attack vectors, as identified by Oracle Vuln# DBC02 in the Reorganize Objects &amp; Convert Tablespace component.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/16287">16