<?xml version="1.0" encoding="UTF-8"?>
<nvd nvd_xml_version="1.2" pub_date="2008-09-05" xmlns="http://nvd.nist.gov/feeds/cve/1.2" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://nvd.nist.gov/feeds/cve/1.2 http://nvd.nist.gov/schema/nvdcve.xsd"><!--This XML file has been upgraded to support CVSS version 2.  The following new attributes have been added to CVS entries:
* CVSS_version - Indicates the version of the CVSS data
* CVSS_base_score - The CVSSv2 base score
* CVSS_impact_subscore - The CVSSv2 impact sub-score
* CVSS_exploit_subscore - the CVSSv2 exploit sub-score

The following attributes have been mapped to new content in CVS entries:
* CVSS_score - This attribute is the same as the CVSS_base_score and is now deprecated.
* CVSS_vector - Contains the new CVSSv2 vector string--><entry CVSS_base_score="3.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="4.9" CVSS_score="3.6" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:P)" CVSS_version="2.0" modified="2008-06-11" name="CVE-2008-0001" published="2008-01-15" seq="2008-0001" severity="Low" type="CVE"><desc><descript source="cve">VFS in the Linux kernel before 2.6.22.16, and 2.6.23.x before 2.6.23.14, performs tests of access mode by using the flag variable instead of the acc_mode variable, which might allow local users to bypass intended permissions and remove directories.</descript></desc><loss_types><avail/><int/></loss_types><range><local/></range><refs><ref source="" url="http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.23.14"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/27280">27280</ref><ref source="" url="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=974a9f0b47da74e28f68b9c8645c3786aa5ace1a"></ref><ref source="" url="http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.22.16"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0151">ADV-2008-0151</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28485">28485</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39672">linux-directory-security-bypass(39672)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/486485/100/0/threaded">20080117 rPSA-2008-0021-1 kernel</ref><ref source="" url="http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0021"></ref><ref source="" url="https://issues.rpath.com/browse/RPL-2146"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/28558">28558</ref><ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00828.html">FEDORA-2008-0748</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2008-0089.html">RHSA-2008:0089</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28628">28628</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28664">28664</ref><ref source="DEBIAN" url="http://www.debian.org/security/2008/dsa-1479">DSA-1479</ref><ref source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2008-0055.html">RHSA-2008:0055</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-574-1">USN-574-1</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28626">28626</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28748">28748</ref><ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2008-02/msg00002.html">SUSE-SA:2008:006</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28706">28706</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1019289">1019289</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28806">28806</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDVSA-2008:044">MDVSA-2008:044</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-578-1">USN-578-1</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28971">28971</ref><ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2008-03/msg00002.html">SUSE-SA:2008:013</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28643">28643</ref><ref source="SECUNIA" url="http://secunia.com/advisories/29245">29245</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.6.22.16" prev="1"/><vers num="2.6.23.14" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="4.9" CVSS_score="5.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_version="2.0" modified="2008-05-07" name="CVE-2008-0002" published="2008-02-11" seq="2008-0002" severity="Medium" type="CVE"><desc><descript source="cve">Apache Tomcat 6.0.0 through 6.0.15 processes parameters in the context of the wrong request when an exception occurs during parameter processing, which might allow remote attackers to obtain sensitive information, as demonstrated by disconnecting during this processing in order to trigger the exception.</descript></desc><loss_types><conf/><int/></loss_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/487812/100/0/threaded">20080208 CVE-2008-0002: Tomcat information disclosure vulnerability</ref><ref source="" url="http://tomcat.apache.org/security-6.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/27703">27703</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0488">ADV-2008-0488</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28834">28834</ref><ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00315.html">FEDORA-2008-1467</ref><ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00460.html">FEDORA-2008-1603</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28915">28915</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200804-10.xml">GLSA-200804-10</ref><ref source="SECUNIA" url="http://secunia.com/advisories/29711">29711</ref><ref source="SREASON" url="http://securityreason.com/securityalert/3638">3638</ref></refs><vuln_soft><prod name="Tomcat" vendor="Apache Software Foundation"><vers num="6.0.10"/><vers num="6.0.11"/><vers num="6.0.12"/><vers num="6.0.13"/><vers num="6.0.14"/><vers num="6.0.15"/><vers num="6.0.5"/><vers num="6.0.6"/><vers num="6.0.7"/><vers num="6.0.8"/><vers num="6.0.9"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-02-26" name="CVE-2008-0003" published="2008-01-08" seq="2008-0003" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in the PAMBasicAuthenticator::PAMCallback function in OpenPegasus CIM management server (tog-pegasus), when compiled to use PAM and without PEGASUS_USE_PAM_STANDALONE_PROC defined, might allow remote attackers to execute arbitrary code via unknown vectors, a different vulnerability than CVE-2007-5360.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs><ref source="" url="https://bugzilla.redhat.com/show_bug.cgi?id=426578"></ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2008-0002.html">RHSA-2008:0002</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28338">28338</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39527">openpegasus-pambasic-bo(39527)</ref><ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00424.html">FEDORA-2008-0506</ref><ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00480.html">FEDORA-2008-0572</ref><ref source="VIM" url="http://www.attrition.org/pipermail/vim/2008-January/001879.html">20080115 vuldb confusion between OpenPegasus issues</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28462">28462</ref><ref source="BID" url="http://www.securityfocus.com/bid/27172">27172</ref><ref source="BID" url="http://www.securityfocus.com/bid/27188">27188</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0063">ADV-2008-0063</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1019159">1019159</ref><ref source="" url="http://www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd?mode=18&amp;ID=4129"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0638">ADV-2008-0638</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/29056">29056</ref><ref source="MLIST" url="http://lists.vmware.com/pipermail/security-announce/2008/000014.html">[Security-announce] 20080415 VMSA-2008-0007 Moderate Updated Service Console packages pcre, net-snmp, and OpenPegasus</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/1234/references">ADV-2008-1234</ref><ref source="SECUNIA" url="http://secunia.com/advisories/29785">29785</ref><ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01438409">HPSBMA02331</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/1391/references">ADV-2008-1391</ref><ref source="SECUNIA" url="http://secunia.com/advisories/29986">29986</ref></refs><vuln_soft><prod name="Management Server" vendor="OpenPegasus"><vers num="2.6.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2008-01-14" name="CVE-2008-0005" published="2008-01-11" seq="2008-0005" severity="Medium" type="CVE"><desc><descript source="cve">mod_proxy_ftp in Apache 2.2.x before 2.2.7-dev, 2.0.x before 2.0.62-dev, and 1.3.x before 1.3.40-dev does not define a charset, which allows remote attackers to conduct cross-site scripting (XSS) attacks using UTF-7 encoding.</descript></desc><loss_types><int/></loss_types><range><network/><user_init/></range><refs><ref source="SECUNIA" url="http://secunia.com/advisories/28471">28471</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDVSA-2008:016">MDVSA-2008:016</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28526">28526</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2008-032.htm"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/28607">28607</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-575-1">USN-575-1</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28749">28749</ref><ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00562.html">FEDORA-2008-1695</ref><ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00541.html">FEDORA-2008-1711</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28977">28977</ref><ref source="SREASONRES" url="http://securityreason.com/achievement_securityalert/49">20080110 Apache (mod_proxy_ftp) Undefined Charset UTF-7 XSS Vulnerability</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39615">apache-modproxyftp-utf7-xss(39615)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/486167/100/0/threaded">20080110 SecurityReason - Apache (mod_proxy_ftp) Undefined Charset UTF-7 XSS Vulnerability</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDVSA-2008:014">MDVSA-2008:014</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDVSA-2008:015">MDVSA-2008:015</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2008-0004.html">RHSA-2008:0004</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2008-0005.html">RHSA-2008:0005</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2008-0006.html">RHSA-2008:0006</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2008-0007.html">RHSA-2008:0007</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2008-0008.html">RHSA-2008:0008</ref><ref source="BID" url="http://www.securityfocus.com/bid/27234">27234</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1019185">1019185</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28467">28467</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200803-19.xml">GLSA-200803-19</ref><ref source="SECUNIA" url="http://secunia.com/advisories/29348">29348</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=307562"></ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html">APPLE-SA-2008-03-18</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0924/references">ADV-2008-0924</ref><ref source="SECUNIA" url="http://secunia.com/advisories/29420">29420</ref><ref source="SREASON" url="http://securityreason.com/securityalert/3526">3526</ref><ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2008-04/msg00004.html">SUSE-SA:2008:021</ref><ref source="SECUNIA" url="http://secunia.com/advisories/29640">29640</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2008-0009.html">RHSA-2008:0009</ref></refs><vuln_soft><prod name="Apache HTTP Server" vendor="Apache Software Foundation"><vers num="1.3"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-02-01" name="CVE-2008-0006" published="2008-01-18" seq="2008-0006" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in (1) X.Org Xserver before 1.4.1, and (2) the libfont and libXfont libraries on some platforms including Sun Solaris, allows context-dependent attackers to execute arbitrary code via a PCF font with a large difference between the last col and first col values in the PCF_BDF_ENCODINGS table.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><range><network/></range><refs><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200801-09.xml">GLSA-200801-09</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDVSA-2008:021">MDVSA-2008:021</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDVSA-2008:022">MDVSA-2008:022</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDVSA-2008:024">MDVSA-2008:024</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28273">28273</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28500">28500</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28592">28592</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28571">28571</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28621">28621</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39767">xorg-pcffont-bo(39767)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/487335/100/0/threaded">20080130 rPSA-2008-0032-1 xorg-x11 xorg-x11-fonts xorg-x11-tools xorg-x11-xfs</ref><ref source="" url="https://issues.rpath.com/browse/RPL-2010"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/28718">28718</ref><ref source="OPENBSD" url="http://www.openbsd.org/errata41.html#012_xorg">[4.1] 20080208 012: SECURITY FIX: February 8, 2008</ref><ref source="OPENBSD" url="http://www.openbsd.org/errata42.html#006_xorg">[4.2] 20080208 006: SECURITY FIX: February 8, 2008</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28843">28843</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0497/references">ADV-2008-0497</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28885">28885</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2008-077.htm"></ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-201230-1">201230</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28941">28941</ref><ref patch="1" source="MLIST" url="http://lists.freedesktop.org/archives/xorg/2008-January/031918.html">[xorg] 20080117 X.Org security advisory: multiple vulnerabilities in the X server</ref><ref patch="1" source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-103192-1">103192</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/27336">27336</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2008-0029.html">RHSA-2008:0029</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2008-0030.html">RHSA-2008:0030</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2008-0064.html">RHSA-2008:0064</ref><ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2008-01/msg00004.html">SUSE-SA:2008:003</ref><ref source="UBUNTU" url="http://www.ubuntulinux.org/support/documentation/usn/usn-571-1">USN-571-1</ref><ref source="BID" url="http://www.securityfocus.com/bid/27352">27352</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0179">ADV-2008-0179</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0184">ADV-2008-0184</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1019232">1019232</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28532">28532</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28535">28535</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28536">28536</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28540">28540</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28542">28542</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28544">28544</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28550">28550</ref><ref source="" url="http://bugs.gentoo.org/show_bug.cgi?id=204362"></ref><ref source="" url="https://bugzilla.redhat.com/show_bug.cgi?id=428044"></ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2008-038.htm"></ref><ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00641.html">FEDORA-2008-0760</ref><ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00674.html">FEDORA-2008-0794</ref><ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00704.html">FEDORA-2008-0831</ref><ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00771.html">FEDORA-2008-0891</ref><ref source="" url="http://www14.software.ibm.com/webapp/set2/subscriptions/ijhifoeblist?mode=7&amp;heading=AIX61&amp;path=/200802/SECURITY/20080227/datafile112539&amp;label=AIX%20X%20server%20multiple%20vulnerabilities"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0703">ADV-2008-0703</ref><ref source="SECUNIA" url="http://secunia.com/advisories/29139">29139</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=307562"></ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html">APPLE-SA-2008-03-18</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0924/references">ADV-2008-0924</ref><ref source="SECUNIA" url="http://secunia.com/advisories/29420">29420</ref><ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2008-04/msg00005.html">SUSE-SR:2008:008</ref><ref source="SECUNIA" url="http://secunia.com/advisories/29622">29622</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200804-05.xml">GLSA-200804-05</ref><ref source="SECUNIA" url="http://secunia.com/advisories/29707">29707</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200805-07.xml">GLSA-200805-07</ref><ref source="SECUNIA" url="http://secunia.com/advisories/30161">30161</ref></refs><vuln_soft><prod name="Solaris libfont" vendor="Sun"><vers num=""/></prod><prod name="Xserver" vendor="X.Org"><vers num="1.4" prev="1"/></prod><prod name="Solaris libXfont" vendor="Sun"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-02-08" name="CVE-2008-0007" published="2008-02-07" seq="2008-0007" severity="High" type="CVE"><desc><descript source="cve">Linux kernel before 2.6.22.17, when using certain drivers that register a fault handler that does not perform range checks, allows local users to access kernel memory via an out-of-range offset.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><local/></range><refs><ref source="MLIST" url="http://lkml.org/lkml/2008/2/6/457">[linux-kernel] 20080206 [patch 60/73] vm audit: add VM_DONTEXPAND to mmap for drivers that need it (CVE-2008-0007)</ref><ref source="" url="http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.22.17"></ref><ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2008-02/msg00002.html">SUSE-SA:2008:006</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0445/references">ADV-2008-0445</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28806">28806</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/487808/100/0/threaded">20080208 rPSA-2008-0048-1 kernel</ref><ref source="" url="http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.24.1"></ref><ref source="" url="http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0048"></ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDVSA-2008:044">MDVSA-2008:044</ref><ref source="BID" url="http://www.securityfocus.com/bid/27686">27686</ref><ref source="BID" url="http://www.securityfocus.com/bid/27705">27705</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1019357">1019357</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28826">28826</ref><ref source="DEBIAN" url="http://www.debian.org/security/2008/dsa-1503">DSA-1503</ref><ref source="DEBIAN" url="http://www.debian.org/security/2008/dsa-1504">DSA-1504</ref><ref source="SECUNIA" url="http://secunia.com/advisories/29058">29058</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDVSA-2008:072">MDVSA-2008:072</ref><ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2008-03/msg00007.html">SUSE-SA:2008:017</ref><ref source="SECUNIA" url="http://secunia.com/advisories/29570">29570</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2008-0211.html">RHSA-2008:0211</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2008-0233.html">RHSA-2008:0233</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2008-0237.html">RHSA-2008:0237</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.6.22.16" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-02-01" name="CVE-2008-0008" published="2008-01-28" seq="2008-0008" severity="High" type="CVE"><desc><descript source="cve">The pa_drop_root function in PulseAudio 0.9.8, and a certain 0.9.9 build, does not check return values from (1) setresuid, (2) setreuid, (3) setuid, and (4) seteuid calls when attempting to drop privileges, which might allow local users to gain privileges by causing those calls to fail via attacks such as resource exhaustion.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><local/></range><refs><ref source="DEBIAN" url="http://www.debian.org/security/2008/dsa-1476">DSA-1476</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDVSA-2008:027">MDVSA-2008:027</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0283">ADV-2008-0283</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28608">28608</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39992">pulseaudio-padroproot-privilege-escalation(39992)</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-573-1">USN-573-1</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28738">28738</ref><ref source="" url="http://pulseaudio.org/changeset/2100"></ref><ref source="" url="https://bugzilla.novell.com/show_bug.cgi?id=347822"></ref><ref source="" url="https://bugzilla.redhat.com/show_bug.cgi?id=425481"></ref><ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00852.html">FEDORA-2008-0963</ref><ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00869.html">FEDORA-2008-0994</ref><ref source="BID" url="http://www.securityfocus.com/bid/27449">27449</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28623">28623</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200802-07.xml">GLSA-200802-07</ref><ref source="" url="http://bugs.gentoo.org/show_bug.cgi?id=207214"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/28952">28952</ref></refs><vuln_soft><prod name="PulseAudio" vendor="PulseAudio"><vers num="0.9.6"/><vers num="0.9.8"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2008-02-12" name="CVE-2008-0009" published="2008-02-12" seq="2008-0009" severity="Low" type="CVE"><desc><descript source="cve">The vmsplice_to_user function in fs/splice.c in the Linux kernel 2.6.22 through 2.6.24 does not validate a certain userspace pointer before dereference, which might allow local users to access arbitrary kernel memory locations.</descript></desc><loss_types><conf/></loss_types><range><local/></range><refs><ref source="" url="http://isec.pl/vulnerabilities/isec-0026-vmsplice_to_kernel.txt"></ref><ref source="" url="http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.24.1"></ref><ref source="" url="https://bugzilla.redhat.com/show_bug.cgi?id=431206"></ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/487982/100/0/threaded">20080212 CSA-L03: Linux kernel vmsplice unchecked user-pointer dereference</ref><ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00254.html">FEDORA-2008-1422</ref><ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00255.html">FEDORA-2008-1423</ref><ref source="BID" url="http://www.securityfocus.com/bid/27704">27704</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0487/references">ADV-2008-0487</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28835">28835</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28896">28896</ref><ref source="BID" url="http://www.securityfocus.com/bid/27799">27799</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.6.22"/><vers num="2.6.22 rc6"/><vers num="2.6.22.1"/><vers num="2.6.22.16"/><vers num="2.6.22.3"/><vers num="2.6.22.4"/><vers num="2.6.22.5"/><vers num="2.6.22.6"/><vers num="2.6.22.7"/><vers num="2.6.23"/><vers num="2.6.23 .2"/><vers num="2.6.23 rc1"/><vers num="2.6.23.09"/><vers num="2.6.23.1"/><vers num="2.6.23.14"/><vers num="2.6.23.2"/><vers num="2.6.23.3"/><vers num="2.6.23.4"/><vers num="2.6.23.5"/><vers num="2.6.23.6"/><vers num="2.6.23.7"/><vers num="2.6.23_rc2"/><vers num="2.6.23rc1"/><vers num="2.6.23rc2"/><vers num="2.6.24 rc2"/><vers num="2.6.24_rc2"/><vers num="2.6.24_rc3"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2008-02-12" name="CVE-2008-0010" published="2008-02-12" seq="2008-0010" severity="Low" type="CVE"><desc><descript source="cve">The copy_from_user_mmap_sem function in fs/splice.c in the Linux kernel 2.6.22 through 2.6.24 does not validate a certain userspace pointer before dereference, which allow local users to read from arbitrary kernel memory locations.</descript></desc><loss_types><conf/></loss_types><range><local/></range><refs><ref source="" url="http://isec.pl/vulnerabilities/isec-0026-vmsplice_to_kernel.txt"></ref><ref source="" url="http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.24.1"></ref><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/5093">5093</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/487982/100/0/threaded">20080212 CSA-L03: Linux kernel vmsplice unchecked user-pointer dereference</ref><ref source="DEBIAN" url="http://www.debian.org/security/2008/dsa-1494">DSA-1494</ref><ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00254.html">FEDORA-2008-1422</ref><ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00255.html">FEDORA-2008-1423</ref><ref source="BID" url="http://www.securityfocus.com/bid/27704">27704</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0487/references">ADV-2008-0487</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28835">28835</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28875">28875</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28896">28896</ref><ref source="BID" url="http://www.securityfocus.com/bid/27796">27796</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.6.22"/><vers num="2.6.22 rc6"/><vers num="2.6.22.1"/><vers num="2.6.22.16"/><vers num="2.6.22.3"/><vers num="2.6.22.4"/><vers num="2.6.22.5"/><vers num="2.6.22.6"/><vers num="2.6.22.7"/><vers num="2.6.23"/><vers num="2.6.23 .2"/><vers num="2.6.23 rc1"/><vers num="2.6.23.09"/><vers num="2.6.23.1"/><vers num="2.6.23.14"/><vers num="2.6.23.2"/><vers num="2.6.23.3"/><vers num="2.6.23.4"/><vers num="2.6.23.5"/><vers num="2.6.23.6"/><vers num="2.6.23.7"/><vers num="2.6.23_rc2"/><vers num="2.6.23rc1"/><vers num="2.6.23rc2"/><vers num="2.6.24 rc2"/><vers num="2.6.24_rc2"/><vers num="2.6.24_rc3"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-06-12" name="CVE-2008-0011" published="2008-06-11" seq="2008-0011" severity="High" type="CVE"><desc><descript source="cve">Microsoft DirectX 8.1 through 9.0c, and DirectX on Microsoft XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008, does not properly perform MJPEG error checking, which allows remote attackers to execute arbitrary code via a crafted MJPEG stream in a (1) AVI or (2) ASF file, aka the &quot;MJPEG Decoder Vulnerability.&quot;</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/><user_init/></range><refs><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms08-033.mspx">MS08-033</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA08-162B.html">TA08-162B</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/29581">29581</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/1780">ADV-2008-1780</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1020222">1020222</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/30579">30579</ref></refs><vuln_soft><prod name="DirectX" vendor="Microsoft"><vers num="7.0"/><vers num="8.1"/><vers num="10.0"/><vers num="9.0"/></prod></vuln_soft></entry><entry CVSS_base_score="6.5" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="6.4" CVSS_score="6.5" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-02-19" name="CVE-2008-0026" published="2008-02-14" seq="2008-0026" severity="Medium" type="CVE"><desc><descript source="cve">SQL injection vulnerability in Cisco Unified CallManager/Communications Manager (CUCM) 5.0/5.1 before 5.1(3a) and 6.0/6.1 before 6.1(1a) allows remote authenticated users to execute arbitrary SQL commands via the key parameter to the (1) admin and (2) user interface pages.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><range><network/></range><refs><ref source="CISCO" url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080949c7c.shtml">20080213 SQL injection in Cisco Unified Communications Manager</ref><ref source="BID" url="http://www.securityfocus.com/bid/27775">27775</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0542">ADV-2008-0542</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28932">28932</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1019404">1019404</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/40484">cucm-interface-sql-injection(40484)</ref></refs><vuln_soft><prod name="Unified Communications Manager" vendor="Cisco"><vers num="5.0"/><vers num="5.0_1"/><vers num="5.0_2"/><vers num="5.0_3"/><vers num="5.0_3a"/><vers num="5.0_4"/><vers num="5.0_4a"/><vers num="5.0_4a_SU1"/><vers num="6.0"/><vers num="6.0_1"/><vers num="6.1"/></prod><prod name="Unified CallManager" vendor="Cisco"><vers num="5.0"/><vers num="5.0(1)"/><vers num="5.0(2)"/><vers num="5.0(3)"/><vers num="5.0(3a)"/><vers num="5.0(4)"/><vers num="5.0_4a"/><vers num="5.1"/><vers num="6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-01-17" name="CVE-2008-0027" published="2008-01-16" seq="2008-0027" severity="High" type="CVE"><desc><descript source="cve">Heap-based buffer overflow in the Certificate Trust List (CTL) Provider service (CTLProvider.exe) in Cisco Unified Communications Manager (CUCM) 4.2 before 4.2(3)SR3 and 4.3 before 4.3(1)SR1, and CallManager 4.0 and 4.1 before 4.1(3)SR5c, allows remote attackers to cause a denial of service or execute arbitrary code via a long request.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/486432/100/0/threaded">20080116 TPTI-08-02: Cisco Call Manager CTLProvider Heap Overflow Vulnerability</ref><ref source="" url="http://dvlabs.tippingpoint.com/advisory/TPTI-08-02"></ref><ref patch="1" source="CISCO" url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080932c61.shtml">20080116 Cisco Unified Communications Manager CTL Provider Heap Overflow</ref><ref source="BID" url="http://www.securityfocus.com/bid/27313">27313</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39704">cisco-cucm-ctl-bo(39704)</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0171">ADV-2008-0171</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1019223">1019223</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28530">28530</ref><ref source="SREASON" url="http://securityreason.com/securityalert/3551">3551</ref></refs><vuln_soft><prod name="Unified Communications Manager" vendor="Cisco"><vers num="4.2"/><vers num="4.2.3 SR2"/><vers num="4.2.3 SR2b"/><vers num="4.3"/></prod><prod name="Unified CallManager" vendor="Cisco"><vers num="4.0"/><vers num="4.1"/><vers num="4.1(3) SR4"/><vers num="4.1(3) SR5"/><vers num="4.1(3) SR5B"/></prod></vuln_soft></entry><entry CVSS_base_score="7.1" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.9" CVSS_score="7.1" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2008-02-01" name="CVE-2008-0028" published="2008-01-23" seq="2008-0028" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Cisco PIX 500 Series Security Appliance and 5500 Series Adaptive Security Appliance (ASA) before 7.2(3)6 and 8.0(3), when the Time-to-Live (TTL) decrement feature is enabled, allows remote attackers to cause a denial of service (device reload) via a crafted IP packet.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-sa-20080123-asa.shtml">20080123 Cisco PIX and ASA Time-to-Live Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/27418">27418</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0259">ADV-2008-0259</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1019262">1019262</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1019263">1019263</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28625">28625</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39862">pix-asa-ttl-dos(39862)</ref></refs><vuln_soft><prod name="PIX 500 Series Security Appliance" vendor="Cisco"><vers num="7.2-2" prev="1"/><vers num="8.0-2" prev="1"/></prod><prod name="5500 Series Adaptive Security Appliance" vendor="Cisco"><vers num="7.2-2" prev="1"/><vers num="8.0-2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-01-23" name="CVE-2008-0029" published="2008-01-23" seq="2008-0029" severity="High" type="CVE"><desc><descript source="cve">Cisco Application Velocity System (AVS) before 5.1.0 is installed with default passwords for some system accounts, which allows remote attackers to gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs><ref source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-sa-20080123-avs.shtml">20080123 Default Passwords in the Application Velocity System</ref><ref source="BID" url="http://www.securityfocus.com/bid/27421">27421</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0260">ADV-2008-0260</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1019259">1019259</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39860">ciscoavs-default-password-admin-account(39860)</ref></refs><vuln_soft><prod name="AVS" vendor="Cisco"><vers num="5.0.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="4.9" CVSS_score="5.8" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:P)" CVSS_version="2.0" modified="2008-01-16" name="CVE-2008-0031" published="2008-01-15" seq="2008-0031" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Apple QuickTime before 7.4 allows remote attackers to cause a denial of service (application termination) and execurte arbitrary code via a crafted Sorenson 3 video file, which triggers memory corruption.</descript></desc><loss_types><avail/><int/></loss_types><range><network/><user_init/></range><refs><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2008/Jan/msg00001.html">APPLE-SA-2008-01-15</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=307301"></ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA08-016A.html">TA08-016A</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0148">ADV-2008-0148</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1019221">1019221</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28502">28502</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39695">quicktime-sorenson-code-execution(39695)</ref><ref source="BID" url="http://www.securityfocus.com/bid/27298">27298</ref></refs><vuln_soft><prod name="Quicktime" vendor="Apple"><vers num="7.3" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="4.9" CVSS_score="5.8" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:P)" CVSS_version="2.0" modified="2008-01-16" name="CVE-2008-0032" published="2008-01-15" seq="2008-0032" severity="Medium" type="CVE"><desc><descript source="cve">Apple QuickTime before 7.4 allows remote attackers to execute arbitrary code via a movie file containing a Macintosh Resource record with a modified length value in the resource header, which triggers heap corruption.</descript></desc><loss_types><avail/><int/></loss_types><range><network/><user_init/></range><refs><ref patch="1" source="IDEFENSE" url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=642">20080115 Apple QuickTime Macintosh Resource Processing Heap Corruption Vulnerability</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2008/Jan/msg00001.html">APPLE-SA-2008-01-15</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=307301"></ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA08-016A.html">TA08-016A</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0148">ADV-2008-0148</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1019221">1019221</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28502">28502</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39696">quicktime-macintosh-code-execution(39696)</ref><ref source="BID" url="http://www.securityfocus.com/bid/27301">27301</ref></refs><vuln_soft><prod name="Quicktime" vendor="Apple"><vers num="7.3" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-01-21" name="CVE-2008-0033" published="2008-01-15" seq="2008-0033" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Apple QuickTime before 7.4 allows remote attackers to cause a denial of service (application termination) and execute arbitrary code via a movie file with Image Descriptor (IDSC) atoms containing an invalid atom size, which triggers memory corruption.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/><user_init/></range><refs><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2008/Jan/msg00001.html">APPLE-SA-2008-01-15</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=307301"></ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/486413/100/0/threaded">20080115 TPTI-08-01: Apple Quicktime Image File IDSC Atom Memory Corruption Vulnerability</ref><ref source="" url="http://dvlabs.tippingpoint.com/advisory/TPTI-08-01"></ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA08-016A.html">TA08-016A</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0148">ADV-2008-0148</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1019221">1019221</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28502">28502</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39697">quicktime-idsc-code-execution(39697)</ref><ref source="BID" url="http://www.securityfocus.com/bid/27299">27299</ref></refs><vuln_soft><prod name="Quicktime" vendor="Apple"><vers num="7.3.1.70" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-01-16" name="CVE-2008-0034" published="2008-01-15" seq="2008-0034" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Passcode Lock in Apple iPhone 1.0 through 1.1.2 allows users with physical access to execute applications without entering the passcode via vectors related to emergency calls.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><range><local/></range><refs><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2008/Jan/msg00000.html">APPLE-SA-2008-01-15</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=307302"></ref><ref source="BID" url="http://www.securityfocus.com/bid/27297">27297</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0147">ADV-2008-0147</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1019219">1019219</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28497">28497</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39701">iphone-passcode-lock-security-bypass(39701)</ref></refs><vuln_soft><prod name="iPhone" vendor="Apple"><vers num="1.0"/><vers num="1.0.1"/><vers num="1.0.2"/><vers num="1.02"/><vers num="1.1.1"/><vers num="1.1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-02-13" name="CVE-2008-0035" published="2008-01-15" seq="2008-0035" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Foundation, as used in Apple iPhone 1.0 through 1.1.2, iPod touch 1.1 through 1.1.2, and Mac OS X 10.5 through 10.5.1, allows remote attackers to cause a denial of service (application termination) or execute arbitrary code via a crafted URL that triggers memory corruption in Safari.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/><user_init/></range><refs><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2008/Jan/msg00000.html">APPLE-SA-2008-01-15</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=307302"></ref><ref source="BID" url="http://www.securityfocus.com/bid/27296">27296</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0147">ADV-2008-0147</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1019220">1019220</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28497">28497</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39700">iphone-ipod-foundation-code-execution(39700)</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2008/Feb/msg00002.html">APPLE-SA-2008-02-11</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=307430"></ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA08-043B.html">TA08-043B</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0495/references">ADV-2008-0495</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28891">28891</ref></refs><vuln_soft><prod name="Safari" vendor="Apple"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-01-16" name="CVE-2008-0036" published="2008-01-15" seq="2008-0036" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in Apple QuickTime before 7.4 allows remote attackers to execute arbitrary code via a crafted compressed PICT image, which triggers the overflow during decoding.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/><user_init/></range><refs><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0148">ADV-2008-0148</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1019221">1019221</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28502">28502</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39698">quicktime-pict-bo(39698)</ref><ref source="BID" url="http://www.securityfocus.com/bid/27300">27300</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2008/Jan/msg00001.html">APPLE-SA-2008-01-15</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=307301"></ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA08-016A.html">TA08-016A</ref></refs><vuln_soft><prod name="Quicktime" vendor="Apple"><vers num="7.3" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2008-02-12" name="CVE-2008-0037" published="2008-02-12" seq="2008-0037" severity="Medium" type="CVE"><desc><descript source="cve">X11 in Apple Mac OS X 10.5 through 10.5.1 does not properly handle when the &quot;Allow connections from network client&quot; preference is disabled, which allows remote attackers to bypass intended access restrictions and connect to the X server.</descript></desc><loss_types><conf/></loss_types><range><network/></range><refs><ref patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2008/Feb/msg00002.html">APPLE-SA-2008-02-11</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=307430"></ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA08-043B.html">TA08-043B</ref><ref source="BID" url="http://www.securityfocus.com/bid/27736">27736</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0495/references">ADV-2008-0495</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1019365">1019365</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28891">28891</ref></refs><vuln_soft><prod name="Mac OS X" vendor="Apple"><vers num="10.5"/><vers num="10.5.1"/></prod></vuln_soft></entry><entry CVSS_base_score="1.9" CVSS_exploit_subscore="3.4" CVSS_impact_subscore="2.9" CVSS_score="1.9" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2008-02-12" name="CVE-2008-0038" published="2008-02-12" seq="2008-0038" severity="Low" type="CVE"><desc><descript source="cve">Launch Services in Apple Mac OS X 10.5 through 10.5.1 allows an uninstalled application to be launched if it is in a Time Machine backup, which might allow local users to bypass intended security restrictions or exploit vulnerabilities in the application.</descript></desc><loss_types><conf/></loss_types><range><local/></range><refs><ref patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2008/Feb/msg00002.html">APPLE-SA-2008-02-11</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=307430"></ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA08-043B.html">TA08-043B</ref><ref source="BID" url="http://www.securityfocus.com/bid/27736">27736</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0495/references">ADV-2008-0495</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1019360">1019360</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28891">28891</ref></refs><vuln_soft><prod name="Mac OS X" vendor="Apple"><vers num="10.5"/><vers num="10.5.1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-02-12" name="CVE-2008-0039" published="2008-02-12" seq="2008-0039" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Mail in Apple Mac OS X 10.4.11 allows remote attackers to execute arbitrary commands via a crafted file:// URL.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><range><network/><user_init/></range><refs><ref patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2008/Feb/msg00002.html">APPLE-SA-2008-02-11</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=307430"></ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA08-043B.html">TA08-043B</ref><ref source="BID" url="http://www.securityfocus.com/bid/27736">27736</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0495/references">ADV-2008-0495</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1019361">1019361</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28891">28891</ref></refs><vuln_soft><prod name="Mail" vendor="Apple"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-02-12" name="CVE-2008-0040" published="2008-02-12" seq="2008-0040" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in NFS in Apple Mac OS X 10.5 through 10.5.1 allows remote attackers to cause a denial of service (system shutdown) or execute arbitrary code via unknown vectors related to mbuf chains that trigger memory corruption.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs><ref patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2008/Feb/msg00002.html">APPLE-SA-2008-02-11</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=307430"></ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA08-043B.html">TA08-043B</ref><ref source="BID" url="http://www.securityfocus.com/bid/27736">27736</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0495/references">ADV-2008-0495</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1019362">1019362</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28891">28891</ref></refs><vuln_soft><prod name="Mac OS X" vendor="Apple"><vers num="10.5"/><vers num="10.5.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2008-02-12" name="CVE-2008-0041" published="2008-02-12" seq="2008-0041" severity="Medium" type="CVE"><desc><descript source="cve">Parental Controls in Apple Mac OS X 10.5 through 10.5.1 contacts www.apple.com &quot;when a website is unblocked,&quot; which allows remote attackers to determine when a system is running Parental Controls.</descript></desc><loss_types><conf/></loss_types><range><network/></range><refs><ref patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2008/Feb/msg00002.html">APPLE-SA-2008-02-11</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=307430"></ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA08-043B.html">TA08-043B</ref><ref source="BID" url="http://www.securityfocus.com/bid/27736">27736</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0495/references">ADV-2008-0495</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1019363">1019363</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28891">28891</ref></refs><vuln_soft><prod name="Mac OS X" vendor="Apple"><vers num="10.5"/><vers num="10.5.1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-02-12" name="CVE-2008-0042" published="2008-02-12" seq="2008-0042" severity="Medium" type="CVE"><desc><descript source="cve">Argument injection vulnerability in Terminal.app in Terminal in Apple Mac OS X 10.4.11 and 10.5 through 10.5.1 allows remote attackers to execute arbitrary code via unspecified URL schemes.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><range><network/><user_init/></range><refs><ref patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2008/Feb/msg00002.html">APPLE-SA-2008-02-11</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=307430"></ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA08-043B.html">TA08-043B</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/774345">VU#774345</ref><ref source="BID" url="http://www.securityfocus.com/bid/27736">27736</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0495/references">ADV-2008-0495</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1019364">1019364</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28891">28891</ref></refs><vuln_soft><prod name="Mac OS X" vendor="Apple"><vers num="10.5"/><vers num="10.5.1"/><vers num="10.4.11"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-02-08" name="CVE-2008-0043" published="2008-02-07" seq="2008-0043" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in Apple iPhoto before 7.1.2 allows remote attackers to execute arbitrary code via photocast subscriptions.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/><user_init/></range><refs><ref source="" url="http://docs.info.apple.com/article.html?artnum=307398"></ref><ref patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2008/Feb/msg00000.html">APPLE-SA-2008-02-05</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0428/references">ADV-2008-0428</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1019307">1019307</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28805">28805</ref><ref source="BID" url="http://www.securityfocus.com/bid/27636">27636</ref></refs><vuln_soft><prod name="iPhoto" vendor="Apple"><vers num="7.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="4.9" CVSS_score="5.8" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:P)" CVSS_version="2.0" modified="2008-03-19" name="CVE-2008-0044" published="2008-03-18" seq="2008-0044" severity="Medium" type="CVE"><desc><descript source="cve">Multiple buffer overflows in AFP Client in Apple Mac OS X 10.4.11 and 10.5.2 allow remote attackers to cause a denial of service (application termination) and execute arbitrary code via a crafted afp:// URL.</descript></desc><loss_types><avail/><int/></loss_types><range><network/><user_init/></range><refs><ref patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html">APPLE-SA-2008-03-18</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=307562"></ref><ref source="BID" url="http://www.securityfocus.com/bid/28320">28320</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1019640">1019640</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA08-079A.html">TA08-079A</ref><ref source="BID" url="http://www.securityfocus.com/bid/28304">28304</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0924/references">ADV-2008-0924</ref><ref source="SECUNIA" url="http://secunia.com/advisories/29420">29420</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.4.11"/><vers num="10.5.2"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.4.11"/><vers num="10.5.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.1" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.9" CVSS_score="7.1" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:N/A:N)" CVSS_version="2.0" modified="2008-03-19" name="CVE-2008-0045" published="2008-03-18" seq="2008-0045" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in AFP Server in Apple Mac OS X 10.4.11 allows remote attackers to bypass cross-realm authentication via unknown manipulations of Kerberos principal realm names.</descript></desc><loss_types><conf/></loss_types><range><network/></range><refs><ref patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html">APPLE-SA-2008-03-18</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=307562"></ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1019642">1019642</ref><ref source="BID" url="http://www.securityfocus.com/bid/28323">28323</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA08-079A.html">TA08-079A</ref><ref source="BID" url="http://www.securityfocus.com/bid/28304">28304</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0924/references">ADV-2008-0924</ref><ref source="SECUNIA" url="http://secunia.com/advisories/29420">29420</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.4.11"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.4.11"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2008-03-19" name="CVE-2008-0046" published="2008-03-18" seq="2008-0046" severity="Medium" type="CVE"><desc><descript source="cve">The Application Firewall in Apple Mac OS X 10.5.2 has an incorrect German translation for the &quot;Set access for specific services and applications&quot; radio button that might cause the user to believe that the button is used to restrict access only to specific services and applications, which might allow attackers to bypass intended access restrictions.</descript></desc><loss_types><conf/></loss_types><range><network/></range><refs><ref patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html">APPLE-SA-2008-03-18</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=307562"></ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1019658">1019658</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA08-079A.html">TA08-079A</ref><ref source="BID" url="http://www.securityfocus.com/bid/28304">28304</ref><ref source="BID" url="http://www.securityfocus.com/bid/28368">28368</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0924/references">ADV-2008-0924</ref><ref source="SECUNIA" url="http://secunia.com/advisories/29420">29420</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.5.2"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.5.2"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-05-12" name="CVE-2008-0047" published="2008-03-18" seq="2008-0047" severity="High" type="CVE"><desc><descript source="cve">Heap-based buffer overflow in the cgiCompileSearch function in CUPS 1.3.5, and other versions including the version bundled with Apple Mac OS X 10.5.2, when printer sharing is enabled, allows remote attackers to execute arbitrary code via crafted search expressions.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs><ref patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html">APPLE-SA-2008-03-18</ref><ref source="IDEFENSE" url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=674">20080318 Multiple Vendor CUPS CGI Heap Overflow Vulnerability</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=307562"></ref><ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2008-03/msg00005.html">SUSE-SA:2008:015</ref><ref source="BID" url="http://www.securityfocus.com/bid/28307">28307</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0921/references">ADV-2008-0921</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1019646">1019646</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/29431">29431</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/29448">29448</ref><ref source="DEBIAN" url="http://www.debian.org/security/2008/dsa-1530">DSA-1530</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA08-079A.html">TA08-079A</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0924/references">ADV-2008-0924</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/29420">29420</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/29485">29485</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200804-01.xml">GLSA-200804-01</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2008-0192.html">RHSA-2008:0192</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/29634">29634</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDVSA-2008:081">MDVSA-2008:081</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-598-1">USN-598-1</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/29573">29573</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/29603">29603</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/29655">29655</ref><ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2008-April/msg00091.html">FEDORA-2008-2131</ref><ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2008-April/msg00105.html">FEDORA-2008-2897</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/29750">29750</ref></refs><vuln_soft><prod name="CUPS" vendor="cups"><vers num="1.3.5"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-03-19" name="CVE-2008-0048" published="2008-03-18" seq="2008-0048" severity="Medium" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in AppKit in Apple Mac OS X 10.4.11 allows context-dependent attackers to execute arbitrary code via the a long file name to the NSDocument API.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><range><network/></range><refs><ref patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html">APPLE-SA-2008-03-18</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=307562"></ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1019647">1019647</ref><ref source="BID" url="http://www.securityfocus.com/bid/28388">28388</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA08-079A.html">TA08-079A</ref><ref source="BID" url="http://www.securityfocus.com/bid/28304">28304</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0924/references">ADV-2008-0924</ref><ref source="SECUNIA" url="http://secunia.com/advisories/29420">29420</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.4.11"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.4.11"/></prod></vuln_soft></entry><entry CVSS_base_score="1.9" CVSS_exploit_subscore="3.4" CVSS_impact_subscore="2.9" CVSS_score="1.9" CVSS_vector="(AV:L/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2008-03-25" name="CVE-2008-0049" published="2008-03-18" seq="2008-0049" severity="Low" type="CVE"><desc><descript source="cve">AppKit in Apple Mac OS X 10.4.11 inadvertently makes an NSApplication mach port available for inter-process communication instead of inter-thread communication, which allows local users to execute arbitrary code via crafted messages to privileged applications.</descript></desc><loss_types><int/></loss_types><range><local/></range><refs><ref patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html">APPLE-SA-2008-03-18</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=307562"></ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1019647">1019647</ref><ref source="BID" url="http://www.securityfocus.com/bid/28340">28340</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA08-079A.html">TA08-079A</ref><ref source="BID" url="http://www.securityfocus.com/bid/28304">28304</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0924/references">ADV-2008-0924</ref><ref source="SECUNIA" url="http://secunia.com/advisories/29420">29420</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.4.11"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.4.11"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2008-03-25" name="CVE-2008-0050" published="2008-03-18" seq="2008-0050" severity="Medium" type="CVE"><desc><descript source="cve">CFNetwork in Apple Mac OS X 10.4.11 allows remote HTTPS proxy servers to spoof secure websites via data in a 502 Bad Gateway error.</descript></desc><loss_types><conf/></loss_types><range><network/></range><refs><ref patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html">APPLE-SA-2008-03-18</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=307562"></ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=307563"></ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1019655">1019655</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA08-079A.html">TA08-079A</ref><ref source="BID" url="http://www.securityfocus.com/bid/28290">28290</ref><ref source="BID" url="http://www.securityfocus.com/bid/28356">28356</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0920/references">ADV-2008-0920</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0924/references">ADV-2008-0924</ref><ref source="SECUNIA" url="http://secunia.com/advisories/29420">29420</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.4.11"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.4.11"/></prod></vuln_soft></entry><entry CVSS_base_score="6.9" CVSS_exploit_subscore="3.4" CVSS_impact_subscore="10.0" CVSS_score="6.9" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-03-19" name="CVE-2008-0051" published="2008-03-18" seq="2008-0051" severity="Medium" type="CVE"><desc><descript source="cve">Integer overflow in CoreFoundation in Apple Mac OS X 10.4.11 might allow local users to execute arbitrary code via crafted time zone data.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><local/></range><refs><ref patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html">APPLE-SA-2008-03-18</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=307562"></ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1019670">1019670</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA08-079A.html">TA08-079A</ref><ref source="BID" url="http://www.securityfocus.com/bid/28304">28304</ref><ref source="BID" url="http://www.securityfocus.com/bid/28375">28375</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0924/references">ADV-2008-0924</ref><ref source="SECUNIA" url="http://secunia.com/advisories/29420">29420</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.4.11"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.4.11"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-03-19" name="CVE-2008-0052" published="2008-03-18" seq="2008-0052" severity="Medium" type="CVE"><desc><descript source="cve">CoreServices in Apple Mac OS X 10.4.11 treats .ief as a safe file type, which allows remote attackers to force Safari users into opening an .ief file in AppleWorks, even when the &quot;Open &apos;Safe&apos; files&quot; preference is set.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><range><network/><user_init/></range><refs><ref patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html">APPLE-SA-2008-03-18</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=307562"></ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1019671">1019671</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA08-079A.html">TA08-079A</ref><ref source="BID" url="http://www.securityfocus.com/bid/28304">28304</ref><ref source="BID" url="http://www.securityfocus.com/bid/28384">28384</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0924/references">ADV-2008-0924</ref><ref source="SECUNIA" url="http://secunia.com/advisories/29420">29420</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.4.11"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.4.11"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-04-25" name="CVE-2008-0053" published="2008-03-18" seq="2008-0053" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in the HP-GL/2-to-PostScript filter in CUPS before 1.3.6 might allow remote attackers to execute arbitrary code via a crafted HP-GL/2 file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs><ref patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html">APPLE-SA-2008-03-18</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=307562"></ref><ref source="BID" url="http://www.securityfocus.com/bid/28334">28334</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1019672">1019672</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA08-079A.html">TA08-079A</ref><ref source="BID" url="http://www.securityfocus.com/bid/28304">28304</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0924/references">ADV-2008-0924</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/29420">29420</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200804-01.xml">GLSA-200804-01</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2008-0192.html">RHSA-2008:0192</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2008-0206.html">RHSA-2008:0206</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/29634">29634</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDVSA-2008:081">MDVSA-2008:081</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-598-1">USN-598-1</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/29573">29573</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/29603">29603</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/29630">29630</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/29655">29655</ref><ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2008-April/msg00105.html">FEDORA-2008-2897</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/29750">29750</ref><ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2008-04/msg00003.html">SUSE-SA:2008:020</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/29659">29659</ref></refs><vuln_soft><prod name="CUPS" vendor="cups"><vers num="1.1.23"/><vers num="1.3"/><vers num="1.3.3"/><vers num="1.3.5" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_version="2.0" modified="2008-03-19" name="CVE-2008-0054" published="2008-03-18" seq="2008-0054" severity="Medium" type="CVE"><desc><descript source="cve">Foundation in Apple Mac OS X 10.4.11 might allow context-dependent attackers to execute arbitrary code via a malformed selector name to the NSSelectorFromString API, which causes an &quot;unexpected selector&quot; to be used.</descript></desc><loss_types><avail/><int/></loss_types><range><network/></range><refs><ref patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html">APPLE-SA-2008-03-18</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=307562"></ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1019649">1019649</ref><ref source="BID" url="http://www.securityfocus.com/bid/28341">28341</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA08-079A.html">TA08-079A</ref><ref source="BID" url="http://www.securityfocus.com/bid/28304">28304</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0924/references">ADV-2008-0924</ref><ref source="SECUNIA" url="http://secunia.com/advisories/29420">29420</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.4.11"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.4.11"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-03-19" name="CVE-2008-0055" published="2008-03-18" seq="2008-0055" severity="High" type="CVE"><desc><descript source="cve">Foundation in Apple Mac OS X 10.4.11 creates world-writable directories while NSFileManager copies files recursively and only modifies the permissions afterward, which allows local users to modify copied files to cause a denial of service and possibly gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><local/></range><refs><ref patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html">APPLE-SA-2008-03-18</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=307562"></ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1019649">1019649</ref><ref source="BID" url="http://www.securityfocus.com/bid/28343">28343</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA08-079A.html">TA08-079A</ref><ref source="BID" url="http://www.securityfocus.com/bid/28304">28304</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0924/references">ADV-2008-0924</ref><ref source="SECUNIA" url="http://secunia.com/advisories/29420">29420</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.4.11"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.4.11"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-03-19" name="CVE-2008-0056" published="2008-03-18" seq="2008-0056" severity="Medium" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in Foundation in Apple Mac OS X 10.4.11 allows context-dependent attackers to execute arbitrary code via a &quot;long pathname with an unexpected structure&quot; that triggers the overflow in NSFileManager.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><range><network/></range><refs><ref patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html">APPLE-SA-2008-03-18</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=307562"></ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1019649">1019649</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA08-079A.html">TA08-079A</ref><ref source="BID" url="http://www.securityfocus.com/bid/28304">28304</ref><ref source="BID" url="http://www.securityfocus.com/bid/28357">28357</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0924/references">ADV-2008-0924</ref><ref source="SECUNIA" url="http://secunia.com/advisories/29420">29420</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.4.11"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.4.11"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-03-25" name="CVE-2008-0057" published="2008-03-18" seq="2008-0057" severity="Medium" type="CVE"><desc><descript source="cve">Multiple integer overflows in a &quot;legacy serialization format&quot; parser in AppKit in Apple Mac OS X 10.4.11 allows remote attackers to execute arbitrary code via a crafted serialized property list.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><range><network/><user_init/></range><refs><ref patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html">APPLE-SA-2008-03-18</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=307562"></ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1019648">1019648</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA08-079A.html">TA08-079A</ref><ref source="BID" url="http://www.securityfocus.com/bid/28304">28304</ref><ref source="BID" url="http://www.securityfocus.com/bid/28358">28358</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0924/references">ADV-2008-0924</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.4.11"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.4.11"/></prod></vuln_soft></entry><entry CVSS_base_score="5.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="4.9" CVSS_score="5.8" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:P)" CVSS_version="2.0" modified="2008-03-19" name="CVE-2008-0058" published="2008-03-18" seq="2008-0058" severity="Medium" type="CVE"><desc><descript source="cve">Race condition in the NSURLConnection cache management functionality in Foundation for Apple Mac OS X 10.4.11 allows remote attackers to execute arbitrary code via unspecified manipulations that cause messages to be sent to a deallocated object.</descript></desc><loss_types><avail/><int/></loss_types><range><network/><user_init/></range><refs><ref patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html">APPLE-SA-2008-03-18</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=307562"></ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1019650">1019650</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA08-079A.html">TA08-079A</ref><ref source="BID" url="http://www.securityfocus.com/bid/28304">28304</ref><ref source="BID" url="http://www.securityfocus.com/bid/28359">28359</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0924/references">ADV-2008-0924</ref><ref source="SECUNIA" url="http://secunia.com/advisories/29420">29420</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.4.11"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.4.11"/></prod></vuln_soft></entry><entry CVSS_base_score="5.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="4.9" CVSS_score="5.8" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:P)" CVSS_version="2.0" modified="2008-03-19" name="CVE-2008-0059" published="2008-03-18" seq="2008-0059" severity="Medium" type="CVE"><desc><descript source="cve">Race condition in NSXML in Foundation for Apple Mac OS X 10.4.11 allows context-dependent attackers to execute arbitrary code via a crafted XML file, related to &quot;error handling logic.&quot;</descript></desc><loss_types><avail/><int/></loss_types><range><network/><user_init/></range><refs><ref patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html">APPLE-SA-2008-03-18</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=307562"></ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1019650">1019650</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA08-079A.html">TA08-079A</ref><ref source="BID" url="http://www.securityfocus.com/bid/28304">28304</ref><ref source="BID" url="http://www.securityfocus.com/bid/28367">28367</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0924/references">ADV-2008-0924</ref><ref source="SECUNIA" url="http://secunia.com/advisories/29420">29420</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.4.11"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.4.11"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-03-19" name="CVE-2008-0060" published="2008-03-18" seq="2008-0060" severity="Medium" type="CVE"><desc><descript source="cve">Help Viewer in Apple Mac OS X 10.4.11 and 10.5.2 allows remote attackers to execute arbitrary Applescript via a help:topic_list URL that injects HTML or JavaScript into a topic list page, as demonstrated using a help:runscript link.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><range><network/><user_init/></range><refs><ref patch="1" source="APPLE" url="http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html">APPLE-SA-2008-03-18</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=307562"></ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1019657">1019657</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA08-079A.html">TA08-079A</ref><ref source="BID" url="http://www.securityfocus.com/bid/28304">28304</ref><ref source="BID" url="http://www.securityfocus.com/bid/28371">28371</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0924/references">ADV-2008-0924</ref><ref source="SECUNIA" url="http://secunia.com/advisories/29420">29420</ref></refs><vuln_soft><prod name="Mac OS X Server" vendor="Apple"><vers num="10.4.11"/><vers num="10.5.2"/></prod><prod name="Mac OS X" vendor="Apple"><vers num="10.4.11"/><vers num="10.5.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2008-01-04" name="CVE-2008-0061" published="2008-01-03" seq="2008-0061" severity="Medium" type="CVE"><desc><descript source="cve">MaraDNS 1.0 before 1.0.41, 1.2 before 1.2.12.08, and 1.3 before 1.3.07.04 allows remote attackers to cause a denial of service via a crafted DNS packet that prevents an authoritative name (CNAME) record from resolving, aka &quot;improper rotation of resource records.&quot;</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref source="" url="http://maradns.blogspot.com/2007/08/maradns-update-all-versions.html"></ref><ref source="" url="http://www.maradns.org/changelog.html"></ref><ref source="DEBIAN" url="http://www.debian.org/security/2008/dsa-1445">DSA-1445</ref><ref source="BID" url="http://www.securityfocus.com/bid/27124">27124</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0026">ADV-2008-0026</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28329">28329</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28334">28334</ref><ref source="" url="http://bugs.gentoo.org/show_bug.cgi?id=204351"></ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200801-16.xml">GLSA-200801-16</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28650">28650</ref></refs><vuln_soft><prod name="MaraDNS" vendor="MaraDNS"><vers num="1.2.12.01"/><vers num="1.2.12.02"/><vers num="1.2.12.03"/><vers num="1.2.12.04"/><vers num="1.2.12.05"/><vers num="1.2.12.06"/><vers num="1.2.12.07"/><vers num="1.3.01"/><vers num="1.3.02"/><vers num="1.3.03"/><vers num="1.3.04"/><vers num="1.3.05"/><vers num="1.3.06"/><vers num="1.3.07"/><vers num="1.3.07.01"/><vers num="1.3.07.02"/><vers num="1.3.07.03"/><vers num="1.0.00"/><vers num="1.0.01"/><vers num="1.0.02"/><vers num="1.0.03"/><vers num="1.0.04"/><vers num="1.0.05"/><vers num="1.0.06"/><vers num="1.0.07"/><vers num="1.0.08"/><vers num="1.0.09"/><vers num="1.0.10"/><vers num="1.0.11"/><vers num="1.0.12"/><vers num="1.0.13"/><vers num="1.0.14"/><vers num="1.0.15"/><vers num="1.0.16"/><vers num="1.0.17"/><vers num="1.0.18"/><vers num="1.0.19"/><vers num="1.0.20"/><vers num="1.0.21"/><vers num="1.0.22"/><vers num="1.0.23"/><vers num="1.0.24"/><vers num="1.0.25"/><vers num="1.0.26"/><vers num="1.0.27"/><vers num="1.0.28"/><vers num="1.0.29"/><vers num="1.0.30"/><vers num="1.0.31"/><vers num="1.0.32"/><vers num="1.0.33"/><vers num="1.0.34"/><vers num="1.0.35"/><vers num="1.0.36"/><vers num="1.0.37"/><vers num="1.0.38"/><vers num="1.0.39"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-03-20" name="CVE-2008-0062" published="2008-03-19" seq="2008-0062" severity="High" type="CVE"><desc><descript source="cve">KDC in MIT Kerberos 5 (krb5kdc) does not set a global variable for some krb4 message types, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted messages that trigger a NULL pointer dereference or double-free.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/489761">20080318 MITKRB5-SA-2008-001: double-free, uninitialized data vulnerabilities in krb5kdc</ref><ref patch="1" source="" url="http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2008-001.txt"></ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=307562"></ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html">APPLE-SA-2008-03-18</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/895609">VU#895609</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDVSA-2008:070">MDVSA-2008:070</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDVSA-2008:071">MDVSA-2008:071</ref><ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2008-03/msg00006.html">SUSE-SA:2008:016</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-587-1">USN-587-1</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0922/references">ADV-2008-0922</ref><ref source="SECUNIA" url="http://secunia.com/advisories/29428">29428</ref><ref source="SECUNIA" url="http://secunia.com/advisories/29438">29438</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/489883/100/0/threaded">20080319 rPSA-2008-0112-1 krb5 krb5-server krb5-services krb5-test krb5-workstation</ref><ref source="" url="http://wiki.rpath.com/Advisories:rPSA-2008-0112"></ref><ref source="" url="http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0112"></ref><ref source="DEBIAN" url="http://www.debian.org/security/2008/dsa-1524">DSA-1524</ref><ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2008-March/msg00537.html">FEDORA-2008-2637</ref><ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2008-March/msg00544.html">FEDORA-2008-2647</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200803-31.xml">GLSA-200803-31</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDVSA-2008:069">MDVSA-2008:069</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2008-0164.html">RHSA-2008:0164</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2008-0180.html">RHSA-2008:0180</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2008-0181.html">RHSA-2008:0181</ref><ref source="BID" url="http://www.securityfocus.com/bid/28303">28303</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0924/references">ADV-2008-0924</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1019626">1019626</ref><ref source="SECUNIA" url="http://secunia.com/advisories/29420">29420</ref><ref source="SECUNIA" url="http://secunia.com/advisories/29435">29435</ref><ref source="SECUNIA" url="http://secunia.com/advisories/29450">29450</ref><ref source="SECUNIA" url="http://secunia.com/advisories/29451">29451</ref><ref source="SECUNIA" url="http://secunia.com/advisories/29457">29457</ref><ref source="SECUNIA" url="http://secunia.com/advisories/29464">29464</ref><ref source="SECUNIA" url="http://secunia.com/advisories/29423">29423</ref><ref source="SECUNIA" url="http://secunia.com/advisories/29462">29462</ref><ref source="SECUNIA" url="http://secunia.com/advisories/29516">29516</ref><ref source="" url="http://support.novell.com/docs/Readmes/InfoDocument/patchbuilder/readme_5022520.html"></ref><ref source="" url="http://support.novell.com/docs/Readmes/InfoDocument/patchbuilder/readme_5022542.html"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/1102/references">ADV-2008-1102</ref><ref source="SECUNIA" url="http://secunia.com/advisories/29663">29663</ref><ref source="SECUNIA" url="http://secunia.com/advisories/29424">29424</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2008-0182.html">RHSA-2008:0182</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/493080/100/0/threaded">20080604 VMSA-2008-0009 Updates to VMware Workstation, VMware Player, VMware ACE, VMware Fusion, VMware Server, VMware VIX API, VMware ESX, VMware ESXi resolve critical security issues</ref><ref source="" url="http://www.vmware.com/security/advisories/VMSA-2008-0009.html"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/1744">ADV-2008-1744</ref><ref source="SECUNIA" url="http://secunia.com/advisories/30535">30535</ref></refs><vuln_soft><prod name="Kerberos 5" vendor="MIT"><vers num="1.6.3_KDC" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2008-03-25" name="CVE-2008-0063" published="2008-03-19" seq="2008-0063" severity="Medium" type="CVE"><desc><descript source="cve">The Kerberos 4 support in KDC in MIT Kerberos 5 (krb5kdc) does not properly clear the unused portion of a buffer when generating an error message, which might allow remote attackers to obtain sensitive information, aka &quot;Uninitialized stack values.&quot;</descript></desc><loss_types><conf/></loss_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/489761">20080318 MITKRB5-SA-2008-001: double-free, uninitialized data vulnerabilities in krb5kdc</ref><ref patch="1" source="" url="http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2008-001.txt"></ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=307562"></ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html">APPLE-SA-2008-03-18</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDVSA-2008:070">MDVSA-2008:070</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDVSA-2008:071">MDVSA-2008:071</ref><ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2008-03/msg00006.html">SUSE-SA:2008:016</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-587-1">USN-587-1</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0922/references">ADV-2008-0922</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/29428">29428</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/29438">29438</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/489883/100/0/threaded">20080319 rPSA-2008-0112-1 krb5 krb5-server krb5-services krb5-test krb5-workstation</ref><ref source="" url="http://wiki.rpath.com/Advisories:rPSA-2008-0112"></ref><ref source="" url="http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0112"></ref><ref source="DEBIAN" url="http://www.debian.org/security/2008/dsa-1524">DSA-1524</ref><ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2008-March/msg00537.html">FEDORA-2008-2637</ref><ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2008-March/msg00544.html">FEDORA-2008-2647</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200803-31.xml">GLSA-200803-31</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDVSA-2008:069">MDVSA-2008:069</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2008-0164.html">RHSA-2008:0164</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2008-0180.html">RHSA-2008:0180</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2008-0181.html">RHSA-2008:0181</ref><ref source="BID" url="http://www.securityfocus.com/bid/28303">28303</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0924/references">ADV-2008-0924</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1019627">1019627</ref><ref source="SECUNIA" url="http://secunia.com/advisories/29420">29420</ref><ref source="SECUNIA" url="http://secunia.com/advisories/29435">29435</ref><ref source="SECUNIA" url="http://secunia.com/advisories/29450">29450</ref><ref source="SECUNIA" url="http://secunia.com/advisories/29451">29451</ref><ref source="SECUNIA" url="http://secunia.com/advisories/29457">29457</ref><ref source="SECUNIA" url="http://secunia.com/advisories/29464">29464</ref><ref source="SECUNIA" url="http://secunia.com/advisories/29423">29423</ref><ref source="SECUNIA" url="http://secunia.com/advisories/29462">29462</ref><ref source="SECUNIA" url="http://secunia.com/advisories/29516">29516</ref><ref source="" url="http://support.novell.com/docs/Readmes/InfoDocument/patchbuilder/readme_5022520.html"></ref><ref source="" url="http://support.novell.com/docs/Readmes/InfoDocument/patchbuilder/readme_5022542.html"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/1102/references">ADV-2008-1102</ref><ref source="SECUNIA" url="http://secunia.com/advisories/29663">29663</ref><ref source="SECUNIA" url="http://secunia.com/advisories/29424">29424</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2008-0182.html">RHSA-2008:0182</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/493080/100/0/threaded">20080604 VMSA-2008-0009 Updates to VMware Workstation, VMware Player, VMware ACE, VMware Fusion, VMware Server, VMware VIX API, VMware ESX, VMware ESXi resolve critical security issues</ref><ref source="" url="http://www.vmware.com/security/advisories/VMSA-2008-0009.html"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/1744">ADV-2008-1744</ref><ref source="SECUNIA" url="http://secunia.com/advisories/30535">30535</ref></refs><vuln_soft><prod name="Kerberos 5" vendor="MIT"><vers num="1.6.3_KDC" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-08-07" name="CVE-2008-0064" published="2008-01-31" seq="2008-0064" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in Pierre-emmanuel Gougelet (1) XnView 1.91 and 1.92, (2) NConvert 4.85, and (3) libgfl280.dll in GFL SDK 2.870 for Windows allows user-assisted remote attackers to execute arbitrary code via a crafted Radiance RGBE (.hdr) file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/><user_init/></range><refs><ref adv="1" source="" url="http://secunia.com/secunia_research/2008-1/advisory"></ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/28326">28326</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28710">28710</ref><ref source="BID" url="http://www.securityfocus.com/bid/27514">27514</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0328">ADV-2008-0328</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0329">ADV-2008-0329</ref></refs><vuln_soft><prod name="XnView" vendor="PierreEGougelet"><vers num="1.91" prev="1"/><vers num="1.92" prev="1"/></prod><prod name="NConvert" vendor="PierreEGougelet"><vers num="4.85" prev="1"/></prod><prod name="GFL SDK" vendor="PierreEGougelet"><vers edition="unknown" num="2.870"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-01-23" name="CVE-2008-0065" published="2008-01-22" seq="2008-0065" severity="High" type="CVE"><desc><descript source="cve">Multiple stack-based buffer overflows in in_mp3.dll in Winamp 5.21, 5.5, and 5.51 allow remote attackers to execute arbitrary code via a long (1) artist or (2) name tag in Ultravox streaming metadata, related to construction of stream titles.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs><ref source="" url="http://secunia.com/secunia_research/2008-2/advisory/"></ref><ref source="" url="http://www.winamp.com/player/version-history"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0183">ADV-2008-0183</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/27865">27865</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39778">winamp-inmp3-bo(39778)</ref><ref source="BID" url="http://www.securityfocus.com/bid/27344">27344</ref></refs><vuln_soft><prod name="Nullsoft Winamp" vendor="Winamp"><vers num="5.21"/><vers num="5.5"/><vers num="5.51"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-04-10" name="CVE-2008-0066" published="2008-04-10" seq="2008-0066" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in htmsr.dll in the HTML speed reader in Autonomy (formerly Verity) KeyView, as used by IBM Lotus Notes 7.0.2 and 7.0.3, allow remote attackers to execute arbitrary code via an HTML document with (1) &quot;large chunks of data,&quot; or a long URL in the (2) BACKGROUND attribute of a BODY element or (3) SRC attribute of an IMG element.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/><user_init/></range><refs><ref adv="1" source="" url="http://secunia.com/secunia_research/2008-3/advisory/"></ref><ref source="" url="http://www-1.ibm.com/support/docview.wss?rs=463&amp;uid=swg21298453"></ref><ref source="BID" url="http://www.securityfocus.com/bid/28454">28454</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/1153">ADV-2008-1153</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/1156">ADV-2008-1156</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28140">28140</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28209">28209</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28210">28210</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/490828/100/0/threaded">20080414 Secunia Research: Lotus Notes htmsr.dll Buffer Overflows</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1019843">1019843</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/41724">autonomy-keyview-html-multiple-bo(41724)</ref></refs><vuln_soft><prod name="KeyView" vendor="Autonomy"><vers num=""/></prod><prod name="Lotus Notes" vendor="IBM"><vers num="6.0"/><vers num="6.5"/><vers num="7.0"/><vers num="8.0"/><vers num="8.0.1"/><vers num="7.0.2"/><vers num="7.0.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2008-04-17" name="CVE-2008-0068" published="2008-04-16" seq="2008-0068" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in OpenView5.exe in HP OpenView Network Node Manager (OV NNM) 7.51, 7.53, and possibly other versions allows remote attackers to read arbitrary files via directory traversal sequences in the Action parameter.</descript></desc><loss_types><conf/></loss_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/490834/100/0/threaded">20080414 Secunia Research: HP OpenView Network Node Manager OpenView5.exeDirectory Traversal</ref><ref source="" url="http://aluigi.altervista.org/adv/closedviewx-adv.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/28745">28745</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/1214/references">ADV-2008-1214</ref><ref source="OSVDB" url="http://www.osvdb.org/44359">44359</ref><ref source="" url="http://secunia.com/secunia_research/2008-4/advisory/"></ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1019838">1019838</ref><ref source="SECUNIA" url="http://secunia.com/advisories/29796">29796</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1019839">1019839</ref></refs><vuln_soft><prod name="openview_network_node_manager" vendor="HP"><vers num="7.51"/><vers num="7.53"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-08-07" name="CVE-2008-0069" published="2008-04-02" seq="2008-0069" severity="Medium" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in XnView 1.92 and 1.92.1 allows user-assisted remote attackers to execute arbitrary code via a long FontName parameter in a slideshow (.sld) file, a different vector than CVE-2008-1461.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/><user_init/></range><refs><ref adv="1" source="" url="http://secunia.com/secunia_research/2008-6/advisory/"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/1044/references">ADV-2008-1044</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/29620">29620</ref><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/5346">5346</ref><ref source="BID" url="http://www.securityfocus.com/bid/28579">28579</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/41542">xnview-slideshow-bo(41542)</ref></refs><vuln_soft><prod name="XnView" vendor="PierreEGougelet"><vers num="1.92" prev="1"/><vers num="1.92.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-03-31" name="CVE-2008-0070" published="2008-03-31" seq="2008-0070" severity="Medium" type="CVE"><desc><descript source="cve">Integer overflow in Orb Networks Orb 2.00.1014 and Winamp Remote BETA allows remote attackers to execute arbitrary code via an RPC request that specifies a large number of array dimensions, which triggers a heap-based buffer overflow.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><range><local/></range><refs><ref adv="1" source="" url="http://secunia.com/secunia_research/2008-5/advisory/"></ref><ref source="BID" url="http://www.securityfocus.com/bid/28431">28431</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0984/references">ADV-2008-0984</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28203">28203</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/41410">orb-dimensions-bo(41410)</ref></refs><vuln_soft><prod name="Orb" vendor="Orb Networks"><vers num="2.0.1014"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2008-06-20" name="CVE-2008-0071" published="2008-06-16" seq="2008-0071" severity="Medium" type="CVE"><desc><descript source="cve">The Web UI interface in (1) BitTorrent before 6.0.3 build 8642 and (2) uTorrent before 1.8beta build 10524 allows remote attackers to cause a denial of service (application crash) via an HTTP request with a malformed Range header.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/493269/100/0/threaded">20080611 Secunia Research: uTorrent / BitTorrent Web UI HTTP </ref><ref adv="1" source="" url="http://secunia.com/secunia_research/2008-7/advisory/"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/29661">29661</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/1808">ADV-2008-1808</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/1809">ADV-2008-1809</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1020266">1020266</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28703">28703</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/30605">30605</ref></refs><vuln_soft><prod name="BitTorrent" vendor="BitTorrent"><vers num="6.0.1"/><vers num="3.9.1"/><vers num="4.0.0"/><vers num="4.0.1"/><vers num="4.0.2"/><vers num="4.0.3"/><vers num="4.0.4"/><vers num="4.1.0"/><vers num="4.1.1"/><vers num="4.1.2"/><vers num="4.1.3"/><vers num="4.1.4"/><vers num="4.1.5"/><vers num="4.1.6"/><vers num="4.1.7"/><vers num="4.1.8"/><vers num="4.2.0"/><vers num="4.2.1"/><vers num="4.2.2"/><vers num="4.20.0"/><vers num="4.20.1"/><vers num="4.20.2"/><vers num="4.20.4"/><vers num="4.20.6"/><vers num="4.20.7"/><vers num="4.20.8"/><vers num="4.20.9"/><vers num="4.22.0"/><vers num="4.22.1"/><vers num="4.22.4"/><vers num="4.24.0"/><vers num="4.24.2"/><vers num="4.26.0"/><vers num="4.27.1"/><vers num="4.27.2"/><vers num="4.3.0"/><vers num="4.3.1"/><vers num="4.3.2"/><vers num="4.3.3"/><vers num="4.3.4"/><vers num="4.3.5"/><vers num="4.3.6"/><vers num="4.4.0"/><vers num="4.4.1"/><vers num="4.9.2"/><vers num="4.9.3"/><vers num="4.9.4"/><vers num="4.9.5"/><vers num="4.9.6"/><vers num="4.9.7"/><vers num="4.9.8"/><vers num="4.9.9"/><vers num="5.0.0"/><vers num="5.0.1"/><vers num="5.0.2"/><vers num="5.0.3"/><vers num="5.0.4"/><vers num="5.0.5"/><vers num="5.0.6"/><vers num="5.0.7"/><vers num="5.0.8"/><vers num="5.0.9"/><vers num="5.2.0"/><vers num="6.0"/><vers num="6.0.2" prev="1"/></prod><prod name="uTorrent" vendor="uTorrent"><vers num="1.7.7" prev="1"/><vers num="1.7"/><vers num="1.7.1"/><vers num="1.7.2"/><vers num="1.7.3"/><vers num="1.7.4"/><vers num="1.7.5"/><vers num="1.7.6"/><vers num="1.1.1"/><vers num="1.1.3"/><vers num="1.1.4"/><vers num="1.1.5"/><vers num="1.1.6"/><vers num="1.1.7"/><vers num="1.2"/><vers num="1.2.1"/><vers num="1.2.2"/><vers num="1.3"/><vers num="1.4"/><vers num="1.4.2"/><vers num="1.5"/><vers num="1.6"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-04-01" name="CVE-2008-0072" published="2008-03-05" seq="2008-0072" severity="Medium" type="CVE"><desc><descript source="cve">Format string vulnerability in the emf_multipart_encrypted function in mail/em-format.c in Evolution 2.12.3 and earlier allows remote attackers to execute arbitrary code via a crafted encrypted message, as demonstrated using the Version field.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><range><network/><user_init/></range><refs><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2008-0178.html">RHSA-2008:0178</ref><ref source="" url="http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0105"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/30437">30437</ref><ref source="SECUNIA" url="http://secunia.com/advisories/30491">30491</ref><ref adv="1" source="" url="http://secunia.com/secunia_research/2008-8/advisory/"></ref><ref patch="1" source="DEBIAN" url="http://www.debian.org/security/2008/dsa-1512">DSA-1512</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2008-0177.html">RHSA-2008:0177</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-583-1">USN-583-1</ref><ref source="BID" url="http://www.securityfocus.com/bid/28102">28102</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0768/references">ADV-2008-0768</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/29057">29057</ref><ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2008-March/msg00190.html">FEDORA-2008-2290</ref><ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2008-March/msg00195.html">FEDORA-2008-2292</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200803-12.xml">GLSA-200803-12</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDVSA-2008:063">MDVSA-2008:063</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1019540">1019540</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/29163">29163</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/29210">29210</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/29244">29244</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/29258">29258</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/29264">29264</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/41011">evolution-emfmultipart-format-string(41011)</ref><ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2008-03/msg00003.html">SUSE-SA:2008:014</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/29317">29317</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/512491">VU#512491</ref></refs><vuln_soft><prod name="Evolution" vendor="GNOME"><vers num="2.12.3" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-03-25" name="CVE-2008-0073" published="2008-03-24" seq="2008-0073" severity="Medium" type="CVE"><desc><descript source="cve">Array index error in the sdpplin_parse function in input/libreal/sdpplin.c in xine-lib 1.1.10.1 allows remote RTSP servers to execute arbitrary code via a large streamid SDP parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><range><network/><user_init/></range><refs><ref adv="1" source="" url="http://secunia.com/secunia_research/2008-10/"></ref><ref patch="1" source="" url="http://sourceforge.net/project/shownotes.php?release_id=585488&amp;group_id=9655"></ref><ref patch="1" source="" url="http://xinehq.de/index.php/news"></ref><ref source="BID" url="http://www.securityfocus.com/bid/28312">28312</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0923">ADV-2008-0923</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28694">28694</ref><ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2008-March/msg00456.html">FEDORA-2008-2569</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1019682">1019682</ref><ref source="SECUNIA" url="http://secunia.com/advisories/29472">29472</ref><ref source="DEBIAN" url="http://www.debian.org/security/2008/dsa-1536">DSA-1536</ref><ref source="SLACKWARE" url="http://www.slackware.org/security/viewer.php?l=slackware-security&amp;y=2008&amp;m=slackware-security.392408">SSA:2008-089-03</ref><ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2008-03/msg00008.html">SUSE-SR:2008:007</ref><ref source="SECUNIA" url="http://secunia.com/advisories/29392">29392</ref><ref source="SECUNIA" url="http://secunia.com/advisories/29578">29578</ref><ref source="SECUNIA" url="http://secunia.com/advisories/29601">29601</ref><ref source="DEBIAN" url="http://www.debian.org/security/2008/dsa-1543">DSA-1543</ref><ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2008-April/msg00143.html">FEDORA-2008-2945</ref><ref source="SECUNIA" url="http://secunia.com/advisories/29766">29766</ref><ref source="SECUNIA" url="http://secunia.com/advisories/29740">29740</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200804-25.xml">GLSA-200804-25</ref><ref source="" url="http://wiki.videolan.org/Changelog/0.8.6f"></ref><ref source="" url="http://www.videolan.org/security/sa0803.php"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/29800">29800</ref><ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2008-06/msg00001.html">SUSE-SR:2008:012</ref></refs><vuln_soft><prod name="xine-lib" vendor="xine"><vers num="1.1.10.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-02-12" name="CVE-2008-0074" published="2008-02-12" seq="2008-0074" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Microsoft Internet Information Services (IIS) 5.0 through 7.0 allows local users to gain privileges via unknown vectors related to file change notifications in the TPRoot, NNTPFile\Root, or WWWRoot folders.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><local/></range><refs><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA08-043C.html">TA08-043C</ref><ref source="BID" url="http://www.securityfocus.com/bid/27101">27101</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0507/references">ADV-2008-0507</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1019384">1019384</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28849">28849</ref><ref source="HP" url="http://marc.info/?l=bugtraq&amp;m=120361015026386&amp;w=2">HPSBST02314</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5389">oval:org.mitre.oval:def:5389</ref></refs><vuln_soft><prod name="IIS" vendor="Microsoft"><vers num="5.0"/><vers num="5.1"/><vers num="6.0"/><vers num="6.0 beta"/><vers num="6.0_beta"/><vers num="7.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-02-12" name="CVE-2008-0075" published="2008-02-12" seq="2008-0075" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Microsoft Internet Information Services (IIS) 5.1 through 6.0 allows remote attackers to execute arbitrary code via crafted inputs to ASP pages.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA08-043C.html">TA08-043C</ref><ref source="BID" url="http://www.securityfocus.com/bid/27676">27676</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0508/references">ADV-2008-0508</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1019385">1019385</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28893">28893</ref><ref source="HP" url="http://marc.info/?l=bugtraq&amp;m=120361015026386&amp;w=2">HPSBST02314</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5308">oval:org.mitre.oval:def:5308</ref></refs><vuln_soft><prod name="IIS" vendor="Microsoft"><vers num="5.1"/><vers num="6.0"/><vers num="6.0 beta"/><vers num="6.0_beta"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-02-13" name="CVE-2008-0076" published="2008-02-12" seq="2008-0076" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Microsoft Internet Explorer 5.01, 6 SP1 and SP2, and 7 allows remote attackers to execute arbitrary code via crafted HTML layout combinations, aka &quot;HTML Rendering Memory Corruption Vulnerability.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/><user_init/></range><refs><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms08-010.mspx">MS08-010</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA08-043C.html">TA08-043C</ref><ref source="BID" url="http://www.securityfocus.com/bid/27668">27668</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0512/references">ADV-2008-0512</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1019379">1019379</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28903">28903</ref><ref source="HP" url="http://marc.info/?l=bugtraq&amp;m=120361015026386&amp;w=2">HPSBST02314</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5487">oval:org.mitre.oval:def:5487</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers edition="Windows 2000 SP4" num="5.01"/><vers edition="Windows Server 2003 SP1" num="6"/><vers edition="Windows XP SP2" num="7"/><vers edition="Windows Server 2003 SP1 Itanium" num="6"/><vers edition="Windows XP SP2" num="6"/><vers edition="Windows XP Professional x64 Edition" num="6"/><vers edition="Windows XP Professional x64 Edition SP2" num="6"/><vers edition="Windows Server 2003 SP2" num="6"/><vers edition="Windows Server 2003 x64 Edition" num="6"/><vers edition="Windows Server 2003 x64 Edition SP2" num="6"/><vers edition="Windows Server 2003 SP2 Itanium" num="6"/><vers edition="Windows Server 2003 SP1" num="7"/><vers edition="Windows XP Professional x64 Edition" num="7"/><vers edition="Windows XP Professional x64 Edition SP2" num="7"/><vers edition="Windows Server 2003 SP2" num="7"/><vers edition="Windows Server 2003 x64 Edition" num="7"/><vers edition="Windows Server 2003 x64 Edition SP2" num="7"/><vers edition="Windows Server 2003 SP1 Itanium" num="7"/><vers edition="Windows Server 2003 SP2 Itanium" num="7"/><vers edition="Windows Vista" num="7"/><vers edition="Windows Vista x64" num="7"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-02-14" name="CVE-2008-0077" published="2008-02-12" seq="2008-0077" severity="High" type="CVE"><desc><descript source="cve">Use-after-free vulnerability in Microsoft Internet Explorer 6 SP1, 6 SP2, and and 7 allows remote attackers to execute arbitrary code by assigning malformed values to certain properties, as demonstrated using the by property of an animateMotion SVG element, aka &quot;Property Memory Corruption Vulnerability.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/><user_init/></range><refs><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms08-010.mspx">MS08-010</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA08-043C.html">TA08-043C</ref><ref source="BID" url="http://www.securityfocus.com/bid/27666">27666</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0512/references">ADV-2008-0512</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1019380">1019380</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28903">28903</ref><ref source="IDEFENSE" url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=661">20080212 Microsoft Internet Explorer Property Memory Corruption Vulnerability</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/488048/100/0/threaded">20080213 ZDI-08-006: Microsoft Internet Explorer SVG animateMotion.by Code Execution Vulnerability</ref><ref source="" url="http://www.zerodayinitiative.com/advisories/ZDI-08-006.html"></ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/228569">VU#228569</ref><ref source="HP" url="http://marc.info/?l=bugtraq&amp;m=120361015026386&amp;w=2">HPSBST02314</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5396">oval:org.mitre.oval:def:5396</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers edition="Windows 2000 SP4" num="5.01"/><vers edition="Windows Server 2003 SP1" num="6"/><vers edition="Windows XP SP2" num="7"/><vers edition="Windows Server 2003 SP1 Itanium" num="6"/><vers edition="Windows XP SP2" num="6"/><vers edition="Windows XP Professional x64 Edition" num="6"/><vers edition="Windows XP Professional x64 Edition SP2" num="6"/><vers edition="Windows Server 2003 SP2" num="6"/><vers edition="Windows Server 2003 x64 Edition" num="6"/><vers edition="Windows Server 2003 x64 Edition SP2" num="6"/><vers edition="Windows Server 2003 SP2 Itanium" num="6"/><vers edition="Windows Server 2003 SP1" num="7"/><vers edition="Windows XP Professional x64 Edition" num="7"/><vers edition="Windows XP Professional x64 Edition SP2" num="7"/><vers edition="Windows Server 2003 SP2" num="7"/><vers edition="Windows Server 2003 x64 Edition" num="7"/><vers edition="Windows Server 2003 x64 Edition SP2" num="7"/><vers edition="Windows Server 2003 SP1 Itanium" num="7"/><vers edition="Windows Server 2003 SP2 Itanium" num="7"/><vers edition="Windows Vista" num="7"/><vers edition="Windows Vista x64" num="7"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-02-13" name="CVE-2008-0078" published="2008-02-12" seq="2008-0078" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in an ActiveX control (dxtmsft.dll) in Microsoft Internet Explorer 5.01, 6 SP1 and SP2, and 7 allows remote attackers to execute arbitrary code via a crafted image, aka &quot;Argument Handling Memory Corruption Vulnerability.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/><user_init/></range><refs><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms08-010.mspx">MS08-010</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA08-043C.html">TA08-043C</ref><ref source="BID" url="http://www.securityfocus.com/bid/27689">27689</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0512/references">ADV-2008-0512</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1019381">1019381</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28903">28903</ref><ref source="HP" url="http://marc.info/?l=bugtraq&amp;m=120361015026386&amp;w=2">HPSBST02314</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4904">oval:org.mitre.oval:def:4904</ref></refs><vuln_soft><prod name="ActiveX" vendor="Microsoft"><vers num=""/></prod><prod name="Internet Explorer" vendor="Microsoft"><vers edition="Windows 2000 SP4" num="5.01"/><vers edition="Windows Server 2003 SP1" num="6"/><vers edition="Windows XP SP2" num="7"/><vers edition="Windows Server 2003 SP1 Itanium" num="6"/><vers edition="Windows XP SP2" num="6"/><vers edition="Windows XP Professional x64 Edition" num="6"/><vers edition="Windows XP Professional x64 Edition SP2" num="6"/><vers edition="Windows Server 2003 SP2" num="6"/><vers edition="Windows Server 2003 x64 Edition" num="6"/><vers edition="Windows Server 2003 x64 Edition SP2" num="6"/><vers edition="Windows Server 2003 SP2 Itanium" num="6"/><vers edition="Windows Server 2003 SP1" num="7"/><vers edition="Windows XP Professional x64 Edition" num="7"/><vers edition="Windows XP Professional x64 Edition SP2" num="7"/><vers edition="Windows Server 2003 SP2" num="7"/><vers edition="Windows Server 2003 x64 Edition" num="7"/><vers edition="Windows Server 2003 x64 Edition SP2" num="7"/><vers edition="Windows Server 2003 SP1 Itanium" num="7"/><vers edition="Windows Server 2003 SP2 Itanium" num="7"/><vers edition="Windows Vista" num="7"/><vers edition="Windows Vista x64" num="7"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-02-13" name="CVE-2008-0080" published="2008-02-12" seq="2008-0080" severity="High" type="CVE"><desc><descript source="cve">Heap-based buffer overflow in the WebDAV Mini-Redirector in Microsoft Windows XP SP2, Server 2003 SP1 and SP2, and Vista allows remote attackers to execute arbitrary code via a crafted WebDAV response.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms08-007.mspx">MS08-007</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA08-043C.html">TA08-043C</ref><ref source="BID" url="http://www.securityfocus.com/bid/27670">27670</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0509/references">ADV-2008-0509</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1019372">1019372</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28894">28894</ref><ref source="HP" url="http://marc.info/?l=bugtraq&amp;m=120361015026386&amp;w=2">HPSBST02314</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5381">oval:org.mitre.oval:def:5381</ref></refs><vuln_soft><prod name="WebDAV Mini-Redirector" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-03-21" name="CVE-2008-0081" published="2008-01-16" seq="2008-0081" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Microsoft Excel 2000 SP3 through 2003 SP2, Viewer 2003, and Office 2004 for Mac allows user-assisted remote attackers to execute arbitrary code via crafted macros, aka &quot;Macro Validation Vulnerability,&quot; a different vulnerability than CVE-2007-3490.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref patch="1" source="" url="http://www.microsoft.com/technet/security/advisory/947563.mspx"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/27305">27305</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0146">ADV-2008-0146</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1019200">1019200</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39699">microsoft-excel-unspecified-code-execution(39699)</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28506">28506</ref><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms08-014.mspx">MS08-014</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0846/references">ADV-2008-0846</ref><ref source="HP" url="http://marc.info/?l=bugtraq&amp;m=120585858807305&amp;w=2">HPSBST02320</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA08-071A.html">TA08-071A</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5546">oval:org.mitre.oval:def:5546</ref></refs><vuln_soft><prod name="Excel Viewer" vendor="Microsoft"><vers num="2003"/></prod><prod name="Office" vendor="Microsoft"><vers num="2004"/></prod><prod name="Excel" vendor="Microsoft"><vers num="2000 sp3"/><vers num="2002"/><vers num="2003_sp2"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-08-14" name="CVE-2008-0082" published="2008-08-12" seq="2008-0082" severity="High" type="CVE"><desc><descript source="cve">An ActiveX control (Messenger.UIAutomation.1) in Windows Messenger 4.7 and 5.1 is marked as safe-for-scripting, which allows remote attackers to &quot;change state,&quot; obtain contact information, and establish audio or video connections without notification via unknown vectors.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms08-050.mspx">MS08-050</ref><ref source="BID" url="http://www.securityfocus.com/bid/30551">30551</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/2354">ADV-2008-2354</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1020681">1020681</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/31446">31446</ref></refs><vuln_soft><prod name="Windows Messenger" vendor="Microsoft"><vers num="4.7"/><vers num="5.1"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-04-15" name="CVE-2008-0083" published="2008-04-08" seq="2008-0083" severity="High" type="CVE"><desc><descript source="cve">The (1) VBScript (VBScript.dll) and (2) JScript (JScript.dll) scripting engines 5.1 and 5.6, as used in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 SP1 and SP2, do not properly decode script, which allows remote attackers to execute arbitrary code via unknown vectors.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/><user_init/></range><refs><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms08-022.mspx">MS08-022</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/28551">28551</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/1146/references">ADV-2008-1146</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1019799">1019799</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/29712">29712</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA08-099A.html">TA08-099A</ref><ref source="HP" url="http://marc.info/?l=bugtraq&amp;m=120845064910729&amp;w=2">HPSBST02329</ref></refs><vuln_soft><prod name="windows-nt" vendor="Microsoft"><vers edition="sp4" num="2000"/><vers edition="sp2" num="XP"/><vers edition="sp1" num="2003"/><vers edition="sp2" num="2003"/><vers edition="sp2" num="2003"/><vers edition="unknown" num="2003"/><vers edition="sp2" num="2003"/><vers edition="sp1" num="2003"/><vers edition="unknown" num="XP"/><vers edition="sp2" num="XP"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2008-02-12" name="CVE-2008-0084" published="2008-02-12" seq="2008-0084" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the TCP/IP support in Microsoft Windows Vista allows remote DHCP servers to cause a denial of service (hang and restart) via a crafted DHCP packet.</descript></desc><sols><sol source="nvd">Apply patches.

Windows Vista:
http://www.microsoft.com/downloads/de...=8ce9608b-7049-47cd-adc4-22a803877d33

Windows Vista x64 Edition:
http://www.microsoft.com/downloads/de...=d7b9c3d1-9c23-4e05-bac6-d0b327feaf53</sol></sols><loss_types><avail/></loss_types><range><network/></range><refs><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA08-043C.html">TA08-043C</ref><ref source="BID" url="http://www.securityfocus.com/bid/27634">27634</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0506/references">ADV-2008-0506</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1019383">1019383</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28828">28828</ref><ref source="HP" url="http://marc.info/?l=bugtraq&amp;m=120361015026386&amp;w=2">HPSBST02314</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5240">oval:org.mitre.oval:def:5240</ref></refs><vuln_soft><prod name="windows-nt" vendor="Microsoft"><vers num="vista"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2008-07-14" name="CVE-2008-0085" published="2008-07-08" seq="2008-0085" severity="Medium" type="CVE"><desc><descript source="cve">Microsoft SQL Server 7.0 SP4, 2000 SP4, 2005 SP2, Microsoft Data Engine (MSDE) 1.0 SP4, SQL Server 2000 Desktop Engine (MSDE 2000) SP4, and 2005 Express Edition SP2 does not initialize memory pages when reallocating memory, which allows database operators to obtain sensitive information (database contents) via unknown vectors related to memory page reuse.</descript></desc><loss_types><conf/></loss_types><range><network/></range><refs><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms08-040.mspx">MS08-040</ref></refs><vuln_soft><prod name="Data Engine" vendor="Microsoft"><vers edition="sp4" num="1.0"/></prod><prod name="SQL Server Desktop Engine" vendor="Microsoft"><vers edition="sp4" num="2000"/></prod><prod name="sql_server" vendor="Microsoft"><vers edition="sp4" num="7.0"/><vers edition="sp4" num="2000"/><vers edition="sp2" num="2005"/></prod></vuln_soft></entry><entry CVSS_base_score="9.0" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="10.0" CVSS_score="9.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-07-14" name="CVE-2008-0086" published="2008-07-08" seq="2008-0086" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the convert function in Microsoft SQL Server 7.0 SP4, 2000 SP4, 2005 SP2, Microsoft Data Engine (MSDE) 1.0 SP4, SQL Server 2000 Desktop Engine (MSDE 2000) SP4, and 2005 Express Edition SP2 allows remote authenticated users to execute arbitrary code via a crafted SQL expression.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms08-040.mspx">MS08-040</ref></refs><vuln_soft><prod name="sql_server_desktop_engine" vendor="Microsoft"><vers edition="sp4" num="2000"/></prod><prod name="data_engine" vendor="Microsoft"><vers edition="sp4" num="1.0"/></prod><prod name="sql_server_express_edition" vendor="Microsoft"><vers edition="sp2" num="2005"/></prod><prod name="sql_server" vendor="Microsoft"><vers edition="sp4" num="7.0"/><vers edition="sp4" num="2000"/><vers edition="sp2" num="2005"/></prod></vuln_soft></entry><entry CVSS_base_score="8.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="9.2" CVSS_score="8.8" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:C/A:C)" CVSS_version="2.0" modified="2008-04-09" name="CVE-2008-0087" published="2008-04-08" seq="2008-0087" severity="High" type="CVE"><desc><descript source="cve">The DNS client in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, and Vista uses predictable DNS transaction IDs, which allows remote attackers to spoof DNS responses.</descript></desc><loss_types><avail/><int/></loss_types><range><network/></range><refs><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms08-020.mspx">MS08-020</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/28553">28553</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/1144/references">ADV-2008-1144</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1019802">1019802</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/29696">29696</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA08-099A.html">TA08-099A</ref><ref source="HP" url="http://marc.info/?l=bugtraq&amp;m=120845064910729&amp;w=2">HPSBST02329</ref></refs><vuln_soft><prod name="windows-nt" vendor="Microsoft"><vers edition="sp4" num="2000"/><vers edition="unknown" num="XP"/><vers edition="sp2" num="XP"/><vers edition="sp1" num="2003"/><vers edition="sp2" num="2003"/><vers edition="sp2" num="2003"/><vers edition="sp1" num="2003"/><vers edition="unknown" num="vista"/><vers edition="unknown" num="vista"/><vers edition="unknown" num="vista"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="6.9" CVSS_score="6.8" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:N/A:C)" CVSS_version="2.0" modified="2008-02-12" name="CVE-2008-0088" published="2008-02-12" seq="2008-0088" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Active Directory on Microsoft Windows 2000 and Windows Server 2003, and Active Directory Application Mode (ADAM) on XP and Server 2003, allows remote attackers to cause a denial of service (hang and restart) via a crafted LDAP request.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms08-003.mspx">MS08-003</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA08-043C.html">TA08-043C</ref><ref source="BID" url="http://www.securityfocus.com/bid/27638">27638</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0505/references">ADV-2008-0505</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1019382">1019382</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28764">28764</ref><ref source="HP" url="http://marc.info/?l=bugtraq&amp;m=120361015026386&amp;w=2">HPSBST02314</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5181">oval:org.mitre.oval:def:5181</ref></refs><vuln_soft><prod name="windows-nt" vendor="Microsoft"><vers num="2000"/><vers num="XP"/></prod><prod name="Windows Server 2003" vendor="Microsoft"><vers num="SP1"/><vers num="SP2"/></prod><prod name="Windows Server 2000" vendor="Microsoft"><vers num="SP4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-01-04" name="CVE-2008-0089" published="2008-01-03" seq="2008-0089" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in uprofile.php in ClipShare allows remote attackers to execute arbitrary SQL commands via the UID parameter.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/4830">4830</ref><ref source="BID" url="http://www.securityfocus.com/bid/27108">27108</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39364">clipshare-uprofile-sql-injection(39364)</ref></refs><vuln_soft><prod name="ClipShare" vendor="Clip-Share"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2008-01-04" name="CVE-2008-0090" published="2008-01-03" seq="2008-0090" severity="Medium" type="CVE"><desc><descript source="cve">A certain ActiveX control in npUpload.dll in DivX Player 6.6.0 allows remote attackers to cause a denial of service (Internet Explorer 7 crash) via a long argument to the SetPassword method.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/4829">4829</ref><ref source="BID" url="http://www.securityfocus.com/bid/27106">27106</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39386">divxwebplayer-npUpload-dos(39386)</ref></refs><vuln_soft><prod name="DivX Player" vendor="DivX"><vers num="6.6.0"/></prod><prod name="Internet Explorer" vendor="Microsoft"><vers num="7"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0" modified="2008-01-04" name="CVE-2008-0091" published="2008-01-03" seq="2008-0091" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in download2.php in AGENCY4NET WEBFTP 1 allows remote attackers to read and delete arbitrary files via a .. (dot dot) in the file parameter.</descript></desc><loss_types><conf/><int/></loss_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/4828">4828</ref><ref source="VIM" url="http://www.attrition.org/pipermail/vim/2008-January/001865.html">20080104 true: AGENCY4NET WEBFTP directory traversal; deletion possible</ref><ref source="BID" url="http://www.securityfocus.com/bid/27092">27092</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0051">ADV-2008-0051</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28309">28309</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39343">agency4net-download2-directory-traversal(39343)</ref></refs><vuln_soft><prod name="WEBFTP" vendor="AGENCY4NET"><vers num="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2008-01-04" name="CVE-2008-0092" published="2008-01-03" seq="2008-0092" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in the search module in Appalachian State University phpWebSite 1.4.0 allows remote attackers to inject arbitrary web script or HTML via the search parameter.</descript></desc><loss_types><int/></loss_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/485704/100/0/threaded">20080101 Cross-Site Scripting (XSS) in phpWebSite 1.4.0 search</ref><ref source="" url="http://phpwebsite.appstate.edu/blog/2143"></ref><ref source="BID" url="http://www.securityfocus.com/bid/27090">27090</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28303">28303</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39391">phpwebsite-search-xss(39391)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/3511">3511</ref></refs><vuln_soft><prod name="phpWebSite" vendor="phpWebsite"><vers num="1.4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2008-01-08" name="CVE-2008-0093" published="2008-01-07" seq="2008-0093" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in newticket.php in eTicket 1.5.5.2, and 1.5.6 RC2 and RC3, allow remote attackers to inject arbitrary web script or HTML via the (1) Name and (2) Subject parameters.</descript></desc><loss_types><int/></loss_types><range><network/><user_init/></range><refs><ref source="" url="http://www.digitrustgroup.com/advisories/web-application-security-eticket.html"></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28331">28331</ref><ref source="BID" url="http://www.securityfocus.com/bid/27130">27130</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39400">eticket-name-subject-xss(39400)</ref></refs><vuln_soft><prod name="eTicket" vendor="eTicket"><vers num="1.5.5.2"/><vers num="1.5.6_RC2"/><vers num="1.5.6_RC3"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0" modified="2008-01-08" name="CVE-2008-0094" published="2008-01-07" seq="2008-0094" severity="Medium" type="CVE"><desc><descript source="cve">Multiple directory traversal vulnerabilities in MODx Content Management System 0.9.6.1 allow remote attackers to (1) include and execute arbitrary local files via a .. (dot dot) in the as_language parameter to assets/snippets/AjaxSearch/AjaxSearch.php, reached through index-ajax.php; and (2) read arbitrary local files via a .. (dot dot) in the file parameter to assets/js/htcmime.php.</descript></desc><loss_types><conf/><int/></loss_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/485707/100/0/threaded">20080102 MODx CMS Source code disclosure, local file inclusion</ref><ref source="" url="http://modxcms.com/forums/index.php/topic,21290.0.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/27096">27096</ref><ref source="BID" url="http://www.securityfocus.com/bid/27097">27097</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/28220">28220</ref><ref source="SREASON" url="http://securityreason.com/securityalert/3522">3522</ref></refs><vuln_soft><prod name="MODxCMS" vendor="MODxCMS"><vers num="0.9.6.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2008-01-08" name="CVE-2008-0095" published="2008-01-07" seq="2008-0095" severity="Medium" type="CVE"><desc><descript source="cve">The SIP channel driver in Asterisk Open Source 1.4.x before 1.4.17, Business Edition before C.1.0-beta8, AsteriskNOW before beta7, Appliance Developer Kit before Asterisk 1.4 revision 95946, and Appliance s800i 1.0.x before 1.0.3.4 allows remote attackers to cause a denial of service (daemon crash) via a BYE message with an Also (Also transfer) header, which triggers a NULL pointer dereference.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/485727/100/0/threaded">20080102 AST-2008-001: Crash from transfer using BYE with Also header</ref><ref patch="1" source="" url="http://bugs.digium.com/view.php?id=11637"></ref><ref patch="1" source="" url="http://downloads.digium.com/pub/security/AST-2008-001.html"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/27110">27110</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0019">ADV-2008-0019</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1019152">1019152</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/28312">28312</ref><ref source="SREASON" url="http://securityreason.com/securityalert/3520">3520</ref></refs><vuln_soft><prod name="AsteriskNOW" vendor="Asterisk"><vers num="Beta 6" prev="1"/></prod><prod name="Asterisk Business Edition" vendor="Asterisk"><vers num="C.1.0beta7" prev="1"/></prod><prod name="Asterisk Appliance Developer Kit" vendor="Asterisk"><vers num="1.4_revision_95945" prev="1"/></prod><prod name="Open Source" vendor="Asterisk"><vers num="1.4.16" prev="1"/></prod><prod name="s800i" vendor="Asterisk"><vers num="1.0.3.3" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-01-08" name="CVE-2008-0096" published="2008-01-07" seq="2008-0096" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in Georgia SoftWorks SSH2 Server (GSW_SSHD) 7.01.0003 and earlier allow remote attackers to execute arbitrary code via a (1) a long username, which triggers an overflow in the log function; or (2) a long password.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/485725/100/0/threaded">20080102 Multiple vulnerabilities in Georgia SoftWorks SSH2 Server 7.01.0003</ref><ref source="" url="http://aluigi.altervista.org/adv/gswsshit-adv.txt"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/28307">28307</ref><ref source="SREASON" url="http://securityreason.com/securityalert/3517">3517</ref></refs><vuln_soft><prod name="SSH2 Server" vendor="Georgia SoftWorks"><vers num="7.01.0003" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-01-08" name="CVE-2008-0097" published="2008-01-07" seq="2008-0097" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in the log function in Georgia SoftWorks SSH2 Server (GSW_SSHD) 7.01.0003 and earlier allows remote attackers to execute arbitrary code via format string specifiers in the username field, as demonstrated by a certain LoginPassword message.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/485725/100/0/threaded">20080102 Multiple vulnerabilities in Georgia SoftWorks SSH2 Server 7.01.0003</ref><ref source="" url="http://aluigi.altervista.org/adv/gswsshit-adv.txt"></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28307">28307</ref><ref source="SREASON" url="http://securityreason.com/securityalert/3517">3517</ref></refs><vuln_soft><prod name="SSH2 Server" vendor="Georgia SoftWorks"><vers num="7.01.0003" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-01-08" name="CVE-2008-0098" published="2008-01-07" seq="2008-0098" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in RealPlayer 11 build 6.0.14.748 allows remote attackers to execute arbitrary code via unspecified vectors.  NOTE: As of 20080103, this disclosure has no actionable information. However, because the VulnDisco Pack author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref source="MLIST" url="http://lists.immunitysec.com/pipermail/dailydave/2008-January/004811.html">[Dailydave] 20080101 0day RealPlayer exploit demo</ref><ref source="" url="http://gleg.net/realplayer11.html"></ref><ref source="" url="http://www.us-cert.gov/current/index.html#public_exploit_code_for_realplayer"></ref><ref source="BID" url="http://www.securityfocus.com/bid/27091">27091</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0016">ADV-2008-0016</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28276">28276</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1019153">1019153</ref></refs><vuln_soft><prod name="RealPlayer" vendor="Real"><vers num="11_build_6.0.14.748"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-01-08" name="CVE-2008-0099" published="2008-01-07" seq="2008-0099" severity="Medium" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in MyPHP Forum 3.0 and earlier allow remote attackers to execute arbitrary SQL commands via the searchtext parameter to search.php, and unspecified other vectors.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/4831">4831</ref></refs><vuln_soft><prod name="MyPHP Forum" vendor="MyPHP Forum"><vers num="3.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-01-08" name="CVE-2008-0100" published="2008-01-07" seq="2008-0100" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in the Scene::errorf function in Scene.cpp in White_Dune 0.29 beta791 and earlier allows remote attackers to execute arbitrary code via a long string in a .WRL file.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/485724/100/0/threaded">20080102 Buffer-overflow and format string in White_Dune 0.29beta791</ref><ref source="" url="http://aluigi.altervista.org/adv/whitedunboffs-adv.txt"></ref><ref source="" url="http://vrml.cip.ica.uni-stuttgart.de/dune/news.html"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/27102">27102</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/28287">28287</ref><ref source="SREASON" url="http://securityreason.com/securityalert/3516">3516</ref></refs><vuln_soft><prod name="White_Dune" vendor="White_Dune"><vers num="0.29beta791" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-01-08" name="CVE-2008-0101" published="2008-01-07" seq="2008-0101" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in the swDebugf function in DuneApp.cpp in White_Dune 0.29 beta791 and earlier allows remote attackers to execute arbitrary code via format string specifiers in a .WRL file.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/485724/100/0/threaded">20080102 Buffer-overflow and format string in White_Dune 0.29beta791</ref><ref source="" url="http://aluigi.altervista.org/adv/whitedunboffs-adv.txt"></ref><ref source="" url="http://vrml.cip.ica.uni-stuttgart.de/dune/news.html"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/27102">27102</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/28287">28287</ref><ref source="SREASON" url="http://securityreason.com/securityalert/3516">3516</ref></refs><vuln_soft><prod name="White_Dune" vendor="White_Dune"><vers num="0.29beta791" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-02-13" name="CVE-2008-0102" published="2008-02-12" seq="2008-0102" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Microsoft Office Publisher 2000, 2002, and 2003 SP2 allows remote attackers to execute arbitrary code via a crafted .pub file, related to invalid &quot;memory values,&quot; aka &quot;Publisher Invalid Memory Reference Vulnerability.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms08-012.mspx">MS08-012</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA08-043C.html">TA08-043C</ref><ref source="BID" url="http://www.securityfocus.com/bid/27739">27739</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0514/references">ADV-2008-0514</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1019376">1019376</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28906">28906</ref><ref source="HP" url="http://marc.info/?l=bugtraq&amp;m=120361015026386&amp;w=2">HPSBST02314</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5305">oval:org.mitre.oval:def:5305</ref></refs><vuln_soft><prod name="Publisher" vendor="Microsoft"><vers num="2000"/><vers num="2002"/><vers edition="SP2" num="2003"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-02-13" name="CVE-2008-0103" published="2008-02-12" seq="2008-0103" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP2, and Office 2004 for Mac allows remote attackers to execute arbitrary code via an Office document that contains a malformed object, related to a &quot;memory handling error,&quot; aka &quot;Microsoft Office Execution Jump Vulnerability.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/><user_init/></range><refs><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms08-013.mspx">MS08-013</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA08-043C.html">TA08-043C</ref><ref source="BID" url="http://www.securityfocus.com/bid/27738">27738</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0515/references">ADV-2008-0515</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1019375">1019375</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28909">28909</ref><ref source="HP" url="http://marc.info/?l=bugtraq&amp;m=120361015026386&amp;w=2">HPSBST02314</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5407">oval:org.mitre.oval:def:5407</ref></refs><vuln_soft><prod name="Office" vendor="Microsoft"><vers edition="sp3" num="2000"/><vers edition="sp2" num="2003"/><vers edition="sp3" num="XP"/></prod><prod name="office macos" vendor="Microsoft"><vers num="2004"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-02-13" name="CVE-2008-0104" published="2008-02-12" seq="2008-0104" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Microsoft Office Publisher 2000, 2002, and 2003 SP2 allows remote attackers to execute arbitrary code via a crafted .pub file, aka &quot;Publisher Memory Corruption Vulnerability.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/><user_init/></range><refs><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms08-012.mspx">MS08-012</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA08-043C.html">TA08-043C</ref><ref source="BID" url="http://www.securityfocus.com/bid/27740">27740</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0514/references">ADV-2008-0514</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1019377">1019377</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28906">28906</ref><ref source="HP" url="http://marc.info/?l=bugtraq&amp;m=120361015026386&amp;w=2">HPSBST02314</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4547">oval:org.mitre.oval:def:4547</ref></refs><vuln_soft><prod name="Office" vendor="Microsoft"><vers num="2000"/><vers num="2002"/><vers edition="sp2" num="2003"/></prod><prod name="Publisher" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-02-13" name="CVE-2008-0105" published="2008-02-12" seq="2008-0105" severity="High" type="CVE"><desc><descript source="cve">Microsoft Works 6 File Converter, as used in Office 2003 SP2 and SP3, Works 8.0, and Works Suite 2005, allows remote attackers to execute arbitrary code via a .wps file with crafted section header index table information, aka &quot;Microsoft Works File Converter Index Table Vulnerability.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/><user_init/></range><refs><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms08-011.mspx">MS08-011</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA08-043C.html">TA08-043C</ref><ref source="BID" url="http://www.securityfocus.com/bid/27658">27658</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0513/references">ADV-2008-0513</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1019387">1019387</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28904">28904</ref><ref source="HP" url="http://marc.info/?l=bugtraq&amp;m=120361015026386&amp;w=2">HPSBST02314</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5009">oval:org.mitre.oval:def:5009</ref></refs><vuln_soft><prod name="Office" vendor="Microsoft"><vers edition="sp2" num="2003"/><vers edition="sp3" num="2003"/></prod><prod name="Works Suite" vendor="Microsoft"><vers num="2005"/></prod><prod name="Works" vendor="Microsoft"><vers num="8.0"/></prod></vuln_soft></entry><entry CVSS_base_score="9.0" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="10.0" CVSS_score="9.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-07-14" name="CVE-2008-0106" published="2008-07-08" seq="2008-0106" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Microsoft SQL Server 7.0 SP4, 2000 SP4, 2005 SP2, Microsoft Data Engine (MSDE) 1.0 SP4, SQL Server 2000 Desktop Engine (MSDE 2000) SP4, and 2005 Express Edition SP2 allows remote authenticated users to execute arbitrary code via a crafted insert statement.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms08-040.mspx">MS08-040</ref></refs><vuln_soft><prod name="sql_server_desktop_engine" vendor="Microsoft"><vers edition="sp4" num="2000"/></prod><prod name="data_engine" vendor="Microsoft"><vers edition="sp4" num="1.0"/></prod><prod name="sql_server_express_edition" vendor="Microsoft"><vers edition="sp2" num="2005"/></prod><prod name="sql_server" vendor="Microsoft"><vers edition="sp4" num="7.0"/><vers edition="sp4" num="2000"/><vers edition="sp2" num="2005"/></prod></vuln_soft></entry><entry CVSS_base_score="9.0" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="10.0" CVSS_score="9.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-07-14" name="CVE-2008-0107" published="2008-07-08" seq="2008-0107" severity="High" type="CVE"><desc><descript source="cve">Integer underflow in Microsoft SQL Server 7.0 SP4, 2000 SP4, 2005 SP2, Microsoft Data Engine (MSDE) 1.0 SP4, SQL Server 2000 Desktop Engine (MSDE 2000) SP4, and 2005 Express Edition SP2 allows remote authenticated users to execute arbitrary code via an on-disk file with a crafted record size value, which triggers a buffer overflow, aka &quot;SQL Server Memory Corruption Vulnerability.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms08-040.mspx">MS08-040</ref></refs><vuln_soft><prod name="sql_server_desktop_engine" vendor="Microsoft"><vers edition="sp4" num="2000"/></prod><prod name="data_engine" vendor="Microsoft"><vers edition="sp4" num="1.0"/></prod><prod name="sql_server_express_edition" vendor="Microsoft"><vers edition="sp2" num="2005"/></prod><prod name="sql_server" vendor="Microsoft"><vers edition="sp4" num="7.0"/><vers edition="sp4" num="2000"/><vers edition="sp2" num="2005"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-02-19" name="CVE-2008-0108" published="2008-02-12" seq="2008-0108" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in wkcvqd01.dll in Microsoft Works 6 File Converter, as used in Office 2003 SP2 and SP3, Works 8.0, and Works Suite 2005, allows remote attackers to execute arbitrary code via a .wps file with crafted field lengths, aka &quot;Microsoft Works File Converter Field Length Vulnerability.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/><user_init/></range><refs><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms08-011.mspx">MS08-011</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA08-043C.html">TA08-043C</ref><ref source="BID" url="http://www.securityfocus.com/bid/27659">27659</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0513/references">ADV-2008-0513</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1019388">1019388</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28904">28904</ref><ref source="IDEFENSE" url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=660">20080208 Microsoft Office Works Converter Stack-based Buffer Overflow Vulnerability</ref><ref source="HP" url="http://marc.info/?l=bugtraq&amp;m=120361015026386&amp;w=2">HPSBST02314</ref><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/5107">5107</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5202">oval:org.mitre.oval:def:5202</ref></refs><vuln_soft><prod name="Office" vendor="Microsoft"><vers edition="sp2" num="2003"/><vers edition="sp3" num="2003"/></prod><prod name="Works Suite" vendor="Microsoft"><vers num="2005"/></prod><prod name="Works" vendor="Microsoft"><vers num="8.0"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-02-14" name="CVE-2008-0109" published="2008-02-12" seq="2008-0109" severity="High" type="CVE"><desc><descript source="cve">Word in Microsoft Office 2000 SP3, XP SP3, Office 2003 SP2, and Office Word Viewer 2003 allows remote attackers to execute arbitrary code via crafted fields within the File Information Block (FIB) of a Word file, which triggers length calculation errors and memory corruption.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/><user_init/></range><refs><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms08-009.mspx">MS08-009</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA08-043C.html">TA08-043C</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/692417">VU#692417</ref><ref source="BID" url="http://www.securityfocus.com/bid/27656">27656</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0511/references">ADV-2008-0511</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1019374">1019374</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28901">28901</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/488071/100/0/threaded">20080213 [Reversemode Advisory] February Advisories : Microsoft Word 2003 + Fortinet Forticlient</ref><ref source="HP" url="http://marc.info/?l=bugtraq&amp;m=120361015026386&amp;w=2">HPSBST02314</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5073">oval:org.mitre.oval:def:5073</ref></refs><vuln_soft><prod name="Office" vendor="Microsoft"><vers num="2000_sp3"/><vers num="2003 Viewer"/><vers num="2003_sp2"/><vers num="XP SP3"/></prod><prod name="Word" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-03-12" name="CVE-2008-0110" published="2008-03-11" seq="2008-0110" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Microsoft Outlook in Office 2000 SP3, XP SP3, 2003 SP2 and Sp3, and Office System allows user-assisted remote attackers to execute arbitrary code via a crafted mailto URI.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/><user_init/></range><refs><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms08-015.mspx">MS08-015</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA08-071A.html">TA08-071A</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/393305">VU#393305</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/28147">28147</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0847/references">ADV-2008-0847</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/29320">29320</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1019579">1019579</ref><ref source="HP" url="http://marc.info/?l=bugtraq&amp;m=120585858807305&amp;w=2">HPSBST02320</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5278">oval:org.mitre.oval:def:5278</ref></refs><vuln_soft><prod name="Office" vendor="Microsoft"><vers edition="sp3" num="2000"/><vers edition="sp3" num="2003"/><vers edition="sp3" num="XP"/><vers edition="sp2" num="2003"/><vers num="2007"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-03-12" name="CVE-2008-0111" published="2008-03-11" seq="2008-0111" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Microsoft Excel 2000 SP3 through 2007, Viewer 2003, Compatibility Pack, and Office 2004 for Mac allows user-assisted remote attackers to execute arbitrary code via crafted data validation records, aka &quot;Excel Data Validation Record Vulnerability.&quot;</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/><user_init/></range><refs><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms08-014.mspx">MS08-014</ref><ref patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA08-071A.html">TA08-071A</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/28094">28094</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0846/references">ADV-2008-0846</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1019582">1019582</ref><ref source="HP" url="http://marc.info/?l=bugtraq&amp;m=120585858807305&amp;w=2">HPSBST02320</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5114">oval:org.mitre.oval:def:5114</ref></refs><vuln_soft><prod name="Office_compatibility_pack_for_word_excel_ppt_2007" vendor="Microsoft"><vers num=""/></prod><prod name="Office" vendor="Microsoft"><vers num="2007"/><vers edition="unknown" num="2004"/></prod><prod name="excel_viewer" vendor="Microsoft"><vers num="2003"/></prod><prod name="Excel" vendor="Microsoft"><vers edition="SP3" num="2000"/><vers edition="SP3" num="2002"/><vers edition="SP2" num="2003"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-03-12" name="CVE-2008-0112" published="2008-03-11" seq="2008-0112" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Microsoft Excel 2000 SP3, and Office for Mac 2004 and 2008 allows user-assisted remote attackers to execute arbitrary code via a crafted .SLK file that is not properly handled when importing the file, aka &quot;Excel File Import Vulnerability.&quot;</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/><user_init/></range><refs><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms08-014.mspx">MS08-014</ref><ref patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA08-071A.html">TA08-071A</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/28095">28095</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0846/references">ADV-2008-0846</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1019583">1019583</ref><ref source="HP" url="http://marc.info/?l=bugtraq&amp;m=120585858807305&amp;w=2">HPSBST02320</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5284">oval:org.mitre.oval:def:5284</ref></refs><vuln_soft><prod name="Office" vendor="Microsoft"><vers edition="unknown" num="2004"/><vers edition="unknown" num="2008"/></prod><prod name="Excel" vendor="Microsoft"><vers edition="SP3" num="2000"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-03-19" name="CVE-2008-0113" published="2008-03-11" seq="2008-0113" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Microsoft Office Excel Viewer 2003 up to SP3 allows user-assisted remote attackers to execute arbitrary code via an Excel document with malformed cell comments that trigger memory corruption from an &quot;allocation error,&quot; aka &quot;Microsoft Office Cell Parsing Memory Corruption Vulnerability.&quot;</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/><user_init/></range><refs><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms08-016.mspx">MS08-016</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA08-071A.html">TA08-071A</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0848/references">ADV-2008-0848</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/29321">29321</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1019578">1019578</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/489415/100/0/threaded">20080311 ZDI-08-008: Microsoft Excel BIFF File Format Cell Record Parsing Memory Corruption Vulnerability</ref><ref source="" url="http://www.zerodayinitiative.com/advisories/ZDI-08-008"></ref><ref source="HP" url="http://marc.info/?l=bugtraq&amp;m=120585858807305&amp;w=2">HPSBST02320</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5421">oval:org.mitre.oval:def:5421</ref></refs><vuln_soft><prod name="excel_viewer" vendor="Microsoft"><vers num="2003"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-03-12" name="CVE-2008-0114" published="2008-03-11" seq="2008-0114" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Microsoft Excel 2000 SP3 through 2003 SP2, Viewer 2003, and Office for Mac 2004 allows user-assisted remote attackers to execute arbitrary code via crafted Style records that trigger memory corruption.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/><user_init/></range><refs><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms08-014.mspx">MS08-014</ref><ref patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA08-071A.html">TA08-071A</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/28166">28166</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0846/references">ADV-2008-0846</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1019584">1019584</ref><ref source="HP" url="http://marc.info/?l=bugtraq&amp;m=120585858807305&amp;w=2">HPSBST02320</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5456">oval:org.mitre.oval:def:5456</ref></refs><vuln_soft><prod name="Office" vendor="Microsoft"><vers edition="unknown" num="2004"/></prod><prod name="excel_viewer" vendor="Microsoft"><vers num="2003"/></prod><prod name="Excel" vendor="Microsoft"><vers edition="SP3" num="2000"/><vers edition="SP3" num="2002"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-03-12" name="CVE-2008-0115" published="2008-03-11" seq="2008-0115" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Microsoft Excel 2000 SP3 through 2007, Viewer 2003, Compatibility Pack, and Office for Mac 2004 allows user-assisted remote attackers to execute arbitrary code via malformed formulas, aka &quot;Excel Formula Parsing Vulnerability.&quot;</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/><user_init/></range><refs><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms08-014.mspx">MS08-014</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/28167">28167</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1019585">1019585</ref><ref patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA08-071A.html">TA08-071A</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0846/references">ADV-2008-0846</ref><ref source="HP" url="http://marc.info/?l=bugtraq&amp;m=120585858807305&amp;w=2">HPSBST02320</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5512">oval:org.mitre.oval:def:5512</ref></refs><vuln_soft><prod name="Office_compatibility_pack_for_word_excel_ppt_2007" vendor="Microsoft"><vers num=""/></prod><prod name="Office" vendor="Microsoft"><vers edition="unknown" num="2004"/></prod><prod name="excel_viewer" vendor="Microsoft"><vers num="2003"/></prod><prod name="Excel" vendor="Microsoft"><vers edition="SP3" num="2000"/><vers edition="SP3" num="2002"/><vers edition="SP2" num="2003"/><vers num="2007"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-03-19" name="CVE-2008-0116" published="2008-03-11" seq="2008-0116" severity="Medium" type="CVE"><desc><descript source="cve">Microsoft Excel 2000 SP3 through 2003 SP2, Viewer 2003, Compatibility Pack, and Office 2004 and 2008 for Mac allows user-assisted remote attackers to execute arbitrary code via malformed tags in rich text, aka &quot;Excel Rich Text Validation Vulnerability.&quot;</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/><user_init/></range><refs><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms08-014.mspx">MS08-014</ref><ref patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA08-071A.html">TA08-071A</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/28168">28168</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0846/references">ADV-2008-0846</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1019586">1019586</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/489430/100/0/threaded">20080311 TPTI-08-03: Microsoft Excel Rich Text Memory Corruption Vulnerability</ref><ref source="" url="http://dvlabs.tippingpoint.com/advisory/TPTI-08-03"></ref><ref source="HP" url="http://marc.info/?l=bugtraq&amp;m=120585858807305&amp;w=2">HPSBST02320</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5212">oval:org.mitre.oval:def:5212</ref></refs><vuln_soft><prod name="Office_compatibility_pack_for_word_excel_ppt_2007" vendor="Microsoft"><vers num=""/></prod><prod name="Office" vendor="Microsoft"><vers edition="unknown" num="2004"/><vers edition="unknown" num="2008"/></prod><prod name="excel_viewer" vendor="Microsoft"><vers num="2003"/></prod><prod name="Excel" vendor="Microsoft"><vers edition="SP3" num="2000"/><vers edition="SP3" num="2002"/><vers edition="SP2" num="2003"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-04-09" name="CVE-2008-0117" published="2008-03-11" seq="2008-0117" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Microsoft Excel 2000 SP3 and 2002 SP2, and Office 2004 and 2008 for Mac, allows user-assisted remote attackers to execute arbitrary code via crafted conditional formatting values, aka &quot;Excel Conditional Formatting Vulnerability.&quot;</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/><user_init/></range><refs><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms08-014.mspx">MS08-014</ref><ref patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA08-071A.html">TA08-071A</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/28170">28170</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0846/references">ADV-2008-0846</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1019587">1019587</ref><ref source="HP" url="http://marc.info/?l=bugtraq&amp;m=120585858807305&amp;w=2">HPSBST02320</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5508">oval:org.mitre.oval:def:5508</ref></refs><vuln_soft><prod name="Excel Viewer" vendor="Microsoft"><vers num="2003"/></prod><prod name="Office" vendor="Microsoft"><vers edition="sp3" num="2000"/><vers edition="unknown" num="2004"/><vers edition="unknown" num="2008"/><vers edition="sp3" num="XP"/><vers edition="sp2" num="2003"/><vers num="2007"/></prod><prod name="compatibility_pack_word_excel_powerpoint_2007" vendor="Microsoft"><vers num=""/></prod><prod name="Excel" vendor="Microsoft"><vers edition="SP3" num="2000"/><vers edition="SP3" num="2002"/><vers edition="SP2" num="2003"/><vers num="2007"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-03-12" name="CVE-2008-0118" published="2008-03-11" seq="2008-0118" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Microsoft Office 2000 SP3, XP SP3, 2003 SP2, Excel Viewer 2003 up to SP3, and Office 2004 for Mac allows user-assisted remote attackers to execute arbitrary code via a crafted Office document that triggers memory corruption from an &quot;allocation error,&quot; aka &quot;Microsoft Office Memory Corruption Vulnerability.&quot;</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/><user_init/></range><refs><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms08-016.mspx">MS08-016</ref><ref patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA08-071A.html">TA08-071A</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/28146">28146</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0848/references">ADV-2008-0848</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/29321">29321</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1019578">1019578</ref><ref source="HP" url="http://marc.info/?l=bugtraq&amp;m=120585858807305&amp;w=2">HPSBST02320</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5190">oval:org.mitre.oval:def:5190</ref></refs><vuln_soft><prod name="Office" vendor="Microsoft"><vers edition="sp3" num="2000"/><vers edition="sp3" num="XP"/><vers edition="sp2" num="2003"/><vers edition="unknown" num="2004"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-05-22" name="CVE-2008-0119" published="2008-05-13" seq="2008-0119" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Microsoft Publisher in Office 2000 and XP SP3, 2003 SP2 and SP3, and 2007 SP1 and earlier allows remote attackers to execute arbitrary code via a Publisher file with crafted object header data that triggers memory corruption, aka &quot;Publisher Object Handler Validation Vulnerability.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/><user_init/></range><refs><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms08-027.mspx">MS08-027</ref><ref source="BID" url="http://www.securityfocus.com/bid/29158">29158</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/1505/references">ADV-2008-1505</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1020015">1020015</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/30150">30150</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA08-134A.html">TA08-134A</ref><ref source="HP" url="http://marc.info/?l=bugtraq&amp;m=121129490723574&amp;w=2">HPSBST02336</ref></refs><vuln_soft><prod name="Office" vendor="Microsoft"><vers num="2000 SP3"/><vers num="2003 SP2"/><vers num="2003 SP3"/><vers num="2007"/><vers num="2007_sp1"/><vers num="XP SP3"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-08-14" name="CVE-2008-0120" published="2008-08-12" seq="2008-0120" severity="High" type="CVE"><desc><descript source="cve">A &quot;memory allocation error&quot; in Microsoft PowerPoint Viewer 2003 allows remote attackers to execute arbitrary code via a PowerPoint file with a malformed picture index that triggers memory corruption, aka &quot;Memory Allocation Vulnerability.&quot;</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/><user_init/></range><refs><ref patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms08-051.mspx">MS08-051</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/2355">ADV-2008-2355</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/31453">31453</ref></refs><vuln_soft><prod name="office_powerpoint_viewer" vendor="Microsoft"><vers num="2003"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-08-14" name="CVE-2008-0121" published="2008-08-12" seq="2008-0121" severity="High" type="CVE"><desc><descript source="cve">A &quot;memory calculation error&quot; in Microsoft PowerPoint Viewer 2003 allows remote attackers to execute arbitrary code via a PowerPoint file with a malformed picture index that triggers memory corruption, aka &quot;Memory Calculation Vulnerability.&quot;</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/><user_init/></range><refs><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms08-051.mspx">MS08-051</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/2355">ADV-2008-2355</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/31453">31453</ref></refs><vuln_soft><prod name="office_powerpoint_viewer" vendor="Microsoft"><vers num="2003"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-02-01" name="CVE-2008-0122" published="2008-01-15" seq="2008-0122" severity="High" type="CVE"><desc><descript source="cve">Off-by-one error in the inet_network function in libbind in ISC BIND 9.4.2 and earlier, as used in libc in FreeBSD 6.2 through 7.0-PRERELEASE, allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted input that triggers memory corruption.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref patch="1" source="FREEBSD" url="http://security.freebsd.org/advisories/FreeBSD-SA-08:02.libc.asc">FreeBSD-SA-08:02</ref><ref source="BID" url="http://www.securityfocus.com/bid/27283">27283</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1019189">1019189</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28367">28367</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39670">freebsd-inetnetwork-bo(39670)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/487000/100/0/threaded">20080124 rPSA-2008-0029-1 bind bind-utils</ref><ref source="" url="http://www.isc.org/index.pl?/sw/bind/bind-security.php"></ref><ref source="" url="https://bugzilla.redhat.com/show_bug.cgi?id=429149"></ref><ref source="" url="https://issues.rpath.com/browse/RPL-2169"></ref><ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00781.html">FEDORA-2008-0903</ref><ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00782.html">FEDORA-2008-0904</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/203611">VU#203611</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0193">ADV-2008-0193</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28579">28579</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28487">28487</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28429">28429</ref><ref source="" url="http://www14.software.ibm.com/webapp/set2/subscriptions/ijhifoeblist?mode=7&amp;heading=AIX61&amp;path=/200802/SECURITY/20080227/datafile123640&amp;label=AIX%20libc%20inet_network%20buffer%20overflow"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0703">ADV-2008-0703</ref><ref source="SECUNIA" url="http://secunia.com/advisories/29161">29161</ref><ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2008-03/msg00004.html">SUSE-SR:2008:006</ref><ref source="SECUNIA" url="http://secunia.com/advisories/29323">29323</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-238493-1">238493</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/1743/references">ADV-2008-1743</ref><ref source="SECUNIA" url="http://secunia.com/advisories/30538">30538</ref></refs><vuln_soft><prod name="BIND" vendor="ISC"><vers num="9.4.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2008-01-14" name="CVE-2008-0123" published="2008-01-11" seq="2008-0123" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in install.php for Moodle 1.8.3, and possibly other versions before 1.8.4, allows remote attackers to inject arbitrary web script or HTML via the dbname parameter.  NOTE: this issue only exists until the installation is complete.</descript></desc><loss_types><int/></loss_types><range><network/><user_init/></range><refs><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2008-01/0202.html">20080111 Cross site scripting (XSS) in Moodle 1.8.3</ref><ref source="" url="http://int21.de/cve/CVE-2008-0123-moodle.html"></ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/486198/100/0/threaded">20080111 Cross site scripting (XSS) in Moodle 1.8.3</ref><ref source="BID" url="http://www.securityfocus.com/bid/27259">27259</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0164">ADV-2008-0164</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39630">moodle-install-xss(39630)</ref><ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2008-02/msg00003.html">SUSE-SR:2008:003</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28838">28838</ref></refs><vuln_soft><prod name="Moodle" vendor="Moodle"><vers num="1.8.3" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2008-08-07" name="CVE-2008-0124" published="2008-02-28" seq="2008-0124" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Serendipity (S9Y) before 1.3-beta1 allows remote authenticated users to inject arbitrary web script or HTML via (1) the &quot;Real name&quot; field in Personal Settings, which is presented to readers of articles; or (2) a file upload, as demonstrated by a .htm, .html, or .js file.</descript></desc><loss_types><int/></loss_types><range><network/><user_init/></range><refs><ref source="" url="http://int21.de/cve/CVE-2008-0124-s9y.html"></ref><ref patch="1" source="" url="http://blog.s9y.org/archives/191-Serendipity-1.3-beta1-released.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/28003">28003</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0700/references">ADV-2008-0700</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1019502">1019502</ref><ref source="SECUNIA" url="http://secunia.com/advisories/29128">29128</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/40851">serendipity-realname-username-xss(40851)</ref><ref source="DEBIAN" url="http://www.debian.org/security/2008/dsa-1528">DSA-1528</ref><ref source="SECUNIA" url="http://secunia.com/advisories/29502">29502</ref></refs><vuln_soft><prod name="Serendipity" vendor="S9Y"><vers num="0.3"/><vers num="0.4"/><vers num="0.5"/><vers num="0.5 pl1"/><vers num="0.6"/><vers num="0.6 pl1"/><vers num="0.6 pl2"/><vers num="0.6 pl3"/><vers num="0.6 rc1"/><vers num="0.6 rc2"/><vers num="0.7"/><vers num="0.7 beta1"/><vers num="0.7 Beta2"/><vers num="0.7 beta3"/><vers num="0.7 Beta4"/><vers num="0.7 rc1"/><vers num="0.7.1"/><vers num="0.8"/><vers num="0.8 beta 6 snapshot"/><vers num="0.8 Beta5"/><vers num="0.8 Beta6"/><vers num="0.8.1"/><vers num="0.8.2"/><vers num="0.9.1"/><vers num="1.0 Beta2"/><vers num="1.0 Beta3"/><vers num="1.0.3"/><vers num="1.0.4"/><vers num="1.1.1"/><vers num="1.1.3"/><vers num="1.1.4"/><vers num="1.2"/><vers num="1.2  beta5"/><vers num="1.2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2008-03-25" name="CVE-2008-0125" published="2008-03-24" seq="2008-0125" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in phpstats.php in Michael Wagner phpstats 0.1 alpha allows remote attackers to inject arbitrary web script or HTML via the baseDir parameter.</descript></desc><loss_types><int/></loss_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/489722/100/0/threaded">20080317 Cross Site Scripting (XSS) in phpstats 0.1_alpha, CVE-2008-0125</ref><ref source="BID" url="http://www.securityfocus.com/bid/28291">28291</ref><ref source="SREASON" url="http://securityreason.com/securityalert/3765">3765</ref></refs><vuln_soft><prod name="phpstats" vendor="PHPStats"><vers num="0.1_alpha"/></prod></vuln_soft></entry><entry CVSS_base_score="8.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="9.2" CVSS_score="8.8" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:C/A:C)" CVSS_version="2.0" modified="2008-01-10" name="CVE-2008-0127" published="2008-01-09" seq="2008-0127" severity="High" type="CVE"><desc><descript source="cve">The administration interface in McAfee E-Business Server 8.5.2 and earlier allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a long initial authentication packet.</descript></desc><loss_types><avail/><int/></loss_types><range><network/></range><refs><ref patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/485992/100/0/threaded">20080109 [INFIGO 2008-01-06]: McAfee E-Business Server Remote Preauth Code Execution / DoS</ref><ref patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/486035/100/0/threaded">20080109 [INFIGO-2008-01-06]: McAfee E-Business Server Remote Preauth Code Execution / DoS - Corrected</ref><ref source="" url="https://knowledge.mcafee.com/SupportSite/dynamickc.do?externalId=614472&amp;sliceId=SAL_Public&amp;command=show&amp;forward=nonthreadedKC&amp;kcId=614472"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/27197">27197</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39563">mcafee-ebusiness-packet-code-execution(39563)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39561">mcafee-ebusiness-authentication-packet-dos(39561)</ref><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/4878">4878</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0087">ADV-2008-0087</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1019170">1019170</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28408">28408</ref><ref source="SREASON" url="http://securityreason.com/securityalert/3530">3530</ref></refs><vuln_soft><prod name="e-Business Server" vendor="McAfee"><vers num="8.5.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2008-01-23" name="CVE-2008-0128" published="2008-01-22" seq="2008-0128" severity="Medium" type="CVE"><desc><descript source="cve">The SingleSignOn Valve (org.apache.catalina.authenticator.SingleSignOn) in Apache Tomcat before 5.5.21 does not set the secure flag for the JSESSIONIDSSO cookie in an https session, which can cause the cookie to be sent in http requests, making it easier for remote attackers to capture this cookie.</descript></desc><loss_types><conf/></loss_types><range><network/></range><refs><ref patch="1" source="" url="http://issues.apache.org/bugzilla/show_bug.cgi?id=41217"></ref><ref source="" url="http://security-tracker.debian.net/tracker/CVE-2008-0128"></ref><ref source="BID" url="http://www.securityfocus.com/bid/27365">27365</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0192">ADV-2008-0192</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28549">28549</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28552">28552</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39804">apache-singlesignon-information-disclosure(39804)</ref><ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2008-03/msg00001.html">SUSE-SR:2008:005</ref><ref source="SECUNIA" url="http://secunia.com/advisories/29242">29242</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2008-0261.html">RHSA-2008:0261</ref></refs><vuln_soft><prod name="Tomcat" vendor="Apache Software Foundation"><vers num="5.5.20" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-01-08" name="CVE-2008-0129" published="2008-01-08" seq="2008-0129" severity="Medium" type="CVE"><desc><descript source="cve">SQL injection vulnerability in starnet/addons/slideshow_full.php in Site@School 2.3.10 and earlier allows remote attackers to execute arbitrary SQL commands via the album_name parameter.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/4832">4832</ref><ref source="BID" url="http://www.securityfocus.com/bid/27120">27120</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39417">siteatschool-slideshowfull-sql-injection(39417)</ref></refs><vuln_soft><prod name="SiteAtSchool" vendor="SiteAtSchool"><vers num="2.3.10" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-01-11" name="CVE-2008-0130" published="2008-01-08" seq="2008-0130" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in login_form.asp in Instant Softwares Dating Site allows remote attackers to execute arbitrary SQL commands via the Username parameter, a different vulnerability than CVE-2007-6671.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28283">28283</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39326">dating-site-login-sql-injection(39326)</ref></refs><vuln_soft><prod name="Dating_Site" vendor="InstantSoftwares"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2008-01-08" name="CVE-2008-0131" published="2008-01-08" seq="2008-0131" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in login_form.asp in Instant Softwares Dating Site allows remote attackers to inject arbitrary web script or HTML via the msg parameter, a different product than CVE-2006-6022.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><int/></loss_types><range><network/><user_init/></range><refs><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28283">28283</ref></refs><vuln_soft><prod name="Dating_Site" vendor="InstantSoftwares"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2008-01-08" name="CVE-2008-0132" published="2008-01-08" seq="2008-0132" severity="Medium" type="CVE"><desc><descript source="cve">Pragma FortressSSH 5.0 Build 4 Revision 293 and earlier handles long input to sshd.exe by creating an error-message window and waiting for the administrator to click in this window before terminating the sshd.exe process, which allows remote attackers to cause a denial of service (connection slot exhaustion) via a flood of SSH connections with long data objects, as demonstrated by (1) a long list of keys and (2) a long username.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref source="" url="http://aluigi.altervista.org/adv/pragmassh-adv.txt"></ref><ref source="" url="http://aluigi.org/poc/pragmassh.zip"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39354">fortressssh-sshd-dos(39354)</ref><ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=119947184730448&amp;w=2">20080104 Some DoS in some telnet servers</ref><ref source="BID" url="http://www.securityfocus.com/bid/27141">27141</ref></refs><vuln_soft><prod name="FortressSSH" vendor="Pragma Systems"><vers num="5.0_build_4_R_293" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-01-08" name="CVE-2008-0133" published="2008-01-08" seq="2008-0133" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in Tribisur 2.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to cat_main.php and the (2) cat parameter to forum.php in a liste action.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/4840">4840</ref><ref source="BID" url="http://www.securityfocus.com/bid/27149">27149</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28362">28362</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39443">tribisur-catmain-forum-sql-injection(39443)</ref></refs><vuln_soft><prod name="Tribisur" vendor="Thomas Perez"><vers num="2.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2008-01-09" name="CVE-2008-0134" published="2008-01-08" seq="2008-0134" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Forums/setup.asp in Snitz Forums 2000 3.4.06 and earlier allows remote attackers to inject arbitrary web script or HTML via the MAIL parameter.</descript></desc><loss_types><int/></loss_types><range><network/><user_init/></range><refs><ref source="" url="http://hackerscenter.com/archive/view.asp?id=28145"></ref><ref source="" url="http://www.packetstormsecurity.org/0801-exploits/snitz-multi.txt"></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28284">28284</ref></refs><vuln_soft><prod name="Snitz Forums" vendor="Snitz Forums 2000"><vers num="3.4.06" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2008-01-09" name="CVE-2008-0135" published="2008-01-08" seq="2008-0135" severity="Medium" type="CVE"><desc><descript source="cve">Snitz Forums 2000 3.4.06 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for forum/snitz_forums_2000.mdb.</descript></desc><loss_types><conf/></loss_types><range><network/></range><refs><ref source="" url="http://hackerscenter.com/archive/view.asp?id=28145"></ref><ref source="" url="http://www.packetstormsecurity.org/0801-exploits/snitz-multi.txt"></ref></refs><vuln_soft><prod name="Snitz Forums" vendor="Snitz Forums 2000"><vers num="3.4.06" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2008-01-09" name="CVE-2008-0136" published="2008-01-08" seq="2008-0136" severity="Medium" type="CVE"><desc><descript source="cve">Snitz Forums 2000 3.4.05 allows remote attackers to obtain sensitive information via a direct request to forum/whereami.asp, which reveals the database path.</descript></desc><loss_types><conf/></loss_types><range><network/></range><refs><ref source="" url="http://hackerscenter.com/archive/view.asp?id=28145"></ref><ref source="" url="http://www.packetstormsecurity.org/0801-exploits/snitz-multi.txt"></ref></refs><vuln_soft><prod name="Snitz Forums" vendor="Snitz Forums 2000"><vers num="3.4.05"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-01-09" name="CVE-2008-0137" published="2008-01-08" seq="2008-0137" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in config.inc.php in SNETWORKS PHP CLASSIFIEDS 5.0 allows remote attackers to execute arbitrary PHP code via a URL in the path_escape parameter.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/4838">4838</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0053">ADV-2008-0053</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39468">snetworks-configinc-file-include(39468)</ref></refs><vuln_soft><prod name="PHP CLASSIFIEDS" vendor="SNETWORKS"><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-02-06" name="CVE-2008-0138" published="2008-01-08" seq="2008-0138" severity="Medium" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in xoopsgallery/init_basic.php in the mod_gallery module for XOOPS, when register_globals is disabled, allows remote attackers to execute arbitrary PHP code via a URL in the GALLERY_BASEDIR parameter.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/4847">4847</ref><ref source="BID" url="http://www.securityfocus.com/bid/27155">27155</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39461">xoops-modgallery-zendhashkey-file-include(39461)</ref></refs><vuln_soft><prod name="XoopsGallery Module" vendor="XOOPS"><vers num="1.3.3 9"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-01-09" name="CVE-2008-0139" published="2008-01-08" seq="2008-0139" severity="Medium" type="CVE"><desc><descript source="cve">Eval injection vulnerability in loudblog/inc/parse_old.php in Loudblog 0.8.0 and earlier allows remote attackers to execute arbitrary PHP code via the template parameter.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref source="MILW0RM" url="http://milw0rm.com/exploits/4849">4849</ref><ref source="BID" url="http://www.securityfocus.com/bid/27157">27157</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28336">28336</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39445">loudblog-template-code-execution(39445)</ref></refs><vuln_soft><prod name="LoudBlog" vendor="LoudBlog"><vers num="0.8.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0" modified="2008-01-09" name="CVE-2008-0140" published="2008-01-08" seq="2008-0140" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in error.php in Uebimiau Webmail 2.7.10 and 2.7.2 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the selected_theme parameter, a different vector than CVE-2007-3172.</descript></desc><loss_types><conf/><int/></loss_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/4846">4846</ref><ref source="VIM" url="http://www.attrition.org/pipermail/vim/2008-January/001867.html">20080107 Uebimiau Web-Mail 2.7.10/2.7.2 Remote File Disclosure Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/27154">27154</ref></refs><vuln_soft><prod name="Webmail" vendor="UebiMiau"><vers num="2.7.10"/><vers num="2.7.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-01-09" name="CVE-2008-0141" published="2008-01-08" seq="2008-0141" severity="High" type="CVE"><desc><descript source="cve">actions.php in WebPortal CMS 0.6-beta generates predictable passwords containing only the time of day, which makes it easier for remote attackers to obtain access to any account via a lostpass action.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/4835">4835</ref><ref source="BID" url="http://www.securityfocus.com/bid/27145">27145</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39486">webportal-action-weak-security(39486)</ref></refs><vuln_soft><prod name="WebPortal CMS" vendor="WebPortal"><vers num="0.6_beta"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-01-09" name="CVE-2008-0142" published="2008-01-08" seq="2008-0142" severity="Medium" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in WebPortal CMS 0.6-beta allow remote attackers to execute arbitrary SQL commands via the user_name parameter to actions.php, and unspecified other vectors.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/4835">4835</ref></refs><vuln_soft><prod name="WebPortal CMS" vendor="WebPortal"><vers num="0.6_beta"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-01-15" name="CVE-2008-0143" published="2008-01-08" seq="2008-0143" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in common/db.php in samPHPweb, possibly 4.2.2 and others, as provided with SAM Broadcaster, allows remote attackers to execute arbitrary PHP code via a URL in the commonpath parameter.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/4834">4834</ref><ref source="BID" url="http://www.securityfocus.com/bid/27137">27137</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39397">samPHPweb-db-file-include(39397)</ref><ref source="" url="http://www.spacialaudio.com/news/index.html"></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28355">28355</ref></refs><vuln_soft><prod name="samPHPweb" vendor="Spacial Audio Solutions"><vers num=""/></prod><prod name="SAM Broadcaster" vendor="Spacial Audio Solutions"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-01-09" name="CVE-2008-0144" published="2008-01-08" seq="2008-0144" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in index.php in NetRisk 1.9.7 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the page parameter.  NOTE: this can also be leveraged for local file inclusion using directory traversal sequences.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/4833">4833</ref><ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=119955114428283&amp;w=2">20080105 NetRisk 1.9.7 Remote File Inclusion Vulnerability</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28328">28328</ref></refs><vuln_soft><prod name="NetRisk" vendor="phpRisk"><vers num="1.9.7"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-01-09" name="CVE-2008-0145" published="2008-01-08" seq="2008-0145" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in glob in PHP before 4.4.8, when open_basedir is enabled, has unknown impact and attack vectors.  NOTE: this issue reportedly exists because of a regression related to CVE-2007-4663.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref source="" url="http://bugs.php.net/bug.php?id=41655"></ref><ref source="" url="http://www.php.net/ChangeLog-4.php"></ref><ref source="" url="http://www.php.net/releases/4_4_8.php"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/28318">28318</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39401">php-glob-openbasedir-security-bypass(39401)</ref><ref source="SLACKWARE" url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2008&amp;m=slackware-security.335136">SSA:2008-045-03</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28936">28936</ref></refs><vuln_soft><prod name="PHP" vendor="PHP"><vers num="4.4.7" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2008-01-09" name="CVE-2008-0146" published="2008-01-08" seq="2008-0146" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in the error page in W3-mSQL allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the top-level URI.</descript></desc><loss_types><int/></loss_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/485736/100/0/threaded">20080103 xss in w3-msql error page</ref><ref source="BID" url="http://www.securityfocus.com/bid/27116">27116</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28294">28294</ref><ref source="SREASON" url="http://securityreason.com/securityalert/3521">3521</ref></refs><vuln_soft><prod name="W3-mSQL" vendor="Hughes Technologies"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-01-09" name="CVE-2008-0147" published="2008-01-08" seq="2008-0147" severity="Medium" type="CVE"><desc><descript source="cve">SQL injection vulnerability in index.php in SmallNuke 2.0.4 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via (1) the user_email parameter and possibly (2) username parameter in a Members action.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/4863">4863</ref><ref source="BID" url="http://www.securityfocus.com/bid/27180">27180</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28301">28301</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39525">smallnuke-index-sql-injection(39525)</ref></refs><vuln_soft><prod name="SmallNuke" vendor="SmallNuke"><vers num="2.0.4"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-01-09" name="CVE-2008-0148" published="2008-01-08" seq="2008-0148" severity="High" type="CVE"><desc><descript source="cve">TUTOS 1.3 does not restrict access to php/admin/cmd.php, which allows remote attackers to execute arbitrary shell commands via the cmd parameter in a direct request.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref source="MILW0RM" url="http://milw0rm.com/exploits/4861">4861</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28291">28291</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39531">tutos-cmd-command-execution(39531)</ref></refs><vuln_soft><prod name="Tutos" vendor="Tutos"><vers num="1.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2008-01-09" name="CVE-2008-0149" published="2008-01-08" seq="2008-0149" severity="Medium" type="CVE"><desc><descript source="cve">TUTOS 1.3 allows remote attackers to read system information via a direct request to php/admin/phpinfo.php, which calls the phpinfo function.</descript></desc><loss_types><int/></loss_types><range><network/></range><refs><ref source="MILW0RM" url="http://milw0rm.com/exploits/4861">4861</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28291">28291</ref></refs><vuln_soft><prod name="Tutos" vendor="Tutos"><vers num="1.3"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-01-09" name="CVE-2008-0150" published="2008-01-08" seq="2008-0150" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the LDAP authentication feature in Aruba Mobility Controller 2.3.6.15, 2.5.2.11, 2.5.4.25, 2.5.5.7, 3.1.1.3, and 2.4.8.11-FIPS or earlier allows remote attackers to bypass authentication mechanisms and obtain management or VPN interface access.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/485831/100/0/threaded">20080104 Aruba Mobility Controller User Authentication Vulnerability - Aruba Advisory ID: AID-122207</ref><ref source="" url="http://www.arubanetworks.com/support/alerts/aid-122207.asc"></ref><ref source="BID" url="http://www.securityfocus.com/bid/27144">27144</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28357">28357</ref><ref source="SREASON" url="http://securityreason.com/securityalert/3529">3529</ref></refs><vuln_soft><prod name="Aruba Mobility Controllers" vendor="aruba_networks"><vers num="2.3.6.15"/><vers num="2.5.2.11"/><vers num="2.5.4.25"/><vers num="2.5.5.7"/><vers num="3.1.1.3"/><vers num="2.4.8.11-FIPS" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2008-01-09" name="CVE-2008-0151" published="2008-01-08" seq="2008-0151" severity="Medium" type="CVE"><desc><descript source="cve">Foxit WAC Server 2.1.0.910 and earlier allows remote attackers to cause a denial of service (crash) via a Telnet request with long options.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/485812/100/0/threaded">20080104 Some DoS in some telnet servers</ref><ref source="" url="http://aluigi.altervista.org/adv/waccaz-adv.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/27142">27142</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28272">28272</ref><ref source="SREASON" url="http://securityreason.com/securityalert/3525">3525</ref></refs><vuln_soft><prod name="WAC Server" vendor="Foxit"><vers num="2.1.0.910" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2008-01-09" name="CVE-2008-0152" published="2008-01-08" seq="2008-0152" severity="Medium" type="CVE"><desc><descript source="cve">SLnet.exe in SeattleLab SLNet RF Telnet Server 4.1.1.3758 and earlier allows user-assisted remote attackers to cause a denial of service (crash) via unpsecified telnet options, which triggers a NULL pointer dereference.  NOTE: the crash is not user-assisted when the server is running in debug mode.</descript></desc><loss_types><avail/></loss_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=119947184730448&amp;w=2">20080104 Some DoS in some telnet servers</ref><ref source="" url="http://aluigi.altervista.org/adv/slnetmsg-adv.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/27134">27134</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28316">28316</ref></refs><vuln_soft><prod name="SLNet RF Telnet Server" vendor="Seattle Lab Software"><vers num="4.1.1.3758" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2008-01-09" name="CVE-2008-0153" published="2008-01-08" seq="2008-0153" severity="Medium" type="CVE"><desc><descript source="cve">telnetd.exe in Pragma TelnetServer 7.0.4.589 allows remote attackers to cause a denial of service (process crash and resource exhaustion) via a crafted TELOPT PRAGMA LOGON telnet option, which triggers a NULL pointer dereference.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=119947184730448&amp;w=2">20080104 Some DoS in some telnet servers</ref><ref source="" url="http://aluigi.altervista.org/adv/pragmatel-adv.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/27143">27143</ref></refs><vuln_soft><prod name="Pragma TelnetServer" vendor="Pragma Systems"><vers num="7.0.4.589"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-01-09" name="CVE-2008-0154" published="2008-01-08" seq="2008-0154" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in index.php in EvilBoard 0.1a (Alpha) allows remote attackers to execute arbitrary SQL commands the c parameter.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/4865">4865</ref></refs><vuln_soft><prod name="EvilBoard" vendor="EvilBoard"><vers num="0.1a"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2008-01-09" name="CVE-2008-0155" published="2008-01-08" seq="2008-0155" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in EvilBoard 0.1a (Alpha) allows remote attackers to inject arbitrary web script or HTML via the c parameter.</descript></desc><loss_types><int/></loss_types><range><network/><user_init/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/4865">4865</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39526">evilboard-index-xss(39526)</ref></refs><vuln_soft><prod name="EvilBoard" vendor="EvilBoard"><vers num="0.1a"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2008-01-09" name="CVE-2008-0156" published="2008-01-08" seq="2008-0156" severity="Medium" type="CVE"><desc><descript source="cve">Absolute path traversal vulnerability in index.php in Million Dollar Script 2.0.14 allows remote attackers to read arbitrary files via encoded &quot;/&quot; (%2F) sequences in the link parameter.</descript></desc><loss_types><int/></loss_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/485882/100/0/threaded">20080107 Million Dollar Script 2.0.14 Remote File Disclosure Vulnerability.</ref><ref source="BID" url="http://www.securityfocus.com/bid/27174">27174</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39492">milliondollarscript-index-dir-traversal(39492)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/3524">3524</ref></refs><vuln_soft><prod name="Million Dollar Script" vendor="Million Dollar Script"><vers num="2.0.14"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-01-09" name="CVE-2008-0157" published="2008-01-08" seq="2008-0157" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in FlexBB 0.6.3 and earlier allows remote attackers to execute arbitrary SQL commands via the flexbb_temp_id parameter in a cookie.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/4858">4858</ref><ref source="BID" url="http://www.securityfocus.com/bid/27164">27164</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39475">flexbb-flexbbtempid-sql-injection(39475)</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28373">28373</ref></refs><vuln_soft><prod name="FlexBB" vendor="FlexBB"><vers num="0.6.3" prev="1"/><vers num="1.0 10005 Beta Release 1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2008-01-09" name="CVE-2008-0158" published="2008-01-08" seq="2008-0158" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in index.php in Shop-Script 2.0 and possibly other versions allows remote attackers to read arbitrary files via a .. (dot dot) in the aux_page parameter.</descript></desc><loss_types><int/></loss_types><range><network/></range><refs><ref source="" url="http://packetstormsecurity.org/0801-exploits/shopscript-disclose.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/27165">27165</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39449">shopscript-index-directory-traversal(39449)</ref><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/4855">4855</ref></refs><vuln_soft><prod name="Shop-Script" vendor="Shop-Script"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-01-14" name="CVE-2008-0159" published="2008-01-08" seq="2008-0159" severity="Medium" type="CVE"><desc><descript source="cve">SQL injection vulnerability in index.php in eggBlog 3.1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the eggblogpassword parameter in a cookie.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/4860">4860</ref><ref source="BID" url="http://www.securityfocus.com/bid/27168">27168</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39473">eggblog-eggblogmail-sql-injection(39473)</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28371">28371</ref></refs><vuln_soft><prod name="eggblog" vendor="eggblog"><vers num="3.1.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-02-25" name="CVE-2008-0162" published="2008-02-22" seq="2008-0162" severity="High" type="CVE"><desc><descript source="cve">misc.c in splitvt 1.6.6 and earlier does not drop group privileges before executing xprop, which allows local users to gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><local/></range><refs><ref patch="1" source="DEBIAN" url="http://www.debian.org/security/2008/dsa-1500">DSA-1500</ref><ref source="BID" url="http://www.securityfocus.com/bid/27936">27936</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/29064">29064</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/29080">29080</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200803-05.xml">GLSA-200803-05</ref><ref source="SECUNIA" url="http://secunia.com/advisories/29190">29190</ref></refs><vuln_soft><prod name="Splitvt" vendor="Sam Lantinga"><vers num="1.6.6" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.4" CVSS_exploit_subscore="3.4" CVSS_impact_subscore="6.4" CVSS_score="4.4" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-02-13" name="CVE-2008-0163" published="2008-02-12" seq="2008-0163" severity="Medium" type="CVE"><desc><descript source="cve">Linux kernel 2.6, when using vservers, allows local users to access resources of other vservers via a symlink attack in /proc.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><local/></range><refs><ref patch="1" source="DEBIAN" url="http://www.debian.org/security/2008/dsa-1494">DSA-1494</ref><ref source="BID" url="http://www.securityfocus.com/bid/27704">27704</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28875">28875</ref><ref source="BID" url="http://www.securityfocus.com/bid/27798">27798</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/40486">linux-kernel-proc-unauth-access(40486)</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.6"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2008-03-20" name="CVE-2008-0164" published="2008-03-19" seq="2008-0164" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site request forgery (CSRF) vulnerabilities in Plone CMS 3.0.5 and 3.0.6 allow remote attackers to (1) add arbitrary accounts via the join_form page and (2) change the privileges of arbitrary groups via the prefs_groups_overview page.</descript></desc><loss_types><int/></loss_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/489544/100/0/threaded">20080313 PR08-02: Plone CMS Security Research - the Art of Plowning</ref><ref source="" url="http://plone.org/about/security/advisories/cve-2008-0164"></ref><ref source="" url="http://www.procheckup.com/Hacking_Plone_CMS.pdf"></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/29361">29361</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/41263">plone-joinform-csrf(41263)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/3754">3754</ref></refs><vuln_soft><prod name="Plone CMS" vendor="Plone"><vers num="3.0.5"/><vers num="3.0.6"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2008-04-21" name="CVE-2008-0165" published="2008-04-21" seq="2008-0165" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site request forgery (CSRF) vulnerability in Ikiwiki before 2.42 allows remote attackers to modify user preferences, including passwords, via the (1) preferences and (2) edit forms.</descript></desc><loss_types><int/></loss_types><range><network/><user_init/></range><refs><ref source="" url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=475445"></ref><ref source="DEBIAN" url="http://www.debian.org/security/2008/dsa-1553">DSA-1553</ref><ref source="" url="http://ikiwiki.info/security/#index31h2"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/1297/references">ADV-2008-1297</ref><ref source="SECUNIA" url="http://secunia.com/advisories/29907">29907</ref><ref source="SECUNIA" url="http://secunia.com/advisories/29932">29932</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/41904">ikiwiki-change-password-csrf(41904)</ref></refs><vuln_soft><prod name="Ikiwiki" vendor="Ikiwiki"><vers num="2.41" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)" CVSS_version="2.0" modified="2008-06-04" name="CVE-2008-0166" published="2008-05-13" seq="2008-0166" severity="High" type="CVE"><desc><descript source="cve">OpenSSL 0.9.8c-1 up to versions before 0.9.8g-9 on Debian-based operating systems uses a random number generator that generates predictable numbers, which makes it easier for remote attackers to conduct brute force guessing attacks against cryptographic keys.</descript></desc><loss_types><conf/></loss_types><range><network/></range><refs><ref patch="1" source="DEBIAN" url="http://www.debian.org/security/2008/dsa-1571">DSA-1571</ref><ref patch="1" source="UBUNTU" url="http://www.ubuntu.com/usn/usn-612-1">USN-612-1</ref><ref patch="1" source="UBUNTU" url="http://www.ubuntu.com/usn/usn-612-2">USN-612-2</ref><ref source="BID" url="http://www.securityfocus.com/bid/29179">29179</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/492112/100/0/threaded">20080515 Debian generated SSH-Keys working exploit</ref><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/5622">5622</ref><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/5632">5632</ref><ref source="" url="http://metasploit.com/users/hdm/tools/debian-openssl/"></ref><ref source="DEBIAN" url="http://www.debian.org/security/2008/dsa-1576">DSA-1576</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-612-3">USN-612-3</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-612-4">USN-612-4</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-612-7">USN-612-7</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/925211">VU#925211</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1020017">1020017</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/30220">30220</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/30221">30221</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/30231">30231</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/30239">30239</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/30249">30249</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/30136">30136</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/42375">openssl-rng-weak-security(42375)</ref><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/5720">5720</ref><ref source="MLIST" url="http://sourceforge.net/mailarchive/forum.php?thread_name=48367252.7070603%40shemesh.biz&amp;forum_name=rsyncrypto-devel">[rsyncrypto-devel] 20080523 Advisory - Rsyncrypto maybe affected from Debian OpenSSL reduced entropy problem</ref></refs><vuln_soft><prod name="OpenSSL" vendor="OpenSSL Project"><vers num="0.9.8c-1"/><vers num="0.9.8c-2"/><vers num="0.9.8c-3"/><vers num="0.9.8c-4"/><vers num="0.9.8c-5"/><vers num="0.9.8c-6"/><vers num="0.9.8c-7"/><vers num="0.9.8c-8"/><vers num="0.9.8c-9"/><vers num="0.9.8d-1"/><vers num="0.9.8d-2"/><vers num="0.9.8d-3"/><vers num="0.9.8d-4"/><vers num="0.9.8d-5"/><vers num="0.9.8d-6"/><vers num="0.9.8d-7"/><vers num="0.9.8d-8"/><vers num="0.9.8d-9"/><vers num="0.9.8e-1"/><vers num="0.9.8e-2"/><vers num="0.9.8e-3"/><vers num="0.9.8e-4"/><vers num="0.9.8e-5"/><vers num="0.9.8e-6"/><vers num="0.9.8e-7"/><vers num="0.9.8e-8"/><vers num="0.9.8e-9"/><vers num="0.9.8f-1"/><vers num="0.9.8f-2"/><vers num="0.9.8f-3"/><vers num="0.9.8f-4"/><vers num="0.9.8f-5"/><vers num="0.9.8f-6"/><vers num="0.9.8f-7"/><vers num="0.9.8f-8"/><vers num="0.9.8f-9"/><vers num="0.9.8g-1"/><vers num="0.9.8g-2"/><vers num="0.9.8g-3"/><vers num="0.9.8g-4"/><vers num="0.9.8g-5"/><vers num="0.9.8g-6"/><vers num="0.9.8g-7"/><vers num="0.9.8g-8"/><vers num="0.9.8g-9"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-05-20" name="CVE-2008-0167" published="2008-05-18" seq="2008-0167" severity="Medium" type="CVE"><desc><descript source="cve">The write_array_file function in utils/include.pl in GForge 4.5.14 updates configuration files by truncating them to zero length and then writing new data, which might allow attackers to bypass intended access restrictions or have unspecified other impact in opportunistic circumstances.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><range><local/></range><refs><ref source="" url="http://security.debian.org/pool/updates/main/g/gforge/gforge_4.5.14-22etch8.diff.gz"></ref><ref patch="1" source="DEBIAN" url="http://www.debian.org/security/2008/dsa-1577">DSA-1577</ref><ref source="BID" url="http://www.securityfocus.com/bid/29215">29215</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/1537/references">ADV-2008-1537</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/30088">30088</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/30286">30286</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/42456">gforge-unspecified-symlink(42456)</ref></refs><vuln_soft><prod name="GForge" vendor="GForge"><vers num="4.5.14"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-06-03" name="CVE-2008-0169" published="2008-06-03" seq="2008-0169" severity="Medium" type="CVE"><desc><descript source="cve">Plugin/passwordauth.pm (aka the passwordauth plugin) in ikiwiki 1.34 through 2.47 allows remote attackers to bypass authentication, and login to any account for which an OpenID identity is configured and a password is not configured, by specifying an empty password during the login sequence.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><range><network/></range><refs><ref source="MLIST" url="http://www.openwall.com/lists/oss-security/2008/05/31/3">[oss-security] 20080531 Re: CVE id request: ikiwiki</ref><ref source="" url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=483770"></ref><ref source="" url="http://ikiwiki.info/news/version_2.48/index.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/1710">ADV-2008-1710</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/30468">30468</ref><ref source="" url="http://ikiwiki.info/security/#index33h2"></ref><ref source="BID" url="http://www.securityfocus.com/bid/29479">29479</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/42798">ikiwiki-openid-passwordauth-auth-bypass(42798)</ref></refs><vuln_soft><prod name="Ikiwiki" vendor="Ikiwiki"><vers num="2.47"/><vers num="1.34"/><vers num="1.34.1"/><vers num="1.34.2"/><vers num="1.35"/><vers num="1.36"/><vers num="1.37"/><vers num="1.38"/><vers num="1.39"/><vers num="1.40"/><vers num="1.41"/><vers num="1.42"/><vers num="1.43"/><vers num="1.44"/><vers num="1.45"/><vers num="1.46"/><vers num="1.47"/><vers num="1.48"/><vers num="1.49"/><vers num="1.5"/><vers num="1.51"/><vers num="2.0"/><vers num="2.1"/><vers num="2.10"/><vers num="2.11"/><vers num="2.12"/><vers num="2.13"/><vers num="2.14"/><vers num="2.15"/><vers num="2.16"/><vers num="2.17"/><vers num="2.18"/><vers num="2.19"/><vers num="2.2"/><vers num="2.20"/><vers num="2.3"/><vers num="2.30"/><vers num="2.31"/><vers num="2.31.1"/><vers num="2.31.2"/><vers num="2.31.3"/><vers num="2.4"/><vers num="2.40"/><vers num="2.41"/><vers num="2.42"/><vers num="2.43"/><vers num="2.44"/><vers num="2.5"/><vers num="2.6"/><vers num="2.7"/><vers num="2.8"/><vers num="2.9"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2008-01-18" name="CVE-2008-0171" published="2008-01-17" seq="2008-0171" severity="Medium" type="CVE"><desc><descript source="cve">regex/v4/perl_matcher_non_recursive.hpp in the Boost regex library (aka Boost.Regex) in Boost 1.33 and 1.34 allows context-dependent attackers to cause a denial of service (failed assertion and crash) via an invalid regular expression.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref source="SECUNIA" url="http://secunia.com/advisories/28705">28705</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28511">28511</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28527">28527</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/488102/100/0/threaded">20080213 rPSA-2008-0063-1 boost</ref><ref source="" url="http://wiki.rpath.com/Advisories:rPSA-2008-0063"></ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200802-08.xml">GLSA-200802-08</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28943">28943</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28860">28860</ref><ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2008-03/msg00004.html">SUSE-SR:2008:006</ref><ref source="SECUNIA" url="http://secunia.com/advisories/29323">29323</ref><ref source="" url="http://bugs.gentoo.org/show_bug.cgi?id=205955"></ref><ref source="" url="http://svn.boost.org/trac/boost/changeset/42674"></ref><ref source="" url="http://svn.boost.org/trac/boost/changeset/42745"></ref><ref source="" url="https://issues.rpath.com/browse/RPL-2143"></ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-570-1">USN-570-1</ref><ref source="BID" url="http://www.securityfocus.com/bid/27325">27325</ref><ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00760.html">FEDORA-2008-0880</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0249">ADV-2008-0249</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28545">28545</ref><ref source="MANDRIVA" url="http://www.mandriva.com/en/security/advisories?name=MDVSA-2008:032">MDVSA-2008:032</ref></refs><vuln_soft><prod name="Boost" vendor="Boost"><vers num="1.33"/><vers num="1.34"/></prod><prod name="Boost Regex Library" vendor="Boost"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2008-01-18" name="CVE-2008-0172" published="2008-01-17" seq="2008-0172" severity="Medium" type="CVE"><desc><descript source="cve">The get_repeat_type function in basic_regex_creator.hpp in the Boost regex library (aka Boost.Regex) in Boost 1.33 and 1.34 allows context-dependent attackers to cause a denial of service (NULL dereference and crash) via an invalid regular expression.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref source="" url="http://bugs.gentoo.org/show_bug.cgi?id=205955"></ref><ref source="" url="http://svn.boost.org/trac/boost/changeset/42674"></ref><ref source="" url="http://svn.boost.org/trac/boost/changeset/42745"></ref><ref source="" url="https://issues.rpath.com/browse/RPL-2143"></ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-570-1">USN-570-1</ref><ref source="BID" url="http://www.securityfocus.com/bid/27325">27325</ref><ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00760.html">FEDORA-2008-0880</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0249">ADV-2008-0249</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28545">28545</ref><ref source="MANDRIVA" url="http://www.mandriva.com/en/security/advisories?name=MDVSA-2008:032">MDVSA-2008:032</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28705">28705</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28511">28511</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28527">28527</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/488102/100/0/threaded">20080213 rPSA-2008-0063-1 boost</ref><ref source="" url="http://wiki.rpath.com/Advisories:rPSA-2008-0063"></ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200802-08.xml">GLSA-200802-08</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28943">28943</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28860">28860</ref><ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2008-03/msg00004.html">SUSE-SR:2008:006</ref><ref source="SECUNIA" url="http://secunia.com/advisories/29323">29323</ref></refs><vuln_soft><prod name="Boost" vendor="Boost"><vers num="1.33"/><vers num="1.34"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-01-15" name="CVE-2008-0173" published="2008-01-15" seq="2008-0173" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in Gforge 4.6.99 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified parameters, related to RSS exports.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref patch="1" source="DEBIAN" url="http://www.debian.org/security/2008/dsa-1459">DSA-1459</ref><ref source="BID" url="http://www.securityfocus.com/bid/27266">27266</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0115">ADV-2008-0115</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28395">28395</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28451">28451</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39666">gforge-multiple-sql-injection(39666)</ref></refs><vuln_soft><prod name="GForge" vendor="GForge"><vers num="4.6.99" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2008-01-29" name="CVE-2008-0174" published="2008-01-28" seq="2008-0174" severity="Medium" type="CVE"><desc><descript source="cve">GE Fanuc Proficy Real-Time Information Portal 2.6 and earlier uses HTTP Basic Authentication, which transmits usernames and passwords in base64-encoded cleartext and allows remote attackers to steal the passwords and gain privileges.</descript></desc><loss_types><conf/></loss_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/487075/100/0/threaded">20080125 C4 Security Advisory - GE Fanuc Proficy Information Portal 2.6 Authentication Vulnerability</ref><ref source="" url="http://support.gefanuc.com/support/index?page=kbchannel&amp;id=KB12459"></ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/180876">VU#180876</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1019273">1019273</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/487244/100/0/threaded">20080129 Re: C4 Security Advisory - GE Fanuc Proficy Information Portal 2.6 Authentication Vulnerability</ref><ref source="SREASON" url="http://securityreason.com/securityalert/3590">3590</ref></refs><vuln_soft><prod name="Proficy Real-Time Information Portal" vendor="GE Fanuc"><vers num="2.6" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-01-29" name="CVE-2008-0175" published="2008-01-28" seq="2008-0175" severity="High" type="CVE"><desc><descript source="cve">Unrestricted file upload vulnerability in GE Fanuc Proficy Real-Time Information Portal 2.6 and earlier allows remote attackers to execute arbitrary code by uploading a file with an executable extension to the main virtual directory.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/487079/100/0/threaded">20080125 C4 Security Advisory - GE Fanuc Proficy Information Portal 2.6 Arbitrary File Upload and Execution</ref><ref source="" url="http://support.gefanuc.com/support/index?page=kbchannel&amp;id=KB12460"></ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/339345">VU#339345</ref><ref source="BID" url="http://www.securityfocus.com/bid/27446">27446</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1019274">1019274</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28678">28678</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/487242/100/0/threaded">20080129 Re: C4 Security Advisory - GE Fanuc Proficy Information Portal 2.6 Arbitrary File Upload and Execution</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0307/references">ADV-2008-0307</ref><ref source="SREASON" url="http://securityreason.com/securityalert/3591">3591</ref></refs><vuln_soft><prod name="Proficy Real-Time Information Portal" vendor="GE Fanuc"><vers num="2.6" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-01-29" name="CVE-2008-0176" published="2008-01-28" seq="2008-0176" severity="High" type="CVE"><desc><descript source="cve">Heap-based buffer overflow in w32rtr.exe in GE Fanuc CIMPLICITY HMI SCADA system 7.0 before 7.0 SIM 9, and earlier versions before 6.1 SP6 Hot fix - 010708_162517_6106, allow remote attackers to execute arbitrary code via unknown vectors.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/487076/100/0/threaded">20080125 C4 Security Advisory - GE Fanuc Cimplicity 6.1 Heap Overflow</ref><ref source="" url="http://support.gefanuc.com/support/index?page=kbchannel&amp;id=KB12458"></ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/308556">VU#308556</ref><ref source="BID" url="http://www.securityfocus.com/bid/27447">27447</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1019275">1019275</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28663">28663</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0306">ADV-2008-0306</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/487241/100/0/threaded">20080129 Re: C4 Security Advisory - GE Fanuc Cimplicity 6.1 Heap Overflow</ref><ref source="SREASON" url="http://securityreason.com/securityalert/3592">3592</ref></refs><vuln_soft><prod name="CIMPLICITY" vendor="GE Fanuc"><vers num="6.1_SP6_HF_010708_162517_6106" prev="1"/><vers num="7.0_SIM8" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2008-02-08" name="CVE-2008-0177" published="2008-02-07" seq="2008-0177" severity="High" type="CVE"><desc><descript source="cve">The ipcomp6_input function in sys/netinet6/ipcomp_input.c in the KAME project before 20071201 does not properly check the return value of the m_pulldown function, which allows remote attackers to cause a denial of service (system crash) via an IPv6 packet with an IPComp header.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref adv="1" source="" url="http://cvsweb.netbsd.org/bsdweb.cgi/src/sys/netinet6/ipcomp_input.c?f=u&amp;only_with_tag=netbsd-3-1"></ref><ref source="" url="http://www.kame.net/dev/cvsweb2.cgi/kame/kame/sys/netinet6/ipcomp_input.c.diff?r1=1.36;r2=1.37"></ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/110947">VU#110947</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/27642">27642</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/28788">28788</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28816">28816</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0441">ADV-2008-0441</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1019314">1019314</ref><ref source="FREEBSD" url="http://security.freebsd.org/advisories/FreeBSD-SA-08:04.ipsec.asc">FreeBSD-SA-08:04</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28979">28979</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0688">ADV-2008-0688</ref><ref source="SECUNIA" url="http://secunia.com/advisories/29130">29130</ref><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/5191">5191</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2008//May/msg00001.html">APPLE-SA-2008-05-28</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA08-150A.html">TA08-150A</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/1697">ADV-2008-1697</ref><ref source="SECUNIA" url="http://secunia.com/advisories/30430">30430</ref></refs><vuln_soft><prod name="IPComp" vendor="KAME"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2008-02-05" name="CVE-2008-0178" published="2008-02-04" seq="2008-0178" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in the Enterprise Admin Session Monitoring component in Liferay Portal 4.3.6 allows remote authenticated users to inject arbitrary web script or HTML via the User-Agent HTTP header.</descript></desc><loss_types><int/></loss_types><range><network/><user_init/></range><refs><ref source="" url="http://support.liferay.com/browse/LEP-4736"></ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/326065">VU#326065</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/27547">27547</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28742">28742</ref></refs><vuln_soft><prod name="Liferay Enterprise Portal" vendor="Liferay"><vers num="4.3.6"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2008-02-05" name="CVE-2008-0179" published="2008-02-04" seq="2008-0179" severity="Low" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in service/impl/UserLocalServiceImpl.java in Liferay Portal 4.3.6 allows remote attackers to inject arbitrary web script or HTML via the User-Agent HTTP header, which is used when composing Forgot Password e-mail messages in HTML format.</descript></desc><loss_types><int/></loss_types><range><network/><user_init/></range><refs><ref source="" url="http://support.liferay.com/browse/LEP-4737"></ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/888209">VU#888209</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/27550">27550</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28742">28742</ref></refs><vuln_soft><prod name="Liferay Enterprise Portal" vendor="Liferay"><vers num="4.3.6"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2008-02-05" name="CVE-2008-0180" published="2008-02-04" seq="2008-0180" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in themes/_unstyled/templates/init.vm in Liferay Portal 4.3.6 allows remote authenticated users to inject arbitrary web script or HTML via the Greeting field in a User Profile.</descript></desc><loss_types><int/></loss_types><range><network/><user_init/></range><refs><ref source="" url="http://support.liferay.com/browse/LEP-4738"></ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/732449">VU#732449</ref><ref source="BID" url="http://www.securityfocus.com/bid/27546">27546</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28742">28742</ref></refs><vuln_soft><prod name="Liferay Enterprise Portal" vendor="Liferay"><vers num="1.0"/><vers num="2.0"/><vers num="2.1.0"/><vers num="2.1.1"/><vers num="2.2.0"/><vers num="3.6.1"/><vers num="4.1"/><vers num="4.1.1"/><vers num="4.1.3"/><vers num="4.3.1"/><vers num="4.3.6"/><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2008-02-05" name="CVE-2008-0181" published="2008-02-04" seq="2008-0181" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in the Admin portlet in Liferay Portal 4.3.6 allows remote authenticated users to inject arbitrary web script or HTML via the Shutdown message.</descript></desc><loss_types><int/></loss_types><range><network/><user_init/></range><refs><ref source="" url="http://support.liferay.com/browse/LEP-4739"></ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/217825">VU#217825</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/27554">27554</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28742">28742</ref></refs><vuln_soft><prod name="Liferay Enterprise Portal" vendor="Liferay"><vers num="4.3.6"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2008-02-05" name="CVE-2008-0182" published="2008-02-04" seq="2008-0182" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site request forgery (CSRF) vulnerability in the Admin portlet in Liferay Portal before 4.4.0 allows remote authenticated users to perform unspecified actions as unspecified other authenticated users via the Shutdown message.</descript></desc><loss_types><int/></loss_types><range><network/><user_init/></range><refs><ref source="" url="http://support.liferay.com/browse/LEP-4739"></ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/767825">VU#767825</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28742">28742</ref></refs><vuln_soft><prod name="Liferay Enterprise Portal" vendor="Liferay"><vers num="4.3.6" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0" modified="2008-01-10" name="CVE-2008-0184" published="2008-01-09" seq="2008-0184" severity="Medium" type="CVE"><desc><descript source="cve">Absolute path traversal vulnerability in index.php in Sys-Hotel on Line System allows remote attackers to read arbitrary files via an encoded &quot;/&quot; (&quot;%2F&quot;) in the file parameter.</descript></desc><loss_types><conf/><int/></loss_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/485940/100/0/threaded">20080108 sysHotel On Line Remote File Disclosure Vulnerability.</ref><ref source="BID" url="http://www.securityfocus.com/bid/27184">27184</ref><ref source="SREASON" url="http://securityreason.com/securityalert/3528">3528</ref></refs><vuln_soft><prod name="SysHotel On Line System" vendor="Prenotazioni On Line"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-01-10" name="CVE-2008-0185" published="2008-01-09" seq="2008-0185" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in index.php in NetRisk 1.9.7 and possibly earlier versions allows remote attackers to execute arbitrary SQL commands via the pid parameter in a profile page (possibly profile.php).</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/4852">4852</ref><ref source="" url="http://sourceforge.net/project/shownotes.php?release_id=551208&amp;group_id=129681"></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28328">28328</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/485834/100/0/threaded">20080106 netrisk 1.9.7 Multiple Remote Vulnerabilities (sql injection/xss)</ref></refs><vuln_soft><prod name="NetRisk" vendor="NetRisk"><vers num="1.9.7"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2008-01-10" name="CVE-2008-0186" published="2008-01-09" seq="2008-0186" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in NetRisk 1.9.7 and possibly earlier allows remote attackers to inject arbitrary web script or HTML via the page parameter, possibly related to CVE-2008-0144.</descript></desc><loss_types><int/></loss_types><range><network/><user_init/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/4852">4852</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/485834/100/0/threaded">20080106 netrisk 1.9.7 Multiple Remote Vulnerabilities (sql injection/xss)</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28369">28369</ref></refs><vuln_soft><prod name="NetRisk" vendor="phpRisk"><vers num="1.9.7" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-01-10" name="CVE-2008-0187" published="2008-01-09" seq="2008-0187" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in songinfo.php in SAM Broadcaster samPHPweb, possibly 4.2.2 and earlier, allows remote attackers to execute arbitrary SQL commands via the songid parameter.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/4836">4836</ref><ref source="BID" url="http://www.securityfocus.com/bid/27147">27147</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39463">sambroadcaster-songinfo-sql-injection(39463)</ref></refs><vuln_soft><prod name="samPHPweb" vendor="Spacial Audio Solutions"><vers num="4.2.2"/></prod></vuln_soft></entry><entry name="CVE-2008-0188" published="2008-01-16" reject="1" seq="2008-0188" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: none.  Reason: This candidate was withdrawn by its requester.  Further investigation showed that it was not a new security issue.  Notes: none.</descript></desc><loss_types/><refs/></entry><entry name="CVE-2008-0189" published="2008-01-16" reject="1" seq="2008-0189" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: none.  Reason: This candidate was withdrawn by its requester.  Further investigation showed that it was not a new security issue.  Notes: none.</descript></desc><loss_types/><refs/></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2008-01-10" name="CVE-2008-0190" published="2008-01-09" seq="2008-0190" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in templates/example_template.php in AwesomeTemplateEngine allow remote attackers to inject arbitrary web script or HTML via the (1) data[title], (2) data[message], (3) data[table][1][item], (4) data[table][1][url], or (5) data[poweredby] parameter.</descript></desc><loss_types><int/></loss_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/485786/100/0/threaded">20080103 securityvulns.com russian vulnerabilities digest</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2008-January/059439.html">20080103 securityvulns.com russian vulnerabilities digest</ref><ref source="" url="http://securityvulns.ru/Sdocument784.html"></ref><ref source="" url="http://websecurity.com.ua/1694/"></ref><ref source="BID" url="http://www.securityfocus.com/bid/27125">27125</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39396">awesometemplateengine-multiple-xss(39396)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/3539">3539</ref></refs><vuln_soft><prod name="AwesomeTemplateEngine" vendor="AwesomeTemplateEngine"><vers num="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2008-01-10" name="CVE-2008-0191" published="2008-01-09" seq="2008-0191" severity="Medium" type="CVE"><desc><descript source="cve">WordPress 2.2.x and 2.3.x allows remote attackers to obtain sensitive information via an invalid p parameter in an rss2 action to the default URI, which reveals the full path and the SQL database structure.</descript></desc><loss_types><conf/></loss_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/485786/100/0/threaded">20080103 securityvulns.com russian vulnerabilities digest</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2008-January/059439.html">20080103 securityvulns.com russian vulnerabilities digest</ref><ref source="" url="http://securityvulns.ru/Sdocument663.html"></ref><ref source="" url="http://websecurity.com.ua/1634/"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39423">wordpress-p-path-disclosure(39423)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/3539">3539</ref></refs><vuln_soft><prod name="WordPress" vendor="WordPress"><vers num="2.2"/><vers num="2.3"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2008-01-10" name="CVE-2008-0192" published="2008-01-09" seq="2008-0192" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in WordPress 2.0.9 and earlier allow remote attackers to inject arbitrary web script or HTML via the popuptitle parameter to (1) wp-admin/post.php or (2) wp-admin/page-new.php.</descript></desc><loss_types><int/></loss_types><range><network/><user_init/></range><refs><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2008-January/059439.html">20080103 securityvulns.com russian vulnerabilities digest</ref><ref source="" url="http://securityvulns.ru/Sdocument714.html"></ref><ref source="" url="http://websecurity.com.ua/1658/"></ref><ref source="BID" url="http://www.securityfocus.com/bid/27123">27123</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39426">wordpress-popuptitle-xss(39426)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/3539">3539</ref></refs><vuln_soft><prod name="WordPress" vendor="WordPress"><vers num="2.0.9" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2008-01-10" name="CVE-2008-0193" published="2008-01-09" seq="2008-0193" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in wp-db-backup.php in WordPress 2.0.11 and earlier, and possibly 2.1.x through 2.3.x, allows remote attackers to inject arbitrary web script or HTML via the backup parameter in a wp-db-backup.php action to wp-admin/edit.php.</descript></desc><loss_types><int/></loss_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/485786/100/0/threaded">20080103 securityvulns.com russian vulnerabilities digest</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2008-January/059439.html">20080103 securityvulns.com russian vulnerabilities digest</ref><ref source="" url="http://securityvulns.ru/Sdocument755.html"></ref><ref source="" url="http://websecurity.com.ua/1676/"></ref><ref source="BID" url="http://www.securityfocus.com/bid/27123">27123</ref><ref source="DEBIAN" url="http://www.debian.org/security/2008/dsa-1502">DSA-1502</ref><ref source="SECUNIA" url="http://secunia.com/advisories/29014">29014</ref><ref source="SREASON" url="http://securityreason.com/securityalert/3539">3539</ref></refs><vuln_soft><prod name="WordPress" vendor="WordPress"><vers num="2.0.11" prev="1"/><vers num="2.1"/><vers num="2.1.1"/><vers num="2.1.2"/><vers num="2.1.3"/><vers num="2.1.3 RC1"/><vers num="2.1.3 RC2"/><vers num="2.2"/><vers num="2.2 Revision5002"/><vers num="2.2 Revision5003"/><vers num="2.2.0"/><vers num="2.2.1"/><vers num="2.2.2"/><vers num="2.2.3"/><vers num="2.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-01-10" name="CVE-2008-0194" published="2008-01-09" seq="2008-0194" severity="High" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in wp-db-backup.php in WordPress 2.0.3 and earlier allows remote attackers to read arbitrary files, delete arbitrary files, and cause a denial of service via a .. (dot dot) in the backup parameter in a wp-db-backup.php action to wp-admin/edit.php.  NOTE: this might be the same as CVE-2006-5705.1.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/485786/100/0/threaded">20080103 securityvulns.com russian vulnerabilities digest</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2008-January/059439.html">20080103 securityvulns.com russian vulnerabilities digest</ref><ref source="" url="http://securityvulns.ru/Sdocument755.html"></ref><ref source="" url="http://websecurity.com.ua/1676/"></ref><ref source="DEBIAN" url="http://www.debian.org/security/2008/dsa-1502">DSA-1502</ref><ref source="SECUNIA" url="http://secunia.com/advisories/29014">29014</ref><ref source="SREASON" url="http://securityreason.com/securityalert/3539">3539</ref></refs><vuln_soft><prod name="WordPress" vendor="WordPress"><vers num="2.0.3" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2008-01-10" name="CVE-2008-0195" published="2008-01-09" seq="2008-0195" severity="Medium" type="CVE"><desc><descript source="cve">WordPress 2.0.11 and earlier allows remote attackers to obtain sensitive information via an empty value of the page parameter to certain PHP scripts under wp-admin/, which reveals the path in various error messages.</descript></desc><loss_types><int/></loss_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/485786/100/0/threaded">20080103 securityvulns.com russian vulnerabilities digest</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2008-January/059439.html">20080103 securityvulns.com russian vulnerabilities digest</ref><ref source="" url="http://securityvulns.ru/Sdocument762.html"></ref><ref source="" url="http://securityvulns.ru/Sdocument768.html"></ref><ref source="" url="http://securityvulns.ru/Sdocument772.html"></ref><ref source="" url="http://securityvulns.ru/Sdocument773.html"></ref><ref source="" url="http://websecurity.com.ua/1679/"></ref><ref source="" url="http://websecurity.com.ua/1683/"></ref><ref source="" url="http://websecurity.com.ua/1686/"></ref><ref source="" url="http://websecurity.com.ua/1687/"></ref><ref source="SREASON" url="http://securityreason.com/securityalert/3539">3539</ref></refs><vuln_soft><prod name="WordPress" vendor="WordPress"><vers num="2.0.11" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2008-01-10" name="CVE-2008-0196" published="2008-01-09" seq="2008-0196" severity="Medium" type="CVE"><desc><descript source="cve">Multiple directory traversal vulnerabilities in WordPress 2.0.11 and earlier allow remote attackers to read arbitrary files via a .. (dot dot) in (1) the page parameter to certain PHP scripts under wp-admin/ or (2) the import parameter to wp-admin/admin.php, as demonstrated by discovering the full path via a request for the \..\..\wp-config pathname; and allow remote attackers to modify arbitrary files via a .. (dot dot) in the file parameter to wp-admin/templates.php.</descript></desc><loss_types><conf/></loss_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/485786/100/0/threaded">20080103 securityvulns.com russian vulnerabilities digest</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2008-January/059439.html">20080103 securityvulns.com russian vulnerabilities digest</ref><ref source="" url="http://securityvulns.ru/Sdocument762.html"></ref><ref source="" url="http://securityvulns.ru/Sdocument768.html"></ref><ref source="" url="http://securityvulns.ru/Sdocument772.html"></ref><ref source="" url="http://securityvulns.ru/Sdocument773.html"></ref><ref source="" url="http://websecurity.com.ua/1679/"></ref><ref source="" url="http://websecurity.com.ua/1683/"></ref><ref source="" url="http://websecurity.com.ua/1686/"></ref><ref source="" url="http://websecurity.com.ua/1687/"></ref><ref source="SREASON" url="http://securityreason.com/securityalert/3539">3539</ref></refs><vuln_soft><prod name="WordPress" vendor="WordPress"><vers num="2.0.11" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2008-01-10" name="CVE-2008-0197" published="2008-01-09" seq="2008-0197" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in wp-contact-form/options-contactform.php in the WP-ContactForm 1.5 alpha and earlier plugin for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) wpcf_email, (2) wpcf_subject, (3) wpcf_question, (4) wpcf_answer, (5) wpcf_success_msg, (6) wpcf_error_msg, or (7) wpcf_msg parameter to wp-admin/admin.php, or (8) the SRC attribute of an IFRAME element.</descript></desc><loss_types><int/></loss_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/485786/100/0/threaded">20080103 securityvulns.com russian vulnerabilities digest</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2008-January/059439.html">20080103 securityvulns.com russian vulnerabilities digest</ref><ref source="" url="http://securityvulns.ru/Sdocument546.html"></ref><ref source="" url="http://securityvulns.ru/Sdocument667.html"></ref><ref source="" url="http://websecurity.com.ua/1600/"></ref><ref source="" url="http://websecurity.com.ua/1641/"></ref><ref source="SREASON" url="http://securityreason.com/securityalert/3539">3539</ref></refs><vuln_soft><prod name="WP-ContactForm" vendor="WordPress"><vers num="1.5_alpha" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2008-01-10" name="CVE-2008-0198" published="2008-01-09" seq="2008-0198" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site request forgery (CSRF) vulnerabilities in wp-contact-form/options-contactform.php in the WP-ContactForm 1.5 alpha and earlier plugin for WordPress allow remote attackers to perform actions as administrators via the (1) wpcf_question, (2) wpcf_success_msg, or (3) wpcf_error_msg parameter to wp-admin/admin.php.</descript></desc><loss_types><int/></loss_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/485786/100/0/threaded">20080103 securityvulns.com russian vulnerabilities digest</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2008-January/059439.html">20080103 securityvulns.com russian vulnerabilities digest</ref><ref source="" url="http://securityvulns.ru/Sdocument546.html"></ref><ref source="" url="http://securityvulns.ru/Sdocument667.html"></ref><ref source="" url="http://websecurity.com.ua/1600/"></ref><ref source="" url="http://websecurity.com.ua/1641/"></ref><ref source="SREASON" url="http://securityreason.com/securityalert/3539">3539</ref></refs><vuln_soft><prod name="WordPress" vendor="WordPress"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2008-01-10" name="CVE-2008-0199" published="2008-01-09" seq="2008-0199" severity="Medium" type="CVE"><desc><descript source="cve">PRO-Search 0.17 and earlier allows remote attackers to cause a denial of service via certain values of the show_page and time parameters to the default URI.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/485786/100/0/threaded">20080103 securityvulns.com russian vulnerabilities digest</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2008-January/059439.html">20080103 securityvulns.com russian vulnerabilities digest</ref><ref source="" url="http://securityvulns.ru/Sdocument731.html"></ref><ref source="" url="http://sourceforge.net/project/shownotes.php?release_id=563784&amp;group_id=149797"></ref><ref source="" url="http://websecurity.com.ua/1259/"></ref><ref source="SREASON" url="http://securityreason.com/securityalert/3539">3539</ref></refs><vuln_soft><prod name="PRO_Search" vendor="PRO_Search"><vers num="0.16" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2008-01-10" name="CVE-2008-0200" published="2008-01-09" seq="2008-0200" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in account/index.html in RotaBanner Local 3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) user or (2) drop parameter.</descript></desc><loss_types><int/></loss_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/485786/100/0/threaded">20080103 securityvulns.com russian vulnerabilities digest</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2008-January/059439.html">20080103 securityvulns.com russian vulnerabilities digest</ref><ref source="" url="http://securityvulns.ru/Sdocument625.html"></ref><ref source="" url="http://websecurity.com.ua/1442/"></ref><ref source="SREASON" url="http://securityreason.com/securityalert/3539">3539</ref></refs><vuln_soft><prod name="RotaBanner Local" vendor="MediaLand"><vers num="3" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2008-01-10" name="CVE-2008-0201" published="2008-01-09" seq="2008-0201" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in ExpressionEngine 1.2.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the URL parameter.</descript></desc><loss_types><int/></loss_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/485786/100/0/threaded">20080103 securityvulns.com russian vulnerabilities digest</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2008-January/059439.html">20080103 securityvulns.com russian vulnerabilities digest</ref><ref source="" url="http://securityvulns.ru/Sdocument472.html"></ref><ref source="" url="http://websecurity.com.ua/1454/"></ref><ref source="SREASON" url="http://securityreason.com/securityalert/3539">3539</ref></refs><vuln_soft><prod name="ExpressionEngine" vendor="ExpressionEngine"><vers num="1.2.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2008-01-10" name="CVE-2008-0202" published="2008-01-09" seq="2008-0202" severity="Medium" type="CVE"><desc><descript source="cve">CRLF injection vulnerability in index.php in ExpressionEngine 1.2.1 and earlier allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the URL parameter.</descript></desc><loss_types><int/></loss_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/485786/100/0/threaded">20080103 securityvulns.com russian vulnerabilities digest</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2008-January/059439.html">20080103 securityvulns.com russian vulnerabilities digest</ref><ref source="" url="http://securityvulns.ru/Sdocument472.html"></ref><ref source="" url="http://websecurity.com.ua/1454/"></ref><ref source="SREASON" url="http://securityreason.com/securityalert/3539">3539</ref></refs><vuln_soft><prod name="ExpressionEngine" vendor="ExpressionEngine"><vers num="1.2.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2008-01-10" name="CVE-2008-0203" published="2008-01-09" seq="2008-0203" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in cryptographp/admin.php in the Cryptographp 1.2 and earlier plugin for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) cryptwidth, (2) cryptheight, (3) bgimg, (4) charR, (5) charG, (6) charB, (7) charclear, (8) tfont, (9) charel, (10) charelc, (11) charelv, (12) charnbmin, (13) charnbmax, (14) charspace, (15) charsizemin, (16) charsizemax, (17) charanglemax, (18) noisepxmin, (19) noisepxmax, (20) noiselinemin, (21) noiselinemax, (22) nbcirclemin, (23) nbcirclemax, or (24) brushsize parameter to wp-admin/options-general.php.</descript></desc><loss_types><int/></loss_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/485786/100/0/threaded">20080103 securityvulns.com russian vulnerabilities digest</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2008-January/059439.html">20080103 securityvulns.com russian vulnerabilities digest</ref><ref source="" url="http://websecurity.com.ua/1596/"></ref><ref source="SREASON" url="http://securityreason.com/securityalert/3539">3539</ref></refs><vuln_soft><prod name="Cryptographp" vendor="WordPress"><vers num="1.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2008-01-10" name="CVE-2008-0204" published="2008-01-09" seq="2008-0204" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in math-comment-spam-protection.php in the Math Comment Spam Protection 2.1 and earlier plugin for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) mcsp_opt_msg_no_answer or (2) mcsp_opt_msg_wrong_answer parameter to wp-admin/options-general.php.</descript></desc><loss_types><int/></loss_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/485786/100/0/threaded">20080103 securityvulns.com russian vulnerabilities digest</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2008-January/059439.html">20080103 securityvulns.com russian vulnerabilities digest</ref><ref source="" url="http://websecurity.com.ua/1576/"></ref><ref source="SREASON" url="http://securityreason.com/securityalert/3539">3539</ref></refs><vuln_soft><prod name="Math Comment Spam Protection Plugin" vendor="WordPress"><vers num="2.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2008-01-10" name="CVE-2008-0205" published="2008-01-09" seq="2008-0205" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site request forgery (CSRF) vulnerabilities in math-comment-spam-protection.php in the Math Comment Spam Protection 2.1 and earlier plugin for WordPress allow remote attackers to perform actions as administrators via the (1) mcsp_opt_msg_no_answer or (2) mcsp_opt_msg_wrong_answer parameter to wp-admin/options-general.php.</descript></desc><loss_types><int/></loss_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/485786/100/0/threaded">20080103 securityvulns.com russian vulnerabilities digest</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2008-January/059439.html">20080103 securityvulns.com russian vulnerabilities digest</ref><ref source="" url="http://websecurity.com.ua/1576/"></ref><ref source="SREASON" url="http://securityreason.com/securityalert/3539">3539</ref></refs><vuln_soft><prod name="Math Comment Spam Protection Plugin" vendor="WordPress"><vers num="2.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2008-01-10" name="CVE-2008-0206" published="2008-01-09" seq="2008-0206" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in captcha\captcha.php in the Captcha! 2.5d and earlier plugin for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) captcha_ttffolder, (2) captcha_numchars, (3) captcha_ttfrange, or (4) captcha_secret parameter.</descript></desc><loss_types><int/></loss_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/485786/100/0/threaded">20080103 securityvulns.com russian vulnerabilities digest</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2008-January/059439.html">20080103 securityvulns.com russian vulnerabilities digest</ref><ref source="" url="http://websecurity.com.ua/1588/"></ref><ref source="SREASON" url="http://securityreason.com/securityalert/3539">3539</ref></refs><vuln_soft><prod name="Captcha" vendor="WordPress"><vers num="2.5d" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2008-01-10" name="CVE-2008-0207" published="2008-01-09" seq="2008-0207" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in PRO-Search 0.17 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) prot, (2) host, (3) path, (4) name, (5) ext, (6) size, (7) search_days, or (8) show_page parameter to the default URI.</descript></desc><loss_types><int/></loss_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/485786/100/0/threaded">20080103 securityvulns.com russian vulnerabilities digest</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2008-January/059439.html">20080103 securityvulns.com russian vulnerabilities digest</ref><ref source="" url="http://securityvulns.ru/Sdocument731.html"></ref><ref source="" url="http://sourceforge.net/project/shownotes.php?release_id=563784&amp;group_id=149797"></ref><ref source="" url="http://websecurity.com.ua/1259/"></ref><ref source="BID" url="http://www.securityfocus.com/bid/27126">27126</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28335">28335</ref><ref source="SREASON" url="http://securityreason.com/securityalert/3539">3539</ref></refs><vuln_soft><prod name="PRO_Search" vendor="PRO_Search"><vers num="0.17" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2008-01-10" name="CVE-2008-0208" published="2008-01-09" seq="2008-0208" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in login.asp in Snitz Forums 2000 3.4.05 and earlier allows remote attackers to inject arbitrary web script or HTML via the target parameter.</descript></desc><loss_types><int/></loss_types><range><network/><user_init/></range><refs><ref source="" url="http://hackerscenter.com/archive/view.asp?id=28145"></ref><ref source="" url="http://www.packetstormsecurity.org/0801-exploits/snitz-multi.txt"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/28284">28284</ref></refs><vuln_soft><prod name="Snitz Forums" vendor="Snitz Forums 2000"><vers num="3.4.05" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="4.9" CVSS_score="5.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_version="2.0" modified="2008-01-15" name="CVE-2008-0209" published="2008-01-09" seq="2008-0209" severity="Medium" type="CVE"><desc><descript source="cve">Open redirect vulnerability in Forums/login.asp in Snitz Forums 2000 3.4.06 and earlier allows remote attackers to redirect users to arbitrary web sites via a URL in the target parameter.</descript></desc><loss_types><conf/><int/></loss_types><range><network/><user_init/></range><refs><ref source="" url="http://hackerscenter.com/archive/view.asp?id=28145"></ref><ref source="" url="http://www.packetstormsecurity.org/0801-exploits/snitz-multi.txt"></ref></refs><vuln_soft><prod name="Snitz Forums" vendor="Snitz Forums 2000"><vers num="3.4.06" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0" modified="2008-01-10" name="CVE-2008-0210" published="2008-01-09" seq="2008-0210" severity="Medium" type="CVE"><desc><descript source="cve">Uebimiau Webmail 2.7.10 and 2.7.2 does not protect authentication state variables from being set through HTTP requests, which allows remote attackers to bypass authentication via a sess[auth]=1 parameter settting.  NOTE: this can be leveraged to conduct directory traversal attacks without authentication by using CVE-2008-0140.</descript></desc><loss_types><conf/><int/></loss_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/4846">4846</ref><ref source="BID" url="http://www.securityfocus.com/bid/27154">27154</ref></refs><vuln_soft><prod name="Webmail" vendor="UebiMiau"><vers num="2.7.10"/><vers num="2.7.2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.9" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.9" CVSS_score="4.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2008-04-01" name="CVE-2008-0211" published="2008-03-31" seq="2008-0211" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the BIOS F.04 through F.11 for the HP Compaq Business Notebook PC allows local users to cause a denial of service via unspecified vectors.</descript></desc><loss_types><avail/></loss_types><range><local/></range><refs><ref patch="1" source="HP" url="http://marc.info/?l=bugtraq&amp;m=120672155821700&amp;w=2">HPSBGN02305</ref><ref source="BID" url="http://www.securityfocus.com/bid/28494">28494</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1019729">1019729</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/1042/references">ADV-2008-1042</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/41520">compaq-businessnotebook-pcbios-dos(41520)</ref></refs><vuln_soft><prod name="6820 Series BIOS" vendor="Compaq"><vers num="F.08" prev="1"/></prod><prod name="8510 Series BIOS" vendor="Compaq"><vers num="F.0E" prev="1"/></prod><prod name="8710 Series BIOS" vendor="Compaq"><vers num="F.08" prev="1"/></prod><prod name="2510 Series BIOS" vendor="Compaq"><vers num="F.08" prev="1"/></prod><prod name="6715 Series BIOS" vendor="Compaq"><vers num="F.0A" prev="1"/></prod><prod name="6510 Series BIOS" vendor="Compaq"><vers num="F.0F" prev="1"/></prod><prod name="6520 Series BIOS" vendor="Compaq"><vers num="F.08" prev="1"/></prod><prod name="6515 Series BIOS" vendor="Compaq"><vers num="F.0A" prev="1"/></prod><prod name="6910 Series BIOS" vendor="Compaq"><vers num="F.11" prev="1"/></prod><prod name="2210 Series BIOS" vendor="Compaq"><vers num="F.04" prev="1"/></prod><prod name="2710 Series BIOS" vendor="Compaq"><vers num="F.0D" prev="1"/></prod><prod name="6710 Series BIOS" vendor="Compaq"><vers num="F.0F" prev="1"/></prod><prod name="6720 Series BIOS" vendor="Compaq"><vers num="F.08" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2008-04-09" name="CVE-2008-0212" published="2008-02-06" seq="2008-0212" severity="High" type="CVE"><desc><descript source="cve">ovtopmd in HP OpenView Network Node Manager (OV NNM) 6.41, 7.01, and 7.51 allows remote attackers to cause a denial of service (crash) via a crafted TCP request that triggers an out-of-bounds memory access.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref source="HP" url="http://www.securityfocus.com/archive/1/archive/1/487586/100/0/threaded">HPSBMA02307</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/27629">27629</ref><ref source="IDEFENSE" url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=652">20080204 Hewlett-Packard Network Node Manager Topology Manager Service DoS Vulnerability</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0424">ADV-2008-0424</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1019306">1019306</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28798">28798</ref></refs><vuln_soft><prod name="OpenView Network Node Manager" vendor="HP"><vers num="6.41"/><vers num="7.01"/><vers num="7.51"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-02-13" name="CVE-2008-0213" published="2008-02-07" seq="2008-0213" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in a certain ActiveX control for HP Virtual Rooms (HPVR) 6 and earlier allows remote attackers to execute arbitrary code via unknown vectors.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><range><network/></range><refs><ref source="HP" url="http://marc.info/?l=bugtraq&amp;m=120231595903371&amp;w=2">HPSBGN02310</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1019311">1019311</ref></refs><vuln_soft><prod name="Virtual Rooms" vendor="HP"><vers num="6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-02-11" name="CVE-2008-0214" published="2008-02-07" seq="2008-0214" severity="High" type="CVE"><desc><descript source="cve">Multiple unspecified vulnerabilities in HP Select Identity 4.00, 4.01, 4.11, 4.12, 4.13, and 4.20 allow remote authenticated users to gain access via unknown vectors.</descript></desc><sols><sol source="nvd">In order to download the patch, user must login.</sol></sols><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><range><network/></range><refs><ref patch="1" source="HP" url="http://marc.info/?l=bugtraq&amp;m=120239931201443&amp;w=2">HPSBMA02309</ref><ref source="BID" url="http://www.securityfocus.com/bid/27667">27667</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0472">ADV-2008-0472</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1019322">1019322</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28844">28844</ref></refs><vuln_soft><prod name="Select Identity" vendor="HP"><vers num="4.00"/><vers num="4.01"/><vers num="4.10"/><vers num="4.11"/><vers num="4.12"/><vers num="4.13"/><vers num="4.20"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-02-12" name="CVE-2008-0215" published="2008-02-11" seq="2008-0215" severity="High" type="CVE"><desc><descript source="cve">Multiple unspecified vulnerabilities in HP Storage Essentials Storage Resource Management (SRM) before 6.0.0 allow remote attackers to obtain unspecified access to a managed device via unknown attack vectors.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs><ref source="HP" url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01316132">HPSBST02302</ref><ref source="BID" url="http://www.securityfocus.com/bid/27643">27643</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0440">ADV-2008-0440</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1019312">1019312</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28813">28813</ref></refs><vuln_soft><prod name="Storage Essentials SRM Standard" vendor="HP"><vers num="5.1.3" prev="1"/></prod><prod name="Storage Essentials SRM Enterprise" vendor="HP"><vers num="5.1.3" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2008-01-16" name="CVE-2008-0216" published="2008-01-15" seq="2008-0216" severity="Low" type="CVE"><desc><descript source="cve">The ptsname function in FreeBSD 6.0 through 7.0-PRERELEASE does not properly verify that a certain portion of a device name is associated with a pty of a user who is calling the pt_chown function, which might allow local users to read data from the pty from another user.</descript></desc><loss_types><int/></loss_types><range><local/></range><refs><ref patch="1" source="FREEBSD" url="http://security.FreeBSD.org/advisories/FreeBSD-SA-08:01.pty.asc">FreeBSD-SA-08:01</ref><ref source="BID" url="http://www.securityfocus.com/bid/27284">27284</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1019191">1019191</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28498">28498</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39667">freebsd-ptsname-information-disclosure(39667)</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="6.0"/><vers num="6.0 Release"/><vers num="6.0 Stable"/><vers num="6.1"/><vers num="6.1 p10 Release"/><vers num="6.1 Release"/><vers num="6.1 Stable"/><vers num="6.2"/><vers num="6.2 Stable"/><vers num="6.3"/><vers num="7.0"/><vers num="7.0 Current"/><vers num="7.0 PreRelease"/></prod></vuln_soft></entry><entry CVSS_base_score="6.9" CVSS_exploit_subscore="3.4" CVSS_impact_subscore="10.0" CVSS_score="6.9" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-01-16" name="CVE-2008-0217" published="2008-01-15" seq="2008-0217" severity="Medium" type="CVE"><desc><descript source="cve">The script program in FreeBSD 5.0 through 7.0-PRERELEASE invokes openpty, which creates a pseudo-terminal with world-readable and world-writable permissions when it is not run as root, which allows local users to read data from the terminal of the user running script.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><local/></range><refs><ref patch="1" source="FREEBSD" url="http://security.FreeBSD.org/advisories/FreeBSD-SA-08:01.pty.asc">FreeBSD-SA-08:01</ref><ref source="BID" url="http://www.securityfocus.com/bid/27284">27284</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1019191">1019191</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28498">28498</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39665">freebsd-openpty-information-disclosure(39665)</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="5.0"/><vers num="5.5"/><vers num="6.0"/><vers num="6.1"/><vers num="6.2"/><vers num="7.0"/><vers num="7.0 PreRelease"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2008-01-11" name="CVE-2008-0218" published="2008-01-10" seq="2008-0218" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in admin/index.html in Merak IceWarp Mail Server allows remote attackers to inject arbitrary web script or HTML via the message parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><int/></loss_types><range><network/><user_init/></range><refs><ref source="" url="http://www.securityfocus.com/data/vulnerabilities/exploits/27189.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/27189">27189</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39564">icewarpmailserver-index-xss(39564)</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0135">ADV-2008-0135</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28460">28460</ref></refs><vuln_soft><prod name="IceWarp Mail Server" vendor="Merak"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-01-11" name="CVE-2008-0219" published="2008-01-10" seq="2008-0219" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in soporte_horizontal_w.php in PHP Webquest 2.6 allows remote attackers to execute arbitrary SQL commands via the id_actividad parameter, a different vector than CVE-2007-4920.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/4867">4867</ref><ref source="BID" url="http://www.securityfocus.com/bid/27192">27192</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/26821">26821</ref></refs><vuln_soft><prod name="php webquest" vendor="php webquest"><vers num="2.6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-01-11" name="CVE-2008-0220" published="2008-01-10" seq="2008-0220" severity="High" type="CVE"><desc><descript source="cve">Multiple stack-based buffer overflows in the WebLaunch.WeblaunchCtl.1 (aka CWebLaunchCtl) ActiveX control in weblaunch.ocx 1.0.0.1 in Gateway Weblaunch allow remote attackers to execute arbitrary code via a long string in the (1) second or (2) fourth argument to the DoWebLaunch method.  NOTE: some of these details are obtained from third party information.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref source="FULLDISC" url="http://marc.info/?l=full-disclosure&amp;m=119984138526735&amp;w=2">20080109 Gateway WebLaunch ActiveX Control Insecure Method</ref><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/4869">4869</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/735441">VU#735441</ref><ref source="BID" url="http://www.securityfocus.com/bid/27193">27193</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0077">ADV-2008-0077</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28379">28379</ref></refs><vuln_soft><prod name="CWebLaunchCtl ActiveX Control" vendor="Gateway"><vers num="1.0.0.1"/></prod><prod name="Weblaunch" vendor="Gateway"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-01-11" name="CVE-2008-0221" published="2008-01-10" seq="2008-0221" severity="High" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in the WebLaunch.WeblaunchCtl.1 (aka CWebLaunchCtl) ActiveX control in weblaunch.ocx 1.0.0.1 in Gateway Weblaunch allows remote attackers to execute arbitrary programs via a ..\ (dot dot backslash) in the second argument to the DoWebLaunch method.  NOTE: some of these details are obtained from third party information.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/><user_init/></range><refs><ref source="FULLDISC" url="http://marc.info/?l=full-disclosure&amp;m=119984138526735&amp;w=2">20080109 Gateway WebLaunch ActiveX Control Insecure Method</ref><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/4869">4869</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0077">ADV-2008-0077</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28379">28379</ref></refs><vuln_soft><prod name="Weblaunch" vendor="Gateway"><vers num="1.0.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-01-11" name="CVE-2008-0222" published="2008-01-10" seq="2008-0222" severity="High" type="CVE"><desc><descript source="cve">Unrestricted file upload vulnerability in ajaxfilemanager.php in the Wp-FileManager 1.2 plugin for WordPress allows remote attackers to upload and execute arbitrary PHP code via unspecified vectors.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/4844">4844</ref><ref source="BID" url="http://www.securityfocus.com/bid/27151">27151</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39462">wordpress-wpfilemanager-file-upload(39462)</ref></refs><vuln_soft><prod name="FileManager" vendor="WordPress"><vers num="1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-01-21" name="CVE-2008-0223" published="2008-01-10" seq="2008-0223" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in JustSystems JSFC.DLL, as used in multiple JustSystems products such as Ichitaro, allows remote attackers to execute arbitrary code via a crafted .JTD file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/><user_init/></range><refs><ref source="" url="http://jvn.jp/jp/JVN%2308237857/index.html"></ref><ref source="" url="http://www.fourteenforty.jp/research/advisory.cgi?FFRRA-20080107"></ref><ref source="" url="http://www.justsystems.com/jp/info/pd8001.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/27153">27153</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0045">ADV-2008-0045</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28275">28275</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39501">justsystems-jsfc-bo(39501)</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1019168">1019168</ref></refs><vuln_soft><prod name="Ichitaro Lite2" vendor="Justsystem"><vers num=""/></prod><prod name="Ichitaro viewer" vendor="Justsystem"><vers num=""/></prod><prod name="Ichitaro" vendor="Justsystem"><vers num="11.0"/><vers num="12.0"/><vers num="13.0"/><vers num="2004"/><vers num="2005"/><vers num="2006"/><vers num="2007"/><vers num="Linux"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-01-11" name="CVE-2008-0224" published="2008-01-10" seq="2008-0224" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in index.php in the Newbb_plus 0.92 and earlier module in RunCMS 1.6.1 allows remote attackers to execute arbitrary SQL commands via the Client-Ip parameter.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref source="MILW0RM" url="http://milw0rm.com/exploits/4845">4845</ref><ref source="BID" url="http://www.securityfocus.com/bid/27152">27152</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28340">28340</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39478">runcms-newbb-client-sql-injection(39478)</ref></refs><vuln_soft><prod name="RunCMS" vendor="RunCMS"><vers num="1.5.3"/><vers num="1.6"/><vers num="1.6.1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0" modified="2008-01-23" name="CVE-2008-0225" published="2008-01-10" seq="2008-0225" severity="Medium" type="CVE"><desc><descript source="cve">Heap-based buffer overflow in the rmff_dump_cont function in input/libreal/rmff.c in xine-lib 1.1.9 and earlier allows remote attackers to execute arbitrary code via the SDP Abstract attribute in an RTSP session, related to the rmff_dump_header function and related to disregarding the max field.  NOTE: some of these details are obtained from third party information.</descript></desc><loss_types><conf/><int/></loss_types><range><network/></range><refs><ref source="" url="http://aluigi.altervista.org/adv/xinermffhof-adv.txt"></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28384">28384</ref><ref source="" url="https://bugzilla.redhat.com/show_bug.cgi?id=428620"></ref><ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00592.html">FEDORA-2008-0718</ref><ref source="BID" url="http://www.securityfocus.com/bid/27198">27198</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28489">28489</ref><ref source="" url="http://sourceforge.net/project/shownotes.php?release_id=567872"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0163">ADV-2008-0163</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDVSA-2008:020">MDVSA-2008:020</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/suse_security_summary_report.html">SUSE-SR:2008:002</ref><ref source="" url="http://bugs.gentoo.org/show_bug.cgi?id=205197"></ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200801-12.xml">GLSA-200801-12</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28636">28636</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28674">28674</ref><ref source="DEBIAN" url="http://www.debian.org/security/2008/dsa-1472">DSA-1472</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28507">28507</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDVSA-2008:045">MDVSA-2008:045</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28955">28955</ref></refs><vuln_soft><prod name="xine-lib" vendor="xine"><vers num="1.1.9" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-01-11" name="CVE-2008-0226" published="2008-01-10" seq="2008-0226" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in yaSSL 1.7.5 and earlier, as used in MySQL and possibly other products, allow remote attackers to execute arbitrary code via (1) the ProcessOldClientHello function in handshake.cpp or (2) &quot;input_buffer&amp; operator&gt;&gt;&quot; in yassl_imp.cpp.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/485810/100/0/threaded">20080104 Multiple vulnerabilities in yaSSL 1.7.5</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/485811/100/0/threaded">20080104 Pre-auth buffer-overflow in mySQL through yaSSL</ref><ref source="BID" url="http://www.securityfocus.com/bid/27140">27140</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28324">28324</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28419">28419</ref><ref source="DEBIAN" url="http://www.debian.org/security/2008/dsa-1478">DSA-1478</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28597">28597</ref><ref source="" url="http://bugs.mysql.com/33814"></ref><ref source="" url="http://dev.mysql.com/doc/refman/5.1/en/news-5-1-23.html"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0560/references">ADV-2008-0560</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-588-1">USN-588-1</ref><ref source="SECUNIA" url="http://secunia.com/advisories/29443">29443</ref><ref source="SREASON" url="http://securityreason.com/securityalert/3531">3531</ref></refs><vuln_soft><prod name="MySQL" vendor="MySQL"><vers num=""/></prod><prod name="yaSSL" vendor="yaSSL"><vers num="1.7.5" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-01-11" name="CVE-2008-0227" published="2008-01-10" seq="2008-0227" severity="High" type="CVE"><desc><descript source="cve">yaSSL 1.7.5 and earlier, as used in MySQL and possibly other products, allows remote attackers to cause a denial of service (crash) via a Hello packet containing a large size value, which triggers a buffer over-read in the HASHwithTransform::Update function in hash.cpp.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/485810/100/0/threaded">20080104 Multiple vulnerabilities in yaSSL 1.7.5</ref><ref source="BID" url="http://www.securityfocus.com/bid/27140">27140</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28324">28324</ref><ref source="DEBIAN" url="http://www.debian.org/security/2008/dsa-1478">DSA-1478</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28597">28597</ref><ref source="" url="http://bugs.mysql.com/33814"></ref><ref source="" url="http://dev.mysql.com/doc/refman/5.1/en/news-5-1-23.html"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0560/references">ADV-2008-0560</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-588-1">USN-588-1</ref><ref source="SECUNIA" url="http://secunia.com/advisories/29443">29443</ref><ref source="SREASON" url="http://securityreason.com/securityalert/3531">3531</ref></refs><vuln_soft><prod name="yaSSL" vendor="yaSSL"><vers num="1.7.5" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-01-11" name="CVE-2008-0228" published="2008-01-10" seq="2008-0228" severity="High" type="CVE"><desc><descript source="cve">Cross-site request forgery (CSRF) vulnerability in apply.cgi in the Linksys WRT54GL Wireless-G Broadband Router with firmware 4.30.9 allows remote attackers to perform actions as administrators.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/485853/100/0/threaded">20080107 Linksys WRT54 GL - Session riding (CSRF)</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28364">28364</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39502">linksys-apply-csrf(39502)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/486362/100/0/threaded">20080115 Re: Linksys WRT54 GL - Session riding (CSRF)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/3534">3534</ref></refs><vuln_soft><prod name="WRT54GL" vendor="Linksys"><vers num="4.30.9"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-01-11" name="CVE-2008-0229" published="2008-01-10" seq="2008-0229" severity="High" type="CVE"><desc><descript source="cve">The telnet service in LevelOne WBR-3460 4-Port ADSL 2/2+ Wireless Modem Router with firmware 1.00.11 and 1.00.12 does not require authentication, which allows remote attackers on the local or wireless network to obtain administrative access.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/485935/100/0/threaded">20080108 Level-One WBR-3460A Grants Root Access</ref><ref source="BID" url="http://www.securityfocus.com/bid/27183">27183</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1019162">1019162</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28397">28397</ref><ref source="SREASON" url="http://securityreason.com/securityalert/3533">3533</ref></refs><vuln_soft><prod name="WBR-3460A" vendor="Level One"><vers num="1.0.11"/><vers num="1.0.12"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-01-11" name="CVE-2008-0230" published="2008-01-10" seq="2008-0230" severity="High" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in php121db.php in osDate 2.0.8 and possibly earlier versions allows remote attackers to execute arbitrary PHP code via a URL in the php121dir parameter.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref source="" url="http://packetstormsecurity.org/0801-exploits/osdata-lfi.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/27208">27208</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39567">osdate-php121db-file-include(39567)</ref><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/4870">4870</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28420">28420</ref></refs><vuln_soft><prod name="osDate" vendor="osDate"><vers num="2.0.8"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-01-21" name="CVE-2008-0231" published="2008-01-10" seq="2008-0231" severity="High" type="CVE"><desc><descript source="cve">Multiple directory traversal vulnerabilities in index.php in Tuned Studios (1) Subwoofer, (2) Freeze Theme, (3) Orange Cutout, (4) Lonely Maple, (5) Endless, (6) Classic Theme, and (7) Music Theme webpage templates allow remote attackers to include and execute arbitrary files via &quot;..&quot; sequences in the page parameter.  NOTE: this can be leveraged for remote file inclusion when running in some PHP 5 environments.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/485991/100/0/threaded">20080109 LFI in Tuned Studios Templates</ref><ref source="BID" url="http://www.securityfocus.com/bid/27196">27196</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39555">tunedstudiostemplates-index-file-include(39555)</ref><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/4876">4876</ref><ref source="SREASON" url="http://securityreason.com/securityalert/3532">3532</ref></refs><vuln_soft><prod name="Music Theme" vendor="Tuned Studios"><vers num=""/></prod><prod name="Lonely Maple" vendor="Tuned Studios"><vers num=""/></prod><prod name="Freeze Theme" vendor="Tuned Studios"><vers num=""/></prod><prod name="Subwoofer" vendor="Tuned Studios"><vers num=""/></prod><prod name="Orange Cutout" vendor="Tuned Studios"><vers num=""/></prod><prod name="Endless" vendor="Tuned Studios"><vers num=""/></prod><prod name="Classic Theme" vendor="Tuned Studios"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-01-11" name="CVE-2008-0232" published="2008-01-10" seq="2008-0232" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in Zero CMS 1.0 Alpha allow remote attackers to execute arbitrary SQL commands via (1) the id parameter to index.php, or the (2) f or t parameters to forums/index.php.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref source="" url="http://packetstormsecurity.org/0801-exploits/zerocms-sql.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/27186">27186</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39530">zerocms-index-sql-injection(39530)</ref><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/4864">4864</ref></refs><vuln_soft><prod name="Zero CMS" vendor="Zero CMS"><vers num="1.0_Alpha"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-01-11" name="CVE-2008-0233" published="2008-01-10" seq="2008-0233" severity="High" type="CVE"><desc><descript source="cve">Unrestricted file upload vulnerability in Zero CMS 1.0 Alpha and earlier allows remote attackers to bypass intended access restrictions and upload and execute arbitrary files by uploading an avatar file with an accepted Content-Type such as image/jpeg.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref source="" url="http://packetstormsecurity.org/0801-exploits/zerocms-sql.txt"></ref><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/4864">4864</ref></refs><vuln_soft><prod name="Zero CMS" vendor="Zero CMS"><vers num="1.0_Alpha"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-02-12" name="CVE-2008-0234" published="2008-01-10" seq="2008-0234" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in Apple Quicktime Player 7.3.1.70 and other versions before 7.4.1, when RTSP tunneling is enabled, allows remote attackers to execute arbitrary code via a long Reason-Phrase response to an rtsp:// request, as demonstrated using a 404 error message.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/486091/100/0/threaded">20080110 Buffer-overflow in Quicktime Player 7.3.1.70</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/486114/100/0/threaded">20080110 Re: Buffer-overflow in Quicktime Player 7.3.1.70</ref><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/4885">4885</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/112179">VU#112179</ref><ref source="BID" url="http://www.securityfocus.com/bid/27225">27225</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/486174/100/0/threaded">20080111 Re: Buffer-overflow in Quicktime Player 7.3.1.70</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/486161/100/0/threaded">20080111 Re: Re: Buffer-overflow in Quicktime Player 7.3.1.70</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/486268/100/0/threaded">20080112 Re: Buffer-overflow in Quicktime Player 7.3.1.70</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/486241/100/0/threaded">20080112 Re: Re: Buffer-overflow in Quicktime Player 7.3.1.70</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/486238/100/0/threaded">20080114 Re: [Full-disclosure] Buffer-overflow in Quicktime Player 7.3.1.70</ref><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/4906">4906</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0107">ADV-2008-0107</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1019178">1019178</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28423">28423</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39601">quicktime-rtsp-responses-bo(39601)</ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2008/Feb/msg00001.html">APPLE-SA-2008-02-06</ref><ref source="SREASON" url="http://securityreason.com/securityalert/3537">3537</ref></refs><vuln_soft><prod name="Quicktime" vendor="Apple"><vers num="7.4" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-01-11" name="CVE-2008-0235" published="2008-01-10" seq="2008-0235" severity="High" type="CVE"><desc><descript source="cve">The Microsoft VFP_OLE_Server ActiveX control allows remote attackers to execute arbitrary code by invoking the foxcommand method.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/><user_init/></range><refs><ref source="" url="http://shinnai.altervista.org/exploits/txt/TXT_rNowA1916DKFNUF48NyS.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/27199">27199</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39559">microsoft-vfpoleserver-command-execution(39559)</ref><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/4875">4875</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28417">28417</ref></refs><vuln_soft><prod name="VFP_OLE_Server ActiveX Control" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="4.9" CVSS_score="5.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_version="2.0" modified="2008-01-11" name="CVE-2008-0236" published="2008-01-10" seq="2008-0236" severity="Medium" type="CVE"><desc><descript source="cve">An ActiveX control for Microsoft Visual FoxPro (vfp6r.dll 6.0.8862.0) allows remote attackers to execute arbitrary commands by invoking the DoCmd method.</descript></desc><loss_types><conf/><int/></loss_types><range><network/><user_init/></range><refs><ref source="" url="http://shinnai.altervista.org/exploits/txt/TXT_DiWu9j82RCq4zpaQAoxn.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/27205">27205</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39558">microsoft-foxserver-command-execution(39558)</ref><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/4873">4873</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28417">28417</ref></refs><vuln_soft><prod name="Visual Fox Pro" vendor="Microsoft"><vers num="6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-01-11" name="CVE-2008-0237" published="2008-01-10" seq="2008-0237" severity="Medium" type="CVE"><desc><descript source="cve">The Microsoft Rich Textbox ActiveX Control (RICHTX32.OCX) 6.1.97.82 allows remote attackers to execute arbitrary commands by invoking the insecure SaveFile method.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><range><network/><user_init/></range><refs><ref source="" url="http://shinnai.altervista.org/exploits/txt/TXT_DZVN8CwCha0I2fI3NeEs.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/27201">27201</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39557">microsoft-richtextbox-file-overwrite(39557)</ref><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/4874">4874</ref></refs><vuln_soft><prod name="Rich Textbox Control" vendor="Microsoft"><vers num="6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-01-14" name="CVE-2008-0238" published="2008-01-11" seq="2008-0238" severity="High" type="CVE"><desc><descript source="cve">Multiple heap-based buffer overflows in the rmff_dump_cont function in input/libreal/rmff.c in xine-lib 1.1.9 allow remote attackers to execute arbitrary code via the SDP (1) Title, (2) Author, or (3) Copyright attribute, related to the rmff_dump_header function, different vectors than CVE-2008-0225.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><sols><sol source="nvd">Please see the following link for more information regarding the exploit:

http://aluigi.altervista.org/adv/xinermffhof-adv.txt</sol></sols><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28384">28384</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDVSA-2008:020">MDVSA-2008:020</ref><ref source="" url="http://bugs.gentoo.org/show_bug.cgi?id=205197"></ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200801-12.xml">GLSA-200801-12</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28674">28674</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDVSA-2008:045">MDVSA-2008:045</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28955">28955</ref></refs><vuln_soft><prod name="xine-lib" vendor="xine"><vers num="1.1.9" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2008-01-14" name="CVE-2008-0239" published="2008-01-11" seq="2008-0239" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Sun Java System Identity Manager 6.0 SP1 through SP3, 7.0, and 7.1 allow remote attackers to inject arbitrary HTML or web script via the (1) cntry or lang parameters to /idm/login.jsp, (2) resultsForm parameter to /idm/account/findForSelect.jsp, or (3) activeControl parameter to /idm/user/main.jsp.</descript></desc><loss_types><int/></loss_types><range><network/><user_init/></range><refs><ref patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/486076/100/0/threaded">20080110 PR07-06, PR07-07, PR07-08, PR07-09, PR07-10, PR07-12: Several XSS, Cross-domain Redirection and Frame Injection on Sun Java System Identity Manager</ref><ref patch="1" source="" url="http://www.procheckup.com/Vulnerability_PR07-06.php"></ref><ref patch="1" source="" url="http://www.procheckup.com/Vulnerability_PR07-07.php"></ref><ref patch="1" source="" url="http://www.procheckup.com/Vulnerability_PR07-08.php"></ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-103180-1">103180</ref><ref source="BID" url="http://www.securityfocus.com/bid/27214">27214</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0089">ADV-2008-0089</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28356">28356</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39581">sun-identity-lang-xss(39581)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39580">sun-identity-login-xss(39580)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39583">sun-identity-main-xss(39583)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39582">sun-identity-resultsform-xss(39582)</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1019175">1019175</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-200558-1">200558</ref><ref source="SREASON" url="http://securityreason.com/securityalert/3535">3535</ref></refs><vuln_soft><prod name="Java System Identity Manager" vendor="Sun"><vers num="6.0_SP1"/><vers num="6.0_SP2"/><vers num="6.0_SP3"/><vers num="7.0"/><vers num="7.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2008-01-14" name="CVE-2008-0240" published="2008-01-11" seq="2008-0240" severity="Medium" type="CVE"><desc><descript source="cve">/idm/help/index.jsp in Sun Java System Identity Manager 6.0 SP1 through SP3, 7.0, and 7.1 allows remote attackers to inject frames from arbitrary web sites and conduct phishing attacks via the helpUrl parameter, aka &quot;frame injection.&quot;</descript></desc><loss_types><int/></loss_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/486076/100/0/threaded">20080110 PR07-06, PR07-07, PR07-08, PR07-09, PR07-10, PR07-12: Several XSS, Cross-domain Redirection and Frame Injection on Sun Java System Identity Manager</ref><ref patch="1" source="" url="http://www.procheckup.com/Vulnerability_PR07-10.php"></ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-103180-1">103180</ref><ref source="BID" url="http://www.securityfocus.com/bid/27214">27214</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0089">ADV-2008-0089</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28356">28356</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39586">sun-identity-index-frame-injection(39586)</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-200558-1">200558</ref><ref source="SREASON" url="http://securityreason.com/securityalert/3535">3535</ref></refs><vuln_soft><prod name="Java System Identity Manager" vendor="Sun"><vers num="6.0_SP1"/><vers num="6.0_SP2"/><vers num="6.0_SP3"/><vers num="7.0"/><vers num="7.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2008-01-14" name="CVE-2008-0241" published="2008-01-11" seq="2008-0241" severity="Medium" type="CVE"><desc><descript source="cve">Open redirect vulnerability in /idm/user/login.jsp in Sun Java System Identity Manager 6.0 SP1 through SP3, 7.0, and 7.1 to allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the nextPage parameter.</descript></desc><loss_types><int/></loss_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/486076/100/0/threaded">20080110 PR07-06, PR07-07, PR07-08, PR07-09, PR07-10, PR07-12: Several XSS, Cross-domain Redirection and Frame Injection on Sun Java System Identity Manager</ref><ref patch="1" source="" url="http://www.procheckup.com/Vulnerability_PR07-12.php"></ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-103180-1">103180</ref><ref source="BID" url="http://www.securityfocus.com/bid/27214">27214</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0089">ADV-2008-0089</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28356">28356</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39590">sun-identity-login-security-bypass(39590)</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-200558-1">200558</ref><ref source="SREASON" url="http://securityreason.com/securityalert/3535">3535</ref></refs><vuln_soft><prod name="Java System Identity Manager" vendor="Sun"><vers num="6.0_SP1"/><vers num="6.0_SP2"/><vers num="6.0_SP3"/><vers num="7.0"/><vers num="7.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-01-14" name="CVE-2008-0242" published="2008-01-11" seq="2008-0242" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in libdevinfo in Sun Solaris 10 allows local users to access files and gain privileges via unknown vectors, related to login device permissions.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><local/></range><refs><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-103165-1">103165</ref><ref source="BID" url="http://www.securityfocus.com/bid/27253">27253</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0131">ADV-2008-0131</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1019187">1019187</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28493">28493</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39629">solaris-libdevinfo-privilege-escalation(39629)</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-200641-1">200641</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5211">oval:org.mitre.oval:def:5211</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers edition="x86" num="10.0"/><vers edition="SPARC" num="10.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2008-01-14" name="CVE-2008-0243" published="2008-01-11" seq="2008-0243" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Lotus Domino 7.0.2 before Fix Pack 3 allows attackers to cause a denial of service via unknown vectors.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref source="" url="http://www-1.ibm.com/support/docview.wss?uid=swg27011539"></ref><ref source="BID" url="http://www.securityfocus.com/bid/27215">27215</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0086">ADV-2008-0086</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28411">28411</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39588">lotus-domino-unspecified-dos(39588)</ref></refs><vuln_soft><prod name="Lotus Domino" vendor="IBM"><vers num="7.0"/><vers num="7.0.1"/><vers num="7.0.2"/><vers num="7.0.2 FP1"/><vers num="7.0.2 FP2"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-01-14" name="CVE-2008-0244" published="2008-01-11" seq="2008-0244" severity="High" type="CVE"><desc><descript source="cve">SAP MaxDB 7.6.03 build 007 and earlier allows remote attackers to execute arbitrary commands via &quot;&amp;&amp;&quot; and other shell metacharacters in exec_sdbinfo and other unspecified commands, which are executed when MaxDB invokes cons.exe.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/486039/100/0/threaded">20080109 Pre-auth remote commands execution in SAP MaxDB 7.6.03.07</ref><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/4877">4877</ref><ref source="" url="http://aluigi.altervista.org/adv/sapone-adv.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/27206">27206</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0104">ADV-2008-0104</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1019171">1019171</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28409">28409</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39573">maxdb-system-command-execution(39573)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/3536">3536</ref></refs><vuln_soft><prod name="MaxDB" vendor="SAP"><vers num="7.6.3 build 007" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-01-14" name="CVE-2008-0245" published="2008-01-11" seq="2008-0245" severity="High" type="CVE"><desc><descript source="cve">admin.php in UploadImage 1.0 does not check for the original password before making a change to a new password, which allows remote attackers to gain administrator privileges via the pass parameter in a nopass (Set Password) action.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/4871">4871</ref><ref source="BID" url="http://www.securityfocus.com/bid/27203">27203</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39571">uploadimage-admin-command-execution(39571)</ref></refs><vuln_soft><prod name="UploadImage" vendor="Uploadscript"><vers num="1.0"/></prod><prod name="Uploadscript" vendor="Uploadscript"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-01-14" name="CVE-2008-0246" published="2008-01-11" seq="2008-0246" severity="High" type="CVE"><desc><descript source="cve">admin.php in UploadScript 1.0 does not check for the original password before making a change to a new password, which allows remote attackers to gain administrator privileges via the pass parameter in a nopass (Set Password) action.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/4871">4871</ref><ref source="BID" url="http://www.securityfocus.com/bid/27203">27203</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39570">uploadscript-admin-command-execution(39570)</ref></refs><vuln_soft><prod name="UploadImage" vendor="Uploadscript"><vers num="1.0"/></prod><prod name="Uploadscript" vendor="Uploadscript"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-01-23" name="CVE-2008-0247" published="2008-01-11" seq="2008-0247" severity="High" type="CVE"><desc><descript source="cve">Heap-based buffer overflow in the Express Backup Server service (dsmsvc.exe) in IBM Tivoli Storage Manager (TSM) Express 5.3 before 5.3.7.3 allows remote attackers to execute arbitrary code via a packet with a large length value.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs><ref patch="1" source="" url="http://www-1.ibm.com/support/docview.wss?uid=swg21291536"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/27235">27235</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0106">ADV-2008-0106</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/28440">28440</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39604">ibm-tsmexpressserver-bo(39604)</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1019182">1019182</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/486270/100/0/threaded">20080114 ZDI-08-001: IBM Tivoli Storage Manager Express Backup Server Heap Overflow Vulnerability</ref><ref source="" url="http://www.zerodayinitiative.com/advisories/ZDI-08-001.html"></ref></refs><vuln_soft><prod name="Tivoli Storage Manager Express" vendor="IBM"><vers num="5.3" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-01-14" name="CVE-2008-0248" published="2008-01-11" seq="2008-0248" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in an ActiveX control in ccpm_0237.dll for StreamAudio ChainCast ProxyManager allows remote attackers to execute arbitrary code via a long URL argument to the InternalTuneIn method.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/><user_init/></range><refs><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2008-January/059572.html">20080111 StreamAudio ChainCast ProxyManager ccpm_0237.dll Buffer Overflow</ref><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/4894">4894</ref><ref source="BID" url="http://www.securityfocus.com/bid/27247">27247</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39622">streamaudio-chaincastproxymanager-bo(39622)</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0133">ADV-2008-0133</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28461">28461</ref></refs><vuln_soft><prod name="ChainCast ProxyManager ActiveX Control" vendor="StreamAudio"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2008-01-14" name="CVE-2008-0249" published="2008-01-11" seq="2008-0249" severity="Medium" type="CVE"><desc><descript source="cve">PHP Webquest 2.6 allows remote attackers to retrieve database credentials via a direct request to admin/backup_phpwebquest.php, which leaks the credentials in an error message if a call to /usr/bin/mysqldump fails.  NOTE: this might only be an issue in limited environments.</descript></desc><loss_types><conf/></loss_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/4872">4872</ref><ref source="BID" url="http://www.securityfocus.com/bid/27202">27202</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39572">phpwebquest-backup-information-disclosure(39572)</ref></refs><vuln_soft><prod name="phpWebquest" vendor="phpWebquest"><vers num="2.6"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-01-15" name="CVE-2008-0250" published="2008-01-11" seq="2008-0250" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Microsoft Visual InterDev 6.0 (SP6) allows user-assisted attackers to execute arbitrary code via a Studio Solution (.SLN) file with a long Project line.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/><user_init/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/4892">4892</ref><ref source="" url="http://shinnai.altervista.org/exploits/txt/TXT_PoEOrFM8py30PXrDF7IY.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/27250">27250</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28482">28482</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/41826">visualinterdev-sln-project-bo(41826)</ref></refs><vuln_soft><prod name="Visual InterDev" vendor="Microsoft"><vers num="6.0_SP6"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-01-15" name="CVE-2008-0251" published="2008-01-11" seq="2008-0251" severity="High" type="CVE"><desc><descript source="cve">Unrestricted file upload vulnerability in PhotoPost vBGallery before 2.4.2 allows remote attackers to upload and execute arbitrary files via unknown vectors.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref source="" url="http://www.photopost.com/forum/showthread.php?t=134909"></ref><ref source="" url="http://www.photopost.com/forum/showthread.php?t=134910"></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28430">28430</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39621">vbgallery-unspecified-code-execution(39621)</ref></refs><vuln_soft><prod name="Photopost vBGallery" vendor="PhotoPost"><vers num="2.4.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-01-16" name="CVE-2008-0252" published="2008-01-11" seq="2008-0252" severity="High" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in the _get_file_path function in (1) lib/sessions.py in CherryPy 3.0.x up to 3.0.2, (2) filter/sessionfilter.py in CherryPy 2.1, and (3) filter/sessionfilter.py in CherryPy 2.x allows remote attackers to create or delete arbitrary files, and possibly read and write portions of arbitrary files, via a crafted session id in a cookie.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref patch="1" source="" url="http://www.cherrypy.org/changeset/1774"></ref><ref patch="1" source="" url="http://www.cherrypy.org/changeset/1775"></ref><ref source="" url="http://www.cherrypy.org/changeset/1776"></ref><ref source="" url="http://www.cherrypy.org/ticket/744"></ref><ref source="" url="https://bugs.gentoo.org/show_bug.cgi?id=204829"></ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0039">ADV-2008-0039</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28354">28354</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/487001/100/0/threaded">20080124 rPSA-2008-0030-1 CherryPy</ref><ref source="" url="https://issues.rpath.com/browse/RPL-2127"></ref><ref source="BID" url="http://www.securityfocus.com/bid/27181">27181</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28611">28611</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200801-11.xml">GLSA-200801-11</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28620">28620</ref><ref source="DEBIAN" url="http://www.debian.org/security/2008/dsa-1481">DSA-1481</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28769">28769</ref></refs><vuln_soft><prod name="CherryPy" vendor="CherryPy"><vers num="2.1.0" prev="1"/><vers num="3.0.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-01-15" name="CVE-2008-0253" published="2008-01-15" seq="2008-0253" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in full_text.php in Binn SBuilder allows remote attackers to execute arbitrary SQL commands via the nid parameter.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/4904">4904</ref><ref source="BID" url="http://www.securityfocus.com/bid/27264">27264</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/486265/100/0/threaded">20080114 Binn SBuilder (nid) Remote Blind Sql Injection Vulnerabily</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39634">binnsbuilder-fulltext-sql-injection(39634)</ref></refs><vuln_soft><prod name="SBuilder" vendor="BinN"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-01-15" name="CVE-2008-0254" published="2008-01-15" seq="2008-0254" severity="Medium" type="CVE"><desc><descript source="cve">SQL injection vulnerability in activate.php in TutorialCMS (aka Photoshop Tutorials) 1.02, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the userName parameter.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/><user_init/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/4901">4901</ref><ref source="BID" url="http://www.securityfocus.com/bid/27263">27263</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28446">28446</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39642">tutorialcms-activate-sql-injection(39642)</ref></refs><vuln_soft><prod name="TutorialCMS" vendor="Wavelink Media"><vers num="1.02"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-07-09" name="CVE-2008-0255" published="2008-01-15" seq="2008-0255" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in archive.php in iGaming 1.5, and 1.3.1 and earlier, allows remote attackers to execute arbitrary SQL commands via the section parameter.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/4886">4886</ref><ref source="BID" url="http://www.securityfocus.com/bid/27230">27230</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28426">28426</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39598">igamingcms-archive-sql-injection(39598)</ref></refs><vuln_soft><prod name="igaming_cms" vendor="igamingcms"><vers num="1.3.1" prev="1"/><vers num="1.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-01-15" name="CVE-2008-0256" published="2008-01-15" seq="2008-0256" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in Matteo Binda ASP Photo Gallery 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to (a) Imgbig.asp, (b) thumb.asp, and (c) thumbricerca.asp and the (2) ricerca parameter to (d) thumbricerca.asp.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/4900">4900</ref><ref source="BID" url="http://www.securityfocus.com/bid/27262">27262</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28447">28447</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39646">aspphotogallery-multiple-sql-injection(39646)</ref></refs><vuln_soft><prod name="ASP Photo Gallery" vendor="Matteo Binda"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2008-01-15" name="CVE-2008-0257" published="2008-01-15" seq="2008-0257" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in search.pl in Dansie Search Engine 2.7 allows remote attackers to inject arbitrary web script or HTML via the keywords parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><int/></loss_types><range><network/><user_init/></range><refs><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28465">28465</ref><ref source="BID" url="http://www.securityfocus.com/bid/27269">27269</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39636">dansiesearchengine-search-xss(39636)</ref></refs><vuln_soft><prod name="Search Engine" vendor="Dansie"><vers num="2.7"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2008-01-15" name="CVE-2008-0258" published="2008-01-15" seq="2008-0258" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in PHP Running Management (phpRunMan) before 1.0.3 allows remote attackers to inject arbitrary web script or HTML via the message parameter.</descript></desc><loss_types><int/></loss_types><range><network/><user_init/></range><refs><ref patch="1" source="" url="http://sourceforge.net/project/shownotes.php?release_id=568237&amp;group_id=103505"></ref><ref source="" url="http://sourceforge.net/tracker/index.php?func=detail&amp;aid=1204199&amp;group_id=103505&amp;atid=634992"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/27268">27268</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/28474">28474</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39639">phprunningmanagement-index-xss(39639)</ref></refs><vuln_soft><prod name="phpRunMan" vendor="PHP Running Management"><vers num="1.0.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0" modified="2008-01-15" name="CVE-2008-0259" published="2008-01-15" seq="2008-0259" severity="Medium" type="CVE"><desc><descript source="cve">Multiple directory traversal vulnerabilities in _mg/php/mg_thumbs.php in minimal Gallery 0.8 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) thumbcat and (2) thumb parameters.</descript></desc><loss_types><conf/><int/></loss_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/4902">4902</ref><ref source="BID" url="http://www.securityfocus.com/bid/27265">27265</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28391">28391</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39649">minimalgallery-mgthumbs-file-include(39649)</ref></refs><vuln_soft><prod name="minimal Gallery" vendor="minimal design"><vers num="0.8"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2008-01-15" name="CVE-2008-0260" published="2008-01-15" seq="2008-0260" severity="Medium" type="CVE"><desc><descript source="cve">minimal Gallery 0.8 allows remote attackers to obtain configuration information via a direct request to php_info.php, which calls the phpinfo function.</descript></desc><loss_types><int/></loss_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/4902">4902</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28391">28391</ref></refs><vuln_soft><prod name="minimal Gallery" vendor="minimal design"><vers num="0.8"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2008-01-15" name="CVE-2008-0261" published="2008-01-15" seq="2008-0261" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the search component and module in Mambo 4.5.x and 4.6.x allows remote attackers to cause a denial of service (query flood) via unspecified vectors.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref patch="1" source="" url="http://forum.mambo-foundation.org/showthread.php?t=9651"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/27239">27239</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/28392">28392</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39613">mambo-search-dos(39613)</ref></refs><vuln_soft><prod name="Mambo Open Source" vendor="Mambo"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-01-15" name="CVE-2008-0262" published="2008-01-15" seq="2008-0262" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in includes/articleblock.php in Agares PhpAutoVideo 2.21 allows remote attackers to execute arbitrary SQL commands via the articlecat parameter.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/4898">4898</ref><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/4905">4905</ref><ref source="BID" url="http://www.securityfocus.com/bid/27258">27258</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39641">agares-articleblock-sql-injection(39641)</ref></refs><vuln_soft><prod name="phpAutoVideo" vendor="Agares Media"><vers num="2.21"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2008-01-15" name="CVE-2008-0263" published="2008-01-15" seq="2008-0263" severity="Medium" type="CVE"><desc><descript source="cve">The SIP module in Ingate Firewall before 4.6.1 and SIParator before 4.6.1 does not reuse SIP media ports in unspecified call hold and send-only stream scenarios, which allows remote attackers to cause a denial of service (port exhaustion) via unspecified vectors.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref adv="1" source="" url="http://www.ingate.com/relnote-461.php"></ref><ref source="BID" url="http://www.securityfocus.com/bid/27222">27222</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0108">ADV-2008-0108</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1019176">1019176</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1019177">1019177</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28394">28394</ref></refs><vuln_soft><prod name="Ingate_SIParator" vendor="Ingate"><vers num="4.6" prev="1"/></prod><prod name="firewall" vendor="Ingate"><vers num="4.6" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-01-15" name="CVE-2008-0264" published="2008-01-15" seq="2008-0264" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the Meta Tags (aka Nodewords) 5.x-1.6 module for Drupal, when images are permitted in node bodies, allows remote authenticated users to execute arbitrary code via unspecified vectors involving creation of a node.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref patch="1" source="" url="http://drupal.org/node/209759"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0129">ADV-2008-0129</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28478">28478</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39638">drupal-metatags-code-execution(39638)</ref></refs><vuln_soft><prod name="Meta_Tags_Module" vendor="Drupal"><vers num="5.x-1.6" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2008-01-23" name="CVE-2008-0265" published="2008-01-15" seq="2008-0265" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in the Search function in the web management interface in F5 BIG-IP 9.4.3 allow remote attackers to inject arbitrary web script or HTML via the SearchString parameter to (1) list_system.jsp, (2) list_pktfilter.jsp, (3) list_ltm.jsp, (4) resources_audit.jsp, and (5) list_asm.jsp in tmui/Control/jspmap/tmui/system/log/; and (6) list.jsp in certain directories.</descript></desc><loss_types><int/></loss_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/486217/100/0/threaded">20080114 F5 BIG-IP Web Management List Search XSS</ref><ref source="BID" url="http://www.securityfocus.com/bid/27272">27272</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1019190">1019190</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39632">f5bigip-searchstring-xss(39632)</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0181">ADV-2008-0181</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28505">28505</ref><ref source="SREASON" url="http://securityreason.com/securityalert/3545">3545</ref></refs><vuln_soft><prod name="BIG-IP" vendor="F5"><vers num="9.4.3"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2008-01-16" name="CVE-2008-0266" published="2008-01-15" seq="2008-0266" severity="Low" type="CVE"><desc><descript source="cve">Cross-site request forgery (CSRF) vulnerability in admin.php in eTicket 1.5.5.2 allows remote attackers to change the administrative password and possibly perform other administrative tasks.  NOTE: either the old password must be known, or the attacker must leverage a separate SQL injection vulnerability.</descript></desc><loss_types><int/></loss_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/485835/100/0/threaded">20080106 eTicket 1.5.5.2 Multiple Vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/27173">27173</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28331">28331</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39490">eticket-admin-csrf(39490)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/3542">3542</ref></refs><vuln_soft><prod name="eTicket" vendor="eTicket"><vers num="1.5.5.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-01-16" name="CVE-2008-0267" published="2008-01-15" seq="2008-0267" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in eTicket 1.5.5.2 allow remote authenticated users to execute arbitrary SQL commands via the (1) status, (2) sort, and (3) way parameters to search.php; and allow remote authenticated administrators to execute arbitrary SQL commands via the (4) msg and (5) password parameters to admin.php.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/485835/100/0/threaded">20080106 eTicket 1.5.5.2 Multiple Vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/27173">27173</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28331">28331</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39489">eticket-search-sql-injection(39489)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/3542">3542</ref></refs><vuln_soft><prod name="eTicket" vendor="eTicket"><vers num="1.5.5.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="4.9" CVSS_score="5.8" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:P)" CVSS_version="2.0" modified="2008-01-16" name="CVE-2008-0268" published="2008-01-15" seq="2008-0268" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in view.php in eTicket 1.5.5.2 allows remote attackers to inject arbitrary web script or HTML via the s parameter.</descript></desc><loss_types><avail/><int/></loss_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/485835/100/0/threaded">20080106 eTicket 1.5.5.2 Multiple Vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/27173">27173</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28331">28331</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39488">eticket-view-xss(39488)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/3542">3542</ref></refs><vuln_soft><prod name="eTicket" vendor="eTicket"><vers num="1.5.5.2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.9" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.9" CVSS_score="4.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2008-01-16" name="CVE-2008-0269" published="2008-01-15" seq="2008-0269" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the dotoprocs function in Sun Solaris 10 allows local users to cause a denial of service (panic) via unspecified vectors.</descript></desc><loss_types><avail/></loss_types><range><local/></range><refs><ref patch="1" source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-103188-1">103188</ref><ref source="BID" url="http://www.securityfocus.com/bid/27260">27260</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0130">ADV-2008-0130</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1019186">1019186</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28491">28491</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39631">solaris-dotoprocs-dos(39631)</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-201513-1">201513</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5400">oval:org.mitre.oval:def:5400</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers num="10"/></prod></vuln_soft></entry><entry CVSS_base_score="6.0" CVSS_exploit_subscore="6.8" CVSS_impact_subscore="6.4" CVSS_score="6.0" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-01-16" name="CVE-2008-0270" published="2008-01-15" seq="2008-0270" severity="Medium" type="CVE"><desc><descript source="cve">SQL injection vulnerability in index.php in TaskFreak! 0.6.1 and earlier allows remote authenticated users to execute arbitrary SQL commands via the sContext parameter.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/4899">4899</ref><ref source="BID" url="http://www.securityfocus.com/bid/27257">27257</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28448">28448</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39645">taskfreak-index-sql-injection(39645)</ref></refs><vuln_soft><prod name="TaskFreak" vendor="TaskFreak"><vers num="0.6.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2008-01-16" name="CVE-2008-0271" published="2008-01-15" seq="2008-0271" severity="Medium" type="CVE"><desc><descript source="cve">The editor deletion form in BUEditor 4.7.x before 4.7.x-1.0 and 5.x before 5.x-1.1, a module for Drupal, does not follow Drupal&apos;s Forms API submission model, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks and delete custom editor interfaces.</descript></desc><loss_types><int/></loss_types><range><network/><user_init/></range><refs><ref patch="1" source="" url="http://drupal.org/node/208534"></ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/28418">28418</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39614">drupal-bueditor-csrf(39614)</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0128">ADV-2008-0128</ref></refs><vuln_soft><prod name="BUEditor" vendor="Drupal"><vers num="4.7.x-1.0" prev="1"/><vers num="5.x-1.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2008-01-16" name="CVE-2008-0272" published="2008-01-15" seq="2008-0272" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site request forgery (CSRF) vulnerability in the aggregator module in Drupal 4.7.x before 4.7.11 and 5.x before 5.6 allows remote attackers to delete items from a feed as privileged users.</descript></desc><loss_types><int/></loss_types><range><network/><user_init/></range><refs><ref source="" url="http://drupal.org/node/208562"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/27238">27238</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28422">28422</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39617">drupal-aggregator-csrf(39617)</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0127">ADV-2008-0127</ref></refs><vuln_soft><prod name="Drupal" vendor="Drupal"><vers num="4.4.1"/><vers num="4.4.2"/><vers num="4.4.3"/><vers num="4.5"/><vers num="4.5.1"/><vers num="4.5.2"/><vers num="4.5.3"/><vers num="4.5.4"/><vers num="4.5.5"/><vers num="4.5.6"/><vers num="4.5.7"/><vers num="4.5.8"/><vers num="4.6"/><vers num="4.6.1"/><vers num="4.6.10"/><vers num="4.6.11"/><vers num="4.6.2"/><vers num="4.6.3"/><vers num="4.6.4"/><vers num="4.6.5"/><vers num="4.6.6"/><vers num="4.6.7"/><vers num="4.6.8"/><vers num="4.6.9"/><vers num="4.7"/><vers num="4.7.1"/><vers num="4.7.10"/><vers num="4.7.2"/><vers num="4.7.3"/><vers num="4.7.4"/><vers num="4.7.5"/><vers num="4.7.6"/><vers num="4.7.7"/><vers num="4.7.8"/><vers num="4.7.9"/><vers num="4.0.0"/><vers num="4.1.0"/><vers num="4.2.0 RC"/><vers num="4.4"/><vers num="4.7 Rev 1.15"/><vers num="4.7 Rev 1.2"/><vers num="5.0"/><vers num="5.1"/><vers num="5.1 rev1.1"/><vers num="5.2"/><vers num="5.3"/><vers num="5.4"/><vers num="5.5."/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2008-01-16" name="CVE-2008-0273" published="2008-01-15" seq="2008-0273" severity="Medium" type="CVE"><desc><descript source="cve">Interpretation conflict in Drupal 4.7.x before 4.7.11 and 5.x before 5.6, when Internet Explorer 6 is used, allows remote attackers to conduct cross-site scripting (XSS) attacks via invalid UTF-8 byte sequences, which are not processed as UTF-8 by Drupal&apos;s HTML filtering, but are processed as UTF-8 by Internet Explorer, effectively removing characters from the document and defeating the HTML protection mechanism.</descript></desc><loss_types><int/></loss_types><range><network/><user_init/></range><refs><ref source="" url="http://drupal.org/node/208564"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/27238">27238</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/28422">28422</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39619">drupal-utf8-xss(39619)</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0127">ADV-2008-0127</ref></refs><vuln_soft><prod name="Drupal" vendor="Drupal"><vers num="4.4.1"/><vers num="4.4.2"/><vers num="4.4.3"/><vers num="4.5"/><vers num="4.5.1"/><vers num="4.5.2"/><vers num="4.5.3"/><vers num="4.5.4"/><vers num="4.5.5"/><vers num="4.5.6"/><vers num="4.5.7"/><vers num="4.5.8"/><vers num="4.6"/><vers num="4.6.1"/><vers num="4.6.10"/><vers num="4.6.11"/><vers num="4.6.2"/><vers num="4.6.3"/><vers num="4.6.4"/><vers num="4.6.5"/><vers num="4.6.6"/><vers num="4.6.7"/><vers num="4.6.8"/><vers num="4.6.9"/><vers num="4.7"/><vers num="4.7.1"/><vers num="4.7.10"/><vers num="4.7.2"/><vers num="4.7.3"/><vers num="4.7.4"/><vers num="4.7.5"/><vers num="4.7.6"/><vers num="4.7.7"/><vers num="4.7.8"/><vers num="4.7.9"/><vers num="4.0.0"/><vers num="4.1.0"/><vers num="4.2.0 RC"/><vers num="4.4"/><vers num="4.7 Rev 1.15"/><vers num="4.7 Rev 1.2"/><vers num="5.0"/><vers num="5.1"/><vers num="5.1 rev1.1"/><vers num="5.2"/><vers num="5.3"/><vers num="5.4"/><vers num="5.5."/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2008-01-16" name="CVE-2008-0274" published="2008-01-15" seq="2008-0274" severity="Low" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Drupal 4.7.x and 5.x, when certain .htaccess protections are disabled, allows remote attackers to inject arbitrary web script or HTML via crafted links involving theme .tpl.php files.</descript></desc><loss_types><int/></loss_types><range><network/><user_init/></range><refs><ref source="" url="http://drupal.org/node/208565"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/27238">27238</ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/28422">28422</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39605">drupal-theme-xss(39605)</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0127">ADV-2008-0127</ref></refs><vuln_soft><prod name="Drupal" vendor="Drupal"><vers num="4.7"/><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2008-01-16" name="CVE-2008-0275" published="2008-01-15" seq="2008-0275" severity="Medium" type="CVE"><desc><descript source="cve">The Atom 4.7 before 4.7.x-1.0 and 5.x before 5.x-1.0 module for Drupal does not properly manage permissions for node (1) titles, (2) teasers, and (3) bodies, which might allow remote attackers to gain access to syndicated content.</descript></desc><loss_types><conf/></loss_types><range><network/></range><refs><ref source="" url="http://drupal.org/node/208527"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39607">drupal-atom-security-bypass(39607)</ref></refs><vuln_soft><prod name="Atom Module" vendor="Drupal"><vers num="4.7" prev="1"/><vers num="5.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2008-01-16" name="CVE-2008-0276" published="2008-01-15" seq="2008-0276" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in the Devel module before 5.x-0.1 for Drupal allows remote attackers to inject arbitrary web script or HTML via a site variable, related to lack of escaping of the variable table.</descript></desc><loss_types><int/></loss_types><range><network/><user_init/></range><refs><ref source="" url="http://drupal.org/node/208524"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39606">drupal-devel-variable-xss(39606)</ref></refs><vuln_soft><prod name="Drupal" vendor="Drupal"><vers num="4.4.1"/><vers num="4.4.2"/><vers num="4.4.3"/><vers num="4.5"/><vers num="4.5.1"/><vers num="4.5.2"/><vers num="4.5.3"/><vers num="4.5.4"/><vers num="4.5.5"/><vers num="4.5.6"/><vers num="4.5.7"/><vers num="4.5.8"/><vers num="4.6"/><vers num="4.6.1"/><vers num="4.6.10"/><vers num="4.6.11"/><vers num="4.6.2"/><vers num="4.6.3"/><vers num="4.6.4"/><vers num="4.6.5"/><vers num="4.6.6"/><vers num="4.6.7"/><vers num="4.6.8"/><vers num="4.6.9"/><vers num="4.7"/><vers num="4.7.1"/><vers num="4.7.10"/><vers num="4.7.2"/><vers num="4.7.3"/><vers num="4.7.4"/><vers num="4.7.5"/><vers num="4.7.6"/><vers num="4.7.7"/><vers num="4.7.8"/><vers num="4.7.9"/><vers num="4.0.0"/><vers num="4.1.0"/><vers num="4.2.0 RC"/><vers num="4.4"/><vers num="4.7 Rev 1.15"/><vers num="4.7 Rev 1.2"/><vers num="5.0"/><vers num="5.1"/><vers num="5.1 rev1.1"/><vers num="5.2"/><vers num="5.3"/><vers num="5.4"/><vers num="5.5."/></prod></vuln_soft></entry><entry CVSS_base_score="8.5" CVSS_exploit_subscore="6.8" CVSS_impact_subscore="10.0" CVSS_score="8.5" CVSS_vector="(AV:N/AC:M/Au:S/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-01-16" name="CVE-2008-0277" published="2008-01-15" seq="2008-0277" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the Fileshare module for Drupal allows remote authenticated users with node-creation privileges to execute arbitrary code via unspecified vectors.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs><ref source="" url="http://drupal.org/node/208537"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39609">drupal-fileshare-code-execution(39609)</ref></refs><vuln_soft><prod name="Fileshare_Module" vendor="Drupal"><vers num="4.7.x"/><vers num="5.x"/></prod></vuln_soft></entry><entry CVSS_base_score="6.0" CVSS_exploit_subscore="6.8" CVSS_impact_subscore="6.4" CVSS_score="6.0" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-02-06" name="CVE-2008-0278" published="2008-01-15" seq="2008-0278" severity="Medium" type="CVE"><desc><descript source="cve">SQL injection vulnerability in index.php in X7 Chat 2.0.5 and possibly earlier allows remote attackers to execute arbitrary SQL commands via the day parameter in a sm_window action.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/4907">4907</ref><ref source="BID" url="http://www.securityfocus.com/bid/27277">27277</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39656">x7chatday-sql-injection(39656)</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28503">28503</ref></refs><vuln_soft><prod name="X7 Chat" vendor="X7 Group"><vers num="2.0.5" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-01-16" name="CVE-2008-0279" published="2008-01-15" seq="2008-0279" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in liretopic.php in Xforum 1.4 and possibly others allows remote attackers to execute arbitrary SQL commands via the topic parameter.  NOTE: the categorie parameter might also be affected.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/4908">4908</ref><ref source="BID" url="http://www.securityfocus.com/bid/27278">27278</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39654">xforum-liretopic-sql-injection(39654)</ref></refs><vuln_soft><prod name="Xforum" vendor="Xforum"><vers num="1.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-01-16" name="CVE-2008-0280" published="2008-01-15" seq="2008-0280" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in index.php in MTCMS 2.0 and possibly earlier versions allows remote attackers to execute arbitrary SQL commands via the (1) a or (2) cid parameter.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/486090/100/0/threaded">20080110 MTCMS &lt;=2.0 SQL Injection Vulnerbility</ref><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/4882">4882</ref><ref source="BID" url="http://www.securityfocus.com/bid/27224">27224</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39597">mtcms-a-sql-injection(39597)</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28428">28428</ref><ref source="SREASON" url="http://securityreason.com/securityalert/3544">3544</ref></refs><vuln_soft><prod name="MTCMS" vendor="MTCMS"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-01-16" name="CVE-2008-0281" published="2008-01-15" seq="2008-0281" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in liste.php in ID-Commerce 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the idFamille parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><range><network/></range><refs><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2008-January/059537.html">20080110 (( PoC)) ID-Commerce Security Advisory - SLR-2007-001 (( PoC))</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2008-January/059533.html">20080110 ID-Commerce Security Advisory - SLR-2007-001</ref><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2008-January/059538.html">20080110 ID-Commerce Security Advisory - SLR-2007-001</ref><ref source="BID" url="http://www.securityfocus.com/bid/27220">27220</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39594">idcommerce-liste-sql-injection(39594)</ref></refs><vuln_soft><prod name="ID-Commerce" vendor="ID-Commerce"><vers num="2.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-01-16" name="CVE-2008-0282" published="2008-01-15" seq="2008-0282" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in welcome/inscription.php in DomPHP 0.81 and earlier allows remote attackers to execute arbitrary SQL commands via the mail parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/4880">4880</ref><ref source="BID" url="http://www.securityfocus.com/bid/27212">27212</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28393">28393</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39593">domphp-inscription-sql-injection(39593)</ref></refs><vuln_soft><prod name="DomPHP" vendor="DomPHP"><vers num="0.81" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-01-16" name="CVE-2008-0283" published="2008-01-15" seq="2008-0283" severity="Medium" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in /aides/index.php in DomPHP 0.81 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the page parameter.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/4883">4883</ref><ref source="BID" url="http://www.securityfocus.com/bid/27226">27226</ref></refs><vuln_soft><prod name="DomPHP" vendor="DomPHP"><vers num="0.81" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2008-01-16" name="CVE-2008-0284" published="2008-01-15" seq="2008-0284" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in Simple Machines Forum (SMF) 1.1.4 and earlier allows remote attackers to inject arbitrary web script or HTML via (1) Itemid or (2) topic arguments.</descript></desc><loss_types><int/></loss_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/486074/100/0/threaded">20080110 Simple Machines Forum Cross-Site Scripting Vulnerabilities</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39585">simplemachinesforum-itemid-xss(39585)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/3540">3540</ref></refs><vuln_soft><prod name="Simple Machines SMF" vendor="Simple Machines"><vers num="1.1.4" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2008-01-16" name="CVE-2008-0285" published="2008-01-15" seq="2008-0285" severity="Medium" type="CVE"><desc><descript source="cve">ngIRCd 0.10.x before 0.10.4 and 0.11.0 before 0.11.0-pre2 allows remote attackers to cause a denial of service (crash) via crafted IRC PART message, which triggers an invalid dereference.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref source="" url="http://arthur.barton.de/cgi-bin/viewcvs.cgi/ngircd/ngircd/src/ngircd/irc-channel.c?r1=1.40&amp;r2=1.41&amp;diff_format=h"></ref><ref source="" url="http://bugs.gentoo.org/show_bug.cgi?id=204834"></ref><ref source="" url="http://ngircd.barton.de/doc/ChangeLog"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/28425">28425</ref><ref source="BID" url="http://www.securityfocus.com/bid/27318">27318</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200801-13.xml">GLSA-200801-13</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28673">28673</ref></refs><vuln_soft><prod name="ngIRCd" vendor="ngIRCd"><vers num="0.10.3" prev="1"/><vers num="0.11.0-pre1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-01-16" name="CVE-2008-0286" published="2008-01-15" seq="2008-0286" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in admin/login.php in Article Dashboard allows remote attackers to execute arbitrary SQL commands via the (1) user or (2) password fields.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/486323/100/0/threaded">20080115 Article DashBoard all version SQL Injection Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/27286">27286</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39657">articledashboard-login-sql-injection(39657)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/486646/100/0/threaded">20080116 Re: Article DashBoard all version SQL Injection Vulnerability</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28495">28495</ref><ref source="SREASON" url="http://securityreason.com/securityalert/3546">3546</ref></refs><vuln_soft><prod name="Article Dashboard" vendor="Article Dashboard"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-01-21" name="CVE-2008-0287" published="2008-01-15" seq="2008-0287" severity="Medium" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in VisionBurst vcart 3.3.2 allows remote attackers to execute arbitrary PHP code via a URL in the abs_path parameter to (1) index.php and (2) checkout.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/4889">4889</ref><ref source="BID" url="http://www.securityfocus.com/bid/27231">27231</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28424">28424</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39616">vcart-checkout-index-file-include(39616)</ref></refs><vuln_soft><prod name="vcart" vendor="VisionBurst"><vers num="3.3.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-01-16" name="CVE-2008-0288" published="2008-01-15" seq="2008-0288" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in ImageAlbum 2.0.0b2 allow remote attackers to execute arbitrary SQL commands via the id, which is not properly handled in (1) classes/IADomain.php, (2) classes/IACollection.php, and (3) classes/IAUser.php, as demonstrated via the id parameter in a collection.imageview action.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/486162/100/0/threaded">20080111 ImageAlbum Remote SQL Injection Vulnerabilities</ref><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/4895">4895</ref><ref source="BID" url="http://www.securityfocus.com/bid/27240">27240</ref><ref source="SREASON" url="http://securityreason.com/securityalert/3548">3548</ref></refs><vuln_soft><prod name="ImageAlbum" vendor="ImageAlbum"><vers num="2.0.0b2"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-01-23" name="CVE-2008-0289" published="2008-01-15" seq="2008-0289" severity="Medium" type="CVE"><desc><descript source="cve">PHP remote file inclusion vulnerability in view_func.php in Member Area System (MAS) 1.7 and possibly others allows remote attackers to execute arbitrary PHP code via a URL in the i parameter.  NOTE: a second vector might exist via the l parameter.  NOTE: as of 20080118, the vendor has disputed the set of affected versions, stating that the issue &quot;is already fixed, for almost a year.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/486172/100/0/threaded">20080111 Member Area System (MAS) Remote File Include Vulnerability (view_func.php)</ref><ref source="BID" url="http://www.securityfocus.com/bid/27244">27244</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39611">mas-viewfunc-file-include(39611)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/486618/100/0/threaded">20080118 Re: Member Area System (MAS) Remote File Include Vulnerability (view_func.php)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/3547">3547</ref></refs><vuln_soft><prod name="Member Area System" vendor="Mansion Productions"><vers num="1.7" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-01-16" name="CVE-2008-0290" published="2008-01-15" seq="2008-0290" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in Digital Hive 2.0 RC2 and earlier allow (1) remote attackers to execute arbitrary SQL commands via the selectskin parameter to an unspecified program, or (2) remote authenticated administrators to execute arbitrary SQL commands via the user_id parameter in the gestion_membre.php page to base.php.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/4887">4887</ref><ref source="BID" url="http://www.securityfocus.com/bid/27232">27232</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39602">digitalhive-base-sql-injection(39602)</ref></refs><vuln_soft><prod name="DigitalHive" vendor="DigitalHive"><vers num="2.0 RC2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-01-17" name="CVE-2008-0291" published="2008-01-16" seq="2008-0291" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in showproduct.asp in RichStrong CMS allows remote attackers to execute arbitrary SQL commands via the cat parameter.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/4910">4910</ref><ref source="BID" url="http://www.securityfocus.com/bid/27281">27281</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/486402/100/0/threaded">20080116 RichStrong CMS (showproduct.asp?cat=) Remote SQL Injection Exploit</ref><ref source="BID" url="http://www.securityfocus.com/bid/27310">27310</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28449">28449</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39668">richstrongcms-showproduct-sql-injection(39668)</ref></refs><vuln_soft><prod name="RichStrong CMS" vendor="Hangzhou Rui-Qiang"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2008-01-17" name="CVE-2008-0292" published="2008-01-16" seq="2008-0292" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in photo_album.pl in Dansie Photo Album 1.0 allows remote attackers to inject arbitrary web script or HTML via the search parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript></desc><loss_types><int/></loss_types><range><network/><user_init/></range><refs><ref source="SECUNIA" url="http://secunia.com/advisories/28501">28501</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39664">dansiephotoalbum-photoalbum-xss(39664)</ref></refs><vuln_soft><prod name="Photo Album" vendor="Dansie"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-01-17" name="CVE-2008-0293" published="2008-01-16" seq="2008-0293" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in cron.php in FreeSeat before 1.1.5d, when format.php has certain modifications, allows remote attackers to bypass authentication and gain privileges via unspecified vectors related to the show_foot function.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><range><network/></range><refs><ref source="" url="http://sourceforge.net/project/shownotes.php?group_id=160239&amp;release_id=568374"></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28459">28459</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39648">freeseat-cron-security-bypass(39648)</ref></refs><vuln_soft><prod name="FreeSeat" vendor="FreeSeat"><vers num="1.1.5c" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2008-01-17" name="CVE-2008-0294" published="2008-01-16" seq="2008-0294" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the seat-locking implementation in FreeSeat before 1.1.5d allows attackers to book a seat more than once via unspecified vectors.</descript></desc><loss_types><int/></loss_types><range><network/></range><refs><ref source="" url="http://sourceforge.net/project/shownotes.php?release_id=568374&amp;group_id=160239"></ref><ref source="BID" url="http://www.securityfocus.com/bid/27270">27270</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28459">28459</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39647">freeseat-seatlocking-security-bypass(39647)</ref></refs><vuln_soft><prod name="FreeSeat" vendor="FreeSeat"><vers num="1.1.5c" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="8.5" CVSS_exploit_subscore="6.8" CVSS_impact_subscore="10.0" CVSS_score="8.5" CVSS_vector="(AV:N/AC:M/Au:S/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-01-17" name="CVE-2008-0295" published="2008-01-16" seq="2008-0295" severity="High" type="CVE"><desc><descript source="cve">Heap-based buffer overflow in modules/access/rtsp/real_sdpplin.c in the Xine library, as used in VideoLAN VLC Media Player 0.8.6d and earlier, allows user-assisted remote attackers to cause a denial of service (crash) or execute arbitrary code via long Session Description Protocol (SDP) data.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref source="" url="http://aluigi.altervista.org/adv/vlcxhof-adv.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/27221">27221</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0105">ADV-2008-0105</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28383">28383</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200803-13.xml">GLSA-200803-13</ref><ref source="SECUNIA" url="http://secunia.com/advisories/29284">29284</ref><ref source="DEBIAN" url="http://www.debian.org/security/2008/dsa-1543">DSA-1543</ref><ref source="SECUNIA" url="http://secunia.com/advisories/29766">29766</ref></refs><vuln_soft><prod name="VLC Media Player" vendor="VideoLAN"><vers num="0.8.6d" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-01-17" name="CVE-2008-0296" published="2008-01-16" seq="2008-0296" severity="High" type="CVE"><desc><descript source="cve">Heap-based buffer overflow in the libaccess_realrtsp plugin in VideoLAN VLC Media Player 0.8.6d and earlier on Windows might allow remote RTSP servers to cause a denial of service (application crash) or execute arbitrary code via a long string.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref source="" url="http://aluigi.altervista.org/adv/vlcxhof-adv.txt"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0105">ADV-2008-0105</ref><ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200803-13.xml">GLSA-200803-13</ref><ref source="SECUNIA" url="http://secunia.com/advisories/29284">29284</ref><ref source="DEBIAN" url="http://www.debian.org/security/2008/dsa-1543">DSA-1543</ref><ref source="SECUNIA" url="http://secunia.com/advisories/29766">29766</ref></refs><vuln_soft><prod name="VLC Media Player" vendor="VideoLAN"><vers num="0.8.6d" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2008-01-17" name="CVE-2008-0297" published="2008-01-16" seq="2008-0297" severity="Medium" type="CVE"><desc><descript source="cve">PhotoKorn allows remote attackers to obtain database credentials via a direct request to update/update3.php, which includes the credentials in its output.</descript></desc><loss_types><conf/></loss_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/4897">4897</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39652">photokorn-update3-information-disclosure(39652)</ref></refs><vuln_soft><prod name="PhotoKorn" vendor="Keil Software"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2008-01-17" name="CVE-2008-0298" published="2008-01-16" seq="2008-0298" severity="Medium" type="CVE"><desc><descript source="cve">KHTML WebKit as used in Apple Safari 2.x allows remote attackers to cause a denial of service (browser crash) via a crafted web page, possibly involving a STYLE attribute of a DIV element.</descript></desc><loss_types><avail/></loss_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/486202/100/0/threaded">20080112 Safari 2 Denial of Service</ref><ref source="" url="http://www.s21sec.com/avisos/s21sec-039-en.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/27261">27261</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/39635">safari-khtml-webkit-dos(39635)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/3549">3549</ref></refs><vuln_soft><prod name="Safari" vendor="Apple"><vers num="2.0"/><vers num="2.0.1"/><vers num="2.0.2"/><vers num="2.0.3"/><vers num="2.0.4"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2008-01-17" name="CVE-2008-0299" published="2008-01-16" seq="2008-0299" severity="Medium" type="CVE"><desc><descript source="cve">common.py in Paramiko 1.7.1 and earlier, when using threads or forked processes, does not properly use RandomPool, which allows one session to obtain sensitive information from another session by predicting the state of the pool.</descript></desc><loss_types><conf/></loss_types><range><network/></range><refs><ref source="" url="http://people.debian.org/~nion/nmu-diff/paramiko-1.6.4-1_1.6.4-1.1.patch"></ref><ref source="" url="https://bugzilla.redhat.com/show_bug.cgi?id=428727"></ref><ref source="" url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=460706"></ref><ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00529.html">FEDORA-2008-0644</ref><ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00594.html">FEDORA-2008-0722</ref><ref source="BID" url="http://www.securityfocus.com/bid/27307">27307</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28488">28488</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28510">28510</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39749">paramiko-randompool-info-disclosure(39749)</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200803-07.xml">GLSA-200803-07</ref><ref source="SECUNIA" url="http://secunia.com/advisories/29168">29168</ref></refs><vuln_soft><prod name="Paramiko" vendor="Python Software Foundation"><vers num="1.7.1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-03-12" name="CVE-2008-0300" published="2008-03-11" seq="2008-0300" severity="Medium" type="CVE"><desc><descript source="cve">mapFiler.php in Mapbender 2.4 to 2.4.4 allows remote attackers to execute arbitrary PHP code via PHP code sequences in the factor parameter, which are not properly handled when accessing a filename that contains those sequences.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/5232">5232</ref><ref source="" url="http://www.redteam-pentesting.de/advisories/rt-sa-2008-001.php"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/28195">28195</ref><ref source="SECUNIA" url="http://secunia.com/advisories/29329">29329</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/41131">mapbender-mapfilter-code-execution(41131)</ref></refs><vuln_soft><prod name="mapbender" vendor="mapbender"><vers num="2.4"/><vers num="2.4.1"/><vers num="2.4.2"/><vers num="2.4.3"/><vers num="2.4.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-03-19" name="CVE-2008-0301" published="2008-03-11" seq="2008-0301" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in Mapbender 2.4.4 allow remote attackers to execute arbitrary SQL commands via the gaz parameter to mod_gazetteer_edit.php and other unspecified vectors.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/489383/100/0/threaded">20080311 Advisory: SQL-Injections in Mapbender</ref><ref source="" url="http://www.redteam-pentesting.de/advisories/rt-sa-2008-002.php"></ref><ref source="FULLDISC" url="http://marc.info/?l=full-disclosure&amp;m=120523564611595&amp;w=2">20080311 Advisory: SQL-Injections in Mapbender</ref><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/5233">5233</ref><ref source="BID" url="http://www.securityfocus.com/bid/28193">28193</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/29329">29329</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/41139">mapbender-gaz-sql-injection(41139)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/3728">3728</ref></refs><vuln_soft><prod name="mapbender" vendor="mapbender"><vers num="2.4"/><vers num="2.4.1"/><vers num="2.4.2"/><vers num="2.4.3"/><vers num="2.4.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-01-17" name="CVE-2008-0302" published="2008-01-16" seq="2008-0302" severity="High" type="CVE"><desc><descript source="cve">Untrusted search path vulnerability in apt-listchanges.py in apt-listchanges before 2.82 allows local users to execute arbitrary code via a malicious apt-listchanges program in the current working directory.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><local/></range><refs><ref source="" url="http://packages.debian.org/changelogs/pool/main/a/apt-listchanges/apt-listchanges_2.82/changelog"></ref><ref source="" url="http://git.madism.org/?p=apt-listchanges.git;a=commitdiff;h=1bcfbf3dc55413bb83a1782dc9a54515a963fb32"></ref><ref source="DEBIAN" url="http://www.debian.org/security/2008/dsa-1465">DSA-1465</ref><ref source="BID" url="http://www.securityfocus.com/bid/27331">27331</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28513">28513</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-572-1">USN-572-1</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28574">28574</ref></refs><vuln_soft><prod name="apt-listchanges" vendor="Debian"><vers num="2.81" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_version="2.0" modified="2008-02-29" name="CVE-2008-0303" published="2008-02-28" seq="2008-0303" severity="Medium" type="CVE"><desc><descript source="cve">The FTP print feature in multiple Canon printers, including imageRUNNER and imagePRESS, allow remote attackers to use the server as an inadvertent proxy via a modified PORT command, aka FTP bounce.</descript></desc><loss_types><avail/><int/></loss_types><range><network/></range><refs><ref source="" url="http://itso.iu.edu/20080229_Canon_MFD_FTP_bounce_attack"></ref><ref source="" url="http://www.usa.canon.com/html/security/pdf/CVA-001.pdf"></ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/568073">VU#568073</ref><ref source="BID" url="http://www.securityfocus.com/bid/28042">28042</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1019528">1019528</ref></refs><vuln_soft><prod name="i-SENSYS" vendor="Canon"><vers num="LBP3360"/><vers num="LBP3460"/><vers num="LBP5360"/></prod><prod name="imageRUNNER" vendor="Canon"><vers num="105plus"/><vers num="2230"/><vers num="2270"/><vers num="2570C"/><vers num="2570Ci"/><vers num="2620"/><vers num="2870"/><vers num="3025"/><vers num="3025N"/><vers num="3035"/><vers num="3035N"/><vers num="3045"/><vers num="3045N"/><vers num="3170C"/><vers num="3170Ci"/><vers num="3180C"/><vers num="3180Ci"/><vers num="3530"/><vers num="3570"/><vers num="4570"/><vers num="5000i"/><vers num="5020"/><vers num="5055"/><vers num="5055N"/><vers num="5065"/><vers num="5065N"/><vers num="5075"/><vers num="5075N"/><vers num="5570"/><vers num="5800C"/><vers num="5800CN"/><vers num="6570"/><vers num="6800C"/><vers num="6800CN"/><vers num="7086"/><vers num="7095"/><vers num="7095P"/><vers num="7105"/><vers num="8070"/><vers num="8500"/><vers num="85plus"/><vers num="9070"/><vers num="C2380i"/><vers num="C2620"/><vers num="C2620N"/><vers num="C2880"/><vers num="C2880i"/><vers num="C3200"/><vers num="C3220"/><vers num="C3220N"/><vers num="C3380"/><vers num="C3380i"/><vers num="C4080i"/><vers num="C4580i"/><vers num="C5185i"/><vers num="C5870"/><vers num="C5870i"/><vers num="C5880"/><vers num="C5880i"/><vers num="C6800"/><vers num="C6870"/><vers num="C6870i"/><vers num="C6880"/><vers num="C6880i"/><vers num="CLC4040"/><vers num="CLC5151"/></prod><prod name="imagePRESS" vendor="Canon"><vers num="C1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-02-29" name="CVE-2008-0304" published="2008-02-29" seq="2008-0304" severity="High" type="CVE"><desc><descript source="cve">Heap-based buffer overflow in Mozilla Thunderbird before 2.0.0.12 and SeaMonkey before 1.1.8 might allow remote attackers to execute arbitrary code via a crafted external-body MIME type in an e-mail message, related to an incorrect memory allocation during message preview.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><range><network/></range><refs><ref source="IDEFENSE" url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=668">20080226 Mozilla Thunderbird MIME External-Body Heap Overflow Vulnerability</ref><ref source="" url="http://www.mozilla.org/security/announce/2008/mfsa2008-12.html"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/28012">28012</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1019504">1019504</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/29133">29133</ref><ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00905.html">FEDORA-2008-2060</ref><ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00946.html">FEDORA-2008-2118</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-582-1">USN-582-1</ref><ref source="SECUNIA" url="http://secunia.com/advisories/29167">29167</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDVSA-2008:062">MDVSA-2008:062</ref><ref source="SLACKWARE" url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2008&amp;m=slackware-security.445399">SSA:2008-061-01</ref><ref source="UBUNTU" url="http://www.ubuntu.com/usn/usn-582-2">USN-582-2</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/661651">VU#661651</ref><ref source="SECUNIA" url="http://secunia.com/advisories/29098">29098</ref><ref source="SECUNIA" url="http://secunia.com/advisories/29211">29211</ref><ref source="SECUNIA" url="http://secunia.com/advisories/30327">30327</ref></refs><vuln_soft><prod name="SeaMonkey" vendor="Mozilla"><vers num="1.1.7" prev="1"/></prod><prod name="Thunderbird" vendor="Mozilla"><vers num="2.0.0.9" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.9" CVSS_exploit_subscore="3.4" CVSS_impact_subscore="10.0" CVSS_score="6.9" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-03-12" name="CVE-2008-0306" published="2008-03-11" seq="2008-0306" severity="Medium" type="CVE"><desc><descript source="cve">sdbstarter in SAP MaxDB 7.6.0.37, and possibly other versions, allows local users to execute arbitrary commands by using unspecified environment variables to modify configuration settings.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><local/></range><refs><ref source="IDEFENSE" url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=670">20080310 SAP MaxDB sdbstarter Privilege Escalation Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/28185">28185</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1019570">1019570</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0844/references">ADV-2008-0844</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/29312">29312</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/41104">maxdb-sdbstarter-privilege-escalation(41104)</ref></refs><vuln_soft><prod name="MaxDB" vendor="SAP"><vers num="7.6.0.37"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-03-12" name="CVE-2008-0307" published="2008-03-11" seq="2008-0307" severity="High" type="CVE"><desc><descript source="cve">Integer signedness error in vserver in SAP MaxDB 7.6.0.37, and possibly other versions, allows remote attackers to execute arbitrary code via unknown vectors that trigger heap corruption.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref source="IDEFENSE" url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=669">20080310 SAP MaxDB Signedness Error Heap Corruption Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/28183">28183</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1019571">1019571</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0844/references">ADV-2008-0844</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/29312">29312</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/41107">maxdb-vserver-code-execution(41107)</ref></refs><vuln_soft><prod name="MaxDB" vendor="SAP"><vers num="7.6.0.37"/></prod></vuln_soft></entry><entry CVSS_base_score="7.1" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.9" CVSS_score="7.1" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2008-08-07" name="CVE-2008-0308" published="2008-02-28" seq="2008-0308" severity="High" type="CVE"><desc><descript source="cve">Symantec Decomposer, as used in certain Symantec antivirus products including Symantec Scan Engine 5.1.2 and other versions before 5.1.6.31, allows remote attackers to cause a denial of service (memory consumption) via a malformed RAR file to the Internet Content Adaptation Protocol (ICAP) port (1344/tcp).</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref source="IDEFENSE" url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=666">20080226 Symantec Scan Engine 5.1.2 RAR File Denial of Service Vulnerability</ref><ref source="" url="http://www.symantec.com/avcenter/security/Content/2008.02.27.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/27911">27911</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0680">ADV-2008-0680</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/29140">29140</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1019503">1019503</ref></refs><vuln_soft><prod name="Symantec AntiVirus_Filtering Domino MPE" vendor="Symantec"><vers edition="AIX" num="3.0.12" prev="1"/><vers edition="Linux" num="3.0.12" prev="1"/><vers edition="Solaris" num="3.0.12" prev="1"/></prod><prod name="Symantec AntiVirus Microsoft SharePoint" vendor="Symantec"><vers num="4.3.16.39" prev="1"/></prod><prod name="Symantec AntiVirus MS ISA" vendor="Symantec"><vers num="4.3.16.39" prev="1"/></prod><prod name="Symantec AntiVirus Messaging" vendor="Symantec"><vers num="4.3.16.39" prev="1"/></prod><prod name="Symantec Mail Security Exchange" vendor="Symantec"><vers num="4.6.5.12" prev="1"/><vers num="5.0.4.363" prev="1"/></prod><prod name="Symantec AntiVirus Scan Engine Caching" vendor="Symantec"><vers num="4.3.16.39" prev="1"/></prod><prod name="Scan Engine" vendor="Symantec"><vers num="5.1.4.24" prev="1"/></prod><prod name="Symantec AntiVirus Network Attached Storage" vendor="Symantec"><vers num="4.3.16.39" prev="1"/></prod><prod name="Symantec AntiVirus Scan Engine" vendor="Symantec"><vers num="4.3.16.39" prev="1"/></prod><prod name="Symantec AntiVirus Clearswift" vendor="Symantec"><vers num="4.3.16.39" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-08-07" name="CVE-2008-0309" published="2008-02-28" seq="2008-0309" severity="Medium" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in Symantec Decomposer, as used in certain Symantec antivirus products including Symantec Scan Engine 5.1.2 and other versions before 5.1.6.31, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a malformed RAR file to the Internet Content Adaptation Protocol (ICAP) port (1344/tcp).</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><range><network/><user_init/></range><refs><ref source="IDEFENSE" url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=667">20080226 Symantec Scan Engine 5.1.2 RAR File Buffer Overflow Vulnerability</ref><ref source="" url="http://www.symantec.com/avcenter/security/Content/2008.02.27.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/27913">27913</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0680">ADV-2008-0680</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/29140">29140</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1019503">1019503</ref></refs><vuln_soft><prod name="Symantec AntiVirus_Filtering Domino MPE" vendor="Symantec"><vers edition="AIX" num="3.0.12" prev="1"/><vers edition="Linux" num="3.0.12" prev="1"/><vers edition="Solaris" num="3.0.12" prev="1"/></prod><prod name="Symantec AntiVirus Scan Engine for Microsoft SharePoint" vendor="Symantec"><vers num="4.3.16.39" prev="1"/></prod><prod name="Symantec AntiVirus Scan Engine Caching" vendor="Symantec"><vers num="4.3.16.39" prev="1"/></prod><prod name="Scan Engine" vendor="Symantec"><vers num="5.1.4.24" prev="1"/></prod><prod name="Symantec Mail Security for Microsoft Exchange" vendor="Symantec"><vers num="4.6.5.12" prev="1"/><vers num="5.0.4.363" prev="1"/></prod><prod name="Symantec AntiVirus Scan Engine Clearswift" vendor="Symantec"><vers num="4.3.16.39" prev="1"/></prod><prod name="Symantec Antivirus Scan Engine for MS ISA" vendor="Symantec"><vers num="4.3.16.39" prev="1"/></prod><prod name="Symantec AntiVirus Scan Engine" vendor="Symantec"><vers num="4.3.16.39" prev="1"/></prod><prod name="Symantec AntiVirus Scan Engine Messaging" vendor="Symantec"><vers num="4.3.16.39" prev="1"/></prod><prod name="Symantec AntiVirus Network Attached Storage" vendor="Symantec"><vers num="4.3.16.39" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.9" CVSS_exploit_subscore="3.4" CVSS_impact_subscore="10.0" CVSS_score="6.9" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-04-08" name="CVE-2008-0310" published="2008-04-07" seq="2008-0310" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in pkgadd in SCO UnixWare 7.1.4 before p534589 allows local users to create or append to arbitrary files via &quot;..&quot; sequences in an unspecified environment variable, probably PKGINST.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><local/></range><refs><ref source="IDEFENSE" url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=676">20080403 SCO UnixWare pkgadd Directory Traversal Vulnerability</ref><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/5355">5355</ref><ref source="SCO" url="http://ftp.sco.com/pub/unixware7/714/security/p534589/p534589.txt">SCOSA-2008.1</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1019787">1019787</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/29657">29657</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/41759">sco-unixware-pkgadd-directory-traversal(41759)</ref></refs><vuln_soft><prod name="UnixWare" vendor="SCO"><vers num="7.1.4"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-04-07" name="CVE-2008-0311" published="2008-04-06" seq="2008-0311" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in the PGMWebHandler::parse_request function in the StarTeam Multicast Service component (STMulticastService) 6.4 in Borland CaliberRM 2006 allows remote attackers to execute arbitrary code via a large HTTP request.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs><ref source="IDEFENSE" url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=675">20080402 Borland CaliberRM StarTeam Multicast Service Buffer Overflow Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/28602">28602</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/1100">ADV-2008-1100</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1019786">1019786</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/29631">29631</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/41647">starteam-pgmwebhandlerparserequest-bo(41647)</ref></refs><vuln_soft><prod name="CaliberRM" vendor="Borland"><vers num="2006"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-04-08" name="CVE-2008-0312" published="2008-04-08" seq="2008-0312" severity="High" type="CVE"><desc><descript source="cve">Stack-based buffer overflow in the AutoFix Support Tool ActiveX control 2.7.0.1 in SYMADATA.DLL in multiple Symantec Norton products, including Norton 360 1.0, AntiVirus 2006 through 2008, Internet Security 2006 through 2008, and System Works 2006 through 2008, allows remote attackers to execute arbitrary code via a long argument to the GetEventLogInfo method.  NOTE: some of these details are obtained from third party information.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/><user_init/></range><refs><ref source="IDEFENSE" url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=677">20080402 Symantec Norton Internet Security 2008 ActiveX Control Buffer Overflow Vulnerability</ref><ref patch="1" source="" url="http://securityresponse.symantec.com/avcenter/security/Content/2008.04.02a.html"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/28507">28507</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/1077/references">ADV-2008-1077</ref><ref patch="1" source="SECTRACK" url="http://www.securitytracker.com/id?1019751">1019751</ref><ref patch="1" source="SECTRACK" url="http://www.securitytracker.com/id?1019752">1019752</ref><ref patch="1" source="SECTRACK" url="http://www.securitytracker.com/id?1019753">1019753</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/29660">29660</ref></refs><vuln_soft><prod name="Norton Internet Security" vendor="Symantec"><vers num="2006"/><vers num="2007"/><vers num="2008"/></prod><prod name="norton_360" vendor="Symantec"><vers num="1.0"/></prod><prod name="Norton System Works" vendor="Symantec"><vers num="2006"/><vers num="2007"/><vers num="2008"/></prod><prod name="Norton Antivirus" vendor="Symantec"><vers num="2006"/><vers num="2007"/><vers num="2008"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-04-08" name="CVE-2008-0313" published="2008-04-08" seq="2008-0313" severity="Medium" type="CVE"><desc><descript source="cve">The ActiveDataInfo.LaunchProcess method in the SymAData.ActiveDataInfo.1 ActiveX control 2.7.0.1 in SYMADATA.DLL in multiple Symantec Norton products including Norton 360 1.0, AntiVirus 2006 through 2008, Internet Security 2006 through 2008, and System Works 2006 through 2008, does not properly determine the location of the AutoFix Tool, which allows remote attackers to execute arbitrary code via a remote (1) WebDAV or (2) SMB share.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><range><network/><user_init/></range><refs><ref source="IDEFENSE" url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=678">20080402 Symantec Internet Security 2008 ActiveDataInfo.LaunchProcess Design Error Vulnerability</ref><ref source="" url="http://securityresponse.symantec.com/avcenter/security/Content/2008.04.02a.html"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/28509">28509</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/1077/references">ADV-2008-1077</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1019751">1019751</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1019752">1019752</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1019753">1019753</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/29660">29660</ref></refs><vuln_soft><prod name="Norton Internet Security" vendor="Symantec"><vers num="2006"/><vers num="2007"/><vers num="2008"/></prod><prod name="system_works" vendor="Symantec"><vers num="2006"/><vers num="2007"/><vers num="2008"/></prod><prod name="norton_360" vendor="Symantec"><vers num="1.0"/></prod><prod name="Norton Antivirus" vendor="Symantec"><vers num="2006"/><vers num="2007"/><vers num="2008"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-04-16" name="CVE-2008-0314" published="2008-04-16" seq="2008-0314" severity="High" type="CVE"><desc><descript source="cve">Heap-based buffer overflow in spin.c in libclamav in ClamAV 0.92.1 allows remote attackers to execute arbitrary code via a crafted PeSpin packed PE binary with a modified length value.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><range><network/></range><refs><ref source="IDEFENSE" url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=686">20080414 ClamAV libclamav PeSpin Heap Overflow Vulnerability</ref><ref source="" url="https://wwws.clamav.net/bugzilla/show_bug.cgi?id=876"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/1227/references">ADV-2008-1227</ref><ref source="" url="http://kolab.org/security/kolab-vendor-notice-20.txt"></ref><ref source="DEBIAN" url="http://www.debian.org/security/2008/dsa-1549">DSA-1549</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/858595">VU#858595</ref><ref source="SECUNIA" url="http://secunia.com/advisories/29863">29863</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/41823">clamav-spin-bo(41823)</ref><ref source="" url="http://svn.clamav.net/svn/clamav-devel/trunk/ChangeLog"></ref><ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2008-04/msg00009.html">SUSE-SA:2008:024</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1019851">1019851</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDVSA-2008:088">MDVSA-2008:088</ref><ref source="BID" url="http://www.securityfocus.com/bid/28784">28784</ref><ref source="SECUNIA" url="http://secunia.com/advisories/29891">29891</ref><ref source="SECUNIA" url="http://secunia.com/advisories/29886">29886</ref><ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2008-April/msg00576.html">FEDORA-2008-3358</ref><ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2008-April/msg00625.html">FEDORA-2008-3420</ref><ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2008-May/msg00249.html">FEDORA-2008-3900</ref><ref source="SECUNIA" url="http://secunia.com/advisories/29975">29975</ref><ref source="SECUNIA" url="http://secunia.com/advisories/30253">30253</ref><ref source="SECUNIA" url="http://secunia.com/advisories/30328">30328</ref></refs><vuln_soft><prod name="ClamAV" vendor="Clam Anti-Virus"><vers num="0.92.1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-02-26" name="CVE-2008-0318" published="2008-02-12" seq="2008-0318" severity="High" type="CVE"><desc><descript source="cve">Integer overflow in the cli_scanpe function in libclamav in ClamAV before 0.92.1, as used in clamd, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted Petite packed PE file, which triggers a heap-based buffer overflow.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs><ref source="IDEFENSE" url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=658">20080212 ClamAV libclamav PE File Integer Overflow Vulnerability</ref><ref patch="1" source="" url="http://sourceforge.net/project/shownotes.php?release_id=575703"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0503">ADV-2008-0503</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28907">28907</ref><ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00462.html">FEDORA-2008-1608</ref><ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00481.html">FEDORA-2008-1625</ref><ref source="BID" url="http://www.securityfocus.com/bid/27751">27751</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1019394">1019394</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28913">28913</ref><ref source="" url="http://support.novell.com/techcenter/psdb/512985d2cd3090bfb93dcb7b551179cf.html"></ref><ref source="" url="http://kolab.org/security/kolab-vendor-notice-19.txt"></ref><ref source="" url="http://bugs.gentoo.org/show_bug.cgi?id=209915"></ref><ref source="DEBIAN" url="http://www.debian.org/security/2008/dsa-1497">DSA-1497</ref><ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200802-09.xml">GLSA-200802-09</ref><ref source="SUSE" url="http://lists.opensuse.org/opensuse-security-announce/2008-02/msg00008.html">SUSE-SR:2008:004</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0606">ADV-2008-0606</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28949">28949</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/29001">29001</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/29026">29026</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/29060">29060</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/29048">29048</ref><ref source="" url="http://docs.info.apple.com/article.html?artnum=307562"></ref><ref source="APPLE" url="http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html">APPLE-SA-2008-03-18</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0924/references">ADV-2008-0924</ref><ref source="SECUNIA" url="http://secunia.com/advisories/29420">29420</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDVSA-2008:088">MDVSA-2008:088</ref></refs><vuln_soft><prod name="ClamAV" vendor="Clam Anti-Virus"><vers num="0.92" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-04-22" name="CVE-2008-0320" published="2008-04-17" seq="2008-0320" severity="High" type="CVE"><desc><descript source="cve">Heap-based buffer overflow in the OLE importer in OpenOffice.org before 2.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an OLE file with a crafted DocumentSummaryInformation stream.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/><user_init/></range><refs><ref source="" url="http://www.openoffice.org/security/bulletin.html"></ref><ref source="DEBIAN" url="http://www.debian.org/security/2008/dsa-1547">DSA-1547</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2008-0175.html">RHSA-2008:0175</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2008-0176.html">RHSA-2008:0176</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/1253/references">ADV-2008-1253</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/29864">29864</ref><ref source="IDEFENSE" url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=694">20080417 Multiple Vendor OpenOffice OLE DocumentSummaryInformation Heap Overflow Vulnerability</ref><ref source="" url="http://www.openoffice.org/security/cves/CVE-2008-0320.html"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/41860">openoffice-ole-bo(41860)</ref><ref source="FEDORA" url="https://www.redhat.com/archives/fedora-package-announce/2008-April/msg00448.html">FEDORA-2008-3251</ref><ref source="SECUNIA" url="http://secunia.com/advisories/29913">29913</ref><ref source="" url="http://www.openoffice.org/security/cves/CVE-2007-4770.html"></ref><ref source="" url="http://www.openoffice.org/security/cves/CVE-2007-5745.html"></ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDVSA-2008:090">MDVSA-2008:090</ref><ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-231642-1">231642</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2008_23_openoffice.html">SUSE-SA:2008:023</ref><ref source="BID" url="http://www.securityfocus.com/bid/28819">28819</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/1375/references">ADV-2008-1375</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1019890">1019890</ref><ref source="SECUNIA" url="http://secunia.com/advisories/29852">29852</ref><ref source="SECUNIA" url="http://secunia.com/advisories/29910">29910</ref><ref source="SECUNIA" url="http://secunia.com/advisories/29844">29844</ref><ref source="SECUNIA" url="http://secunia.com/advisories/29871">29871</ref><ref source="SECUNIA" url="http://secunia.com/advisories/29987">29987</ref><ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDVSA-2008:095">MDVSA-2008:095</ref></refs><vuln_soft><prod name="OpenOffice.org" vendor="OpenOffice"><vers num="2.0.3"/><vers num="2.1"/><vers num="2.2"/><vers num="2.2.1"/><vers num="2.3"/><vers num="2.3.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-05-13" name="CVE-2008-0322" published="2008-05-13" seq="2008-0322" severity="High" type="CVE"><desc><descript source="cve">The I2O Utility Filter driver (i2omgmt.sys) 5.1.2600.2180 for Microsoft Windows XP sets Everyone/Write permissions for the &quot;\\.\I2OExc&quot; device interface, which allows local users to gain privileges.  NOTE: this issue can be leveraged to overwrite arbitrary memory and execute code via an IOCTL call with a crafted DeviceObject pointer.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><local/></range><refs><ref patch="1" source="IDEFENSE" url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=699">20080512 Microsoft Windows I2O Filter Utility Driver (i2omgmt.sys) Local Privilege Escalation Vulnerability</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/29171">29171</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/1476/references">ADV-2008-1476</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/30203">30203</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1020006">1020006</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/42358">win-i2omgmt-code-execution(42358)</ref></refs><vuln_soft><prod name="windows-nt" vendor="Microsoft"><vers num="XP"/></prod></vuln_soft></entry><entry CVSS_base_score="4.9" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.9" CVSS_score="4.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2008-01-17" name="CVE-2008-0324" published="2008-01-16" seq="2008-0324" severity="Medium" type="CVE"><desc><descript source="cve">Cisco Systems VPN Client IPSec Driver (CVPNDRVA.sys) 5.0.02.0090 allows local users to cause a denial of service (crash) by calling the 0x80002038 IOCTL with a small size value, which triggers memory corruption.</descript></desc><loss_types><avail/></loss_types><range><local/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/4911">4911</ref><ref source="BID" url="http://www.securityfocus.com/bid/27289">27289</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39694">cisco-vpnclient-cvpndrva-dos(39694)</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0170">ADV-2008-0170</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1019240">1019240</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28472">28472</ref></refs><vuln_soft><prod name="VPN Client" vendor="Cisco"><vers edition="Windows" num="5.0.2.0090"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-01-18" name="CVE-2008-0325" published="2008-01-17" seq="2008-0325" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in show.php in FaScript FaPersian Petition allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/4916">4916</ref><ref source="BID" url="http://www.securityfocus.com/bid/27302">27302</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28522">28522</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39716">fascriptfapersian-show-sql-injection(39716)</ref></refs><vuln_soft><prod name="FaPersian Petition" vendor="FaScript"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-01-18" name="CVE-2008-0326" published="2008-01-17" seq="2008-0326" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in class/show.php in FaScript FaPersianHack 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter to show.php.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/4917">4917</ref><ref source="BID" url="http://www.securityfocus.com/bid/27302">27302</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28565">28565</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39717">fascriptfapersianhack-show-sql-injection(39717)</ref></refs><vuln_soft><prod name="FaPersianHack" vendor="FaScript"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-01-18" name="CVE-2008-0327" published="2008-01-17" seq="2008-0327" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in show.php in FaScript FaMp3 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/4914">4914</ref><ref source="BID" url="http://www.securityfocus.com/bid/27302">27302</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28566">28566</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39714">fascriptfamp3-show-sql-injection(39714)</ref></refs><vuln_soft><prod name="FaMp3" vendor="FaScript"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-01-18" name="CVE-2008-0328" published="2008-01-17" seq="2008-0328" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in page.php in FaScript FaName 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/4915">4915</ref><ref source="BID" url="http://www.securityfocus.com/bid/27303">27303</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28528">28528</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39715">fascriptfaname-page-sql-injection(39715)</ref></refs><vuln_soft><prod name="FaName" vendor="FaScript"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2008-01-18" name="CVE-2008-0329" published="2008-01-17" seq="2008-0329" severity="Medium" type="CVE"><desc><descript source="cve">LulieBlog 1.0.1 and 1.0.2 does not restrict access to (1) article_suppr.php, (2) comment_accepter.php, and (3) comment_refuser.php in Admin/, which allows remote attackers to accept comments, delete comments, and delete articles via the id parameter.</descript></desc><loss_types><int/></loss_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/4912">4912</ref><ref source="BID" url="http://www.securityfocus.com/bid/27290">27290</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28432">28432</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39669">lulieblog-admin-security-bypass(39669)</ref></refs><vuln_soft><prod name="LulieBlog" vendor="Julien_Plesniak"><vers num="1.0.1"/><vers num="1.0.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2008-01-23" name="CVE-2008-0330" published="2008-01-17" seq="2008-0330" severity="High" type="CVE"><desc><descript source="cve">Open System Consultants (OSC) Radiator before 4.0 allows remote attackers to cause a denial of service (daemon crash) via malformed RADIUS requests, as demonstrated by packets sent by nmap.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref source="" url="http://www.open.com.au/radiator/history.html"></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28463">28463</ref><ref source="BID" url="http://www.securityfocus.com/bid/27306">27306</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0598">ADV-2008-0598</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39730">radiator-radius-dos(39730)</ref></refs><vuln_soft><prod name="RADIUS_Server" vendor="Radiator"><vers num="3.17.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2008-01-18" name="CVE-2008-0331" published="2008-01-17" seq="2008-0331" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Funkwerk System Software before 7.4.1 PATCH 9 for certain Funkwerk Router / VPN devices allows remote attackers to cause a denial of service (panic and reboot) via unspecified DNS requests.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref source="" url="http://www.funkwerk-ec.com/portal/downloadcenter/dateien/x2300/r7401p09/readme_741p9_en.pdf"></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28085">28085</ref><ref source="BID" url="http://www.securityfocus.com/bid/27314">27314</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39731">x2300-dns-dos(39731)</ref></refs><vuln_soft><prod name="System Software" vendor="Funkwerk"><vers num="7.4.1 Patch 8" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2008-01-18" name="CVE-2008-0332" published="2008-01-17" seq="2008-0332" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in arias/help/effect.php in aria 0.99-6 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the page parameter.</descript></desc><loss_types><int/></loss_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/4920">4920</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/486406/100/0/threaded">20080116 [DSECRG-08-002] Local File Include in arias 0.99-6</ref><ref source="BID" url="http://www.securityfocus.com/bid/27311">27311</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39712">aria-effect-file-include(39712)</ref></refs><vuln_soft><prod name="Aria" vendor="Aria"><vers num="0.99-6"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2008-01-18" name="CVE-2008-0333" published="2008-01-17" seq="2008-0333" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in download_view_attachment.aspx in AfterLogic MailBee WebMail Pro 4.1 for ASP.NET allows remote attackers to read arbitrary files via a .. (dot dot) in the temp_filename parameter.</descript></desc><loss_types><int/></loss_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/4921">4921</ref><ref source="BID" url="http://www.securityfocus.com/bid/27312">27312</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28521">28521</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39724">mailbeewebmail-download-directory-traversal(39724)</ref></refs><vuln_soft><prod name="MailBee WebMail Pro" vendor="AfterLogic"><vers num="4.1"/></prod><prod name="ASP.NET" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2008-01-18" name="CVE-2008-0334" published="2008-01-17" seq="2008-0334" severity="Low" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in pm/language/spanish/preferences.php in PMachine Pro 2.4.1 allows remote attackers to inject arbitrary web script or HTML via the L_PREF_NAME[855] parameter.</descript></desc><loss_types><int/></loss_types><range><network/><user_init/></range><refs><ref source="" url="http://packetstormsecurity.org/0801-exploits/pMachinePro-241-xss.txt"></ref><ref source="BID" url="http://www.securityfocus.com/bid/27282">27282</ref></refs><vuln_soft><prod name="PMachine Pro" vendor="pMachine"><vers num="2.4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2008-01-18" name="CVE-2008-0335" published="2008-01-17" seq="2008-0335" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in BugTracker.NET before 2.7.2 allows remote attackers to inject arbitrary web script or HTML via an arbitrary custom text field.</descript></desc><loss_types><int/></loss_types><range><network/><user_init/></range><refs><ref patch="1" source="" url="http://sourceforge.net/project/shownotes.php?release_id=568160"></ref><ref source="" url="http://sourceforge.net/tracker/index.php?func=detail&amp;aid=1867089&amp;group_id=66812&amp;atid=515837"></ref><ref source="BID" url="http://www.securityfocus.com/bid/27275">27275</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28481">28481</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39650">bugtrackernet-bug-xss(39650)</ref></refs><vuln_soft><prod name="Bugtracker.NET" vendor="Bugtracker.NET"><vers num="2.7.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2008-01-18" name="CVE-2008-0336" published="2008-01-17" seq="2008-0336" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site request forgery (CSRF) vulnerabilities in BugTracker.NET before 2.7.2 allow remote attackers to delete arbitrary bugs and perform other administrative tasks via unspecified vectors, possibly related to delete_*.aspx pages, and massedit.aspx, subscribe.aspx, flag.aspx, and relationships.aspx.</descript></desc><loss_types><int/></loss_types><range><network/><user_init/></range><refs><ref patch="1" source="" url="http://sourceforge.net/project/shownotes.php?group_id=66812&amp;release_id=568160"></ref><ref source="" url="http://sourceforge.net/tracker/index.php?func=detail&amp;aid=1867089&amp;group_id=66812&amp;atid=515837"></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28481">28481</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39651">bugtrackernet-http-csrf(39651)</ref></refs><vuln_soft><prod name="Bugtracker.NET" vendor="Bugtracker.NET"><vers num="2.7.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-01-18" name="CVE-2008-0337" published="2008-01-17" seq="2008-0337" severity="High" type="CVE"><desc><descript source="cve">Heap-based buffer overflow in the _mwProcessReadSocket function in http.c in MiniWeb HTTP Server 0.8.19 allows remote attackers to execute arbitrary code via a long URI.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/4923">4923</ref><ref source="" url="http://www.bugtraq.ir/adv/miniweb_english.pdf"></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28512">28512</ref><ref source="BID" url="http://www.securityfocus.com/bid/27319">27319</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0176">ADV-2008-0176</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39718">miniweb-mwprocessreadsocket-bo(39718)</ref></refs><vuln_soft><prod name="MiniWeb HTTP Server" vendor="MiniWeb HTTP Server"><vers num="0.8.19"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2008-01-18" name="CVE-2008-0338" published="2008-01-17" seq="2008-0338" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in the mwGetLocalFileName function in http.c in MiniWeb HTTP Server 0.8.19 allows remote attackers to read arbitrary files and list arbitrary directories via a (1) .%2e (partially encoded dot dot) or (2) %2e%2e (encoded dot dot) in the URI.</descript></desc><loss_types><int/></loss_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/4923">4923</ref><ref source="" url="http://www.bugtraq.ir/adv/miniweb_english.pdf"></ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28512">28512</ref><ref source="BID" url="http://www.securityfocus.com/bid/27319">27319</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0176">ADV-2008-0176</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39713">miniweb-mwgetlocal-directory-traversal(39713)</ref></refs><vuln_soft><prod name="MiniWeb HTTP Server" vendor="MiniWeb HTTP Server"><vers num="0.8.19"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-01-18" name="CVE-2008-0339" published="2008-01-17" seq="2008-0339" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the XML DB component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.3 has unknown impact and remote attack vectors, aka DB01.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref patch="1" source="" url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2008.html"></ref><ref patch="1" source="HP" url="http://marc.info/?l=bugtraq&amp;m=120058413923005&amp;w=2">HPSBMA02133</ref><ref patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA08-017A.html">TA08-017A</ref><ref source="BID" url="http://www.securityfocus.com/bid/27229">27229</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0150">ADV-2008-0150</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1019218">1019218</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28518">28518</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0180">ADV-2008-0180</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28556">28556</ref></refs><vuln_soft><prod name="Oracle Database" vendor="Oracle"><vers num="10.1.0.5"/><vers num="10.2.0.3"/><vers num="9.2.0.8DV"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-01-18" name="CVE-2008-0340" published="2008-01-17" seq="2008-0340" severity="High" type="CVE"><desc><descript source="cve">Multiple unspecified vulnerabilities in Oracle Database 9.0.1.5 FIPS+, 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.3 have unknown impact and remote attack vectors, related to the (1) Advanced Queuing component (DB02) and (2) Oracle Spatial component (DB04).</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs><ref patch="1" source="" url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2008.html"></ref><ref source="HP" url="http://marc.info/?l=bugtraq&amp;m=120058413923005&amp;w=2">HPSBMA02133</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA08-017A.html">TA08-017A</ref><ref source="BID" url="http://www.securityfocus.com/bid/27229">27229</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0150">ADV-2008-0150</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1019218">1019218</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28518">28518</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0180">ADV-2008-0180</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28556">28556</ref></refs><vuln_soft><prod name="Database 10g" vendor="Oracle"><vers num="10.1.0.5"/></prod><prod name="E-Business Suite 11i" vendor="Oracle"><vers num="11.5.10"/><vers num="11.5.10_CU2"/><vers num="11.5.9"/></prod><prod name="Oracle 10g Database Release 2" vendor="Oracle"><vers num="10.2.0.2"/><vers num="10.2.0.3"/></prod><prod name="Oracle10g Application Server Release 2" vendor="Oracle"><vers num="10.1.2.0.2"/><vers num="10.1.2.1.0"/><vers num="10.1.2.2.0"/></prod><prod name="PeopleSoft Enterprise PeopleTools" vendor="Oracle"><vers num="8.47"/><vers num="8.48"/><vers num="8.49"/></prod><prod name="Application Server 9i Release 1" vendor="Oracle"><vers num="1.0.2.2"/></prod><prod name="Oracle 10g Application Server Release 3" vendor="Oracle"><vers num="10.1.3.0.0"/><vers num="10.1.3.1.0"/><vers num="10.1.3.3.0"/></prod><prod name="Database 11g" vendor="Oracle"><vers num="11.1.0.6"/></prod><prod name="Oracle10g Application Server" vendor="Oracle"><vers num="9.0.4.3"/></prod><prod name="Database 9i" vendor="Oracle"><vers num="9.0.1.5 FIPS+"/></prod><prod name="E-Business Suite 12" vendor="Oracle"><vers num="12.0.0"/><vers num="12.0.1"/><vers num="12.0.2"/><vers num="12.0.3"/></prod><prod name="Oracle 9i Database Release 2" vendor="Oracle"><vers num="9.2.0.8"/><vers num="9.2.0.8DV"/></prod><prod name="Collaboration Suite 10g" vendor="Oracle"><vers num="10.1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-01-18" name="CVE-2008-0341" published="2008-01-17" seq="2008-0341" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the Advanced Queuing component in Oracle Database 9.0.1.5 FIPS+ and 10.1.0.5 has unknown impact and remote attack vectors, aka DB03.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref patch="1" source="" url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2008.html"></ref><ref source="HP" url="http://marc.info/?l=bugtraq&amp;m=120058413923005&amp;w=2">HPSBMA02133</ref><ref patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA08-017A.html">TA08-017A</ref><ref source="BID" url="http://www.securityfocus.com/bid/27229">27229</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0150">ADV-2008-0150</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1019218">1019218</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28518">28518</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0180">ADV-2008-0180</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28556">28556</ref></refs><vuln_soft><prod name="Oracle Database" vendor="Oracle"><vers num="10.1.0.5"/><vers num="9.0.1.5 FIPS+"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-01-18" name="CVE-2008-0342" published="2008-01-17" seq="2008-0342" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the Upgrade/Downgrade component in Oracle Database 9.2.0.8, 10.1.0.5, and 10.2.0.3 has unknown impact and remote attack vectors, aka DB05.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref patch="1" source="" url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2008.html"></ref><ref patch="1" source="HP" url="http://marc.info/?l=bugtraq&amp;m=120058413923005&amp;w=2">HPSBMA02133</ref><ref patch="1" source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA08-017A.html">TA08-017A</ref><ref source="BID" url="http://www.securityfocus.com/bid/27229">27229</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0150">ADV-2008-0150</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1019218">1019218</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28518">28518</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0180">ADV-2008-0180</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28556">28556</ref></refs><vuln_soft><prod name="Oracle Database" vendor="Oracle"><vers num="10.1.0.5"/><vers num="10.2.0.3"/><vers num="9.2.0.8"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-01-18" name="CVE-2008-0343" published="2008-01-17" seq="2008-0343" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the Oracle Spatial component in Oracle Database 9.0.1.5 FIPS+, 9.2.0.8, 9.2.0.8DV, and 10.1.0.5 has unknown impact and remote attack vectors, aka DB06.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs><ref patch="1" source="" url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2008.html"></ref><ref source="HP" url="http://marc.info/?l=bugtraq&amp;m=120058413923005&amp;w=2">HPSBMA02133</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA08-017A.html">TA08-017A</ref><ref source="BID" url="http://www.securityfocus.com/bid/27229">27229</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0150">ADV-2008-0150</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1019218">1019218</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28518">28518</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0180">ADV-2008-0180</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28556">28556</ref></refs><vuln_soft><prod name="Database 10g" vendor="Oracle"><vers num="10.1.0.5"/></prod><prod name="E-Business Suite 11i" vendor="Oracle"><vers num="11.5.10"/><vers num="11.5.10_CU2"/><vers num="11.5.9"/></prod><prod name="Oracle 10g Database Release 2" vendor="Oracle"><vers num="10.2.0.2"/><vers num="10.2.0.3"/></prod><prod name="Oracle10g Application Server Release 2" vendor="Oracle"><vers num="10.1.2.0.2"/><vers num="10.1.2.1.0"/><vers num="10.1.2.2.0"/></prod><prod name="PeopleSoft Enterprise PeopleTools" vendor="Oracle"><vers num="8.47"/><vers num="8.48"/><vers num="8.49"/></prod><prod name="Application Server 9i Release 1" vendor="Oracle"><vers num="1.0.2.2"/></prod><prod name="Oracle 10g Application Server Release 3" vendor="Oracle"><vers num="10.1.3.0.0"/><vers num="10.1.3.1.0"/><vers num="10.1.3.3.0"/></prod><prod name="Database 11g" vendor="Oracle"><vers num="11.1.0.6"/></prod><prod name="Oracle10g Application Server" vendor="Oracle"><vers num="9.0.4.3"/></prod><prod name="Database 9i" vendor="Oracle"><vers num="9.0.1.5 FIPS+"/></prod><prod name="E-Business Suite 12" vendor="Oracle"><vers num="12.0.0"/><vers num="12.0.1"/><vers num="12.0.2"/><vers num="12.0.3"/></prod><prod name="Oracle 9i Database Release 2" vendor="Oracle"><vers num="9.2.0.8"/><vers num="9.2.0.8DV"/></prod><prod name="Collaboration Suite 10g" vendor="Oracle"><vers num="10.1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-01-18" name="CVE-2008-0344" published="2008-01-17" seq="2008-0344" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the Oracle Spatial component in Oracle Database 10.1.0.5 and 10.2.0.3 has unknown impact and remote attack vectors, aka DB07.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs><ref patch="1" source="" url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2008.html"></ref><ref source="HP" url="http://marc.info/?l=bugtraq&amp;m=120058413923005&amp;w=2">HPSBMA02133</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA08-017A.html">TA08-017A</ref><ref source="BID" url="http://www.securityfocus.com/bid/27229">27229</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0150">ADV-2008-0150</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1019218">1019218</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28518">28518</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0180">ADV-2008-0180</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28556">28556</ref></refs><vuln_soft><prod name="Database 10g" vendor="Oracle"><vers num="10.1.0.5"/></prod><prod name="E-Business Suite 11i" vendor="Oracle"><vers num="11.5.10"/><vers num="11.5.10_CU2"/><vers num="11.5.9"/></prod><prod name="Oracle 10g Database Release 2" vendor="Oracle"><vers num="10.2.0.2"/><vers num="10.2.0.3"/></prod><prod name="Oracle10g Application Server Release 2" vendor="Oracle"><vers num="10.1.2.0.2"/><vers num="10.1.2.1.0"/><vers num="10.1.2.2.0"/></prod><prod name="PeopleSoft Enterprise PeopleTools" vendor="Oracle"><vers num="8.47"/><vers num="8.48"/><vers num="8.49"/></prod><prod name="Application Server 9i Release 1" vendor="Oracle"><vers num="1.0.2.2"/></prod><prod name="Oracle 10g Application Server Release 3" vendor="Oracle"><vers num="10.1.3.0.0"/><vers num="10.1.3.1.0"/><vers num="10.1.3.3.0"/></prod><prod name="Database 11g" vendor="Oracle"><vers num="11.1.0.6"/></prod><prod name="Oracle10g Application Server" vendor="Oracle"><vers num="9.0.4.3"/></prod><prod name="Database 9i" vendor="Oracle"><vers num="9.0.1.5 FIPS+"/></prod><prod name="E-Business Suite 12" vendor="Oracle"><vers num="12.0.0"/><vers num="12.0.1"/><vers num="12.0.2"/><vers num="12.0.3"/></prod><prod name="Oracle 9i Database Release 2" vendor="Oracle"><vers num="9.2.0.8"/><vers num="9.2.0.8DV"/></prod><prod name="Collaboration Suite 10g" vendor="Oracle"><vers num="10.1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-01-18" name="CVE-2008-0345" published="2008-01-17" seq="2008-0345" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the Core RDBMS component in Oracle Database 11.1.0.6 has unknown impact and remote attack vectors, aka DB08.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs><ref patch="1" source="" url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2008.html"></ref><ref source="HP" url="http://marc.info/?l=bugtraq&amp;m=120058413923005&amp;w=2">HPSBMA02133</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA08-017A.html">TA08-017A</ref><ref source="BID" url="http://www.securityfocus.com/bid/27229">27229</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0150">ADV-2008-0150</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1019218">1019218</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28518">28518</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0180">ADV-2008-0180</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28556">28556</ref></refs><vuln_soft><prod name="Database 10g" vendor="Oracle"><vers num="10.1.0.5"/></prod><prod name="E-Business Suite 11i" vendor="Oracle"><vers num="11.5.10"/><vers num="11.5.10_CU2"/><vers num="11.5.9"/></prod><prod name="Oracle 10g Database Release 2" vendor="Oracle"><vers num="10.2.0.2"/><vers num="10.2.0.3"/></prod><prod name="Oracle10g Application Server Release 2" vendor="Oracle"><vers num="10.1.2.0.2"/><vers num="10.1.2.1.0"/><vers num="10.1.2.2.0"/></prod><prod name="PeopleSoft Enterprise PeopleTools" vendor="Oracle"><vers num="8.47"/><vers num="8.48"/><vers num="8.49"/></prod><prod name="Application Server 9i Release 1" vendor="Oracle"><vers num="1.0.2.2"/></prod><prod name="Oracle 10g Application Server Release 3" vendor="Oracle"><vers num="10.1.3.0.0"/><vers num="10.1.3.1.0"/><vers num="10.1.3.3.0"/></prod><prod name="Database 11g" vendor="Oracle"><vers num="11.1.0.6"/></prod><prod name="Oracle10g Application Server" vendor="Oracle"><vers num="9.0.4.3"/></prod><prod name="Database 9i" vendor="Oracle"><vers num="9.0.1.5 FIPS+"/></prod><prod name="E-Business Suite 12" vendor="Oracle"><vers num="12.0.0"/><vers num="12.0.1"/><vers num="12.0.2"/><vers num="12.0.3"/></prod><prod name="Oracle 9i Database Release 2" vendor="Oracle"><vers num="9.2.0.8"/><vers num="9.2.0.8DV"/></prod><prod name="Collaboration Suite 10g" vendor="Oracle"><vers num="10.1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-01-18" name="CVE-2008-0346" published="2008-01-17" seq="2008-0346" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the Oracle Jinitiator component in Oracle Application Server 1.3.1.27 and E-Business Suite 11.5.10.2 has unknown impact and remote attack vectors, aka AS01.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs><ref patch="1" source="" url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2008.html"></ref><ref source="HP" url="http://marc.info/?l=bugtraq&amp;m=120058413923005&amp;w=2">HPSBMA02133</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA08-017A.html">TA08-017A</ref><ref source="BID" url="http://www.securityfocus.com/bid/27229">27229</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0150">ADV-2008-0150</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1019218">1019218</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28518">28518</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0180">ADV-2008-0180</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28556">28556</ref></refs><vuln_soft><prod name="Database 10g" vendor="Oracle"><vers num="10.1.0.5"/></prod><prod name="E-Business Suite 11i" vendor="Oracle"><vers num="11.5.10"/><vers num="11.5.10_CU2"/><vers num="11.5.9"/></prod><prod name="Oracle 10g Database Release 2" vendor="Oracle"><vers num="10.2.0.2"/><vers num="10.2.0.3"/></prod><prod name="Oracle10g Application Server Release 2" vendor="Oracle"><vers num="10.1.2.0.2"/><vers num="10.1.2.1.0"/><vers num="10.1.2.2.0"/></prod><prod name="PeopleSoft Enterprise PeopleTools" vendor="Oracle"><vers num="8.47"/><vers num="8.48"/><vers num="8.49"/></prod><prod name="Application Server 9i Release 1" vendor="Oracle"><vers num="1.0.2.2"/></prod><prod name="Oracle 10g Application Server Release 3" vendor="Oracle"><vers num="10.1.3.0.0"/><vers num="10.1.3.1.0"/><vers num="10.1.3.3.0"/></prod><prod name="Database 11g" vendor="Oracle"><vers num="11.1.0.6"/></prod><prod name="Oracle10g Application Server" vendor="Oracle"><vers num="9.0.4.3"/></prod><prod name="Database 9i" vendor="Oracle"><vers num="9.0.1.5 FIPS+"/></prod><prod name="E-Business Suite 12" vendor="Oracle"><vers num="12.0.0"/><vers num="12.0.1"/><vers num="12.0.2"/><vers num="12.0.3"/></prod><prod name="Oracle 9i Database Release 2" vendor="Oracle"><vers num="9.2.0.8"/><vers num="9.2.0.8DV"/></prod><prod name="Collaboration Suite 10g" vendor="Oracle"><vers num="10.1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-02-14" name="CVE-2008-0347" published="2008-01-17" seq="2008-0347" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the Oracle Ultra Search component in Oracle Collaboration Suite 10.1.2; Database 9.2.0.8, 10.1.0.5, and 10.2.0.3; and Application Server 9.0.4.3 and 10.1.2.0.2; has unknown impact and local attack vectors, aka OCS01.  NOTE: Oracle has not disputed a reliable claim that this issue is related to WKSYS schema privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs><ref patch="1" source="" url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2008.html"></ref><ref source="HP" url="http://marc.info/?l=bugtraq&amp;m=120058413923005&amp;w=2">HPSBMA02133</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA08-017A.html">TA08-017A</ref><ref source="BID" url="http://www.securityfocus.com/bid/27229">27229</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0150">ADV-2008-0150</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1019218">1019218</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28518">28518</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0180">ADV-2008-0180</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28556">28556</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/487322/100/100/threaded">20080130 PeteFinnigan.com Limited advisory for Oracle January 2008 CPU</ref><ref source="" url="http://www.petefinnigan.com/Advisory_CPU_Jan_2008.htm"></ref></refs><vuln_soft><prod name="Database 10g" vendor="Oracle"><vers num="10.1.0.5"/></prod><prod name="E-Business Suite 11i" vendor="Oracle"><vers num="11.5.10"/><vers num="11.5.10_CU2"/><vers num="11.5.9"/></prod><prod name="Oracle 10g Database Release 2" vendor="Oracle"><vers num="10.2.0.2"/><vers num="10.2.0.3"/></prod><prod name="Application Server 9i" vendor="Oracle"><vers num="10.1.2.0.2"/><vers num="9.0.4.3"/></prod><prod name="Oracle10g Application Server Release 2" vendor="Oracle"><vers num="10.1.2.0.2"/><vers num="10.1.2.1.0"/><vers num="10.1.2.2.0"/></prod><prod name="PeopleSoft Enterprise PeopleTools" vendor="Oracle"><vers num="8.47"/><vers num="8.48"/><vers num="8.49"/></prod><prod name="Application Server 9i Release 1" vendor="Oracle"><vers num="1.0.2.2"/></prod><prod name="Oracle 10g Application Server Release 3" vendor="Oracle"><vers num="10.1.3.0.0"/><vers num="10.1.3.1.0"/><vers num="10.1.3.3.0"/></prod><prod name="Database 11g" vendor="Oracle"><vers num="11.1.0.6"/></prod><prod name="Oracle10g Application Server" vendor="Oracle"><vers num="9.0.4.3"/></prod><prod name="Database 9i" vendor="Oracle"><vers num="9.0.1.5 FIPS+"/></prod><prod name="E-Business Suite 12" vendor="Oracle"><vers num="12.0.0"/><vers num="12.0.1"/><vers num="12.0.2"/><vers num="12.0.3"/></prod><prod name="Oracle 9i Database Release 2" vendor="Oracle"><vers num="9.2.0.8"/><vers num="9.2.0.8DV"/></prod><prod name="Collaboration Suite 10g" vendor="Oracle"><vers num="10.1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-01-18" name="CVE-2008-0348" published="2008-01-17" seq="2008-0348" severity="High" type="CVE"><desc><descript source="cve">Multiple unspecified vulnerabilities in the PeopleTools component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.22.18, 8.48.15, and 8.49.07 have unknown impact and remote attack vectors, aka (1) PSE01, (2) PSE03, and (3) PSE04.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs><ref patch="1" source="" url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2008.html"></ref><ref source="HP" url="http://marc.info/?l=bugtraq&amp;m=120058413923005&amp;w=2">HPSBMA02133</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA08-017A.html">TA08-017A</ref><ref source="BID" url="http://www.securityfocus.com/bid/27229">27229</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0150">ADV-2008-0150</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1019218">1019218</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28518">28518</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0180">ADV-2008-0180</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28556">28556</ref></refs><vuln_soft><prod name="Database 10g" vendor="Oracle"><vers num="10.1.0.5"/></prod><prod name="E-Business Suite 11i" vendor="Oracle"><vers num="11.5.10"/><vers num="11.5.10_CU2"/><vers num="11.5.9"/></prod><prod name="Oracle 10g Database Release 2" vendor="Oracle"><vers num="10.2.0.2"/><vers num="10.2.0.3"/></prod><prod name="Oracle10g Application Server Release 2" vendor="Oracle"><vers num="10.1.2.0.2"/><vers num="10.1.2.1.0"/><vers num="10.1.2.2.0"/></prod><prod name="PeopleSoft Enterprise PeopleTools" vendor="Oracle"><vers num="8.47"/><vers num="8.48"/><vers num="8.49"/></prod><prod name="Application Server 9i Release 1" vendor="Oracle"><vers num="1.0.2.2"/></prod><prod name="Oracle 10g Application Server Release 3" vendor="Oracle"><vers num="10.1.3.0.0"/><vers num="10.1.3.1.0"/><vers num="10.1.3.3.0"/></prod><prod name="Database 11g" vendor="Oracle"><vers num="11.1.0.6"/></prod><prod name="Oracle10g Application Server" vendor="Oracle"><vers num="9.0.4.3"/></prod><prod name="Database 9i" vendor="Oracle"><vers num="9.0.1.5 FIPS+"/></prod><prod name="E-Business Suite 12" vendor="Oracle"><vers num="12.0.0"/><vers num="12.0.1"/><vers num="12.0.2"/><vers num="12.0.3"/></prod><prod name="Oracle 9i Database Release 2" vendor="Oracle"><vers num="9.2.0.8"/><vers num="9.2.0.8DV"/></prod><prod name="Collaboration Suite 10g" vendor="Oracle"><vers num="10.1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-01-18" name="CVE-2008-0349" published="2008-01-17" seq="2008-0349" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in the PeopleTools component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.48.15 and 8.49.07 has unknown impact and remote attack vectors, aka PSE02.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs><ref patch="1" source="" url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2008.html"></ref><ref source="HP" url="http://marc.info/?l=bugtraq&amp;m=120058413923005&amp;w=2">HPSBMA02133</ref><ref source="CERT" url="http://www.us-cert.gov/cas/techalerts/TA08-017A.html">TA08-017A</ref><ref source="BID" url="http://www.securityfocus.com/bid/27229">27229</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0150">ADV-2008-0150</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1019218">1019218</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28518">28518</ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0180">ADV-2008-0180</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28556">28556</ref></refs><vuln_soft><prod name="Database 10g" vendor="Oracle"><vers num="10.1.0.5"/></prod><prod name="E-Business Suite 11i" vendor="Oracle"><vers num="11.5.10"/><vers num="11.5.10_CU2"/><vers num="11.5.9"/></prod><prod name="Oracle 10g Database Release 2" vendor="Oracle"><vers num="10.2.0.2"/><vers num="10.2.0.3"/></prod><prod name="Oracle10g Application Server Release 2" vendor="Oracle"><vers num="10.1.2.0.2"/><vers num="10.1.2.1.0"/><vers num="10.1.2.2.0"/></prod><prod name="PeopleSoft Enterprise PeopleTools" vendor="Oracle"><vers num="8.47"/><vers num="8.48"/><vers num="8.49"/></prod><prod name="Application Server 9i Release 1" vendor="Oracle"><vers num="1.0.2.2"/></prod><prod name="Oracle 10g Application Server Release 3" vendor="Oracle"><vers num="10.1.3.0.0"/><vers num="10.1.3.1.0"/><vers num="10.1.3.3.0"/></prod><prod name="Database 11g" vendor="Oracle"><vers num="11.1.0.6"/></prod><prod name="Oracle10g Application Server" vendor="Oracle"><vers num="9.0.4.3"/></prod><prod name="Database 9i" vendor="Oracle"><vers num="9.0.1.5 FIPS+"/></prod><prod name="E-Business Suite 12" vendor="Oracle"><vers num="12.0.0"/><vers num="12.0.1"/><vers num="12.0.2"/><vers num="12.0.3"/></prod><prod name="Oracle 9i Database Release 2" vendor="Oracle"><vers num="9.2.0.8"/><vers num="9.2.0.8DV"/></prod><prod name="Collaboration Suite 10g" vendor="Oracle"><vers num="10.1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-01-18" name="CVE-2008-0350" published="2008-01-17" seq="2008-0350" severity="High" type="CVE"><desc><descript source="cve">admin/index.php in Evilsentinel 1.0.9 and earlier sends a redirect to the web browser but does not exit, which allows remote attackers to gain administrative privileges and make arbitrary configuration changes.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/4884">4884</ref><ref source="" url="http://evilsentinel.altervista.org/forum/index.php?topic=49.0"></ref><ref patch="1" source="SECUNIA" url="http://secunia.com/advisories/28427">28427</ref></refs><vuln_soft><prod name="Evilsentinel" vendor="Evilsentinel"><vers num="1.0.9" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2008-01-18" name="CVE-2008-0351" published="2008-01-17" seq="2008-0351" severity="Medium" type="CVE"><desc><descript source="cve">admin/config.php in Evilsentinel 1.0.9 and earlier allows remote attackers to bypass the CAPTCHA test by omitting the es_security_captcha parameter and not invoking captcha.php.</descript></desc><loss_types><conf/></loss_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/4884">4884</ref></refs><vuln_soft><prod name="Evilsentinel" vendor="Evilsentinel"><vers num="1.0.9" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2008-01-18" name="CVE-2008-0352" published="2008-01-17" seq="2008-0352" severity="High" type="CVE"><desc><descript source="cve">The Linux kernel 2.6.20 through 2.6.21.1 allows remote attackers to cause a denial of service (panic) via a certain IPv6 packet, possibly involving the Jumbo Payload hop-by-hop option (jumbogram).</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/4893">4893</ref><ref source="" url="http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.21.2"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39643">linux-kernel-ipv6-jumbogram-dos(39643)</ref><ref source="" url="http://bugzilla.kernel.org/show_bug.cgi?id=8450"></ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.6.2"/><vers num="2.6.2 rc1"/><vers num="2.6.2 rc2"/><vers num="2.6.2 rc3"/><vers num="2.6.20"/><vers num="2.6.20.1"/><vers num="2.6.20.10"/><vers num="2.6.20.11"/><vers num="2.6.20.12"/><vers num="2.6.20.13"/><vers num="2.6.20.14"/><vers num="2.6.20.15"/><vers num="2.6.20.2"/><vers num="2.6.20.3"/><vers num="2.6.20.4"/><vers num="2.6.20.5"/><vers num="2.6.20.6"/><vers num="2.6.20.7"/><vers num="2.6.20.8"/><vers num="2.6.20.9"/><vers num="2.6.20_rc2"/><vers num="2.6.21"/><vers num="2.6.21 git1"/><vers num="2.6.21 git2"/><vers num="2.6.21 git3"/><vers num="2.6.21 git4"/><vers num="2.6.21 git5"/><vers num="2.6.21 git6"/><vers num="2.6.21 git7"/><vers num="2.6.21.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-01-21" name="CVE-2008-0353" published="2008-01-18" seq="2008-0353" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in visualizza_tabelle.php in php-residence 0.7.2 and 1.0 allows remote attackers to execute arbitrary SQL commands via the cognome_cerca parameter.  NOTE: some of these details are obtained from third party information.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/4925">4925</ref><ref source="BID" url="http://www.securityfocus.com/bid/27320">27320</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28516">28516</ref></refs><vuln_soft><prod name="Php-residence" vendor="Php-residence"><vers num="0.7.2"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2008-01-21" name="CVE-2008-0354" published="2008-01-18" seq="2008-0354" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in the chat client in IBM Lotus Sametime 7.5 and 7.5.1 allows user-assisted remote attackers to inject arbitrary web script or HTML via a crafted message, which triggers code execution after a mouseover event initiated by the victim.</descript></desc><loss_types><int/></loss_types><range><network/><user_init/></range><refs><ref source="" url="http://www-1.ibm.com/support/docview.wss?uid=swg21292938"></ref><ref source="BID" url="http://www.securityfocus.com/bid/27316">27316</ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0168">ADV-2008-0168</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1019224">1019224</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/27942">27942</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39726">sametime-client-mouseover-xss(39726)</ref></refs><vuln_soft><prod name="Lotus Sametime" vendor="IBM"><vers num="7.5"/><vers num="7.5.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-01-21" name="CVE-2008-0355" published="2008-01-18" seq="2008-0355" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in index.php in the forum module in PHPEcho CMS, probably 2.0-rc3 and earlier, allows remote attackers to execute arbitrary SQL commands via the id parameter in a section action, a different vector than CVE-2007-2866.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/4929">4929</ref><ref source="BID" url="http://www.securityfocus.com/bid/27326">27326</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39741">phpechocms-index-sql-injection(39741)</ref></refs><vuln_soft><prod name="PHPEcho CMS" vendor="PHPEcho CMS"><vers num="2.0-rc3" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-01-21" name="CVE-2008-0356" published="2008-01-18" seq="2008-0356" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the Independent Management Architecture (IMA) service in Citrix Presentation Server (MetaFrame Presentation Server) 4.5 and earlier, Access Essentials 2.0 and earlier, and Desktop Server 1.0 allows remote attackers to execute arbitrary code via an invalid size value in a packet to TCP port 2512 or 2513.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref patch="1" source="" url="http://support.citrix.com/article/CTX114487"></ref><ref source="" url="http://zerodayinitiative.com/advisories/ZDI-08-002.html"></ref><ref adv="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0172">ADV-2008-0172</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28508">28508</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/486585/100/0/threaded">20080117 ZDI-08-002: Citrix Presentation Server IMA Service Heap Overflow Vulnerability</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/412228">VU#412228</ref><ref source="BID" url="http://www.securityfocus.com/bid/27329">27329</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1019231">1019231</ref></refs><vuln_soft><prod name="Access Essentials" vendor="Citrix"><vers num="2.0" prev="1"/></prod><prod name="MetaFrame Presentation Server" vendor="Citrix"><vers num="4.5" prev="1"/></prod><prod name="Desktop Server" vendor="Citrix"><vers num="1.0"/></prod><prod name="Independent Management Architecture" vendor="Citrix"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2008-01-21" name="CVE-2008-0357" published="2008-01-18" seq="2008-0357" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in pages/upload.php in Galaxyscripts Mini File Host 1.2.1 and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the language parameter.</descript></desc><loss_types><conf/></loss_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/4930">4930</ref><ref source="BID" url="http://www.securityfocus.com/bid/27327">27327</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28504">28504</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39799">minifilehost-uploadphp-file-include(39799)</ref></refs><vuln_soft><prod name="Mini File Host" vendor="Galaxyscripts"><vers num="1.2.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-01-21" name="CVE-2008-0358" published="2008-01-18" seq="2008-0358" severity="Medium" type="CVE"><desc><descript source="cve">SQL injection vulnerability in index.php in Pixelpost 1.7 allows remote attackers to execute arbitrary SQL commands via the parent_id parameter.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/4924">4924</ref><ref patch="1" source="" url="http://www.pixelpost.org/forum/showthread.php?t=7716"></ref><ref source="BID" url="http://www.securityfocus.com/bid/27242">27242</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28499">28499</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1019238">1019238</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39721">pixelpost-indexphp-sql-injection(39721)</ref></refs><vuln_soft><prod name="Pixelpost" vendor="Pixelpost"><vers num="1.7"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2008-01-21" name="CVE-2008-0359" published="2008-01-18" seq="2008-0359" severity="Medium" type="CVE"><desc><descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in BLOG:CMS 4.2.1b allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) admin.php or (2) index.php in photo/.</descript></desc><loss_types><int/></loss_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=120049816924383&amp;w=2">20080116 [DSECRG-08-003] blogcms 4.2.1b Multiple Security Vulnerabilities</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/4919">4919</ref><ref source="" url="http://blogcms.com/wiki/changelog"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/27317">27317</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28523">28523</ref></refs><vuln_soft><prod name="Blog CMS" vendor="Blog CMS"><vers num="4.2.1_c"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-01-21" name="CVE-2008-0360" published="2008-01-18" seq="2008-0360" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in BLOG:CMS 4.2.1b allow remote attackers to execute arbitrary SQL commands via (1) the blogid parameter to index.php, (2) the user parameter to action.php, or (3) the field parameter to admin/plugins/table/index.php.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=120049816924383&amp;w=2">20080116 [DSECRG-08-003] blogcms 4.2.1b Multiple Security Vulnerabilities</ref><ref source="MILW0RM" url="http://milw0rm.com/exploits/4919">4919</ref><ref source="" url="http://blogcms.com/wiki/changelog"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/27317">27317</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28523">28523</ref></refs><vuln_soft><prod name="Blog CMS" vendor="Blog CMS"><vers num="4.2.1_c"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2008-01-21" name="CVE-2008-0361" published="2008-01-18" seq="2008-0361" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in agregar_info.php in GradMan 0.1.3 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the tabla parameter.</descript></desc><loss_types><conf/></loss_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/486444/100/0/threaded">20080116 Gradman &lt;= 0.1.3 (agregar_info.php?tabla=) Local File Inclusion Exploit</ref><ref source="MILW0RM" url="http://www.milw0rm.com/exploits/4926">4926</ref><ref source="BID" url="http://www.securityfocus.com/bid/27324">27324</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/28520">28520</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39732">gradman-agregarinfo-file-include(39732)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/3552">3552</ref></refs><vuln_soft><prod name="GradMan" vendor="Instituto Politicnico Nacional"><vers num="0.1.3" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2008-01-21" name="CVE-2008-0362" published="2008-01-18" seq="2008-0362" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting (XSS) vulnerability in gallery.php in Clever Copy 3.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the album parameter.</descript></desc><loss_types><int/></loss_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/486492/100/0/threaded">20080117 Clever Copy &lt;=3.0 Multiple Remote Vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/27335">27335</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28560">28560</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39747">clevercopy-gallery-xss(39747)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/3553">3553</ref></refs><vuln_soft><prod name="Clever Copy" vendor="Clever Copy"><vers num="3.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-01-21" name="CVE-2008-0363" published="2008-01-18" seq="2008-0363" severity="High" type="CVE"><desc><descript source="cve">Multiple SQL injection vulnerabilities in Clever Copy 3.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) ID parameter to postcomment.php and the (2) album parameter to gallery.php.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/486492/100/0/threaded">20080117 Clever Copy &lt;=3.0 Multiple Remote Vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/27335">27335</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28560">28560</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39746">clevercopy-postcomment-sql-injection(39746)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/3553">3553</ref></refs><vuln_soft><prod name="Clever Copy" vendor="Clever Copy"><vers num="3.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2008-01-21" name="CVE-2008-0364" published="2008-01-18" seq="2008-0364" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in (1) BitTorrent 6.0 and earlier; and (2) uTorrent 1.7.5 and earlier, and 1.8-alpha-7834 and earlier in the 1.8.x series; on Windows allows remote attackers to cause a denial of service (application crash) via a long Unicode string representing a client version identifier.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/486426/100/0/threaded">20080116 Peers static overflow in BitTorrent 6.0 and uTorrent 1.7.5</ref><ref source="" url="http://aluigi.altervista.org/adv/ruttorrent-adv.txt"></ref><ref source="" url="http://aluigi.org/poc/ruttorrent.zip"></ref><ref source="" url="http://download.utorrent.com/1.7.6/utorrent-1.7.6.txt"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/27321">27321</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39719">bittorrent-peers-bo(39719)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39720">utorrent-peers-bo(39720)</ref><ref source="" url="http://forum.utorrent.com/viewtopic.php?id=29330"></ref><ref source="SECUNIA" url="http://secunia.com/advisories/28533">28533</ref><ref source="SECUNIA" url="http://secunia.com/advisories/28537">28537</ref><ref source="SREASON" url="http://securityreason.com/securityalert/3554">3554</ref></refs><vuln_soft><prod name="BitTorrent" vendor="BitTorrent"><vers num="6.0" prev="1"/></prod><prod name="uTorrent" vendor="uTorrent"><vers num="1.7.5" prev="1"/><vers num="1.8-alpha-7834"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-01-22" name="CVE-2008-0365" published="2008-01-18" seq="2008-0365" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in CORE FORCE before 0.95.172 allow local users to cause a denial of service (system crash) and possibly execute arbitrary code in the kernel context via crafted arguments to (1) IOCTL functions in the Firewall module or (2) SSDT hook handler functions in the Registry module.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><local/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/486513/100/0/threaded">20080117 CORE-2007-1119: CORE FORCE Kernel Buffer Overflow</ref><ref source="" url="http://www.coresecurity.com/?action=item&amp;id=2025"></ref><ref source="BID" url="http://www.securityfocus.com/bid/27341">27341</ref><ref source="" url="http://force.coresecurity.com/index.php?module=articles&amp;func=display&amp;aid=32"></ref><ref source="FRSIRT" url="http://www.frsirt.com/english/advisories/2008/0242">ADV-2008-0242</ref><ref source="SECTRACK" url="http://www.securitytracker.com/id?1019245">1019245</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/39758">coreforce-firewall-registry-bo(39758)</ref><ref source="SREASON" url="http://securityreason.com/securityalert/3555">3555</ref></refs><vuln_soft><prod name="CORE FORCE" vendor="Core Security Technologies"><vers num="0.95.167" p